Data Processing Agreement
Effective date: January 1, 2026
This Data Processing Addendum ("DPA") forms part of the Bixora Terms of Service between VR Data Experts Inc., doing business as Bixora ("Bixora", "Processor") and the Customer ("Controller"). It applies to personal information Bixora processes on the Customer's behalf in providing the Services.
1. Roles
The Customer is the controller (or, in Canada, the organization accountable) for personal information about its callers, leads, website visitors and users. Bixora is the processor (service provider) and acts on the Customer's documented instructions, which are the Terms, this DPA, the Customer's configuration of the Services, and any written instructions the parties agree.
Bixora is an independent controller for the limited personal information it collects about the Customer's Users and Requesters for account administration, billing, security and B2B marketing, as described in the Privacy Policy.
2. Details of processing
| Subject matter | Attribution, recording, transcription and grading of calls and forms; sending outcome signals to advertising platforms; reporting |
| Duration | The term of the Customer's account plus the deletion period in Section 9 |
| Nature and purpose | Hosting, collection, recording, transcription, automated analysis, storage, transmission to platforms the Customer connects, display to the Customer |
| Categories of data subjects | Callers, website visitors, leads, the Customer's users and staff |
| Categories of personal information | Contact details (phone, email, name), call audio and transcripts, form content, click and session identifiers, IP address, device data, grading outputs, and any personal information callers or visitors choose to provide |
| Sensitive information | Not intended. The Customer must not direct sensitive information to the Services without prior written agreement |
3. Bixora's obligations
Bixora will:
- process personal information only on the Customer's documented instructions, unless required by law (in which case Bixora will inform the Customer before processing, unless the law prohibits it);
- ensure personnel with access are bound by confidentiality;
- implement the technical and organizational measures in Annex 1;
- engage service providers only under Section 5;
- assist the Customer, taking into account the nature of processing, with responding to data-subject requests, with security, breach notification, and privacy impact assessments, at the Customer's reasonable cost where the request is extensive;
- delete or return personal information at the end of the Services per Section 9;
- make available information reasonably necessary to demonstrate compliance and allow audits per Section 8.
4. Customer's obligations
The Customer warrants that it has a lawful basis to collect the personal information it directs to the Services and to share it with Bixora and with the advertising platforms it connects; that it has provided all notices and obtained all consents required, including for call recording; that its instructions comply with law; and that it will not direct sensitive personal information to the Services without written agreement.
5. Service providers
The Customer authorizes Bixora to use service providers (subprocessors) for hosting and database infrastructure, telephony, transcription, AI processing, workflow automation, payments, transactional email, analytics and bot protection. Bixora will provide the current list of providers relevant to the Customer's account on written request, and will give at least fifteen (15) days' notice (by email or portal notice) before adding a new provider that will process the Customer's personal information. If the Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected Services. Bixora remains responsible for its providers' performance.
6. Data-subject requests
Bixora will, without undue delay, forward to the Customer any request it receives from a data subject relating to the Customer's data, and will not respond except to acknowledge receipt and direct the person to the Customer, unless the Customer instructs otherwise or the law requires.
7. Security incidents
Bixora will notify the Customer without undue delay, and in any case within seventy-two (72) hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Customer's personal information. The notice will describe what is known, the likely consequences, and the measures taken or proposed. Bixora will cooperate reasonably with the Customer's investigation and notification obligations.
8. Audits
Once per year, or after a security incident affecting the Customer, the Customer may request written information and reasonable evidence (such as summaries of policies, third-party assessments, or certifications when available) to verify compliance with this DPA. Where that is not sufficient, the Customer may conduct an audit on at least thirty (30) days' notice, during business hours, at its own cost, under confidentiality, limited to the Services and not disrupting Bixora's operations or exposing other customers' data.
9. Return and deletion
On termination, the Customer may export its data from the portal. Bixora will delete the Customer's personal information within ninety (90) days after termination, except (a) backups, which are overwritten on the normal cycle, (b) information Bixora must retain by law, and (c) aggregated or de-identified data. On written request Bixora will confirm deletion.
10. International transfers
Personal information is processed in Canada and the United States, and in other countries where service providers operate. Where a transfer requires additional safeguards, the parties agree the European Commission's Standard Contractual Clauses (Module 2, Controller to Processor) and, for the UK, the UK Addendum, are incorporated by reference, with Bixora as data importer, and the Customer may request a signed copy.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms.
Annex 1 — Security measures
- Encryption in transit (TLS) for all connections; encryption at rest for database and file storage.
- Authentication via managed identity provider; passwords hashed; admin access limited by role; multi-factor authentication for Bixora staff.
- Per-customer data isolation enforced at the database layer (row-level security).
- Least-privilege service credentials, stored in a secrets manager, rotated on personnel change or suspected exposure.
- Logging of administrative actions and outcome-signal transmissions; logs retained for audit.
- Automated bot protection and rate limiting on public endpoints.
- Vendor due diligence; service providers bound by written data-protection terms.
- Backups with defined retention; tested restore procedures.
- Incident response procedure with defined roles and notification steps.
- Access to recordings and transcripts limited to the Customer's authorized Users and to Bixora support staff on a need-to-know basis.