Data Processing Agreement
Version 1.0 — July 27, 2026
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
- Data Controller: The customer who uses Poolaxy to process personal data of their end users.
- Data Processor: Jordan Digitals, operating Poolaxy at poolaxy.com.
2. Subject Matter and Duration
This DPA governs the processing of personal data by Poolaxy on behalf of the Controller for the duration of the Controller's active subscription. Processing begins when the Controller connects a number or account to the pool and ends when the Controller's account is deleted or all numbers are disconnected.
3. Nature and Purpose of Processing
Poolaxy processes personal data to provide channel warming services. This includes: matching accounts with pool partners, generating AI conversations, scheduling and sending messages through the Controller's provider credentials, monitoring account health, and maintaining conversation memory for relationship continuity.
4. Type of Personal Data Processed
- Phone numbers (WhatsApp)
- Provider API credentials (encrypted at rest)
- Conversation metadata (summaries, relationship stage, topics discussed)
- Account health metrics (send counts, failure rates)
- Pool identity information (persona name, occupation, interests)
5. Categories of Data Subjects
End users whose numbers or accounts are connected to Poolaxy by the Controller. Pool partners who are matched with the Controller's accounts (identity anonymized).
6. Obligations of the Processor
Poolaxy will:
- Process personal data only on documented instructions from the Controller
- Ensure persons authorized to process personal data are under appropriate confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not engage sub-processors without prior written authorization
- Assist the Controller in responding to data subject requests
- Delete or return personal data upon termination of the agreement
7. Sub-processors
Poolaxy uses the following sub-processors:
- Stripe, Inc. — Payment processing (USA)
- Paystack Limited — Payment processing (Nigeria/Global)
- Straico — AI conversation generation
- StartHost / 20i — Server hosting (United Kingdom)
- StackMail — Transactional email delivery
8. Data Transfers
Primary data processing occurs on servers located in the United Kingdom (StartHost). AI processing occurs via Straico's API infrastructure. Payment data is processed by Stripe (USA) and Paystack (Nigeria). Where data is transferred outside the EEA, appropriate safeguards are in place including Standard Contractual Clauses where applicable.
9. Security Measures
- Provider credentials encrypted using AES-256 in the database
- 2FA secret keys encrypted with application-level key
- All connections over HTTPS/TLS
- Admin panel IP-restricted
- Session cookies: httponly, secure, SameSite=Lax
- Password hashing with bcrypt (PASSWORD_DEFAULT)
- PDO prepared statements throughout (SQL injection prevention)
10. Breach Notification
Poolaxy will notify the Controller of any personal data breach without undue delay and within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, categories of data affected, approximate number of data subjects, and measures taken to address the breach.
11. Return or Deletion of Data
Upon termination of the agreement, Poolaxy will, at the Controller's choice, delete or return all personal data. Pool conversation summaries may be retained in anonymized form for pool integrity. The Controller may request a data export at any time from the Settings page or by emailing hello@poolaxy.com.
12. Contact
For DPA inquiries, amendments, or to request a signed copy: hello@poolaxy.com