1. Background, Incorporation and Effectiveness
1.1 This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the FixAdmin Terms of Service (the "Agreement") between FixAdmin Inc., a Florida corporation, with its principal place of business in the State of Florida, United States ("FixAdmin") and the business customer that accepts the Agreement (the "Customer"). It governs FixAdmin's Processing of Personal Data contained in Customer Data on behalf of the Customer in connection with the Service.
1.2 Effectiveness; no signature required. This DPA takes effect for the Customer upon the Customer's acceptance of the Agreement. No signature, counter-signature or separate execution is required for this DPA to be valid and binding. A copy of this DPA as accepted by the Customer, with its version and hash, is available on request to [email protected].
1.3 Duration. This DPA remains in force for as long as FixAdmin Processes Personal Data contained in Customer Data on the Customer's behalf, including during the deletion and residual-backup periods described in Section 12, notwithstanding any earlier termination or expiry of the Agreement.
1.4 Capitalized terms not defined in this DPA have the meanings given in the Agreement.
2. Definitions
2.1 "Authorized User" means an individual authorized by the Customer to use the Service under the Customer's account (for example, an administrator, technician or salesperson).
2.2 "Customer Data" means the data, including Personal Data, that the Customer or its Authorized Users submit to, generate in, or have synchronized into the Service in the course of using it, relating in particular to End Customers and to the Customer's repair, sales and inventory records. Customer Data does not include account, billing, telemetry, support, or legal-acceptance-evidence data that FixAdmin processes as an independent controller as described in the Privacy Policy.
2.3 "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, as applicable to the Customer: Colombian Law 1581 of 2012 and its regulatory decrees; Chilean Law 21.719; the Brazilian General Data Protection Law (Law 13.709/2018, "LGPD"); the Mexican Federal Law on the Protection of Personal Data Held by Private Parties ("LFPDPPP"); Peruvian Law 29733 and its regulations; Argentine Law 25.326 and its regulations; the EU and UK General Data Protection Regulation ("GDPR") where applicable; and any other applicable data protection or privacy law.
2.4 "End Customer" means a natural person who is a customer of the Customer's repair business (including the natural-person representative of a business customer of the Customer) and whose data the Customer records in the Service.
2.5 "Order" means a repair order created by the Customer in the Service in respect of an End Customer's device.
2.6 "Personal Data", "Processing" (and "Process"), "controller", "processor" and "data subject" have the meanings given in the Data Protection Laws applicable to the Customer; local equivalents of "controller" and "processor" are identified in Section 3.
2.7 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data contained in Customer Data Processed by FixAdmin.
2.8 "Service" means the FixAdmin software-as-a-service platform for repair businesses, as described in the Agreement, together with its related applications and features made available under the Customer's Subscription.
2.9 "Subprocessor" means a third party engaged by FixAdmin to Process Personal Data contained in Customer Data on the Customer's behalf.
2.10 "Subscription" has the meaning given in Section 2.8 of the Agreement.
3. Roles of the Parties; Scope; Local-Law Figures
3.1 Roles. For all Personal Data contained in Customer Data, the Customer acts as controller (or the equivalent figure under applicable Data Protection Laws) and FixAdmin acts as processor, Processing such Personal Data only on the Customer's behalf and on the Customer's documented instructions. Where the Customer itself acts as a processor for a third party, FixAdmin acts as the Customer's subprocessor, and the Customer warrants that its own controller has authorized the engagement of FixAdmin on the terms of this DPA.
