Quote Automation Call Answering FAQ Contact Book a demo
This Data Processing Agreement is incorporated into Axle customer agreements where applicable to the customer's use of the service. See also the Service Terms and Conditions and the Privacy Policy. A separately signed copy is available on request.

Axle Data Processing Agreement

Startup Sales Consulting LLC (d/b/a Axle) | Last revised: August 17, 2026

This Data Processing Agreement ("DPA") is entered into between the client identified on the applicable Order Form ("Client") and Startup Sales Consulting LLC, a Delaware limited liability company doing business as Axle ("Axle"). This DPA is subject to and incorporated into the services agreement between Axle and Client consisting of the Axle Service Terms and Conditions and the applicable Order Form(s) (the "Services Agreement"), and is effective as of the effective date of the Services Agreement. Capitalized terms not defined in this DPA have the meanings given in the Services Agreement. Under the Services Agreement, Axle provides services that involve processing Client data, which may include Personal Information.

1. Definitions and Interpretation

"Authorized Persons" means the persons or categories of persons Client authorizes to give Axle Personal Information processing instructions.

"Business Purpose" means the services described in the Services Agreement and the purposes identified in Appendix A.

"Data Subject" means an identified or identifiable individual to whom Personal Information relates.

"Personal Information" means any information Axle processes for Client that identifies or relates to an individual who can be identified, directly or indirectly, from that information alone or combined with other information in Axle's possession or control, or that applicable Privacy and Data Protection Requirements otherwise define as protected personal information or personal data.

"Processing" means any operation performed on Personal Information, including collecting, recording, storing, organizing, amending, retrieving, using, disclosing, transferring, restricting, erasing, or destroying it, and any other activity that applicable law defines as processing.

"Privacy and Data Protection Requirements" means all applicable federal, state, and foreign laws and regulations relating to the processing, protection, or privacy of Personal Information, including as applicable the California Consumer Privacy Act as amended ("CCPA"), other U.S. state privacy laws, the EU and UK General Data Protection Regulation ("GDPR"), and telecommunications privacy laws applicable to call recording and text messaging.

"Security Breach" means any act or omission that compromises the security, confidentiality, or integrity of Personal Information or the safeguards protecting it, including loss of, unauthorized access to, or unauthorized disclosure or acquisition of Personal Information.

"Standard Contractual Clauses" or "SCCs" means the European Commission's standard contractual clauses for transfers of personal data to third countries adopted under Commission Implementing Decision (EU) 2021/914.

The Appendices form part of this DPA. A reference to writing includes email. In the event of conflict: this DPA prevails over the Services Agreement with respect to the processing of Personal Information; the body of this DPA prevails over the Appendices; and any executed SCCs prevail over this DPA.

2. Roles; Personal Information Types and Processing Purposes

As between the Parties, Client is the controller (or business) and Axle is the processor (or service provider) with respect to Personal Information processed under this DPA. Client retains control of the Personal Information and is responsible for: compliance with Privacy and Data Protection Requirements applicable to Client, including providing notices and obtaining consents from Data Subjects (including recording and messaging consents); the accuracy and lawful origin of the Personal Information; and the processing instructions it gives Axle. Appendix A describes the categories of Personal Information and Data Subjects processed under this DPA. Client discloses Personal Information to Axle only for the limited and specified Business Purposes.

3. Axle Obligations

Axle will process, retain, use, and disclose Personal Information only: (a) as necessary for the Business Purposes; (b) in accordance with Client's documented instructions, including the Services Agreement and Client's configuration of the Service; and (c) in compliance with this DPA and applicable Privacy and Data Protection Requirements. Axle will promptly notify Client if, in Axle's opinion, an instruction violates Privacy and Data Protection Requirements. Axle will promptly comply with Client instructions to amend, transfer, or delete Personal Information, and to stop or remediate unauthorized processing.

Axle will not: sell Personal Information; share it for cross-context behavioral advertising; retain, use, or disclose it outside the direct business relationship with Client or for any purpose other than the Business Purposes (including any commercial purpose of Axle's own); or combine it with personal information Axle receives from other sources, except as permitted for service providers under the CCPA. Axle certifies that it understands and will comply with these restrictions. Axle will disclose Personal Information to third parties only as authorized by Client, as permitted under this DPA, or as required by law; if disclosure is required by law, Axle will inform Client before disclosing unless legally prohibited from doing so.

Axle will provide reasonable assistance to Client in meeting Client's compliance obligations under Privacy and Data Protection Requirements, taking into account the nature of Axle's processing and the information available to Axle, and will notify Client of legal or regulatory changes known to Axle that materially affect Axle's ability to perform under this DPA.

4. Personnel

Axle will limit access to Personal Information to personnel who need access to perform under this DPA, and only to the data required for their duties. Axle will ensure such personnel are bound by written or statutory confidentiality obligations, receive appropriate privacy and security training, and are subject to reasonable measures to ensure their reliability.

