Axle Data Processing Agreement
Startup Sales Consulting LLC (d/b/a Axle) | Last revised: August 17, 2026
This Data Processing Agreement ("DPA") is entered into between the client identified on the applicable Order Form ("Client") and Startup Sales Consulting LLC, a Delaware limited liability company doing business as Axle ("Axle"). This DPA is subject to and incorporated into the services agreement between Axle and Client consisting of the Axle Service Terms and Conditions and the applicable Order Form(s) (the "Services Agreement"), and is effective as of the effective date of the Services Agreement. Capitalized terms not defined in this DPA have the meanings given in the Services Agreement. Under the Services Agreement, Axle provides services that involve processing Client data, which may include Personal Information.
1. Definitions and Interpretation
"Authorized Persons" means the persons or categories of persons Client authorizes to give Axle Personal Information processing instructions.
"Business Purpose" means the services described in the Services Agreement and the purposes identified in Appendix A.
"Data Subject" means an identified or identifiable individual to whom Personal Information relates.
"Personal Information" means any information Axle processes for Client that identifies or relates to an individual who can be identified, directly or indirectly, from that information alone or combined with other information in Axle's possession or control, or that applicable Privacy and Data Protection Requirements otherwise define as protected personal information or personal data.
"Processing" means any operation performed on Personal Information, including collecting, recording, storing, organizing, amending, retrieving, using, disclosing, transferring, restricting, erasing, or destroying it, and any other activity that applicable law defines as processing.
"Privacy and Data Protection Requirements" means all applicable federal, state, and foreign laws and regulations relating to the processing, protection, or privacy of Personal Information, including as applicable the California Consumer Privacy Act as amended ("CCPA"), other U.S. state privacy laws, the EU and UK General Data Protection Regulation ("GDPR"), and telecommunications privacy laws applicable to call recording and text messaging.
"Security Breach" means any act or omission that compromises the security, confidentiality, or integrity of Personal Information or the safeguards protecting it, including loss of, unauthorized access to, or unauthorized disclosure or acquisition of Personal Information.
"Standard Contractual Clauses" or "SCCs" means the European Commission's standard contractual clauses for transfers of personal data to third countries adopted under Commission Implementing Decision (EU) 2021/914.
The Appendices form part of this DPA. A reference to writing includes email. In the event of conflict: this DPA prevails over the Services Agreement with respect to the processing of Personal Information; the body of this DPA prevails over the Appendices; and any executed SCCs prevail over this DPA.
2. Roles; Personal Information Types and Processing Purposes
As between the Parties, Client is the controller (or business) and Axle is the processor (or service provider) with respect to Personal Information processed under this DPA. Client retains control of the Personal Information and is responsible for: compliance with Privacy and Data Protection Requirements applicable to Client, including providing notices and obtaining consents from Data Subjects (including recording and messaging consents); the accuracy and lawful origin of the Personal Information; and the processing instructions it gives Axle. Appendix A describes the categories of Personal Information and Data Subjects processed under this DPA. Client discloses Personal Information to Axle only for the limited and specified Business Purposes.
3. Axle Obligations
Axle will process, retain, use, and disclose Personal Information only: (a) as necessary for the Business Purposes; (b) in accordance with Client's documented instructions, including the Services Agreement and Client's configuration of the Service; and (c) in compliance with this DPA and applicable Privacy and Data Protection Requirements. Axle will promptly notify Client if, in Axle's opinion, an instruction violates Privacy and Data Protection Requirements. Axle will promptly comply with Client instructions to amend, transfer, or delete Personal Information, and to stop or remediate unauthorized processing.
Axle will not: sell Personal Information; share it for cross-context behavioral advertising; retain, use, or disclose it outside the direct business relationship with Client or for any purpose other than the Business Purposes (including any commercial purpose of Axle's own); or combine it with personal information Axle receives from other sources, except as permitted for service providers under the CCPA. Axle certifies that it understands and will comply with these restrictions. Axle will disclose Personal Information to third parties only as authorized by Client, as permitted under this DPA, or as required by law; if disclosure is required by law, Axle will inform Client before disclosing unless legally prohibited from doing so.