3.2 Local-law figures. Without limiting Section 3.1, the parties acknowledge that, under the Data Protection Laws named below, their respective roles are as follows:
| Jurisdiction / law | Customer | FixAdmin |
|---|---|---|
| Colombia — Law 1581 of 2012 | *Responsable del tratamiento* | *Encargado del tratamiento* |
| Chile — Law 21.719 | *Responsable de datos* | *Encargado* (third party processing on behalf of the responsable) |
| Brazil — LGPD | *Controlador* | *Operador* |
| Mexico — LFPDPPP | *Responsable* | *Encargado* |
| Peru — Law 29733 | *Titular del banco de datos personales* / responsible party | *Encargado de tratamiento* |
| Argentina — Law 25.326 | *Responsable* | *Encargado* (data-processing services provider, Section 25) |
| EU/UK — GDPR (where applicable) | Controller | Processor |
3.3 This DPA as the required local contract. This DPA is intended to constitute, and shall be construed as, the written contract or equivalent binding instrument governing Processing on behalf of another that is required by applicable Data Protection Laws, including: the *contrato de transmisión* of Personal Data from a *responsable* to an *encargado* contemplated by Colombian Law 1581 of 2012 and its regulatory decrees; the processing mandate (*encargo*) required under Chilean Law 21.719; the operator agreement contemplated by the LGPD; the *encargado* terms required under the LFPDPPP and its regulations; the processing arrangement required under Peruvian Law 29733 and its regulations; and the data-processing services arrangement contemplated by Section 25 of Argentine Law 25.326. Where the GDPR applies, this DPA is intended to address the requirements of Article 28(3) GDPR. No further processing agreement is required between the parties for FixAdmin to Process Customer Data under the Service.
3.4 Scope of Processing. FixAdmin Processes Personal Data contained in Customer Data only: (a) to provide, secure, maintain and support the Service, including automated server-side operations (scheduled jobs, purges, message dispatch and similar operations that are part of the Service); (b) as instructed under Section 4; and (c) as required by applicable law, in which case FixAdmin will inform the Customer of that legal requirement before Processing unless the law prohibits such disclosure on important grounds of public interest. The subject matter, duration, nature and purposes of Processing, the types of Personal Data and the categories of data subjects are described in Annex A.
4. Customer Instructions
4.1 Documented instructions. The Customer's complete and final documented instructions to FixAdmin consist of: (a) the Agreement, including this DPA and the documents it incorporates; and (b) the Customer's and its Authorized Users' configuration and use of the features of the Service (including, by way of example, creating Orders, configuring WhatsApp reminder levels and automations, publishing or unpublishing marketplace listings, and initiating deactivation of the Customer's company account). Any additional instruction requires the written agreement of both parties, and FixAdmin may charge reasonable fees for complying with instructions that fall outside the ordinary operation of the Service.
4.2 Apparently unlawful instructions. FixAdmin will inform the Customer if, in FixAdmin's opinion, an instruction from the Customer appears to infringe applicable Data Protection Laws. FixAdmin is not obliged to perform a legal review of the Customer's instructions, and the Customer remains solely responsible for the lawfulness of its instructions. FixAdmin may suspend performance of an instruction it reasonably considers unlawful until the parties resolve the matter.
5. Customer Responsibilities
5.1 Lawfulness. As controller, the Customer is solely responsible, to the maximum extent permitted by applicable law, for: (a) the accuracy, quality and lawfulness of Customer Data and of the means by which it was obtained; (b) establishing and maintaining a valid legal basis for the Processing of End Customer Personal Data through the Service; (c) providing End Customers with any legally required privacy notices; (d) obtaining any consents and opt-ins required by applicable law and by the Meta Business Messaging Policy for messages sent to End Customers through the Customer's WhatsApp Business account; and (e) responding to data subjects and authorities in its capacity as controller.
5.2 Prohibited data. The Service does not request and does not need any sensitive Personal Data. In accordance with the Acceptable Use Policy, the Customer must not enter into the Service — including free-text fields, notes, device or fault descriptions, and photo or video uploads — any data concerning health, biometric data, government-issued identification numbers of individuals (such as cédula, RUT, DNI or passport numbers), other than a business tax identification number that the Customer voluntarily provides for its own company profile, or financial data of third parties. This prohibition applies regardless of whether the Customer believes it has a legal basis; the Service is not designed to process such data; any such data submitted in breach is the Customer's sole responsibility, and FixAdmin may require its removal.
