Bookxy policy
Data Processing Addendum
Last updated: July 26, 2026
This addendum applies when a client or partner (the controller) instructs Bookxy (the processor) to process personal data as part of a Bookxy engagement. It sits alongside our main service agreement.
1. Roles
The client is the controller of any personal data supplied to Bookxy for a project. Bookxy acts as processor and only processes that data on the client's documented instructions.
2. Subject matter and duration
Processing lasts for the term of the underlying service agreement and covers the personal data described in the project brief - typically names, contact details, and any content the controller uploads for annotation or evaluation.
3. Contributor duties
Everyone working on the platform is bound by written confidentiality obligations and by Bookxy's Community Guidelines. Access to project data is limited to contributors assigned to that project.
4. Security
Bookxy applies appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control, audit logging, and regular security reviews. Details are available on request under NDA.
5. Sub-processors
Bookxy uses trusted sub-processors for cloud hosting, identity verification, payments, and communications. A current list is available on request. We give controllers advance notice of material changes to that list and a right to object.
6. Cross-border transfers
Personal data may be processed in the client's country, in other AfCFTA member states, and in the countries where our cloud providers operate. Transfers use approved safeguards under the applicable African data protection laws (for example the Nigeria Data Protection Act, POPIA in South Africa, and the Kenya Data Protection Act) and, where relevant, equivalent international frameworks.
7. Data subject requests
If a data subject contacts Bookxy directly about data belonging to a client project, we will not respond on our own. We will pass the request to the controller and support them in answering it.
8. Breach notification
Bookxy will notify the controller without undue delay after becoming aware of a personal data breach affecting the project, and will provide the information the controller needs to meet its own notification duties.
9. Deletion and return
On termination of the underlying agreement, Bookxy will delete or return the project's personal data as instructed, except where local law requires retention.
10. Audits
Controllers may audit Bookxy's compliance with this addendum once per year, or more often if required by a regulator, on reasonable notice and under NDA.
Questions? Reach us at support@bookxy.com.