Last updated: [October 5, 2026]
Data Processing Addendum
01
How This Addendum Applies
This Data Processing Addendum (“DPA”) is part of the Muvix Terms of Service or other written agreement (the “Agreement”) between Muvix, Inc. (“Muvix”) and the customer that accepted the Agreement (“Customer”). It governs how Muvix handles personal information that Customer puts into, or collects through, the Services. If this DPA and the Agreement conflict on the handling of personal information, this DPA controls.
02
Definitions
Customer Personal Information means personal information about leads, consumers, and Customer’s own users that Muvix processes for Customer through the Services.
Privacy Laws means the U.S. federal and state privacy and data security laws that apply to Customer Personal Information, including the Gramm-Leach-Bliley Act, state insurance privacy laws, and state consumer privacy laws such as the California Consumer Privacy Act.
Security Incident means confirmed unauthorized access to, or loss or disclosure of, Customer Personal Information held by Muvix or its Subprocessors.
Subprocessor means a third party Muvix uses to process Customer Personal Information.
Other capitalized terms have the meaning given in the Agreement.
03
Roles
Customer decides why and how Customer Personal Information is processed. Muvix processes it only on Customer’s behalf, as a service provider or processor under Privacy Laws. Each party will comply with the Privacy Laws that apply to it.
Customer is responsible for its privacy notices, for obtaining the consents needed to collect, text, call, record, and process the information, and for the lawfulness of its instructions.
04
Muvix’s Processing Commitments
Muvix will:
Process Customer Personal Information only to provide the Services, as described in Annex A, and as Customer instructs through the Agreement and its use of the Services
Not sell Customer Personal Information or share it for cross-context behavioral advertising
Not keep, use, or disclose it for any purpose other than the business purposes in the Agreement, or outside the direct business relationship with Customer
Not combine it with personal information from other sources, except as Privacy Laws allow a service provider to do
Tell Customer if Muvix decides it can no longer meet its obligations under Privacy Laws, or if it believes an instruction breaks the law
Require everyone who handles Customer Personal Information to keep it confidential
Muvix may use aggregated or de-identified data that does not identify Customer or any individual to operate and improve the Services, and will not attempt to re-identify it.
05
Security
Muvix will maintain administrative, technical, and physical safeguards designed to protect Customer Personal Information, including the measures in Annex B. Muvix may update those measures as long as the overall level of protection does not materially decrease.
Customer is responsible for using the Services securely, including managing user access, protecting credentials, and setting agent permissions.
06
Subprocessors
Customer authorizes Muvix to use the Subprocessors listed in Annex C.
Muvix will bind each Subprocessor to written data protection terms at least as protective as this DPA, and remains responsible for its Subprocessors’ performance.
Muvix will give at least [15] days’ notice before adding a Subprocessor, by email or by updating the list at [muvix.ai/subprocessors]. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may end the affected Services and receive a refund of prepaid fees for the unused term.
Muvix will not allow AI model providers to train their public models on Customer Personal Information.
07
Consumer Requests
If an individual sends Muvix a request about Customer Personal Information, such as access, deletion, or correction, Muvix will refer it to Customer and will not respond on its own unless the law requires. Taking into account the tools available in the Services, Muvix will give reasonable help so Customer can respond.
Muvix will apply opt-out requests (such as a reply of STOP) received through the Services to Customer’s messaging automatically.
08
Security Incidents
Muvix will notify Customer without undue delay, and no later than [72 hours], after confirming a Security Incident. The notice will describe what happened, the information affected, and the steps Muvix is taking, and Muvix will provide updates as it learns more. Muvix will take reasonable steps to contain and remedy the incident.
Customer is responsible for any notices it owes to individuals and regulators. Muvix’s notice of a Security Incident is not an admission of fault.
09
Financial and Health Information
Financial information. Where Customer is a financial institution, Customer Personal Information may include nonpublic personal information under the Gramm-Leach-Bliley Act. Muvix will use and disclose it only to carry out the Services or as the law permits, will maintain safeguards appropriate to its sensitivity, and will require the same of its Subprocessors.
Credit information. Customer will load consumer report information only where it has a permissible purpose and the right to share it with a service provider.
Health information. Customer will not submit protected health information or other medical or health details unless the parties have signed a separate written agreement covering that use, including a business associate agreement where HIPAA applies.
10
Audits and Assistance
On written request, no more than once a year, Muvix will make available information reasonably needed to show compliance with this DPA, such as security questionnaire responses and [any third-party audit report Muvix holds]. If that information is not enough, Customer may request an audit on [30] days’ notice, during business hours, at Customer’s cost, and under confidentiality terms. Audits must not expose other customers’ data.
Muvix will give reasonable help with risk assessments Customer must perform under Privacy Laws, and with regulator inquiries about Muvix’s processing.
11
Return and Deletion
During the term, Customer can export or delete Customer Personal Information using the Services or by contacting support. Within [30] days after the Agreement ends, Muvix will delete Customer Personal Information, except copies held in backups until they expire in the ordinary course, and copies the law requires Muvix to keep. Retained copies stay protected by this DPA.
12
Liability
Each party’s liability under this DPA is subject to the limits and exclusions in the Agreement.
13
Term and Changes
This DPA lasts as long as Muvix processes Customer Personal Information. Muvix may update it to reflect changes in law or the Services, and will give notice of material changes as described in the Agreement. The governing law and dispute terms of the Agreement apply to this DPA.
A
Annex A: Details of Processing
Providing the Services: AI-assisted texting, calling, email, lead management, scheduling, transcription, and related support
The term of the Agreement, plus the deletion period in Section 11
Customer’s leads and customers, and Customer’s own users
Contact details; product details such as loan or coverage information; messages, call recordings, and transcripts; CRM notes and activity; user account and usage data
Financial account, income, and credit details where Customer loads them; no health information unless separately agreed
[United States]
B
Annex B: Security Measures
Encryption of data in transit using TLS
[Encryption of stored data and credentials at rest]
Logical separation of each customer’s workspace data
Role-based access with least privilege, and [multi-factor authentication] for production systems
[Logging and monitoring of access to production systems]
[Regular backups and tested restoration]
[Vulnerability scanning and timely patching]
Confidentiality obligations and [security training] for personnel
Security review of Subprocessors before use
A documented incident response process
C
Annex C: Subprocessors
Hosting and database
Text messaging and voice
Call transcription
AI model processing
Payment processing
Email delivery
Product analytics