5.3 Minors. The Service is not directed to minors. The Customer must not knowingly enter personal data of a minor into the Service except identification of a device's owner provided by the minor's parent or legal guardian in the course of a repair, under the Customer's sole responsibility.
5.4 Device unlock codes. The device unlock PIN or pattern field is optional. If the Customer chooses to record an unlock PIN or pattern, the Customer does so on its own responsibility and must have the End Customer's permission to do so. The treatment of this field in the Service is described in Annex A.
6. Personnel and Confidentiality
6.1 FixAdmin ensures that every person it authorizes to Process Personal Data contained in Customer Data is bound by a contractual or statutory duty of confidentiality and Processes such data only as needed to perform the Service.
6.2 FixAdmin personnel access to internal administration tooling is limited by access rules and recorded in an immutable log, as further described in Annex B. FixAdmin's internal administration panel does not provide personnel with access to the Customer's Orders, sales records or End Customer records; server-side automated processing (scheduled jobs, purges, message dispatch) operates on Customer Data as part of the Service.
7. Security Measures
7.1 Taking into account the nature of the Processing and the information available to it, FixAdmin implements and maintains the technical and organizational measures described in Annex B, designed to protect Personal Data contained in Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
7.2 FixAdmin may update the measures in Annex B from time to time, provided the updated measures do not materially reduce the overall level of protection during the term of the Agreement.
7.3 No security measure is infallible, and FixAdmin does not warrant that the Service will be free from security incidents. FixAdmin makes no representation that it holds any security certification, and none is claimed in this DPA. Backups exist for FixAdmin's disaster-recovery purposes; FixAdmin does not warrant that any particular data can be restored from backups, and backups are not a data-recovery service offered to Customer.
8. Subprocessors
8.1 General authorization. The Customer grants FixAdmin a general authorization to engage Subprocessors to provide the Service. FixAdmin's current Subprocessors are identified in the published Subprocessor List, which is incorporated into this DPA by reference and identifies, for each Subprocessor, the service performed, the categories of data involved and the location of Processing.
8.2 Notice of changes; right to object. FixAdmin will give the Customer at least thirty (30) days' advance notice (by email or in-app) before authorizing a new Subprocessor to Process Personal Data contained in Customer Data. If the Customer objects on reasonable data-protection grounds within that notice period, the parties will discuss the objection in good faith. If no resolution is reached, the Customer's sole and exclusive remedy, to the maximum extent permitted by applicable law, is to terminate the Agreement before the change takes effect, in which case FixAdmin will refund any prepaid fees covering the period after the effective date of termination, in accordance with the termination and data-lifecycle provisions of the Agreement and Section 12 of this DPA.
8.3 Flow-down; responsibility. FixAdmin will impose on each Subprocessor, by written contract, data protection obligations that are materially no less protective of Customer Data than those in this DPA, to the extent applicable to the service the Subprocessor performs. FixAdmin remains responsible to the Customer for the performance of its Subprocessors' obligations under those contracts to the same extent FixAdmin is liable under this DPA and the Agreement. FixAdmin's responsibility under this Section does not extend to Meta Platforms' processing performed under the Customer's own agreements with Meta as holder of its WhatsApp Business Account, which is governed by Section 9 of the Agreement.
9. Assistance to the Customer
9.1 Data subject requests. Taking into account the nature of the Processing, FixAdmin will provide reasonable assistance, through the features of the Service and, where those are insufficient, through [email protected], to enable the Customer to respond to requests from data subjects to exercise their rights under applicable Data Protection Laws (including access, rectification, deletion, objection and, where applicable, portability), including, on the Customer's written instruction, manual deletion of specific Customer Data items (such as individual evidence files or an individual End Customer's record) within 30 calendar days. If a data subject contacts FixAdmin directly regarding Customer Data, FixAdmin will, where the request identifies the Customer, refer the data subject to the Customer and will not respond substantively on the Customer's behalf except on the Customer's instruction or where required by law.
