Data Processing Agreement
Effective: 2/26/2026 SECURE DOCUMENT
# Data Processing Agreement
**Effective Date:** January 1, 2024
## 1. Parties
This Data Processing Agreement ("DPA") is entered into between Strix VPN ("Processor") and the user ("Controller") who uses our VPN services.
## 2. Scope
This DPA applies to the processing of personal data by Processor on behalf of Controller in connection with VPN services.
## 3. Data Processing Details
### Nature of Processing
Provision of VPN services, including:
- User authentication
- Service delivery
- Technical support
- Billing and subscription management
### Categories of Data Subjects
Individual users of VPN services.
### Types of Personal Data
- Name and email address
- Payment information (processed by third parties)
- Device identifiers
- Connection metadata (temporary, per our Privacy Policy)
## 4. Processor Obligations
Processor agrees to:
- Process personal data only on documented instructions from Controller
- Ensure personnel authorized to process data are bound by confidentiality
- Implement appropriate security measures
- Not engage sub-processors without prior authorization
- Assist Controller in responding to data subject requests
- Delete or return personal data upon termination
## 5. Security Measures
Processor implements:
- AES-256 encryption
- Access controls and authentication
- Regular security assessments
- Employee training
- Incident response procedures
## 6. Sub-Processors
Processor may use the following sub-processors:
- Cloud infrastructure providers
- Payment processors (Stripe, PayPal)
- Customer support tools
## 7. Data Breach Notification
Processor will notify Controller of any personal data breach within 72 hours of becoming aware of it.
## 8. Audits
Processor will make available information necessary to demonstrate compliance and allow for audits.
## 9. Governing Law
This DPA is governed by the laws of the State of Delaware.
## Contact
**Strix VPN**
Email: legal@strixvpn.com