Axle will provide reasonable assistance to Client in meeting Client's compliance obligations under Privacy and Data Protection Requirements, taking into account the nature of Axle's processing and the information available to Axle, and will notify Client of legal or regulatory changes known to Axle that materially affect Axle's ability to perform under this DPA.
4. Personnel
Axle will limit access to Personal Information to personnel who need access to perform under this DPA, and only to the data required for their duties. Axle will ensure such personnel are bound by written or statutory confidentiality obligations, receive appropriate privacy and security training, and are subject to reasonable measures to ensure their reliability.
5. Security
Axle will implement and maintain appropriate technical and organizational measures designed to protect Personal Information against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, as described in Appendix C. Axle will maintain reasonable backup and restoration procedures designed to prevent the loss or corruption of Personal Information, and will update its measures as reasonably necessary to reflect technological developments.
6. Security Breaches
Axle will notify Client without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Security Breach affecting Personal Information. The notice will include, to the extent known, the nature of the breach, the categories and approximate volume of Personal Information and Data Subjects affected, the measures taken or proposed to address it, and a contact point. The Parties will cooperate in good faith to investigate and remediate the breach, and Axle will provide Client with reasonable assistance, including relevant logs and records. As between the Parties, Client has sole authority to determine whether and how to notify affected Data Subjects, regulators, or others, and Axle will not make any such notification identifying Client without Client's prior written consent unless required by law. If a Security Breach results from Axle's breach of this DPA, Axle will reimburse Client's reasonable and documented out-of-pocket breach-response costs, subject to the limitations of liability in the Services Agreement.
7. Cross-Border Transfers
Axle will store and process Personal Information only in the countries listed in Appendix A and will not transfer Personal Information outside those countries without Client's prior written consent. Any permitted transfer will comply with applicable Privacy and Data Protection Requirements, including, where applicable, the mechanisms described in Appendix B.
8. Subprocessors
Client provides general authorization for Axle to engage the subprocessors listed in Appendix A. Axle will: (a) give Client at least fourteen (14) days' prior notice of any intended addition or replacement of a subprocessor, during which Client may object on reasonable data-protection grounds (and if the Parties cannot resolve a reasonable objection, Client may terminate the affected portion of the Service); (b) impose on each subprocessor, by written contract, data protection obligations materially equivalent to those in this DPA; and (c) remain fully liable to Client for the performance of each subprocessor's obligations.
9. Data Subject Requests and Complaints
Axle will notify Client without undue delay if Axle receives a request from a Data Subject to exercise rights regarding Personal Information (including access, correction, deletion, restriction, portability, or opt-out requests) or any complaint or regulatory communication relating to the processing of Personal Information under this DPA. Axle will not respond to such a request except to direct the Data Subject to Client, unless instructed by Client or required by law, and will provide Client with reasonable assistance in responding.
10. Term
This DPA remains in effect for as long as the Services Agreement is in effect or Axle retains Personal Information processed under it, whichever is longer. Provisions that by their nature should survive termination survive, including Sections 3, 5, 6, 11, and 12.
11. Return and Deletion
On Client's request during the term, Axle will provide Client with a copy of Personal Information in a commonly used, machine-readable format. On termination or expiration of the Services Agreement, Axle will, at Client's election, return or delete the Personal Information, except that Axle may retain: (a) one archival copy solely to demonstrate compliance and resolve disputes; and (b) Personal Information that Axle is required by law to retain, in which case Axle will notify Client of the legal basis, the retention period, and the deletion timeline, and will continue to protect the retained information under this DPA.
12. Records and Audit
Axle will maintain accurate records of its processing of Personal Information sufficient to demonstrate compliance with this DPA, including records of security measures, subprocessors, and processing purposes. No more than once in any twelve (12) month period (except following a Security Breach or where required by a regulator), and on at least thirty (30) days' written notice, Axle will make such records available to Client and will respond to Client's reasonable written security and compliance questionnaires, and will permit Client or its independent auditor (bound by confidentiality) to audit Axle's compliance with this DPA during normal business hours, at Client's expense and without unreasonable disruption to Axle's operations. This right continues for one (1) year after termination.
