Legal · Last updated May 23, 2026

Data Processing Addendum

This Data Processing Addendum (DPA) forms part of the NAVIZIX Terms of Service, order form, subscription agreement, pilot agreement, or other agreement between NAVIZIX and the customer using the NAVIZIX services.

This DPA applies where NAVIZIX processes Personal Data on behalf of the Customer in connection with the Services.

1. Parties

Customer: The company, organisation, or individual that enters into the Agreement and uses NAVIZIX for business purposes.

Processor: Navizix LTD, a company registered in England and Wales, registered office: Office 458, Unit 5, 399–405 Oxford Street, Mayfair, London W1C 2BU. ICO registration is in progress; the reference will be added once issued. Email: privacy@navizix.ai.

Together, the Customer and NAVIZIX are the "Parties".

2. Definitions

"Applicable Data Protection Laws" means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including where applicable the UK GDPR, the Data Protection Act 2018, the EU GDPR, and any other relevant data protection laws.

"Controller" means the party that determines the purposes and means of processing Personal Data.

"Customer Personal Data" means Personal Data submitted to, uploaded to, connected to, generated through, or otherwise processed by NAVIZIX on behalf of the Customer in connection with the Services.

"Data Subject" means an identified or identifiable individual.

"Personal Data" means information relating to an identified or identifiable individual.

"Processor" means the party that processes Personal Data on behalf of the Controller.

"Processing" means any operation performed on Personal Data, including collection, recording, storage, organisation, structuring, analysis, retrieval, use, disclosure, transmission, restriction, deletion, or destruction.

"Sub-processor" means any third party engaged by NAVIZIX to process Customer Personal Data on behalf of the Customer.

3. Roles Of The Parties

For Customer Personal Data processed through the Services: Customer is the Controller; NAVIZIX is the Processor.

Customer determines the purposes and means of processing Customer Personal Data.

NAVIZIX processes Customer Personal Data only on behalf of the Customer and in accordance with this DPA and the Agreement.

NAVIZIX may act as an independent Controller for certain limited personal data relating to account administration, billing, website analytics, security, support, sales, and legal compliance. That processing is governed by the NAVIZIX Privacy Policy, not this DPA.

4. Scope Of Processing

NAVIZIX will process Customer Personal Data only to:

  • provide, operate, maintain, and improve the Services;
  • create and manage customer workspaces;
  • provide dashboards, reports, workflows, SOPs, onboarding documents, and AI-assisted outputs;
  • enable integrations, imports, exports, and data intake features;
  • provide support, troubleshooting, security, and maintenance;
  • comply with the Customer's documented instructions;
  • comply with legal obligations applicable to NAVIZIX.

The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Schedule 1.

5. Customer Instructions

Customer instructs NAVIZIX to process Customer Personal Data as necessary to provide the Services and as described in the Agreement, this DPA, Customer's use and configuration of the Services, and written instructions provided by Customer.

NAVIZIX will not process Customer Personal Data for purposes outside these instructions unless required by law. If NAVIZIX is required by law to process Customer Personal Data outside Customer's instructions, NAVIZIX will inform Customer unless legally prohibited from doing so.

If NAVIZIX believes an instruction violates Applicable Data Protection Laws, NAVIZIX will inform Customer where legally permitted.

6. Customer Responsibilities

Customer is responsible for:

  • ensuring it has a lawful basis for processing and providing Customer Personal Data to NAVIZIX;
  • providing required privacy notices to Data Subjects;
  • obtaining required consents or permissions;
  • ensuring the accuracy, quality, and legality of Customer Personal Data;
  • deciding which users have access to Customer Personal Data;
  • configuring permissions appropriately;
  • reviewing AI-generated outputs before using them;
  • ensuring that NAVIZIX is used in accordance with Applicable Data Protection Laws.

Customer must not submit Personal Data to NAVIZIX unless it has the legal right to do so.

7. Confidentiality

NAVIZIX will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

NAVIZIX will limit access to Customer Personal Data to personnel who need access to provide, secure, support, or maintain the Services.

8. Security Measures

NAVIZIX will implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure.

These measures may include, as appropriate:

  • access controls;
  • authentication controls;
  • encryption in transit;
  • encryption at rest where supported;
  • role-based access controls;
  • logging and monitoring;
  • secure development practices;
  • backup and recovery measures;
  • vulnerability management;
  • separation of customer workspaces where applicable;
  • internal confidentiality controls;
  • incident response procedures.

A summary of technical and organisational measures is set out in Schedule 2.

9. Sub-Processors

Customer authorises NAVIZIX to engage Sub-processors to provide the Services.

