rechtliches
Data Processing Agreement (Annex A)
Version 1.0, 1 September 2026
This Data Processing Agreement (“DPA”, Annex A) forms part of the contract between NOCTIXAL SARL-S (“Noctixal”, the processor) and the client (the controller) under the Noctixal General Terms and Conditions. It applies wherever Noctixal processes personal data on behalf of the client in the course of hosting and operating the client’s website or software, per Article 28 of Regulation (EU) 2016/679 (GDPR). This annex exists in English only.
1. Subject matter and duration
Noctixal processes personal data on the client’s behalf to host, operate, maintain and support the service ordered (the tier and add-ons stated in the order contract). Processing lasts for the duration of the subscription and ends with the deletion or return described in Section 9.
2. Nature and purpose of processing
Hosting and storage, backup and restoration, transmission (serving the site or application to its visitors and users, sending its transactional email), technical support, and maintenance. Noctixal processes this data only to provide the contracted service, never for its own purposes.
3. Categories of data subjects and data
Data subjects: visitors and users of the client’s website or application, and the persons whose data the client stores in it (for example customers, staff, booking contacts). Categories of data: contact and identification data, account data, booking and order data, content the client or its users store in the service, and technical data (IP addresses, logs). The client does not commission the processing of special categories of data (Article 9 GDPR) unless separately agreed in writing.
4. Instructions
Noctixal processes personal data only on the client’s documented instructions, including regarding transfers to third countries, unless required to do so by Union or Luxembourg law; in that case Noctixal informs the client before processing, unless the law prohibits it. The contract, these terms and the service configuration chosen by the client constitute the initial instructions. Noctixal informs the client if, in its opinion, an instruction infringes data protection law.
5. Confidentiality
Persons authorised to process the personal data (today: the operator identified in the legal notice) are committed to confidentiality.
6. Security
Noctixal implements the technical and organisational measures appropriate to the risk (Article 32 GDPR): EU-only infrastructure, encryption in transit, access control with authentication, isolated per-client environments per the ordered tier, regular backups with the retention stated for the tier, logging, and timely security updates of the managed stack.
7. Sub-processors
The client gives general authorisation for the sub-processors named in the Privacy Policy (hosting, email delivery, payment processing). Noctixal informs the client of any intended addition or replacement, giving the client the opportunity to object on reasonable data-protection grounds within 14 days. Noctixal imposes on every sub-processor the same data-protection obligations as in this annex and remains fully liable to the client for their performance.
8. Assistance
Taking into account the nature of the processing, Noctixal assists the client with appropriate technical and organisational measures in fulfilling the client’s obligations to respond to data-subject requests (Articles 12 to 23 GDPR), and in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments), insofar as the information is available to Noctixal.
9. Personal data breaches
Noctixal notifies the client without undue delay after becoming aware of a personal data breach affecting the client’s data, with the information reasonably required for the client’s own notification obligations.
10. Deletion and return
At the end of the subscription the export and deletion rules of the General Terms apply: on request within the stated window, Noctixal returns the client’s data in a common machine-readable format, then deletes remaining personal data from the live systems; backups expire on their normal rolling schedule. Statutory retention duties (for example invoicing records) remain unaffected.
11. Audits
Noctixal makes available the information necessary to demonstrate compliance with this annex and allows for and contributes to audits conducted by the client or an auditor mandated by the client, on reasonable notice, at most once per year, during business hours, and without access to other clients’ data.
12. Transfers
Processing takes place within the European Union. Where a sub-processor named in the Privacy Policy involves a transfer outside the EU/EEA, it is covered by an adequacy decision or the European Commission’s Standard Contractual Clauses, as stated there.
13. Miscellaneous
This annex prevails over the General Terms for the processing it governs. Liability follows the General Terms. Luxembourg law applies; the courts of the district of Luxembourg have exclusive jurisdiction. Questions: contact@noctixal.com.