9.2 DPIAs and consultations. FixAdmin will provide the Customer with reasonable assistance, based on information available to FixAdmin, with data protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under applicable Data Protection Laws and that concern the Processing under this DPA.
9.3 Costs. Assistance under this Section 9 is provided at no charge where it requires only immaterial effort. Where assistance requires material time or resources, FixAdmin may charge the Customer reasonable costs, notified in advance.
10. Personal Data Breach Notification
10.1 FixAdmin will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data contained in Customer Data.
10.2 The notification will include, to the extent then known: (a) the nature of the breach; (b) the categories and approximate volume of data and data subjects concerned; (c) the likely consequences; and (d) the measures taken or proposed to address the breach and mitigate its effects. Where full details are not available at the time of the initial notification, FixAdmin will provide the remaining information in phases as it becomes available, without undue further delay.
10.3 FixAdmin will reasonably cooperate with the Customer and provide the information reasonably needed for the Customer to meet its own breach notification obligations to authorities and data subjects. As between the parties, the Customer is responsible for making any legally required notifications to authorities and data subjects in its capacity as controller, and for their content and timing.
10.4 FixAdmin's notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.
11. Government and Authority Requests
11.1 If FixAdmin receives a request or demand from a court, law-enforcement body, supervisory authority or other public authority for disclosure of, or access to, Personal Data contained in Customer Data, FixAdmin will: (a) notify the Customer without undue delay, unless legally prohibited from doing so; (b) where reasonably practicable and lawful, redirect the authority to request the data directly from the Customer; and (c) disclose only the minimum data legally required. Where notification is prohibited, FixAdmin will use reasonable efforts to obtain a waiver of the prohibition and to inform the Customer as soon as it is lawfully permitted.
12. Deletion and Return of Customer Data
12.1 Export before deactivation. During the Subscription and during the grace period described below, the Customer may export reports and inventory in XLSX format and receipts in PDF format through the Service, and may request a comprehensive export of Customer Data in writing to [email protected]; manual export requests are fulfilled within thirty (30) calendar days. Automated, self-service portability of the entire dataset is not a feature of the Service. Customer should complete or request any export before initiating deactivation. If FixAdmin receives a comprehensive export request during the grace period, FixAdmin will extend the grace period (delaying the purge) as needed to deliver the export, no later than 30 calendar days after the request, after which the purge proceeds automatically. FixAdmin has no obligation to recover data from backups to fulfill a request made after the purge.
12.2 Deletion of individual Authorized User accounts. An Authorized User account may be deleted in-app (Profile) or via the public account-deletion page. Employee accounts are deleted immediately (authentication account, database profile and personal storage). Historical Orders and sales records created through the account are retained as the Customer's business records and remain subject to this Section 12.
12.3 Company deactivation, grace period and purge. When the Customer's owner initiates deactivation of the company account, the company account is deactivated with a seven (7) day grace period. FixAdmin sends an immediate email confirmation and a reminder approximately twenty-four (24) hours before the purge. The Customer may reactivate the company at any time during the grace period. After the grace period expires, FixAdmin purges the company's data: all user accounts, all company storage (including device evidence photos and videos), and all of the company's database collections.
12.4 Exceptions that survive the purge. The following categories survive the purge, and the Customer instructs and authorizes FixAdmin to retain them:
12.4.1 De-identified business records (5 years). Orders and sales records are retained for five (5) years in de-identified form. Direct identifiers are removed (End Customer name replaced with "Anonymous"; telephone and other contact fields cleared). FixAdmin does not further review record contents; the Customer must not embed identifying details in free-text fields (AUP §3). FixAdmin retains these de-identified records as an independent controller, solely for accounting, audit and legal-defense purposes, and does not use them for any other purpose.
12.4.2 Legal-acceptance-evidence records. Records evidencing acceptance of legal terms are retained as evidence of acceptance of legal terms, anonymized of IP address and user-agent data at purge.