NAVIZIX will ensure that Sub-processors are bound by written obligations that provide a level of protection for Customer Personal Data that is materially equivalent to this DPA.

NAVIZIX remains responsible for the performance of its Sub-processors in relation to Customer Personal Data.

NAVIZIX will maintain a list of Sub-processors in Schedule 3 or another location made available to Customer.

NAVIZIX will provide notice of material changes to Sub-processors where required by Applicable Data Protection Laws or where commercially reasonable.

If Customer objects to a new Sub-processor on reasonable data protection grounds, Customer must notify NAVIZIX in writing within 10 days of notice. The Parties will work in good faith to resolve the objection. If no reasonable resolution is available, Customer may stop using the affected Services.

10. Data Subject Rights

Taking into account the nature of the processing, NAVIZIX will provide reasonable assistance to Customer, where technically possible, to help Customer respond to Data Subject requests under Applicable Data Protection Laws.

Such requests may include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where applicable.

If NAVIZIX receives a Data Subject request relating to Customer Personal Data, NAVIZIX will, where legally permitted, direct the Data Subject to Customer or notify Customer.

NAVIZIX will not respond directly to the request unless authorised by Customer or required by law.

11. Personal Data Breach

NAVIZIX will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will include, where available:

  • a description of the nature of the breach;
  • categories and approximate number of affected Data Subjects;
  • categories and approximate number of affected records;
  • likely consequences of the breach;
  • measures taken or proposed to address the breach;
  • contact point for further information.

NAVIZIX will take reasonable steps to investigate, contain, and mitigate the breach.

Customer is responsible for determining whether notification to a regulator or Data Subjects is required.

12. Assistance With Compliance

Taking into account the nature of the processing and information available to NAVIZIX, NAVIZIX will provide reasonable assistance to Customer with Customer's obligations relating to security of processing, breach notifications, data protection impact assessments, and prior consultation with regulators, where required.

NAVIZIX may charge reasonable fees for assistance that goes beyond standard support, unless the assistance is required due to NAVIZIX's breach of this DPA.

13. Return Or Deletion Of Data

Upon termination or expiry of the Agreement, Customer may request export or deletion of Customer Personal Data, where technically available.

NAVIZIX will delete or return Customer Personal Data within a reasonable period after termination, unless retention is required by law, backup systems, security, dispute resolution, accounting, or legitimate business purposes.

Backup copies may remain for a limited period until overwritten or deleted according to NAVIZIX's backup retention practices.

14. Audits And Information

NAVIZIX will make available information reasonably necessary to demonstrate compliance with this DPA.

Customer may request reasonable information about NAVIZIX's processing of Customer Personal Data.

Any audit must be:

  • subject to reasonable notice;
  • limited to once per year unless required by law or following a confirmed material breach;
  • conducted during normal business hours;
  • conducted in a way that does not disrupt NAVIZIX operations;
  • subject to confidentiality obligations;
  • limited to information relevant to Customer Personal Data.

NAVIZIX may satisfy audit requests by providing security documentation, policies, certifications, third-party audit reports, or written responses where available.

15. International Transfers

NAVIZIX and its Sub-processors may process Customer Personal Data in countries outside the UK, the EEA, or the Customer's country.

Where such processing involves a restricted transfer under Applicable Data Protection Laws, NAVIZIX will use an appropriate transfer mechanism, which may include:

  • adequacy regulations or adequacy decisions;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • the EU Standard Contractual Clauses;
  • another lawful transfer mechanism.

Customer authorises NAVIZIX to make such transfers where necessary to provide the Services, subject to appropriate safeguards required by Applicable Data Protection Laws.

16. AI Processing

Where NAVIZIX uses AI-assisted features to process Customer Personal Data, NAVIZIX will process such data only as necessary to provide the Services and in accordance with Customer's instructions.

Customer is responsible for deciding whether Customer Personal Data should be used with AI-assisted features.

Customer should avoid submitting unnecessary sensitive, special category, confidential, or high-risk data into AI prompts or generated documents unless there is a lawful basis and appropriate internal approval.

NAVIZIX does not use Customer Personal Data to train public AI models unless expressly agreed in writing or clearly enabled by Customer through a specific product setting.

17. Sensitive Data

Customer must not submit special category data, criminal offence data, children's data, medical data, biometric data, financial account credentials, government identity documents, or other highly sensitive data unless:

  • the Services are designed to process that data;
  • Customer has a lawful basis;
  • Customer has informed NAVIZIX in writing where required;
  • appropriate safeguards are in place.

NAVIZIX may reject, restrict, or delete high-risk data if it creates a legal, security, or operational risk.

