August 17, 2026
This Data Processing Agreement ("DPA") forms part of the agreement
between UNYX AI LTD, a company incorporated in the United
Kingdom with registered office at 1 Beauchamp Court, 10 Victors Way, Barnet, Hertfordshire, United Kingdom, EN5 5TZ ("UNYX",
"Processor"), and the customer identified in the applicable order form
or agreement ("Customer", "Controller"), governing UNYX's processing
of personal data on Customer's behalf in connection with the UNYX platform
(the "Service").
Capitalised terms not defined here have the meaning given in the applicable
Master Services Agreement / Terms of Service between the parties.
"GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR
(the EU GDPR was incorporated into UK law by the Data Protection Act 2018).
"Data Protection Laws" means the GDPR together with any other applicable
data protection or privacy legislation in force from time to time.
"Personal Data", "Processing", "Controller", "Processor",
"Data Subject", "Sub-processor", and "Personal Data Breach" have
the meanings given in the GDPR.
"Customer Personal Data" means personal data processed by UNYX on behalf
of Customer in connection with the Service, as further described in Annex 1.
2.1. As between the parties, Customer is the Controller and UNYX is the
Processor of Customer Personal Data. UNYX will process Customer Personal Data
only for the purposes described in this DPA and the underlying agreement.
2.2. Each party will comply with its respective obligations under Data
Protection Laws applicable to its role.
3.1. UNYX will process Customer Personal Data only:
(a) to provide, maintain, and support the Service;
(b) on Customer's documented instructions, including as set out in the
underlying agreement and this DPA (unless required to do otherwise by law, in
which case UNYX will inform Customer before processing, unless legally
prohibited from doing so); and
(c) as further specified in Annex 1 (Details of Processing).
3.2. UNYX will promptly inform Customer if, in its opinion, an instruction
infringes Data Protection Laws.
UNYX will ensure that personnel authorised to process Customer Personal Data
are subject to appropriate confidentiality obligations.
5.1. UNYX will implement appropriate technical and organisational measures to
ensure a level of security appropriate to the risk, as described in Annex 3
(Security Measures).
5.2. UNYX will notify Customer without undue delay, and in any event within
72 hours of becoming aware, of any Personal Data Breach affecting Customer
Personal Data, and will provide reasonable information and cooperation to
help Customer meet their own breach notification obligations.
6.1. Customer provides general authorisation for UNYX to engage
Sub-processors to process Customer Personal Data, subject to this Section 6.
6.2. UNYX's current list of Sub-processors is published at
https://trust.unyx.ai#sub-processors_card
(the "Sub-processor List"). Before engaging a new Sub-processor, UNYX will
update the Sub-processor List and provide notice to Customer (by publishing
the update and, where Customer has subscribed to notifications, by email) at
least 30 days in advance.
6.3. Customer may object to a new Sub-processor on reasonable data protection
grounds within 30 days of notice. If the parties cannot resolve the objection,
Customer may terminate the affected portion of the Service as its sole
remedy.
6.4. UNYX will impose data protection obligations no less protective than
this DPA on each Sub-processor, and remains liable to Customer for each
Sub-processor's performance of its obligations.
UNYX will provide reasonable assistance to Customer, taking into account the
nature of the processing, to enable Customer to respond to requests from Data
Subjects to exercise their rights under Data Protection Laws. If UNYX
receives such a request directly, it will not respond (other than to confirm
receipt) without Customer's authorisation, and will forward the request to
Customer without undue delay.
UNYX will provide reasonable assistance to Customer with any data protection
impact assessments, and prior consultations with supervisory authorities,
which Customer reasonably considers necessary, taking into account the nature
of the processing and information available to UNYX.
9.1. UNYX will not transfer Customer Personal Data outside the UK or European
Economic Area unless it has taken measures necessary to ensure the transfer
is compliant with Data Protection Laws, including (where applicable) by
relying on:
(a) an adequacy decision covering the recipient country; or
(b) the UK International Data Transfer Addendum / EU Standard Contractual
Clauses, which are incorporated by reference into this DPA where required.
9.2. Details of the location of processing for each Sub-processor are set out
in the Sub-processor List.
Upon Customer's written request, and no more than once per year (except
following a Personal Data Breach or where required by a supervisory
authority), UNYX will make available information reasonably necessary to
demonstrate compliance with this DPA, which may be satisfied by providing a
recent third-party audit report or certification. UNYX will allow for, and
contribute to, audits conducted by Customer or an auditor mandated by
Customer, subject to reasonable confidentiality and scheduling conditions.
On termination of the Service, UNYX will, at Customer's election, delete or
return all Customer Personal Data, and delete existing copies, within
90, unless retention is required by applicable law.
UNYX is incorporated in, and established in, the United Kingdom. As UNYX has
a UK establishment, no separate UK representative is required under Article
27 UK GDPR.
Where this DPA applies to processing subject to the EU GDPR, and because
UNYX has no establishment in the European Economic Area, UNYX's EU
Representative appointed under Article 27 EU GDPR is:
Guy Stiebel
Email:gs@unyx.ai
Queries regarding this DPA or UNYX's data protection practices may be
directed to UNYX's Data Protection Officer:
Buki Ben Natan — dpo@unyx.ai.
Each party's liability arising under this DPA is subject to the limitations
and exclusions of liability set out in the underlying agreement between the
parties.
This DPA forms part of, and is incorporated into, the agreement between
UNYX and Customer for the Service, and takes effect for as long as UNYX
processes Customer Personal Data on Customer's behalf.
Subject matter: UNYX's provision of the Service to Customer.
Duration: For the term of the underlying agreement, plus the period
described in Section 11.
Nature and purpose of processing: Hosting, storage, transmission, and
processing of data submitted by or collected on behalf of Customer through
the Service, for the purpose of providing the Service's core functionality
(including account management, transaction processing, and — where enabled —
AI-assisted matching).
Categories of Data Subjects: Customer's authorised users; end customers
or counterparties of Customer whose data is submitted to the Service.
Types of Personal Data: Contact details (name, email, phone), account
credentials, transaction and account activity data, and — where applicable
and submitted by Customer — identity verification data.
Special categories of data: None processed by design; Customer should not
submit special category data unless separately agreed in writing.
See the current Sub-processor List at
https://trust.unyx.ai/#sub-processors_card
UNYX maintains technical and organisational measures appropriate to the risk
of processing, including encryption in transit and at rest, access controls
and multi-factor authentication for production systems, network
segmentation, logging and monitoring, regular vulnerability scanning, an
incident response plan, and employee security training.
The current, detailed description of these measures is published and kept
up to date at UNYX's Trust Center: https://trust.unyx.ai#faq_card.