Legal

Data Processing Addendum

Last updated June 2026

This is a starting template, not legal advice — have counsel review before launch.

This Data Processing Addendum (“DPA”) forms part of the agreement between NoxusHub and the agency customer (“Customer”) for use of the Service. It governs the processing of personal data contained in connected HubSpot portals and other Customer Data.

Roles of the parties

The Customer (the agency) acts as the controller of the HubSpot client data it connects. Where the agency processes that data on behalf of its own end clients, the agency may itself be a processor and the end client the controller. NoxusHub acts as a processor(or sub-processor) and processes Customer Data only on the Customer's documented instructions.

Scope & purpose

NoxusHub processes Customer Data solely to provide the Service — running audits, generating AI output, and executing the agent workflows the Customer configures. Categories of data may include CRM records such as contacts, companies, deals, tickets, and engagement history. The duration of processing is the term of the agreement.

Processor obligations

  • Process Customer Data only on documented instructions from the Customer.
  • Ensure personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures.
  • Assist the Customer in responding to data-subject requests and regulatory obligations.
  • Make available information needed to demonstrate compliance.
  • Not use Customer Data to train third-party AI models.

Sub-processors

The Customer authorizes NoxusHub to engage sub-processors to deliver the Service. The current list is maintained on our Subprocessors page. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We notify Customers of new sub-processors before they begin processing.

Security measures

  • Encryption of data in transit (TLS) and at rest.
  • Read-only-by-default access to HubSpot, with writes only where explicitly enabled.
  • Role-based access controls, logging, and monitoring of production systems.
  • Regular review of access and security practices.

Data-subject requests

Taking into account the nature of the processing, NoxusHub will assist the Customer with appropriate technical and organizational measures to respond to requests from data subjects to exercise their rights. If we receive such a request directly, we will refer it to the relevant Customer (controller).

International transfers

Where Customer Data is transferred across borders, NoxusHub relies on lawful transfer mechanisms such as Standard Contractual Clauses or equivalent safeguards, and ensures sub-processors are bound by comparable terms.

Deletion on termination

On termination of the agreement or disconnection of a HubSpot portal, NoxusHub will delete or return Customer Data within 30 days, unless retention is required by law. Backups are purged on their ordinary cycle.

Contact

To request a signed copy of this DPA or ask questions, email privacy@noxushub.com.