Bookxy policy

Data Processing Addendum

Last updated: July 26, 2026

This addendum applies when a client or partner (the controller) instructs Bookxy (the processor) to process personal data as part of a Bookxy engagement. It sits alongside our main service agreement.

1. Roles

The client is the controller of any personal data supplied to Bookxy for a project. Bookxy acts as processor and only processes that data on the client's documented instructions.

2. Subject matter and duration

Processing lasts for the term of the underlying service agreement and covers the personal data described in the project brief - typically names, contact details, and any content the controller uploads for annotation or evaluation.

3. Contributor duties

Everyone working on the platform is bound by written confidentiality obligations and by Bookxy's Community Guidelines. Access to project data is limited to contributors assigned to that project.

4. Security

Bookxy applies appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control, audit logging, and regular security reviews. Details are available on request under NDA.

5. Sub-processors

Bookxy uses trusted sub-processors for cloud hosting, identity verification, payments, and communications. A current list is available on request. We give controllers advance notice of material changes to that list and a right to object.

6. Cross-border transfers

Personal data may be processed in the client's country, in other AfCFTA member states, and in the countries where our cloud providers operate. Transfers use approved safeguards under the applicable African data protection laws (for example the Nigeria Data Protection Act, POPIA in South Africa, and the Kenya Data Protection Act) and, where relevant, equivalent international frameworks.

7. Data subject requests

If a data subject contacts Bookxy directly about data belonging to a client project, we will not respond on our own. We will pass the request to the controller and support them in answering it.

8. Breach notification

Bookxy will notify the controller without undue delay after becoming aware of a personal data breach affecting the project, and will provide the information the controller needs to meet its own notification duties.

9. Deletion and return

On termination of the underlying agreement, Bookxy will delete or return the project's personal data as instructed, except where local law requires retention.

10. Audits

Controllers may audit Bookxy's compliance with this addendum once per year, or more often if required by a regulator, on reasonable notice and under NDA.

Questions? Reach us at support@bookxy.com.