12.4.3 Backup residual (up to 98 days). Copies of purged data may persist in database backups for up to ninety-eight (98) additional days (daily backups, São Paulo region, plus seven (7) days of point-in-time recovery), after which they expire and are overwritten in the ordinary backup cycle. Backups are not used to restore purged data except where required by law or as part of a disaster-recovery operation; if a disaster-recovery restore reinstates data that had been purged, FixAdmin will re-apply the purge without undue delay. Data in backups remains protected under the security measures in Annex B and the confidentiality obligations of this DPA until expiry.
12.5 Subscription expiry without deactivation. If the Subscription simply expires and the Customer does not initiate deactivation, Customer Data is retained to allow reactivation, subject to the access restrictions described in the Agreement. The Customer may initiate deactivation at any time through the in-app deactivation flow, or request deletion via [email protected].
12.6 Operational log retentions. The Service applies the following fixed retention periods to operational records: WhatsApp activity logs, webhook events, system error records and notifications — ninety (90) days; automation traces — four hundred (400) days; archived de-identified Orders post-purge — five (5) years, as per Section 12.4.1.
12.7 Legal holds. FixAdmin may retain Personal Data beyond the periods above only where and for as long as retention is required by applicable law, in which case the data remains protected under this DPA and is Processed only for that retention purpose.
13. Audits and Information
13.1 Documentation and reports. On the Customer's written request, no more than once per twelve (12) month period, FixAdmin will make available documentation and reports reasonably necessary to demonstrate compliance with this DPA, including a description of the measures in Annex B as then in effect and relevant information about Subprocessors, and will provide reasonable written responses to the Customer's reasonable follow-up questions. This documentation, together with those written responses, is the means by which FixAdmin makes available the information necessary to demonstrate compliance and contributes to audits, including inspections, conducted by or on behalf of the Customer, except as provided in Section 13.2.
13.2 On-site audits. An on-site audit or inspection is available only where: (a) a supervisory authority with jurisdiction over the Customer requires it; (b) a Personal Data Breach has affected Personal Data contained in Customer Data; or (c) the Customer reasonably demonstrates that the documentation and responses provided under Section 13.1 are insufficient to demonstrate FixAdmin's compliance with this DPA. Any such audit is subject to: (i) at least thirty (30) days' prior written notice; (ii) the audit being conducted during business hours, with minimal disruption to FixAdmin's operations and without access to data of other customers; (iii) the Customer bearing the costs of the audit, including FixAdmin's reasonable costs of supporting it, unless the audit reveals a material breach of this DPA by FixAdmin; and (iv) the auditor (who must not be a competitor of FixAdmin) and the Customer entering into confidentiality undertakings acceptable to FixAdmin. Audit results are Confidential Information under the Agreement.
13.3 Information obtained under this Section 13 may be used by the Customer only to verify compliance with this DPA and to meet its regulatory obligations.
14. International Transfers
14.1 The Customer acknowledges and authorizes that Personal Data contained in Customer Data is transferred to FixAdmin, which is established in the United States, and is Processed onward by FixAdmin's Subprocessors in the United States and Brazil (Google Cloud), and other regions of the applicable provider, as identified in the Subprocessor List.
14.2 Where a transfer of Personal Data under this DPA is an international transfer restricted by the Data Protection Laws applicable to the Customer, the transfer terms in Annex C apply, in each case only where and to the extent required by the law applicable to the Customer.
15. Liability
15.1 To the maximum extent permitted by applicable law, each party's total aggregate liability arising out of or related to this DPA — whether in contract, tort or otherwise — is subject to the exclusions and to the limitation-of-liability cap set out in the Agreement, and liability under this DPA and under the Agreement counts toward a single, combined cap, not separate caps.
15.2 Nothing in this Section 15 limits either party's liability where such limitation is not permitted by applicable law, nor does it affect the rights of data subjects to claim directly against the party responsible under mandatory Data Protection Laws.
