Data Processing Agreement

Last updated: 27 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the Customer (the "Controller") and AxioVendo Ltd (the "Processor") and applies wherever AxioVendo processes personal data on the Customer's behalf under UK GDPR and the Data Protection Act 2018.

1. Roles

The Customer is the data controller of personal data contained in questionnaires, answers, evidence documents, and team member records. AxioVendo is the data processor and processes such data only on the Customer's documented instructions, as expressed through use of the service.

2. Processing details

ItemDescription
Subject matterCompletion of vendor assessment questionnaires
DurationTerm of the agreement plus 30-day deletion period
Nature and purposeStorage, extraction, suggestion of answers, workflow routing, approval tracking, export
Data categoriesBusiness contact details of team members (name, email, role); any personal data contained in customer documents. On the BYO plan, document content is not processed on AxioVendo infrastructure — only structured Q&A pairs, passage references, and workflow metadata.
Data subjectsCustomer's employees and, incidentally, individuals named in customer documents

3. Processor obligations

4. Sub-processors

The Controller authorises the sub-processors listed below. AxioVendo will give at least 30 days' notice of any addition or replacement, during which the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, storageEU (AWS eu-west-1)
VercelHostingEU-preferred compute
ResendEmail deliveryEU/US (SCCs)
StripePaymentsEU/US (SCCs)

On the free and PAYG plans, AxioVendo's AI provider also acts as a sub-processor for document content, under terms that prohibit training on customer data. On the BYO plan the Customer's own AI provider is engaged directly by the Customer and is not an AxioVendo sub-processor.

5. International transfers

Transfers outside the UK/EEA are made only under the UK IDTA or EU SCCs with the UK Addendum, or another lawful transfer mechanism.

6. Security measures

7. Breach notification and audits

AxioVendo will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data, providing the nature of the breach, likely consequences, and measures taken. The Controller may audit compliance once per year on 30 days' notice, by written questionnaire or, where reasonably required, a remote review, at the Controller's cost.

8. Deletion on termination

Within 30 days of termination, AxioVendo will delete all Controller personal data (including backups on their rotation cycle) or, at the Controller's prior request, return it in a machine-readable format before deletion.

9. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms & Conditions. This DPA is governed by the laws of England & Wales.