Legal
Data Processing Addendum
Last updated: 3 August 2026
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Service (the "Agreement") between the Client and, as applicable per the Agreement, ModenX Inc., a Delaware corporation (United States Clients) or ModenX India Private Limited (CIN U46512TN2024PTC167731) (India Clients) (each, "modenX", "we", "us").
1. Definitions
- "Data Protection Laws" — the California Consumer Privacy Act as amended by the CPRA and other applicable US state privacy laws (US Clients); the Digital Personal Data Protection Act, 2023 and its Rules (India Clients).
- "Client Data" — personal data about visitors to Client's physical Locations that modenX processes on Client's behalf to provide the Service (presence/recognition signals, visit timestamps, loyalty/recognition identifiers, and any transaction data Client's own systems provide to the platform). Does not include modenX's own account and billing data about Client's personnel, which modenX processes as its own controller/Data Fiduciary under the Privacy Policy.
- "Presora Data" — personal data an individual has independently chosen to share via the Presora consumer app, processed by modenX in its own capacity as the Presora product operator, not on Client's behalf. Out of scope of this DPA — see §2.2.
- "Data Fiduciary" / "Data Processor" — as defined in the DPDP Act (India).
- "Business" / "Service Provider" — as defined in the CCPA/CPRA (US).
- "Sub-processor" — a third party modenX engages to process Client Data on modenX's behalf.
- "Security Incident" — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Data.
2. Roles of the parties
2.1 As between Client and modenX, Client is the Data Fiduciary (India) / Business (US) for Client Data, and modenX is the Data Processor (India) / Service Provider (US), processing Client Data only on Client's documented instructions as set out in the Agreement and this DPA.
2.2 This DPA does not apply to Presora Data. Where a visitor holds a Presora account and has independently consented in the Presora app to share a score or tier, modenX acts as its own controller/Data Fiduciary for that specific processing — see the Terms and the Privacy Policy's Presora sections. Client never receives more than the score/tier the visitor chooses to share.
2.3 Client is solely responsible for (a) the accuracy and legality of the Client Data it provides to or generates via the platform, and (b) having a lawful basis — including any consent, notice or signage its own local law requires — for modenX's processing of that data as instructed.
3. Subject matter, duration, nature and purpose of processing
3.1 Subject matter: modenX's provision of the presence-intelligence and customer-recognition Service described in the Agreement.
3.2 Duration: for the term of the Agreement, plus the post-termination export/retention window set out in the Terms.
3.3 Nature and purpose: collection and processing of presence/visit signals (BLE/Wi-Fi presence detection, QR/check-in scans, and Client-system transaction data where integrated) to generate recognition, analytics, reporting and recommendations for Client.
3.4 Categories of data subjects: visitors to Client's physical Locations.
3.5 Categories of personal data: device/proximity identifiers, visit timestamps and location, recognition/loyalty identifiers, and Client-provided transaction data. modenX does not process any sensitive personal data other than precise geolocation (already disclosed in the Privacy Policy) and does not perform facial recognition or other biometric processing.
4. modenX's obligations
4.1 Process Client Data only on Client's documented instructions (including those in the Agreement and configured via the platform), unless required otherwise by law — in which case modenX will notify Client first unless legally prohibited from doing so.
4.2 Ensure personnel authorised to process Client Data are bound by confidentiality obligations.
4.3 Implement the security measures described in §7.
4.4 Provide reasonable assistance to Client, at Client's cost, in responding to a data subject/data principal request or regulator inquiry concerning Client Data, to the extent modenX's own systems permit.
4.5 Not sell Client Data, and not "share" it (as the CCPA defines that term) for cross-context behavioural advertising.
4.6 Not combine Client Data with data from another Client or from other sources, except for the fully aggregated, de-identified cross-Client benchmarks already described in the Terms.
4.7 Notify Client without undue delay after becoming aware of a Security Incident affecting Client Data, and provide reasonably available information to support Client's own notification obligations.
4.8 On termination, make Client Data available for export for the retention window set out in the Terms, and thereafter delete or anonymise it except where retention is legally required.
