Legal

Data Processing Agreement

Last updated: September 14, 2026

This Data Processing Agreement ("DPA") forms part of the Maax Terms of Service (the "Terms") between BOOTHIC SMPC, a single-member private company incorporated in Greece, GEMI No. 153029403000, VAT No. EL801264656 ("BOOTHIC", "we", "us"), and the professional or organization that holds the Maax account (the "Customer", "you"). It applies whenever we process personal data on your behalf to provide Maax and the GDPR — or an equivalent data-protection law — applies to that processing. It is incorporated into the Terms automatically, without signature; request a countersigned copy at support@maax.app.

1. Roles and scope

You are the controller of Customer Data; we are your processor. "Customer Data" means the knowledge you give your agents — Q&A pairs, context, uploaded files and the website pages you have us crawl — the gaps recorded on your agents, and the call data Maax processes in transit for you: the audio of your calls and the live transcripts derived from it, including the personal data in any of these. For account, billing, usage-metering, support and website data we are an independent controller, as described in our Privacy Policy; that processing sits outside this DPA. If you use Maax as a processor for someone else, you warrant that your controller has authorized these terms, and we act as your sub-processor.

2. Details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

3. Instructions

We process Customer Data only on your documented instructions: this DPA, the Terms, and the actions you take in the app — starting and stopping a session, building or editing an agent, asking a question, deleting content — and any further written instructions we agree to. We will tell you if we believe an instruction infringes the GDPR, though we are not obliged to run legal checks on your behalf. You remain responsible for the lawfulness of the data you process with Maax, including informing call participants and securing any consent or other lawful basis needed to transcribe and analyze them (Terms, section 6), and for having the right to use the websites and files you add to an agent.

4. Confidentiality

Only people who need Customer Data to operate the service can access it, and every one of them is bound by contractual or statutory confidentiality obligations.

5. Security

We implement and maintain the technical and organizational measures in Annex 2 and will not materially weaken them during your use of the service. Taking into account the state of the art, the costs of implementation and the risks of the processing, these measures are designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as Article 32 GDPR requires.

6. Sub-processors

You give general written authorization for the sub-processors listed in Annex 3; the current list is always maintained on our Privacy Policy page. Before adding or replacing a sub-processor we will update that list and notify you — by email or in the app — at least 30 days in advance. You may object within 15 days of the notice on reasonable data-protection grounds; we will then work with you in good faith on a solution, and if there is none, you may terminate the affected subscription and we will refund any fees prepaid for the period after termination. We impose data-protection obligations materially equivalent to this DPA on every sub-processor by written contract, and we remain fully liable to you for their performance (Article 28(4) GDPR).

7. International transfers

Customer Data is processed in the EEA and the United States (Annex 3). Where a transfer out of the EEA needs safeguards, we rely on adequacy decisions — including the EU–US Data Privacy Framework where the provider is certified — or the European Commission's Standard Contractual Clauses, alongside supplementary measures such as encryption in transit and at rest. For transfers subject to UK or Swiss rules, the UK Addendum or the Swiss amendments apply as required, with the necessary adaptations.

8. Assistance

Taking into account the nature of the processing, we assist you with your own GDPR obligations:

  • Data subject rights (Articles 12–23) — the app's editing and deletion tools for agent content, gaps and the account are the primary means of assistance; audio and transcripts are never retained, so there is nothing to retrieve or erase from them. If a data subject contacts us directly about Customer Data, we forward the request to you without undue delay and do not answer it ourselves, beyond directing them to you, unless the law requires more.
  • Security, breach notification and impact assessments (Articles 32–36) — we provide reasonable assistance and the information in our control, including for data protection impact assessments and consultations with supervisory authorities.

9. Personal data breaches

If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and give you the information Article 33(3) GDPR calls for — the nature of the breach, the categories and approximate numbers affected, likely consequences, and the measures taken or proposed — as it becomes available, so you can meet your own notification duties. Our notification is not an admission of fault.

10. Audits and information

On written request, we will demonstrate compliance with this DPA by providing our current security documentation, summaries of third-party attestations covering our infrastructure, and answers to reasonable written security questionnaires — once in any 12-month period, unless a breach has occurred or a supervisory authority requires more. Where the GDPR gives you a mandatory audit right that this does not satisfy, you or an independent auditor bound to confidentiality (and not a competitor of ours) may audit on at least 30 days' notice, during business hours, without disrupting the service, at your cost.

