Data Protection Addendum

    Effective Date: October 28, 2025

    1. Purpose & Scope

    This Data Protection Addendum ("DPA") supplements our Privacy Policy and Terms & Conditions. It applies to all personal data processed by 0x Agency LLC on behalf of clients and governs our compliance with data protection laws including GDPR, CCPA, and other applicable regulations.

    2. Definitions

    • Personal Data: Any information relating to an identified or identifiable individual;
    • Processing: Any operation performed on personal data (collection, storage, use, disclosure, etc.);
    • Data Controller: The entity determining purposes and means of processing (typically the Client);
    • Data Processor: The entity processing data on behalf of the Controller (0x Agency LLC);
    • Data Subject: The individual whose personal data is being processed;
    • Sub-processor: Third-party service provider engaged to process data.

    3. Data Processing Principles

    We process personal data in accordance with the following principles:

    • Lawfulness, Fairness, Transparency: Processing is legal, fair, and transparent;
    • Purpose Limitation: Data is collected for specified, legitimate purposes;
    • Data Minimization: Only necessary data is collected;
    • Accuracy: Data is kept accurate and up-to-date;
    • Storage Limitation: Data is retained only as long as necessary;
    • Integrity & Confidentiality: Appropriate security measures are in place;
    • Accountability: We can demonstrate compliance.

    4. Processor Obligations

    As a Data Processor, we commit to:

    • Process data only on documented instructions from the Client;
    • Ensure personnel processing data are bound by confidentiality;
    • Implement appropriate technical and organizational security measures;
    • Engage sub-processors only with prior authorization;
    • Assist with Data Subject requests and compliance obligations;
    • Delete or return data upon contract termination;
    • Provide information necessary to demonstrate compliance;
    • Notify the Client of any data breaches without undue delay.

    5. Controller Obligations

    As a Data Controller, the Client must:

    • Ensure they have a lawful basis for processing;
    • Provide clear instructions for data processing;
    • Obtain necessary consents from Data Subjects;
    • Implement their own security and compliance measures;
    • Respond to Data Subject requests as required;
    • Maintain records of processing activities;
    • Notify us of any changes affecting data protection requirements.

    6. Security Measures

    We implement industry-standard security measures including:

    • Encryption: Data encrypted in transit (TLS) and at rest (AES-256);
    • Access Controls: Role-based access with multi-factor authentication;
    • Network Security: Firewalls, intrusion detection, and regular security audits;
    • Physical Security: Data centers with restricted access and surveillance;
    • Incident Response: Documented breach notification procedures;
    • Regular Testing: Penetration testing and vulnerability assessments;
    • Employee Training: Ongoing security and privacy training for all staff.

    7. Sub-processors

    We engage the following categories of sub-processors:

    • Cloud Infrastructure: Hosting and computing services;
    • Authentication Services: Identity verification providers;
    • Payment Processing: Payment gateway and fraud prevention;
    • Communication Tools: Email and messaging platforms;
    • Analytics Services: Website and application analytics.

    A current list of sub-processors is available upon request. We will notify Clients of any changes at least 30 days in advance.

    8. International Data Transfers

    Data may be transferred to and processed in countries outside your jurisdiction. We ensure adequate protection through:

    • Standard Contractual Clauses (SCCs): EU-approved data transfer mechanisms;
    • Adequacy Decisions: Transfers to countries deemed adequate by relevant authorities;
    • Privacy Shield (where applicable): Compliance with recognized frameworks;
    • Data Localization: Option to store data in specific regions.

    9. Data Subject Rights

    We assist Clients in responding to Data Subject requests including:

    • Right of Access: Obtain confirmation and copy of personal data;
    • Right to Rectification: Correct inaccurate or incomplete data;
    • Right to Erasure: Delete data ("right to be forgotten");
    • Right to Restriction: Limit processing under certain conditions;
    • Right to Data Portability: Receive data in machine-readable format;
    • Right to Object: Object to certain types of processing;
    • Rights Related to Automated Decision-Making: Not be subject to solely automated decisions.

    Requests should be directed to the Data Controller (Client). We will assist within 30 days of receiving the request.

    10. Data Breach Notification

    In the event of a personal data breach, we will:

    • Notify the Client without undue delay (within 72 hours when possible);
    • Provide details of the breach, affected data, and potential consequences;
    • Describe measures taken to address the breach;
    • Recommend steps the Client should take;
    • Cooperate with investigations and regulatory inquiries.

    11. Audits & Inspections

    Clients have the right to:

    • Audit our compliance with this DPA (upon reasonable notice);
    • Request documentation demonstrating compliance;
    • Engage third-party auditors (subject to confidentiality agreements);
    • Review security certifications and audit reports.

    12. Data Retention & Deletion

    Upon termination or expiration of services:

    • We will delete or return all personal data within 90 days;
    • Clients may request earlier deletion;
    • Backup copies will be securely deleted within 180 days;
    • Data required for legal compliance may be retained as necessary;
    • Deletion will be certified upon request.

    13. Liability & Indemnification

    Each party is liable for damages caused by their breach of data protection obligations. We will indemnify Clients against claims arising from our failure to comply with this DPA, subject to reasonable limitations.

    14. Amendments

    This DPA may be amended to reflect changes in data protection laws or our processing activities. Material changes will be communicated at least 30 days in advance.

    15. Governing Law

    This DPA is governed by the same laws as our main Terms & Conditions (Wyoming, USA), except where data protection laws of another jurisdiction apply.

    16. Contact

    Data Protection Officer
    0x Agency LLC
    30 N Gould Street Ste 40042
    Sheridan, WY 82801 USA
    📧 privacy@0x.agency
    📧 dpo@0x.agency