13. General
Each Party is responsible for its own compliance with Privacy and Data Protection Requirements. Client represents that its processing instructions comply with applicable law. This DPA is subject to the limitations of liability in the Services Agreement. Notices under this DPA must be in writing; notices to Client will be sent to the email address on the applicable Order Form, and notices to Axle to hello@getaxle.ai.
Appendix A. Processing Details
Business Purposes
- Operating the Call Answering service: answering, routing, recording, and transcribing calls with End Users; capturing job, site, and contact details; sending job notifications and summaries to Client; and scheduling or dispatching work in Client's systems as configured.
- Operating the Quote Automation service: ingesting Client's price book, catalog, inventory, templates, and historical quotes; generating bills of materials, quotes, and proposals; and delivering quotes to End Users by text message or email as configured.
- Providing support, security, billing, and service analytics, and improving the Service for Client as described in the Services Agreement.
Categories of Personal Information
- Names, phone numbers, email addresses, company names, and job titles.
- Call audio recordings, call transcripts, and the contents of text messages and emails handled through the Service.
- Order, job, and quote details, including requested products and services, quantities, site or lease locations, and delivery information.
- Communication history, scheduling information, and related metadata.
Data Subject Types
- End Users: Client's customers, prospective customers, and other individuals who call or message Client through the Service.
- Client personnel, including office staff and field technicians who use or are referenced in the Service.
- Individuals submitting inquiries to Client.
Processing Duration
For the term of the Services Agreement, plus any retention period specified by Client in writing or required by law, subject to Section 11 (Return and Deletion).
Approved Subprocessors
This list reflects Axle's subprocessors as of the date of this DPA and is updated from time to time in accordance with Section 8.
| Provider | Function | Location |
|---|---|---|
| Railway | Application hosting and infrastructure | USA |
| Cloudflare | Network proxy and TLS termination for web and application traffic | USA / Global |
| Anthropic | AI language models | USA |
| OpenAI | AI language models | USA |
| Deepgram | Speech-to-text transcription | USA |
| Vapi | Voice AI orchestration | USA |
| Twilio | Telephony, call connectivity, and SMS delivery | USA |
| Business email | USA | |
| Resend | Transactional email (account invites and password resets) | USA |
| Microsoft (Clarity) | Product usage analytics | USA |
| Sentry | Error tracking and application monitoring | USA |
Countries Where Personal Information May Be Stored or Processed
United States.
Appendix B. International Transfers
This Appendix applies only if and to the extent Axle processes Personal Information subject to the GDPR or UK GDPR that is transferred to a country not recognized as providing adequate protection. In that case: the SCCs (Module Two: controller to processor) are incorporated into this DPA, with Client as data exporter and Axle as data importer; the optional docking clause applies; the subprocessor objection mechanics of Section 8 apply; Appendix A supplies the information required by the SCC annexes and Appendix C supplies the security measures; and for transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs applies with the information above. If the Parties execute SCCs separately, those prevail over this Appendix.
Appendix C. Technical and Organizational Measures
- Encryption of Personal Information in transit (TLS) and at rest.
- Access controls based on least privilege, unique credentials, and multi-factor authentication for administrative access.
- Logical separation of each customer's data, including catalogs, quotes, and call records.
- Logging and monitoring of production access and material system events.
- Secure software development practices, including code review and dependency management for changes affecting Personal Information.
- Vendor diligence for subprocessors, including review of security practices and contractual data protection terms.
- Regular backups of production data and tested restoration procedures.
- A written incident response process covering detection, containment, remediation, and the notification obligations in Section 6.
- Confidentiality obligations and security awareness for all personnel with access to Personal Information.
- Deletion and return procedures implementing Section 11 of this DPA.