Skip to main content
Cathrix Network

Data Processing Addendum

Processing of Personal Information in Customer Content

This Data Processing Addendum (“DPA”) forms part of the agreement between Cathrix Network Inc. (“Cathrix”) and the person or entity that has entered into the applicable agreement (“Customer”) when Cathrix processes Customer Personal Data on the Customer’s behalf.

Capitalized terms not defined in this DPA have the meanings given in the General Terms of Service, applicable Supplemental Terms, or Order.

1. Scope, Roles, and Priority

1.1 Definitions and Roles

Customer Personal Data” means personal information contained in Customer Content that Cathrix processes on the Customer’s behalf through the Services. The Customer determines the purposes of processing Customer Personal Data and provides instructions to Cathrix. Cathrix acts as a service provider (data processor) to the Customer for that processing.

1.2 Exclusions

This DPA does not apply to account, contact, billing, usage, security, or other personal information that Cathrix processes for its own purposes. Such data is governed by our Privacy Policy.

1.3 Term and Priority

This DPA applies for as long as Cathrix processes Customer Personal Data on the Customer’s behalf.

If this DPA conflicts with another part of the applicable agreement, a separately signed overriding agreement and then the applicable Order retain priority over this DPA, in that order, as stated in the General Terms. Subject to those two priority levels, this DPA controls only with respect to the processing of Customer Personal Data. All other terms, including applicable liability limitations, continue to apply. Additional terms required for a particular jurisdiction apply only if stated in an Order or a separate written agreement.

2. Processing Instructions and Responsibilities

2.1 Cathrix’s Processing Instructions

The Customer instructs Cathrix to process Customer Personal Data only as reasonably necessary to:

  • provide, configure, maintain, secure, and support the Services;
  • carry out the Customer’s use and configuration of the Services;
  • follow the applicable agreement and documented instructions accepted by Cathrix; and
  • comply with applicable law.

Cathrix will not sell Customer Personal Data or use it for unrelated advertising. If Cathrix reasonably believes that an instruction violates applicable law, Cathrix may suspend that instruction and will notify the Customer unless prohibited by law. Cathrix is not required to follow an instruction that is unlawful, technically infeasible, or outside the scope of the Services.

2.2 Customer Responsibilities

The Customer is responsible for:

  • complying with privacy and data-protection laws applicable to Customer Personal Data;
  • providing required notices and obtaining required consents or other lawful authority;
  • ensuring that its instructions and use of the Services are lawful;
  • responding to requests from individuals concerning Customer Personal Data; and
  • not submitting regulated, highly sensitive, or legally restricted information unless an applicable Order expressly permits it and required safeguards are in place.

3. Service Providers and Locations

3.1 Use of Sub-processors

Cathrix may engage service providers to process Customer Personal Data as reasonably necessary to provide, secure, or support the Services. Cathrix will require those providers by written agreement to process Customer Personal Data only for authorized purposes and to apply appropriate confidentiality and security safeguards. Cathrix remains responsible for Customer Personal Data under its control to the extent required by applicable law and the agreement.

3.2 Processing Locations

Our Privacy Policy describes the countries in which processing may occur and the authorized purposes. The Customer may contact the Privacy Officer for written information about service providers and processing locations.

4. Security, Incidents, and Compliance

4.1 Confidentiality and Security

Cathrix will limit access to Customer Personal Data to personnel and service providers who need access to perform the Services or comply with law and who are subject to appropriate confidentiality obligations. Cathrix will maintain reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of Customer Personal Data and the nature of the Services. However, no Service can be guaranteed to be completely secure.

4.2 Privacy and Security Incidents

A “Customer Data Incident” means a loss of, unauthorized access to, or unauthorized disclosure of Customer Personal Data resulting from a breach of safeguards while the information is in the custody or control of Cathrix or its service providers. It does not include unsuccessful attempts or events that do not compromise Customer Personal Data.

In the event of a Customer Data Incident, Cathrix will:

  • notify the Customer without unreasonable delay after determining that an incident has occurred;
  • provide reasonably available information about the nature of the incident, affected information, mitigation, and corrective measures; and
  • provide reasonable cooperation with the Customer’s response.

The Customer is responsible for notifications to individuals, regulators, and other persons unless applicable law assigns that responsibility to Cathrix. Cathrix may provide a notification where required by law or reasonably necessary to reduce a risk of harm.

4.3 Compliance Information

On reasonable request, Cathrix will provide information reasonably necessary to demonstrate its compliance with this DPA, subject to confidentiality, security, and legal restrictions. Any additional audit, certification, or assessment requirement must be agreed upon in writing or required by applicable law.

5. Data Rights, Disclosures, and Deletion

5.1 Individual Requests

If Cathrix receives a request from an individual concerning Customer Personal Data, Cathrix will normally direct the individual to the Customer unless applicable law requires Cathrix to respond directly. Taking into account the nature of the Services and information available to Cathrix, Cathrix will provide reasonable assistance for the Customer to respond to access, correction, deletion, or other legally required requests. The Customer remains responsible for evaluating and responding to each request.

Cathrix will disclose Customer Personal Data only on the Customer’s instructions, with legally valid consent, or where permitted or required by applicable law. Where legally permitted and reasonably practicable, Cathrix will notify the Customer before disclosing Customer Personal Data in response to legal process. Cathrix will limit a disclosure to information that is reasonably necessary and legally authorized in the circumstances.

5.3 Return and Deletion

The Customer is responsible for exporting Customer Personal Data before the Service ends unless the applicable Service provides a post-termination retrieval period. After termination, Cathrix will delete or return Customer Personal Data in accordance with the applicable agreement and the Customer’s documented instructions, except where retention is required or permitted by law. Customer Personal Data may remain temporarily in protected backups until overwritten or expired under the applicable backup cycle and will not be restored except for disaster recovery, security, or legal purposes.

5.4 Contact Information

Questions concerning this DPA should be sent to our designated Privacy Officer at [email protected].

Last Updated on August 26, 2026

Effective as of August 26, 2026