Data Processing Agreement
Last updated 29 September 2026
Scope
This agreement applies where growixHR processes personal data on behalf of a customer (the controller) in providing the service.
Roles
The customer is the controller and growixHR is the processor. growixHR processes personal data only on documented instructions from the customer.
Security measures
We maintain technical and organizational measures including encryption in transit and at rest, access controls, audit logging and regular backups.
Sub-processors
| Category | Purpose | Region |
|---|---|---|
| Cloud hosting | Infrastructure and storage | US / EU / APAC |
| Email delivery | Service notifications | US / EU |
| Payments | Billing and invoicing | US |
Data subject requests
We will assist the customer in responding to requests from individuals exercising their rights under applicable law.
Breach notification
We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data.
Return and deletion
On termination, we will return or delete customer personal data as instructed, unless retention is required by law.