1. Scope and Parties
This Data Processing Agreement (“DPA”) forms an integral part of the service agreement between the customer contracting for Axisforge services (“Customer” or “Controller”) and Axisforge GmbH, Friedrichstraße 68, 10117 Berlin, Germany (“Axisforge” or “Processor”).
This agreement applies to all processing of Personal Data carried out by Axisforge on behalf of the Customer in connection with the Axisforge Events telemetry platform and associated cloud consulting services.
2. Subject Matter and Nature of Processing
The subject matter of data processing comprises the ingestion, transient routing, real-time chunked streaming delivery, buffering, and retention-limited storage of structured event records transmitted by Customer publishers to Axisforge API endpoints (/api/v1/sync/events).
3. Categories of Data and Data Subjects
The categories of data processed include:
- Technical Telemetry: Timestamp, channel name, source identifier, event types, application metrics, and diagnostics.
- Network Metadata: IP addresses, user agent strings, and request routing headers required for transport delivery and rate limiting.
- Payload Attributes: Custom JSON fields provided by Customer publishers. Customer is responsible for sanitizing unnecessary personal data before transmission.
Data subjects may include Customer employees, end users, or operational personnel whose identifiers appear in event payloads.
4. Location of Processing & Subprocessors
All primary data processing, event buffering, retention lifecycle management, and cold data storage are executed exclusively within facilities in Frankfurt, Germany.
Subprocessor Authorization: The Customer grants general authorization for Axisforge to engage infrastructure hosting providers and regional delivery partners. Regional delivery partners relay HTTPS traffic; processing and storage happen in Frankfurt. Regional edge endpoints (such as cis.axisforge.tech) provide transport termination and low-latency packet forwarding without persistent local payload storage.
Axisforge ensures that all engaged subprocessors are bound by written data protection obligations no less restrictive than those set forth in this DPA.
5. Technical and Organizational Measures
Axisforge maintains robust technical and organizational measures to ensure a level of security appropriate to the risk, including:
- HTTPS transport encryption using TLS 1.3 and TLS 1.2 across all edge endpoints and origin relays.
- AES-256 encryption at rest for persistent storage volumes and automated system backups in Frankfurt.
- Cryptographic hashing of authentication tokens (
?t=YOUR_API_KEY). - Role-based access controls and ephemeral multi-factor authentication for operational infrastructure access.
6. Rights of Data Subjects
To the extent Customer does not have the ability to address a data subject request directly through the API or console, Axisforge shall provide reasonable assistance to Customer to fulfill obligations under applicable data protection legislation.
7. Security Incident Notification
In the event of a confirmed personal data breach affecting Customer data, Axisforge shall notify Customer without undue delay, and in any event within 48 hours of becoming aware of the breach, providing relevant details to support Customer compliance obligations.
8. Return and Deletion of Data
Telemetry event records are automatically deleted upon expiration of the applicable retention period (7 days for Developer, 30 days for Growth, 90+ days for Enterprise). Upon termination of services, Axisforge shall purge remaining customer event records from operational buffers within 30 days.
9. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the Federal Republic of Germany.