This Data Processing Agreement ("DPA") forms part of the Terms of Service between Nuevexa ("Provider," "We," "Processor"), operating the BayX platform, and the Customer ("Controller," "You").
Registered Office: LR Towers, Kochi, Kerala, India 682025
GSTIN: 32CFKPJ9589J1ZQ
1. DEFINITIONS
"Personal Data" means any information relating to an identified or identifiable person that the Customer uploads to the Platform.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
"Applicable Data Protection Law" means GDPR, UK GDPR, India DPDP Act 2023, and other applicable privacy laws.
"Sub-processor" means any third party We engage to process Personal Data.
2. ROLES AND SCOPE
You (Customer) are the Controller who determines how and why Personal Data is processed.
We (Provider) are the Processor who processes Personal Data only on Your behalf and according to Your instructions.
This DPA applies to all Personal Data processed through the BayX Platform, including customer records, vehicle information, service history, and communications.
3. PROCESSING INSTRUCTIONS
We will process Personal Data only:
- To provide the BayX Services as described in the Terms of Service
- According to Your instructions through use of the Platform
- As You direct in writing to privacy@bayx.app
- As required by law
If we believe any instruction violates data protection law, we will notify You immediately.
4. YOUR RESPONSIBILITIES (CONTROLLER)
You represent and warrant that:
- You have lawful bases to collect and process Personal Data
- You have obtained necessary consents from individuals
- You have provided privacy notices to individuals
- Your instructions comply with applicable data protection laws
5. OUR OBLIGATIONS (PROCESSOR)
We will:
- Process Personal Data only per Your instructions
- Keep Personal Data confidential
- Implement appropriate security measures
- Assist You with data subject rights requests
- Notify You of data breaches within 72 hours
- Delete or return Personal Data upon termination
6. SECURITY MEASURES
We implement industry-standard security measures including:
- Encryption of data in transit (TLS 1.2+)
- Access controls and authentication
- Regular security monitoring and updates
- Automated backups and disaster recovery
- Security assessments of Sub-processors
7. SUB-PROCESSORS
We use the following types of Sub-processors:
- Cloud hosting providers (US, Europe, or Singapore)
- Email delivery services
- Payment processors
- Analytics and monitoring tools
Notice of Changes: We will notify You 30 days before adding new Sub-processors. You may object within 14 days if You have reasonable data protection concerns.
8. DATA SUBJECT RIGHTS
We will assist You in responding to requests from individuals to access, correct, delete, or export their Personal Data by providing Platform tools and responding to Your requests within 10 business days.
If an individual contacts us directly, we will redirect them to You.
9. DATA BREACHES
If a security breach affects Your Personal Data, we will notify You within 72 hours and provide details of what happened, what data was affected, and what steps we're taking to address it.
You remain responsible for determining whether to notify authorities or affected individuals per applicable law.
10. INTERNATIONAL DATA TRANSFERS
Personal Data may be processed in India, United States, Europe, or Singapore.
For EEA/UK Customers: We use Standard Contractual Clauses (SCCs) approved by the European Commission for transfers outside the EEA/UK.
For other jurisdictions: We comply with applicable cross-border transfer requirements.
11. DATA RETENTION AND DELETION
We retain Personal Data during Your active subscription plus 30 days after termination to allow data retrieval.
To export Your data: Contact privacy@bayx.app (available as CSV/JSON export)
After 30 days: We permanently delete all Personal Data unless legally required to retain it.
12. AUDITS
Upon reasonable written request (maximum once per year), we will provide documentation of our security and data protection practices, subject to confidentiality.
13. LIABILITY
Liability under this DPA is subject to the limitations in Section 14 of the Terms of Service, except for liability that cannot be limited by law (fraud, gross negligence, intentional violations).
14. TERM AND TERMINATION
This DPA remains in effect during Your subscription and for 30 days after termination (for data retention period).
Sections 6 (Security), 11 (Deletion), and 13 (Liability) survive termination.
15. AMENDMENTS
We may update this DPA to reflect legal changes. Material changes will be notified 30 days in advance.
16. GOVERNING LAW
This DPA is governed by the laws of India, except where Standard Contractual Clauses apply (which have their own governing law provisions).
17. CONTACT INFORMATION
For all data protection inquiries:
Email: privacy@bayx.app
Data Protection Officer:
Email: privacy@bayx.app
Technical Support:
Email: support@bayx.app
Contact Information
Legal Inquiries: privacy@bayx.app
Governing Law: India