16. Order of Precedence; General
16.1 Conflict. In the event of a conflict between this DPA and the Agreement with respect to the Processing or protection of Personal Data, this DPA prevails. In the event of a conflict between this DPA and any transfer terms incorporated under Annex C, the transfer terms prevail to the extent of the conflict for the transfers they govern.
16.2 Amendments. FixAdmin may update this DPA in accordance with the modification procedure of the Agreement, provided that updates do not materially reduce the protection of Customer Data during the term of the Agreement, other than as required to reflect changes in applicable law. If FixAdmin makes a material amendment to this DPA that is adverse to the Customer, the Customer may terminate the Agreement before the amendment takes effect, in which case FixAdmin will refund any prepaid fees covering the period after the effective date of termination.
16.3 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision shall be replaced with a valid provision that most closely achieves its intent.
16.4 Governing law and venue. This DPA is governed by the laws of the State of Florida, United States, excluding its conflict-of-laws rules, and disputes arising out of or relating to this DPA are subject to the Dispute Resolution section of the Agreement (including its arbitration provisions, class action waiver and carve-outs), except where the mandatory Data Protection Laws of the Customer's jurisdiction require otherwise for data protection matters.
Annex A — Description of Processing
A.1 Subject matter
FixAdmin's Processing of Personal Data contained in Customer Data as processor on the Customer's behalf, in order to provide the Service (a multi-tenant, cloud-based management platform for repair businesses, including repair-order management, sales, inventory, reporting, public order tracking, an optional public marketplace listing, and WhatsApp messaging features operated through the Customer's own WhatsApp Business account).
A.2 Duration
The term of the Agreement, plus the deletion and residual periods described in Section 12 of this DPA (7-day grace period; purge; up to 98 additional days of backup residual; retention of de-identified records and legal-acceptance-evidence records as described therein).
A.3 Nature and purposes of Processing
Collection (as entered or synchronized by the Customer), storage, structuring, retrieval, consultation, use, disclosure by transmission (including dispatch of WhatsApp messages and push notifications configured by the Customer), restriction, erasure and destruction — in each case solely to provide, secure, maintain and support the Service, including automated server-side operations (scheduled jobs, reminder and automation dispatch, deactivation and purge routines) that form part of the Service.
A.4 Types of Personal Data
Personal Data contained in Customer Data, comprising:
- End Customer identification and contact data: name and telephone number. The Service displays an email field for End Customers but does not persist it; no End Customer email addresses are stored.
- Order content: device and fault descriptions in free-text fields; amounts owed and debt balances associated with an End Customer.
- Device unlock PIN or pattern (optional field): stored in the Service as entered; automatically destroyed when the Order is closed; excluded from the public order-tracking page. FixAdmin does not represent that this field is encrypted at field level.
- Device evidence media: photos and videos of devices uploaded by the Customer (up to 5 MB per photo and 100 MB per video); not individually deletable; deleted upon company purge.
- WhatsApp messaging data: End Customer telephone number and name, and message template variables (which may include amounts and dates), transmitted through the WhatsApp Business Cloud API from the Customer's own WhatsApp Business account; message status webhook data.
- Synchronized WhatsApp data: where the Customer connects its WhatsApp Business App number in coexistence mode, Meta synchronizes the Customer's existing contacts and chat history into the Cloud API, and such data becomes available in the Service.
- Public tracking data: the public order-tracking page, accessible via a random 12-character code, displays only the End Customer's first name and the Order status; it never displays telephone numbers, prices or unlock PINs.
The Service does not request and does not need sensitive Personal Data, government-issued identification numbers of individuals (other than a business tax identification number that the Customer voluntarily provides for its own company profile), dates of birth, or financial, health or biometric data of natural persons, and the Customer is prohibited from submitting such data (Sections 5.2 and 5.3 and the Acceptable Use Policy).
A.5 Categories of data subjects
- End Customers of the Customer (natural persons, including the natural-person representatives of the Customer's business customers);
- Contacts of the Customer whose data is synchronized from the Customer's WhatsApp Business App in coexistence mode;
- Authorized Users, to the extent their Personal Data appears within Customer Data (for example, as the creator of an Order).
