Last updated: [October 5, 2026]

Data Processing Addendum

This Data Processing Addendum (“DPA”) is part of the Muvix Terms of Service or other written agreement between Muvix, Inc. and the customer that accepted it. It governs how Muvix handles personal information that the customer puts into, or collects through, the Services.

01

How This Addendum Applies

This Data Processing Addendum (“DPA”) is part of the Muvix Terms of Service or other written agreement (the “Agreement”) between Muvix, Inc. (“Muvix”) and the customer that accepted the Agreement (“Customer”). It governs how Muvix handles personal information that Customer puts into, or collects through, the Services. If this DPA and the Agreement conflict on the handling of personal information, this DPA controls.

02

Definitions

  • Customer Personal Information means personal information about leads, consumers, and Customer’s own users that Muvix processes for Customer through the Services.

  • Privacy Laws means the U.S. federal and state privacy and data security laws that apply to Customer Personal Information, including the Gramm-Leach-Bliley Act, state insurance privacy laws, and state consumer privacy laws such as the California Consumer Privacy Act.

  • Security Incident means confirmed unauthorized access to, or loss or disclosure of, Customer Personal Information held by Muvix or its Subprocessors.

  • Subprocessor means a third party Muvix uses to process Customer Personal Information.

Other capitalized terms have the meaning given in the Agreement.

03

Roles

Customer decides why and how Customer Personal Information is processed. Muvix processes it only on Customer’s behalf, as a service provider or processor under Privacy Laws. Each party will comply with the Privacy Laws that apply to it.

Customer is responsible for its privacy notices, for obtaining the consents needed to collect, text, call, record, and process the information, and for the lawfulness of its instructions.

04

Muvix’s Processing Commitments

Muvix will:

  • Process Customer Personal Information only to provide the Services, as described in Annex A, and as Customer instructs through the Agreement and its use of the Services

  • Not sell Customer Personal Information or share it for cross-context behavioral advertising

  • Not keep, use, or disclose it for any purpose other than the business purposes in the Agreement, or outside the direct business relationship with Customer

  • Not combine it with personal information from other sources, except as Privacy Laws allow a service provider to do

  • Tell Customer if Muvix decides it can no longer meet its obligations under Privacy Laws, or if it believes an instruction breaks the law

  • Require everyone who handles Customer Personal Information to keep it confidential

Muvix may use aggregated or de-identified data that does not identify Customer or any individual to operate and improve the Services, and will not attempt to re-identify it.

05

Security

Muvix will maintain administrative, technical, and physical safeguards designed to protect Customer Personal Information, including the measures in Annex B. Muvix may update those measures as long as the overall level of protection does not materially decrease.

Customer is responsible for using the Services securely, including managing user access, protecting credentials, and setting agent permissions.

06

Subprocessors

  • Customer authorizes Muvix to use the Subprocessors listed in Annex C.

  • Muvix will bind each Subprocessor to written data protection terms at least as protective as this DPA, and remains responsible for its Subprocessors’ performance.

  • Muvix will give at least [15] days’ notice before adding a Subprocessor, by email or by updating the list at [muvix.ai/subprocessors]. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may end the affected Services and receive a refund of prepaid fees for the unused term.

  • Muvix will not allow AI model providers to train their public models on Customer Personal Information.

07

Consumer Requests

If an individual sends Muvix a request about Customer Personal Information, such as access, deletion, or correction, Muvix will refer it to Customer and will not respond on its own unless the law requires. Taking into account the tools available in the Services, Muvix will give reasonable help so Customer can respond.

Muvix will apply opt-out requests (such as a reply of STOP) received through the Services to Customer’s messaging automatically.

08

Security Incidents

Muvix will notify Customer without undue delay, and no later than [72 hours], after confirming a Security Incident. The notice will describe what happened, the information affected, and the steps Muvix is taking, and Muvix will provide updates as it learns more. Muvix will take reasonable steps to contain and remedy the incident.

Customer is responsible for any notices it owes to individuals and regulators. Muvix’s notice of a Security Incident is not an admission of fault.

09

Financial and Health Information

Financial information. Where Customer is a financial institution, Customer Personal Information may include nonpublic personal information under the Gramm-Leach-Bliley Act. Muvix will use and disclose it only to carry out the Services or as the law permits, will maintain safeguards appropriate to its sensitivity, and will require the same of its Subprocessors.

Credit information. Customer will load consumer report information only where it has a permissible purpose and the right to share it with a service provider.

Health information. Customer will not submit protected health information or other medical or health details unless the parties have signed a separate written agreement covering that use, including a business associate agreement where HIPAA applies.

10

Audits and Assistance

On written request, no more than once a year, Muvix will make available information reasonably needed to show compliance with this DPA, such as security questionnaire responses and [any third-party audit report Muvix holds]. If that information is not enough, Customer may request an audit on [30] days’ notice, during business hours, at Customer’s cost, and under confidentiality terms. Audits must not expose other customers’ data.

Muvix will give reasonable help with risk assessments Customer must perform under Privacy Laws, and with regulator inquiries about Muvix’s processing.

11

Return and Deletion

During the term, Customer can export or delete Customer Personal Information using the Services or by contacting support. Within [30] days after the Agreement ends, Muvix will delete Customer Personal Information, except copies held in backups until they expire in the ordinary course, and copies the law requires Muvix to keep. Retained copies stay protected by this DPA.

12

Liability

Each party’s liability under this DPA is subject to the limits and exclusions in the Agreement.

13

Term and Changes

This DPA lasts as long as Muvix processes Customer Personal Information. Muvix may update it to reflect changes in law or the Services, and will give notice of material changes as described in the Agreement. The governing law and dispute terms of the Agreement apply to this DPA.

A

Annex A: Details of Processing

Purpose

Purpose

Providing the Services: AI-assisted texting, calling, email, lead management, scheduling, transcription, and related support

Duration

Duration

The term of the Agreement, plus the deletion period in Section 11

Individuals

Individuals

Customer’s leads and customers, and Customer’s own users

Types of information

Types of information

Contact details; product details such as loan or coverage information; messages, call recordings, and transcripts; CRM notes and activity; user account and usage data

Sensitive information

Sensitive information

Financial account, income, and credit details where Customer loads them; no health information unless separately agreed

Location

Location

[United States]

B

Annex B: Security Measures

  • Encryption of data in transit using TLS

  • [Encryption of stored data and credentials at rest]

  • Logical separation of each customer’s workspace data

  • Role-based access with least privilege, and [multi-factor authentication] for production systems

  • [Logging and monitoring of access to production systems]

  • [Regular backups and tested restoration]

  • [Vulnerability scanning and timely patching]

  • Confidentiality obligations and [security training] for personnel

  • Security review of Subprocessors before use

  • A documented incident response process

C

Annex C: Subprocessors

[Cloud hosting provider]

[Cloud hosting provider]

Hosting and database

Location: [United States]

Location: [United States]

[Twilio / Telnyx]

[Twilio / Telnyx]

Text messaging and voice

Location: [United States]

Location: [United States]

[Transcription provider]

[Transcription provider]

Call transcription

Location: [United States]

Location: [United States]

[Anthropic, OpenAI, Google]

[Anthropic, OpenAI, Google]

AI model processing

Location: [United States]

Location: [United States]

[Stripe]

[Stripe]

Payment processing

Location: [United States]

Location: [United States]

[Email delivery provider]

[Email delivery provider]

Email delivery

Location: [United States]

Location: [United States]

[Analytics provider]

[Analytics provider]

Product analytics

Location: [United States]

Location: [United States]