Nox - The Guardian
    DPA

    Data Processing Addendum

    Black X DPA for customers subject to GDPR, UK GDPR, or comparable data-protection laws.

    Last Updated: June 19, 2026

    1. Scope

    This Data Processing Addendum ("DPA") supplements the Black X Terms of Service between BlackX Technologies Inc. ("Processor") and the customer ("Controller") and applies to the extent the Processor processes personal data on behalf of the Controller subject to the EU GDPR, UK GDPR, Swiss FADP, or comparable laws.

    2. Roles

    For customer-uploaded contracts, deal data, and end-user records, the Controller determines the purposes and means of processing and the Processor processes personal data on its instructions. For Black X account data (billing, authentication), BlackX is an independent Controller.

    3. Subprocessors

    The Controller authorizes BlackX to engage subprocessors. We provide reasonable advance notice of new subprocessors. Current subprocessors include:

    • Lovable Cloud — database, authentication, storage, and edge functions
    • Paddle.com Market Limited — payments and Merchant of Record
    • Resend — transactional email delivery

    A current list is available on request to hello@blackx.app.

    4. International Transfers

    Where personal data is transferred outside the EEA, UK, or Switzerland, the parties rely on the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, incorporated by reference.

    5. Security Measures

    BlackX implements appropriate technical and organizational measures including:

    • Encryption in transit (TLS 1.2+) and at rest
    • Role-based access controls and least-privilege service credentials
    • Row-level security in the database
    • Audit logging and continuous monitoring

    See the /security page for additional detail.

    6. Breach Notification & Audit

    BlackX will notify the Controller without undue delay (and in any event within 72 hours of awareness) of any personal-data breach affecting Controller data. The Controller may audit BlackX's compliance once per year on reasonable notice, or rely on third-party reports made available by BlackX.

    7. Execution

    To execute a countersigned DPA, email hello@blackx.app with the subject line "DPA Request" and your legal entity name. We countersign within five business days.

    Nox - The Guardian

    8. Contact Us

    Need a countersigned DPA?

    hello@blackx.app

    BlackX Technologies Inc. · Remote-first, United States