Data Processing Addendum
Last updated: 11 June 2026
This Data Processing Addendum ("DPA") supplements the FYXO Terms of Service and applies when Fyxo Limited ("Processor") processes personal data on behalf of a business customer or channel partner ("Controller") under the EU GDPR and/or UK GDPR.
If you are a B2B customer, a reseller, an installer, or a partner whose end-customers' personal data will be processed by FYXO, this DPA forms part of our contract. To execute, email a signed copy to kgma@fyxo.io; otherwise, your use of the Service in respect of end-customer data constitutes acceptance of these terms.
1. Definitions
Capitalised terms have the meaning given in the GDPR. "End-Customer Data" means personal data of Controller's end-customers (including device data, energy usage, contact details) that Processor processes on behalf of Controller through the Service.
2. Subject matter and duration
Processor will process End-Customer Data only on Controller's documented instructions and for the duration of the Service contract, plus any retention period required by law.
3. Nature and purpose
Processing is performed to provide the Service: monitoring electricity prices, optimising energy assets, executing dispatch commands, producing reports, and providing technical support.
4. Categories of data and data subjects
- Categories of data: contact details, account identifiers, device identifiers, electricity usage and tariff data, schedule and dispatch decisions, audit logs.
- Data subjects: end-customers, household members, employees of Controller, installer personnel.
5. Obligations of Processor
Processor shall:
- process End-Customer Data only on documented instructions from Controller, including with regard to international transfers;
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (see Annex A below);
- not engage a sub-processor without prior general or specific written authorisation;
- assist Controller, taking into account the nature of processing, in responding to data-subject requests and security incidents;
- at Controller's choice, delete or return all End-Customer Data after the end of the Service, subject to retention required by law;
- make available all information necessary to demonstrate compliance with Article 28 GDPR.
6. Sub-processors
Controller provides general authorisation for Processor to engage sub-processors listed in the Privacy Policy. Processor will notify Controller of any new sub-processor at least 30 days in advance. Controller may object on reasonable grounds within that period.
7. International transfers
End-Customer Data is primarily stored in the EU (Frankfurt). Any transfer outside the EEA/UK is covered by Standard Contractual Clauses (SCCs) and applicable supplementary measures.
8. Security incidents
Processor shall notify Controller without undue delay (and in any event within 72 hours of becoming aware) of any Personal Data Breach affecting End-Customer Data, providing the information needed for Controller to fulfil its Article 33 obligations.
9. Audits
Processor will make available certifications, security reports, or summaries on request to demonstrate compliance. On-site audits require 30 days' written notice and reasonable scope, must not unreasonably disrupt Processor's business, and are at Controller's cost.
10. Liability
Each party's liability under this DPA is subject to the limitation of liability in the FYXO Terms of Service. Nothing in this DPA limits liability that cannot be limited under applicable law.
11. Order of precedence
If there is any conflict between this DPA, the Terms of Service, and applicable law, the order of precedence is: (a) applicable law; (b) this DPA; (c) the Terms of Service.
Annex A — Security measures
- Encryption in transit (TLS 1.2+) and at rest (Supabase storage encryption)
- OAuth 2.0 with PKCE (S256) and refresh-token rotation; revocation detection
- Row-level security policies in the database
- Rate limiting, geofencing, sandbox validation, and conflict locks for write operations
- Audit logging of every write action with operator, asset, and timestamp
- Principle of least privilege for staff access
- Regular dependency updates and supply-chain attestation (npm provenance for client packages)
- Incident response and breach-notification procedures
Signatures
Controller: signature, name, title, date, company, address
Processor: Fyxo Limited, CRO 813642, 4 Kirkpatrick House, Spencer Dock, Dublin, D01 DY86, Ireland.