5. Sub-processors
5.1 Client authorises modenX to engage the sub-processors below, and any successor sub-processor performing an equivalent role:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Cloud hosting and infrastructure | Currently Central India for all Clients — see the Privacy Policy for the current, up-to-date location |
| Auth0 (Okta) | Identity and authentication | US |
| Firebase Authentication (Google) | Identity and authentication for app users globally | US |
| Razorpay (India Clients) / Stripe (US Clients) | Client's own subscription billing — not Client Data under this DPA | India / US respectively |
5.1A Transactional and account emails (e.g. billing notices, security alerts) are sent directly by modenX from [email protected] to Clients globally — this is not outsourced to a third-party email service provider and so is not a sub-processor under this DPA.
5.2 modenX will give Client at least 30 days' notice before engaging a new sub-processor with access to Client Data (by posting an updated version of this table or notifying by email), during which Client may object on reasonable data-protection grounds. If unresolved, Client may terminate the affected part of the Service.
5.3 modenX remains liable for each sub-processor's acts and omissions to the same extent as if modenX performed those services itself.
6. Data location and cross-border transfer
6.1 As of the "Last updated" date on the Privacy Policy, Client Data is stored and processed on Microsoft Azure infrastructure in the Central India region, for India and US Clients alike — see the Privacy Policy for the current, authoritative statement (including any future US-region move).
6.2 (US Clients) Applicable US state privacy laws do not currently impose a Standard-Contractual-Clauses-style cross-border transfer mechanism; this section will be revisited if that changes.
6.3 (India Clients) modenX does not transfer Client Data outside India except to a jurisdiction not restricted by the Central Government under the DPDP Act.
7. Security measures
modenX maintains technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access controls limiting Client Data access to personnel who need it to perform the Service, logging and monitoring, and incident response procedures.
8. Audit rights
8.1 No more than once every 12 months (or promptly following a Security Incident), Client may request a summary of modenX's then-current security measures, or ask modenX to complete a reasonable written security questionnaire, in lieu of an on-site audit.
8.2 modenX will provide reasonable cooperation with a regulator-mandated audit.
9. Data subject / data principal requests received directly
If modenX receives a request directly from an individual concerning Client Data, modenX will direct the individual to Client (as the responsible Data Fiduciary/Business) and will not itself respond substantively, beyond confirming receipt.
10. Liability
Each party's liability under this DPA is subject to the limitation of liability and exclusions set out in the Terms, which apply to this DPA as if set out here in full.
11. Term and termination
This DPA remains in effect for as long as modenX processes Client Data on Client's behalf under the Agreement, and terminates automatically on the earlier of termination of the Agreement or modenX ceasing to process Client Data on Client's behalf.
12. Order of precedence
If this DPA conflicts with the Terms regarding the processing of personal data, this DPA prevails.
Annex 1 — United States: CCPA/CPRA Service Provider Terms
(a) modenX is a "service provider" as defined in Cal. Civ. Code §1798.140.
(b) modenX will process personal information only for the "business purpose" of providing the Service under the Agreement, and will not: (i) sell or share personal information; (ii) retain, use or disclose personal information for any purpose other than that business purpose; (iii) retain, use or disclose personal information outside the direct business relationship between Client and modenX; or (iv) combine personal information received from Client with personal information from other sources, except as the CCPA permits.
(c) modenX certifies it understands and will comply with the restrictions in (b).
(d) Client may take reasonable steps, including via the audit rights in §8 above, to confirm modenX uses personal information consistently with Client's own obligations under the CCPA.
Annex 2 — India: DPDP Act Processor Terms
(a) modenX is a "Data Processor" as defined in the Digital Personal Data Protection Act, 2023.
(b) modenX will process personal data only pursuant to a valid contract with Client (this DPA and the Agreement), and only per Client's instructions.
(c) modenX will implement reasonable security safeguards to prevent a personal data breach, per DPDP Act §8(5).
(d) modenX will notify Client of a personal data breach without delay, so Client can meet its own notification obligations to the Data Protection Board of India and affected Data Principals.
(e) On termination, modenX will, per Client's instruction, delete or return personal data, unless retention is required by law.