11. Deletion and return

You can view and edit your agent knowledge and gaps in the app at any time. Deletion follows the controls you already hold: delete a pair, a page, a file or an agent, and it is removed together with its search index; delete your account, and everything is purged. When the agreement ends, we delete remaining Customer Data within 30 days of account closure or your deletion request, except copies the law requires us to keep, which stay protected by this DPA until destroyed. Deleted data leaves backups on their rolling replacement cycle. Call audio and transcripts are never stored at all — they are processed in real time and immediately discarded.

12. Liability, precedence and governing law

Liability under this DPA is subject to the limitations and exclusions in the Terms, applied in aggregate across both documents. If this DPA conflicts with the Terms on data protection, this DPA prevails; where mandatory data-protection law requires something different, that law prevails over both. This DPA is governed by the same law and courts as the Terms. We may update this DPA to reflect changes in law, in the service or in Annex 3; material changes follow the notice process in the Terms and, for sub-processors, section 6 above.

Annex 1 — Details of processing

Subject matter and duration

Provision of Maax, the live call assistant, for the term of the Terms and until deletion under section 11.

Nature and purpose

Real-time speech-to-text of call audio captured on the Customer's own computer, with immediate discard of the audio; detection of questions and hard moments in the live transcript; retrieval of answers from the Customer's agent knowledge and their display to the Customer; AI generation of Q&A, hard-moment lines and context from websites and files the Customer provides; indexing of that knowledge for search; storage of agent knowledge and gaps; a chat with the agent; and support.

Categories of data subjects

The Customer and its users; participants in the Customer's calls, such as prospects, customers and colleagues; and individuals who appear in the websites and files the Customer adds to an agent or are mentioned in conversations.

Types of personal data

Identity and contact data (names, email addresses); professional data (role, employer); the content of communications — everything said on calls while a session runs, processed transiently, and the questions recorded as gaps; the content of documents and web pages the Customer provides; and usage data. The service is not intended to process special categories of data or children's data; if participants volunteer such information it may pass through transcription incidentally, and the Customer is responsible for the lawfulness of processing it.

Annex 2 — Technical and organizational measures

  • Encryption in transit and at rest across the entire pipeline.
  • Zero audio and transcript retention by design: audio is transcribed in real time and discarded; transcripts live only in the Customer's session and in transient analysis requests, never written to storage.
  • Capture on the Customer's own device; no server-side participant joins any call.
  • Per-account isolation: every agent, source, page, pair and gap is owned by one account and accessible only to it.
  • Authentication through a dedicated identity provider; sessions bound to the user's browser or the desktop application's own profile.
  • Least-privilege access: production data is accessible only to the few people who need it to run the service, under confidentiality obligations.
  • Infrastructure providers holding SOC 2 Type II attestations, with replicated backups.
  • Customer-controlled deletion: content, agents and the account can be deleted at any time; account deletion purges every record and search index.
  • Logging and monitoring of production systems; a documented incident-response process with customer notification under section 9.
  • Vendor management: written data-processing agreements with every sub-processor; no sub-processor may use Customer Data to train models.

Annex 3 — Sub-processors

Sub-processors of Customer Data as of the date above; the current list is always on the Privacy Policy page:

  • Clerk, Inc. (United States) — authentication and account management.
  • Convex, Inc. (United States) — database and backend infrastructure.
  • Cloudflare, Inc. (United States / EEA) — application hosting, network edge and installer storage.
  • Soniox, Inc. (United States) — real-time speech-to-text; receives live call audio solely to return the transcript.
  • Google LLC (United States / EEA) — Gemini models for detection, answers and generation; File Search indexing of agent knowledge.
  • Exa AI, Inc. (United States) — fetching of the web pages the Customer asks to crawl.
  • Inngest, Inc. (United States) — durable execution of crawl and upload pipelines.

Polar, our merchant of record, is an independent controller of payment data, and the analytics and form providers used on the marketing website do not touch Customer Data — none of them are sub-processors under this DPA.

Contact

BOOTHIC SMPC — single-member private company incorporated in Greece
29 Tavoulari Str., Greece · GEMI No. 153029403000 · VAT No. EL801264656
Operating Maax · support@maax.app