Data Processing Agreement (DPA)
Version: 1.0 · Effective date: 2026-08-18 · GDPR Article 28
Between the Customer (controller) and TriStiX S.L. (VAT ESB26925016), Avenida Maisonnave 41, 3º H, 03003 Alicante/Alacant, España (processor, operating the TraXmark® platform).
1. Subject matter and duration
Processing is limited to providing the TraXmark Service and lasts for the duration of the subscription.
2. Nature and purpose of processing
Processing engagement signals (opens, clicks, replies), document analytics and related metadata strictly to operate the Service for the Customer.
3. Categories of data subjects and personal data
Data subjects: Customer's contacts and users. Personal data: contact identifiers, pseudonymized engagement telemetry, document interaction data.
4. Processor obligations (Art. 28(3))
The Processor shall:
- process personal data only on documented instructions from the Customer;
- ensure confidentiality of persons authorized to process;
- implement appropriate technical and organizational security measures (see Annex II);
- not engage sub-processors without notice and the Customer's right to object;
- assist the Customer with data subject requests (Art. 12–22);
- delete or return personal data after termination per the Customer's choice;
- make available information necessary to demonstrate compliance and allow audits.
5. Security measures (Annex II summary)
Encryption in transit (TLS 1.2+) and at rest; envelope encryption (AES-256-GCM) for credentials; row-level tenant isolation; immutable audit logs; MFA for administrative access; pseudonymization of IP/user-agent at ingestion.
6. Sub-processors
The current sub-processor list is provided on request. The Customer may object to changes; continued processing with the objected sub-processor is then terminated for that Customer.
7. International transfers
Data is hosted in the EU. Any transfer outside the EEA relies on Standard Contractual Clauses (SCCs) and supplementary measures.
8. Data subject rights
The Processor notifies the Customer without undue delay upon receiving a data subject request and assists with fulfillment.
9. Breach notification
The Processor notifies the Customer without undue delay (no later than 72 hours) after becoming aware of a personal data breach, with known details and remediation.
10. Liability and audit
Liability under this DPA follows the main agreement and applicable law. The Customer may audit compliance via documentation and, where strictly necessary and agreed, on-site audits.
Document integrity (SHA-256): c6cc229146684fcb