CYBIX
Data Processing Agreement
Last updated 26 August 2026 (version 1.0)
The Article 28 GDPR agreement under which Multichoiceagency (CYBIX) processes personal data on behalf of its customers. It is written to be read, and it applies to every hosted workspace.
1. Parties and scope
This Data Processing Agreement (“DPA”) is between the customer that has accepted the CYBIX Terms (the “Controller”) and Multichoiceagency, Johannes Brandstraat 28, 3072 BH Rotterdam, The Netherlands, operating the CYBIX service (the “Processor”). It forms part of the main agreement and applies to all processing of personal data the Processor performs on the Controller’s behalf in providing CYBIX: the shared inbox, BIX AI agent, messenger, ticketing, contacts, knowledge base, calls and the mobile apps.
It is accepted by using the service. Customers who need a countersigned copy, or their own template reviewed, email support@cybix.app; we return a signed PDF within five working days.
2. Subject matter, duration, nature and purpose
The Processor processes personal data to deliver customer communication for the Controller: receiving, storing, routing, translating, answering (by BIX or by the Controller’s team) and reporting on conversations, and notifying the Controller’s users of them. Processing lasts as long as the main agreement, plus the deletion period in section 10.
Types of data: identification and contact data of the Controller’s customers and visitors (name, email, phone, company, custom attributes), the content of messages, tickets, notes, attachments and — if enabled — call transcripts; technical data (IP address, approximate location, browser, page URL); account data of the Controller’s team (name, email, role); billing contact data.
Data subjects: the Controller’s customers, prospects and website visitors; the Controller’s employees and contractors who use CYBIX.
The Controller alone decides what special-category data (Art. 9 GDPR) may enter the service and must enable restricted mode for workspaces that handle it.
3. Instructions
The Processor processes personal data only on documented instructions from the Controller. The main agreement, this DPA and the settings the Controller chooses in the dashboard are those instructions. If the Processor believes an instruction infringes data protection law, it informs the Controller without delay and may suspend that instruction until it is confirmed.
4. Confidentiality
Only Processor staff who need access to operate or support the service have it, under a contractual duty of confidentiality and after data protection training. Access to production systems is personal, logged and revoked when no longer needed.
5. Security (Art. 32 GDPR)
The Processor implements the technical and organisational measures in Appendix 2 and keeps them current with the state of the art. Substantial changes are documented; the level of protection is never lowered. The current description is published at cybix.app/security.
6. Processing location and international transfers
Storage and processing take place in the European Union / EEA. The Processor’s hosting provider, Hetzner Online GmbH, commits contractually to EU-only processing for the server locations used and to EU-based support.
A transfer to a third country happens only for the named sub-processors and purposes in Appendix 3 (for example the AI model call), under an adequacy decision, the EU-US Data Privacy Framework or Standard Contractual Clauses with supplementary measures. Any other transfer requires the Controller’s prior consent.
7. Sub-processors
The Controller authorises the sub-processors listed at cybix.app/legal/subprocessors (Appendix 3). Each is bound by written terms that impose the same data protection duties as this DPA; the Processor remains fully liable for their performance.
The Processor gives at least 14 days’ notice by email before adding or replacing a sub-processor. The Controller may object in writing on reasonable data protection grounds within that period; if no solution is found, the Controller may terminate the affected service without penalty. Self-hosted installations involve no CYBIX sub-processors.
8. Assistance and data subject rights
The Processor helps the Controller respond to data subject requests (access, rectification, erasure, restriction, portability, objection) with the search and deletion tools in the dashboard, the API, and, where those are not enough, by hand within ten working days. Requests received directly from a data subject are forwarded to the Controller without answering on the merits.
The Processor supports data protection impact assessments and prior consultations with the information in this DPA, the security page and the sub-processor list, and answers further questions on request.
9. Personal data breaches
The Processor notifies the Controller without undue delay, and at the latest within 48 hours of becoming aware, of a personal data breach affecting the Controller’s data: what happened, which data and data subjects are affected as far as known, likely consequences, and the measures taken. Notifications go to the workspace owner’s email address. The Processor cooperates in the Controller’s notification to the supervisory authority and to data subjects.
10. Deletion and return
During the agreement the Controller can retrieve conversations, contacts and tickets through the API, or request a full export, delivered within ten working days. On termination, or on deleting the workspace, the Processor erases all personal data immediately; backups holding it expire within 30 days. Data is retained longer only where EU or member-state law requires it, and then only for that purpose.
11. Audit
The Processor makes available the information needed to demonstrate compliance with Art. 28: this DPA, the security documentation, the hosting provider’s certifications (ISO 27001, BSI C5 Type 2) and annual independent TOM audit reports. Where that is not sufficient, the Controller may audit once a year, or after a breach, with 14 days’ notice, during business hours, by an auditor bound to confidentiality, at the Controller’s cost and without access to other customers’ data.
12. Liability, term and precedence
Liability follows the main agreement. This DPA lasts as long as the Processor processes personal data for the Controller. Where it conflicts with the Terms on data protection, this DPA prevails; where a customer’s own signed DPA exists, that document prevails over this page. Dutch law applies.
13. Appendix 2 — Technical and organisational measures (summary)
- Physical access: ISO 27001 / BSI C5 certified data centres (Hetzner, DE/FI) with electronic access control, logging, video surveillance and 24/7 staffing.
- System access: personal accounts, scrypt-hashed passwords, Google/SSO sign-in, signed short-lived tokens; production access limited to named engineers via multi-factor authenticated, key-based access.
- Data access: role-based permissions (owner, admin, agent, lite); every record scoped to a workspace and filtered on it; restricted mode hides content from previews and notifications.
- Transfer control: TLS for all connections; DTLS-SRTP for calls; sub-processor calls limited to the data needed for the step.
- Isolation: logical separation per workspace on the hosted service; separate stacks, databases and volumes for white-label and self-hosted customers.
- Availability: reproducible container deployments; provider-level redundant power, cooling and network; regular backups of workspace data with a tested restore procedure.
- Integrity and logging: server logs (30 days) for security and troubleshooting; conversation history kept immutable for the workspace.
- Organisation: secrets held only in server configuration; least-privilege access reviewed on staff changes; incident response process with the notification duty in section 9; sub-processor due diligence before onboarding.
Contact
Countersigned copies, custom templates and sub-processor notifications: support@cybix.app.