Version 1.0 · Effective date: 22 June 2026
Data Processing Agreement
Version 1.0 · Effective date: 22 June 2026
This Data Processing Agreement (DPA) applies when Catalogix processes personal data for a business customer using the Catalogix service. It forms part of the customer’s agreement for the service. Catalogix is the processor and the customer is the controller, unless the parties document another role for a particular processing activity. Each party will comply with applicable data protection law.
1. Documented instructions and scope
Catalogix processes customer personal data only on the customer’s documented instructions, including to provide, secure, support and improve the service as described in the service agreement and public documentation. The customer determines the purposes and means of processing, categories of data and retention periods. Catalogix will inform the customer if an instruction appears to infringe applicable law and may suspend that instruction while seeking clarification.
The service is designed for supplier catalogue and product data. The customer must not upload sensitive personal data, payment data, customer records, employee records or regulated data unless the parties have agreed in writing that the service is suitable and the required safeguards are in place.
2. Processing details and confidentiality
The subject matter is hosting, organising, comparing and exporting the customer’s files and related account records. Processing lasts for the term of the service and any limited period needed to return or delete data. Catalogix ensures that persons authorised to process personal data are bound by confidentiality obligations.
3. Security
Catalogix applies reasonable technical and organisational measures appropriate to the service and its risks, including authenticated access, organisation-level access separation, password hashing, session controls and operational access controls. Catalogix does not promise a particular security certification or absolute security. The customer is responsible for access management on its side and for reviewing the suitability of the service for its data.
4. Personal-data incidents
Catalogix will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data, to the extent information is available. The notice will describe the known nature of the incident, likely consequences and mitigation steps. Catalogix will reasonably cooperate with the customer’s response and will not make a public attribution that identifies the customer without good reason or legal obligation.
5. Assistance
Taking account of the nature of processing and information available to Catalogix, Catalogix will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments and consultations with supervisory authorities. The customer remains responsible for responding to data subjects and regulators. Assistance that is disproportionate or outside ordinary service support may be subject to reasonable charges agreed in advance.
6. Audits and information
Catalogix will make information reasonably necessary to demonstrate compliance available to the customer, subject to confidentiality and security restrictions. A customer may request one remote audit or questionnaire per year on reasonable notice, and additional reviews after a material incident or where required by law. Audits must not disrupt the service or expose another customer’s information.
7. Subprocessors
The customer authorises Catalogix to use the subprocessors listed on the public Subprocessors page. Catalogix will impose written data-protection obligations on subprocessors and remains responsible for their processing as required by applicable law. Catalogix will provide notice of a material intended change where required; the customer may raise a reasonable, specific objection on data-protection grounds.
8. International transfers
Catalogix will not knowingly make a restricted international transfer of customer personal data without a lawful transfer mechanism. The parties will document any applicable safeguards before such transfer. No region, adequacy decision, standard contractual clause or transfer location is promised by this public DPA; contractual owner confirmation is pending where the provider list marks it as pending.
9. Return and deletion
At the customer’s choice, and subject to applicable law, Catalogix will return or make available customer data through the service and delete it after the service ends within a reasonable operational period. Catalogix may retain a limited copy where required by law or for the establishment, exercise or defence of legal claims, protected by confidentiality and deleted when no longer required. The customer should export data before termination because Catalogix is not a permanent archive.
10. Liability and precedence
The service agreement governs fees, warranties, liability and termination. If this DPA conflicts with the service agreement on data processing, this DPA controls for that conflict. Nothing in this DPA limits mandatory rights or obligations under applicable data protection law.
Annex 1 — Processing description
Data subjects: business users and contacts whose details the customer puts into the service. Data categories: account and organisation details, contact details, supplier and catalogue records, support correspondence and operational identifiers. Special-category data: not intended and must not be uploaded. Operations: collection through the service, hosting, organisation, comparison, transformation, export, support and deletion. Purpose: provide the customer’s catalogue workflow. Duration: the service term plus the return/deletion period.
Annex 2 — Approved subprocessors
Replit/infrastructure is used for application hosting and runtime infrastructure. PostgreSQL infrastructure is listed as pending contractual owner confirmation. Zoho Mail is used only if SMTP is enabled and then handles business correspondence. Stripe is used only when billing is enabled and then handles billing information. Google Frontend (GAESA) is listed for frontend delivery where enabled; the applicable transfer and region details require contractual owner confirmation. See the public Subprocessors page for current status.
Contact: hello@catalogix.io