Annex B — Technical and Organizational Security Measures
FixAdmin implements and maintains the following measures:
- Tenant isolation: company-level data isolation enforced in database security rules and server-side logic, with deny-by-default rules.
- Server-controlled permissions: roles and permissions are assigned exclusively by backend logic using signed claims; clients cannot self-assign privileges.
- Application attestation: app-integrity checks (App Check) enforced on server functions.
- Verified access: a verified email address is required to operate an account; optional SMS two-factor authentication is available to Authorized Users.
- Secrets protection: WhatsApp access tokens are encrypted with AES-256-GCM, with encryption keys held in a managed secret store.
- Server-side integrity of critical operations: operations affecting money and record states are executed only on the server.
- Abuse controls: rate limiting using hashed IP addresses.
- Audit trail: an immutable, per-company audit trail of high-impact actions.
- Restricted internal access: FixAdmin personnel access to the internal administration panel is limited by access rules and recorded in an immutable log; the panel does not expose Orders, sales or End Customer records.
- Webhook authenticity: inbound webhooks are verified by signature.
- Encryption in transit and at rest: TLS for data in transit and the cloud platform's encryption at rest.
- Log hygiene: masking of personal data in logs and limited log retention periods.
These measures are designed to provide a level of security appropriate to the risk of the Processing. FixAdmin does not represent that any measure guarantees absolute security.
Annex C — International Transfer Terms
C.1 Scope. The primary transfer under this DPA is the transfer of Personal Data contained in Customer Data from the Customer to FixAdmin, which is established in the United States and acts as the primary data importer. Onward transfers are made to FixAdmin's Subprocessors located in the United States and Brazil (Google Cloud) and in other regions of the applicable provider, as identified in the Subprocessor List. This Annex applies to those transfers, in each case only where and to the extent the transfer is restricted by the Data Protection Laws applicable to the Customer.
C.2 EU/EEA and UK data (GDPR). Where Personal Data subject to the GDPR is in scope and the transfer is not otherwise permitted, the parties incorporate by reference the EU Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914: Module Two (controller to processor) where the Customer acts as controller, and Module Three (processor to processor) where the Customer acts as processor; with the Customer as data exporter and FixAdmin as data importer; Annexes A and B of this DPA serving as the corresponding SCC annexes; the optional docking clause included; and, for UK transfers, the UK International Data Transfer Addendum applied to those clauses. Where FixAdmin or the receiving Subprocessor participates in a lawful adequacy framework recognized by the law applicable to the Customer (such as the EU-U.S. Data Privacy Framework, including its UK Extension, and the Swiss-U.S. Data Privacy Framework), that framework may serve as the transfer mechanism instead.
C.3 Brazilian data (LGPD). Where the LGPD requires a transfer mechanism for international transfers of Personal Data, the parties incorporate by reference the standard contractual clauses approved by the Brazilian National Data Protection Authority (ANPD), with the roles, subject matter and safeguards completed by reference to this DPA and its Annexes.
C.4 Argentine data. Where the law applicable to the Customer is Argentine Law 25.326 and it requires a transfer mechanism, the parties incorporate by reference the model transfer contract clauses approved by the Argentine data protection authority for transfers to processors, completed by reference to this DPA and its Annexes.
C.5 Other jurisdictions. For other jurisdictions whose Data Protection Laws (including those named in Section 3.2) condition international transfers on contractual safeguards, notice or authorization, this DPA and this Annex constitute the parties' contractual safeguards, and the Customer, as controller, is responsible for any notice to, or authorization from, data subjects or authorities that its local law requires for the transfers described in Section C.1.
C.6 Precedence. Where transfer terms incorporated under this Annex conflict with this DPA, the transfer terms prevail for the transfers they govern (Section 16.1).
*End of Data Processing Agreement — Version 4.0.2 — August 2026.*