Data Processing Agreement

Effective: 2/26/2026 SECURE DOCUMENT
# Data Processing Agreement **Effective Date:** January 1, 2024 ## 1. Parties This Data Processing Agreement ("DPA") is entered into between Strix VPN ("Processor") and the user ("Controller") who uses our VPN services. ## 2. Scope This DPA applies to the processing of personal data by Processor on behalf of Controller in connection with VPN services. ## 3. Data Processing Details ### Nature of Processing Provision of VPN services, including: - User authentication - Service delivery - Technical support - Billing and subscription management ### Categories of Data Subjects Individual users of VPN services. ### Types of Personal Data - Name and email address - Payment information (processed by third parties) - Device identifiers - Connection metadata (temporary, per our Privacy Policy) ## 4. Processor Obligations Processor agrees to: - Process personal data only on documented instructions from Controller - Ensure personnel authorized to process data are bound by confidentiality - Implement appropriate security measures - Not engage sub-processors without prior authorization - Assist Controller in responding to data subject requests - Delete or return personal data upon termination ## 5. Security Measures Processor implements: - AES-256 encryption - Access controls and authentication - Regular security assessments - Employee training - Incident response procedures ## 6. Sub-Processors Processor may use the following sub-processors: - Cloud infrastructure providers - Payment processors (Stripe, PayPal) - Customer support tools ## 7. Data Breach Notification Processor will notify Controller of any personal data breach within 72 hours of becoming aware of it. ## 8. Audits Processor will make available information necessary to demonstrate compliance and allow for audits. ## 9. Governing Law This DPA is governed by the laws of the State of Delaware. ## Contact **Strix VPN** Email: legal@strixvpn.com