5. Security

Axle will implement and maintain appropriate technical and organizational measures designed to protect Personal Information against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, as described in Appendix C. Axle will maintain reasonable backup and restoration procedures designed to prevent the loss or corruption of Personal Information, and will update its measures as reasonably necessary to reflect technological developments.

6. Security Breaches

Axle will notify Client without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Security Breach affecting Personal Information. The notice will include, to the extent known, the nature of the breach, the categories and approximate volume of Personal Information and Data Subjects affected, the measures taken or proposed to address it, and a contact point. The Parties will cooperate in good faith to investigate and remediate the breach, and Axle will provide Client with reasonable assistance, including relevant logs and records. As between the Parties, Client has sole authority to determine whether and how to notify affected Data Subjects, regulators, or others, and Axle will not make any such notification identifying Client without Client's prior written consent unless required by law. If a Security Breach results from Axle's breach of this DPA, Axle will reimburse Client's reasonable and documented out-of-pocket breach-response costs, subject to the limitations of liability in the Services Agreement.

7. Cross-Border Transfers

Axle will store and process Personal Information only in the countries listed in Appendix A and will not transfer Personal Information outside those countries without Client's prior written consent. Any permitted transfer will comply with applicable Privacy and Data Protection Requirements, including, where applicable, the mechanisms described in Appendix B.

8. Subprocessors

Client provides general authorization for Axle to engage the subprocessors listed in Appendix A. Axle will: (a) give Client at least fourteen (14) days' prior notice of any intended addition or replacement of a subprocessor, during which Client may object on reasonable data-protection grounds (and if the Parties cannot resolve a reasonable objection, Client may terminate the affected portion of the Service); (b) impose on each subprocessor, by written contract, data protection obligations materially equivalent to those in this DPA; and (c) remain fully liable to Client for the performance of each subprocessor's obligations.

9. Data Subject Requests and Complaints

Axle will notify Client without undue delay if Axle receives a request from a Data Subject to exercise rights regarding Personal Information (including access, correction, deletion, restriction, portability, or opt-out requests) or any complaint or regulatory communication relating to the processing of Personal Information under this DPA. Axle will not respond to such a request except to direct the Data Subject to Client, unless instructed by Client or required by law, and will provide Client with reasonable assistance in responding.

10. Term

This DPA remains in effect for as long as the Services Agreement is in effect or Axle retains Personal Information processed under it, whichever is longer. Provisions that by their nature should survive termination survive, including Sections 3, 5, 6, 11, and 12.

11. Return and Deletion

On Client's request during the term, Axle will provide Client with a copy of Personal Information in a commonly used, machine-readable format. On termination or expiration of the Services Agreement, Axle will, at Client's election, return or delete the Personal Information, except that Axle may retain: (a) one archival copy solely to demonstrate compliance and resolve disputes; and (b) Personal Information that Axle is required by law to retain, in which case Axle will notify Client of the legal basis, the retention period, and the deletion timeline, and will continue to protect the retained information under this DPA.

12. Records and Audit

Axle will maintain accurate records of its processing of Personal Information sufficient to demonstrate compliance with this DPA, including records of security measures, subprocessors, and processing purposes. No more than once in any twelve (12) month period (except following a Security Breach or where required by a regulator), and on at least thirty (30) days' written notice, Axle will make such records available to Client and will respond to Client's reasonable written security and compliance questionnaires, and will permit Client or its independent auditor (bound by confidentiality) to audit Axle's compliance with this DPA during normal business hours, at Client's expense and without unreasonable disruption to Axle's operations. This right continues for one (1) year after termination.

13. General

Each Party is responsible for its own compliance with Privacy and Data Protection Requirements. Client represents that its processing instructions comply with applicable law. This DPA is subject to the limitations of liability in the Services Agreement. Notices under this DPA must be in writing; notices to Client will be sent to the email address on the applicable Order Form, and notices to Axle to hello@getaxle.ai.

Appendix A. Processing Details

Business Purposes

Categories of Personal Information

Data Subject Types

Processing Duration

For the term of the Services Agreement, plus any retention period specified by Client in writing or required by law, subject to Section 11 (Return and Deletion).

Approved Subprocessors

This list reflects Axle's subprocessors as of the date of this DPA and is updated from time to time in accordance with Section 8.

Countries Where Personal Information May Be Stored or Processed

United States.

Appendix B. International Transfers

This Appendix applies only if and to the extent Axle processes Personal Information subject to the GDPR or UK GDPR that is transferred to a country not recognized as providing adequate protection. In that case: the SCCs (Module Two: controller to processor) are incorporated into this DPA, with Client as data exporter and Axle as data importer; the optional docking clause applies; the subprocessor objection mechanics of Section 8 apply; Appendix A supplies the information required by the SCC annexes and Appendix C supplies the security measures; and for transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs applies with the information above. If the Parties execute SCCs separately, those prevail over this Appendix.

Appendix C. Technical and Organizational Measures