1. Roles and Scope
This DPA supplements the Terms and Conditions. For the purposes of global data protection laws (including GDPR), the Enterprise Client operates as the Data Controller (determining the purpose of data processing), and iHexe operates as the Data Processor (processing data solely on the documented instructions of the Controller).
2. Security of Processing
iHexe implements military-grade technical and organizational measures to ensure a level of security appropriate to the risk. This includes:
- •AES-256 encryption for data at rest.
- •TLS 1.3 encryption for data in transit.
- •Zero-Trust network architecture and Least Privilege Access (LPA) for all iHexe engineers.
3. Sub-Processors
The Controller grants iHexe general authorization to engage sub-processors (e.g., AWS, n8n cloud) to deliver our architecture. iHexe remains fully liable to the Controller for the performance of the sub-processors' data protection obligations.
4. Incident Response Protocol (Breach Notification)
In the event of a verified security breach impacting the Controller's isolated VPC or data payload, iHexe will notify the Controller without undue delay, and in no event later than 72 hours after confirming the breach.