18. Records

NAVIZIX will maintain records of processing activities where required by Applicable Data Protection Laws.

Customer is responsible for maintaining its own records of processing activities as Controller.

19. Liability

Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless Applicable Data Protection Laws require otherwise.

20. Conflict

If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA will control.

21. Term

This DPA remains in effect for as long as NAVIZIX processes Customer Personal Data on behalf of Customer.

22. Governing Law

This DPA is governed by the same law as the Agreement, unless Applicable Data Protection Laws require otherwise.

Schedule 1: Details Of Processing

1. Subject Matter — NAVIZIX processes Customer Personal Data to provide an AI-powered business operating platform, dashboard, document generation tools, workflow tools, SOP builder, onboarding tools, customer journey mapping, inventory summaries, integrations, reporting, and related business support services.

2. Duration — For the duration of the Agreement and any period required for deletion, return, backup retention, legal compliance, dispute resolution, or security purposes.

3. Nature Of Processing — Collection, recording, organisation, structuring, storage, retrieval, consultation, analysis, use, transmission, display, hosting, AI-assisted processing, document generation, workflow generation, reporting, export, deletion, and support.

4. Purpose Of Processing — To provide, operate, secure, maintain, support, and improve the Services, including:

  • workspace management;
  • business dashboards;
  • integrations and data intake;
  • SOP generation;
  • onboarding document generation;
  • customer journey mapping;
  • employee and team records;
  • inventory summaries;
  • CRM and sales summaries;
  • HR and performance summaries;
  • finance and cashflow summaries;
  • marketing and campaign summaries;
  • AI-assisted reports and recommendations;
  • customer support;
  • security and troubleshooting.

5. Categories Of Data Subjects — Depending on Customer's use of the Services, Data Subjects may include:

  • Customer employees;
  • managers;
  • contractors;
  • job applicants;
  • customers;
  • leads and prospects;
  • suppliers;
  • partners;
  • business contacts;
  • end users;
  • account administrators;
  • support contacts.

6. Types Of Personal Data — Depending on Customer's use of the Services, Customer Personal Data may include name, email address, phone number, job title, department, manager name, work location, employment start date, role responsibilities, onboarding status, training records, performance notes, task ownership, CRM notes, customer journey records, lead source, sales pipeline information, communication records, supplier contact details, user account details, business documents uploaded by Customer, operational notes, support requests, and metadata related to use of the Services.

7. Special Category Data — The Services are not intended for special category data unless expressly agreed in writing. Customer should not upload special category data unless it has a lawful basis and appropriate safeguards.

8. Frequency Of Processing — Continuous, as necessary to provide the Services.

Schedule 2: Technical And Organisational Measures

NAVIZIX will maintain appropriate technical and organisational measures, which may include:

1. Access Control — user authentication; role-based access controls; administrative access restrictions; workspace-based access separation; password protection; access review where applicable.

2. Data Security — encryption in transit; encryption at rest where supported; secure hosting providers; secure database configuration; secure API access; protection against unauthorised access.

3. Application Security — secure development practices; input validation where applicable; error handling; security testing where appropriate; dependency monitoring where available.

4. Operational Security — limited personnel access; confidentiality obligations; incident response procedures; backup and recovery measures; logging and monitoring where available.

5. Customer Controls — account permissions; workspace management; user invitations; data export where available; data deletion requests where available.

6. AI Controls — AI output review by Customer; limitation of AI use to service provision; no public AI model training using Customer Personal Data unless expressly agreed; prompt and output safeguards where available.

Schedule 3: Sub-Processors

NAVIZIX may use the following categories of Sub-processors:

  • Cloud hosting providers
  • Database providers
  • Authentication providers
  • Email service providers
  • Payment processors
  • Analytics providers
  • Error monitoring providers
  • Customer support tools
  • AI infrastructure providers
  • File storage providers
  • Communication and notification providers

The current list of named Sub-processors is published on the Sub-processors page at /legal/sub-processors and is updated when material changes occur.

Schedule 4: Customer Instructions

Customer instructs NAVIZIX to process Customer Personal Data to:

  • create and manage Customer workspaces;
  • provide user accounts and permissions;
  • store and display Customer Data;
  • generate dashboards, documents, SOPs, onboarding packs, reports, and AI-assisted outputs;
  • process uploaded, imported, or connected business data;
  • provide support and troubleshooting;
  • secure and maintain the Services;
  • export or delete data upon request where technically available;
  • use Sub-processors as necessary to provide the Services;
  • transfer data internationally where necessary and subject to appropriate safeguards.