Legal
Data Processing Agreement (DPA)
Being finalized. This page is a plain-language summary of Noxlyt's Data Processing Agreement and is pending legal review. It is not the signable instrument. For the current signable DPA (and Standard Contractual Clauses), contactprivacy@noxlyt.com.
Last updated: 30 June 2026
This summary describes how Noxlyt Systems P.S.A. ("Processor", "Noxlyt") processes personal data on behalf of a business client ("Controller", "Client") under article 28 of Regulation (EU) 2016/679 (GDPR / RODO), in connection with the noxlyt.app release-validation service.
Processor:
Noxlyt Systems prosta spółka akcyjna (Noxlyt Systems P.S.A.)
ul. Chęcińska 26B/44, 25-020 Kielce, Poland
KRS 0001245297 · NIP 9592093594 · REGON 544903117
Contact: privacy@noxlyt.comThe signable DPA forms part of, and is governed by, the commercial agreement between the Client and Noxlyt.
1. Subject matter, nature and purpose of processing
Noxlyt processes personal data only to provide the Client with the contracted release-validation service: running the Client's automated (Playwright) tests against the Client's systems, storing the test code/results and a tenant database, and reporting the outcomes back to the Client. The duration of processing matches the term of the commercial agreement plus the retention period in clause 10.
2. Roles
The Client is the controller (and may itself be a processor for its own customers); Noxlyt is the processor. Each party complies with its obligations under the GDPR.
3. Processing on documented instructions
Noxlyt processes personal data only on the Client's documented instructions — including the configuration of the service and this DPA — unless required to do otherwise by EU or Member-State law (in which case Noxlyt will inform the Client beforehand, unless the law prohibits it). Noxlyt will promptly inform the Client if, in its opinion, an instruction infringes the GDPR or other data-protection law.
4. Confidentiality
Noxlyt ensures that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality and process the data only as instructed.
5. Security of processing (GDPR art. 32)
Noxlyt implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A summary of current measures (Annex II) includes:
- multi-tenant isolation of Client data, enforced at the application and database layer;
- EU-region storage and execution of application data (clause 8);
- encryption in transit; access controls and least-privilege service identities;
- audit logging of security-relevant access;
- secret management and key handling via a managed secret store;
- backup and recovery of the production database.
The detailed, current measures are provided with the signable DPA.
6. Sub-processing
The Client provides general authorisation for Noxlyt to engage the sub-processors listed in Annex III (and on our public sub-processor page). Noxlyt:
- imposes the same data-protection obligations on each sub-processor by contract (flow-down), and remains fully liable to the Client for its sub-processors;
- gives the Client advance notice of any intended addition or replacement of a sub-processor, allowing the Client a reasonable period to object on reasonable data-protection grounds.
Annex III — sub-processors (current):
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google Cloud (Google Ireland / Google LLC) | Hosting, database, storage, queue, test execution | EU — europe-west1 (Belgium) | DPA/SCCs; DPF-certified |
| GitHub (GitHub Inc. / Microsoft) | Version control of test-project source | United States | DPA/SCCs; DPF (Microsoft) |
| Cloudflare | DNS/CDN/edge, anti-bot (Turnstile), contact-form processing | Global edge | DPA/SCCs; DPF |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Send via Ireland (eu-west-1); account data/metadata/logs in the United States | DPA/SCCs; DPF-certified (EU-U.S. DPF) |
7. Assistance to the Controller
Taking into account the nature of processing, Noxlyt assists the Client by appropriate technical and organisational measures, insofar as possible, with:
- responding to data-subject requests (GDPR art. 12–23);
- security of processing (art. 32);
- personal-data-breach notification and communication (art. 33–34);
- data-protection impact assessments and prior consultation (art. 35–36).
8. International transfers and residency
Application data — the Client's test results and database — is stored in the EU(Google Cloud, Belgium, europe-west1) and tests execute on EU-region infrastructure. Test-project source is version-controlled in GitHub (United States); web traffic is routed via Cloudflare's global network; transactional email is sent via Resend's EU send-region while Resend's account data, metadata and logs are in the United States. Transfers outside the EEA are covered by Standard Contractual Clauses and, where available, the EU-U.S. Data Privacy Framework. The SCCs accompany the signable DPA.
9. Personal-data-breach notification (GDPR art. 33)
Noxlyt notifies the Client without undue delay after becoming aware of a personal-data breach affecting the Client's data, providing the information the Client reasonably needs to meet its own notification obligations.
10. Deletion or return on termination (GDPR art. 28(3)(g))
On termination of the service, and at the Client's choice, Noxlyt deletes or returnsall personal data processed on the Client's behalf and deletes existing copies, unless EU or Member-State law requires storage. Deletion of tenant/project data follows the retention window described in the Privacy Policy and Client's plan terms.
11. Audit and information (GDPR art. 28(3)(h))
Noxlyt makes available to the Client the information necessary to demonstrate compliance with art. 28 and allows for and contributes to audits, including inspections, conducted by the Client or an auditor it mandates, subject to reasonable confidentiality and scheduling arrangements.
12. Details of processing (Annex I)
- Subject matter: provision of the noxlyt.app release-validation service.
- Duration: the term of the commercial agreement plus the retention period (clause 10).
- Nature & purpose: running, storing and reporting the Client's automated tests.
- Categories of data subjects: the Client's authorised users; and any data subjects whose personal data is contained in the Client's test data (determined by the Client).
- Categories of personal data: account/identity data of Client users; any personal data the Client includes in its test code, test data, or test results (determined by the Client). Special-category data only if separately agreed.
13. Delivery
This DPA is available as this public summary plus a signable copy on request (with the SCCs and current Annexes) from privacy@noxlyt.com. We do not publish the signed instrument; it is supplied per Client.
14. Contact
privacy@noxlyt.com — for the signable DPA, sub-processor queries, or any art. 28 matter.