Nordax OS betaLegal center

Data protection

Data Processing Addendum

Effective August 30, 2026Updated August 30, 2026

This addendum governs Nordax Digital’s processing of personal data on behalf of a Nordax OS tenant and forms part of the tenant’s platform agreement.

1. Parties and definitions

The tenant is the “Customer,” and Northern Axis, LLC, doing business as Nordax Digital (“Nordax Digital”), is the “Processor” for Customer Personal Data processed to provide Nordax OS. Nordax OS is a product of Nordax Digital. “Data Protection Law” means privacy and data-protection law applicable to the processing. Terms such as controller, processor, service provider, personal data, process, and data subject have the meanings given by applicable law.

2. Processing instructions

Nordax Digital will process Customer Personal Data only to provide, secure, support, and improve the contracted user-facing service; follow documented Customer instructions; prevent fraud or abuse; or comply with law. The platform agreement, enabled modules, tenant configuration, support requests, and authorized user actions constitute documented instructions.

3. Processing details

Subject matter and purpose: Hosting and operating the tenant’s business-management, customer, scheduling, billing, communications, analytics, and optional module workflows.

Duration: The service term plus the retention, export, deletion, and backup period described in the agreement.

Data subjects: Tenant users, employees, contractors, customers, prospects, vendors, members, website visitors, communication recipients, and other people whose data the tenant submits.

Data types: Identity and contact data; account and role data; appointment, job, service, and location data; communications and consent records; invoices and payment metadata; files and form responses; technical logs; analytics; and connected-service data.

4. Confidentiality and security

Nordax Digital will ensure people authorized to process Customer Personal Data are bound by confidentiality and will maintain measures appropriate to the risk, including access control, tenant isolation, authentication, encryption in transit, provider controls, logging, backups, vulnerability management, and incident response. Customer is responsible for its users, endpoint security, permissions, configuration, and lawful instructions.

5. Subprocessors

Customer authorizes Nordax Digital to use the providers listed in the Subprocessor Notice. Nordax Digital will impose data-protection obligations appropriate to the services they perform and remains responsible for its subprocessor obligations to the extent required by law. Material additions may be announced through the platform or updated notice.

6. Assistance and incidents

Taking into account the nature of processing, Nordax Digital will provide reasonable assistance with data-subject requests, security obligations, impact assessments, regulator consultations, and demonstrated compliance. Nordax Digital will notify Customer without undue delay after confirming a breach of Customer Personal Data and will provide available information reasonably needed for Customer’s response.

7. Return and deletion

On termination or written instruction, Nordax Digital will make Customer Personal Data available for export and delete or return it according to the agreement, unless retention is required by law. Deletion from backups may occur through normal backup rotation. Data necessary to establish legal claims, preserve security records, or meet financial-record obligations may be retained with access restricted.

8. Reviews and audits

Nordax Digital will make information reasonably necessary to demonstrate compliance available to Customer. No more than once annually, unless required by law or following a confirmed incident, Customer may request a reasonable review. Reviews must protect other tenants, confidential systems, and provider information and may use current third-party reports or questionnaires where sufficient.

9. U.S. state privacy terms

Where applicable, Nordax Digital acts as Customer’s service provider or contractor, will not sell or share Customer Personal Data for cross-context behavioral advertising, and will not retain, use, or disclose it outside the direct business relationship except as permitted by Data Protection Law. Customer may take reasonable steps to verify compliant use and may require remediation of unauthorized processing.

10. International transfers

If Data Protection Law requires a transfer mechanism for processing in another country, the parties will use the applicable standard contractual clauses or another legally recognized safeguard. This addendum controls over conflicting platform terms concerning Customer Personal Data.

Questions about this document may be sent to privacy@nordaxos.com.
Nordax OS beta

A connected business operating system. Currently in private beta.

Copyright © 2026 Northern Axis, LLC. All rights reserved. Nordax OS is a product of Nordax Digital, a trade name of Northern Axis, LLC.

Nordax DigitalLegalPrivacyTermsMessaging