Skip to content
Hoxigen

Data Processing Addendum

Last updated 2026-09-27

This addendum sets out how Hoxigen (“we”) processes personal data on your behalf, as Article 28 of the GDPR requires. It forms part of the Terms of Service: accepting the Terms, or using Hoxigen, accepts it too. Nothing needs signing.

Where this addendum and the Terms disagree about personal data, this addendum wins.

1 · Roles

Who is controller and who is processor

For the content you connect and create in Hoxigen — your sites, posts, comments, leads, newsletter lists and knowledge base — you are the controller and we are your processor. If you are an agency acting for a client, you are that client's processor and we are your sub-processor; you confirm your client has authorised that.

For your own account — sign-in, billing and usage — we are the controller. That data is covered by the Privacy Policy, not by this addendum.

2 · Scope

Subject matter, duration, nature and purpose

  • Subject matter: the personal data in the content you process with Hoxigen.
  • Duration: as long as the Terms are in force, and afterwards until the data is deleted under section 10.
  • Nature: storing, analysing, generating from, publishing, reading back and deleting data, automatically and on your instruction.
  • Purpose: providing the service to you: generating marketing content from your site and knowledge base, publishing it to the channels you connect, reading back comments and results, capturing leads and sending your newsletters, and reporting on your site's search and traffic figures.
3 · Data

Types of personal data and data subjects

Depending on the features you use, the personal data can include:

  • Leads and newsletter recipients — name, email address, phone number, the page they signed up on, and when they confirmed or unsubscribed.
  • People who comment on or react to your posts — their public name or handle, profile identifiers, and what they wrote.
  • People in your content and knowledge base — anyone named or pictured in what you upload or what is generated from it, including a presenter's photo and chosen voice.
  • Your team and your connected accounts — the names, handles, page identifiers and access tokens of the accounts you connect.
  • People posting in public — where you turn on Listening, the public Reddit and X posts that match your topics, with their author handles.

We do not ask for special categories of data (health, religion, and the like) and you agree not to put them into Hoxigen unless you have a lawful basis to.

4 · Our obligations

What we promise as your processor

  • Your instructions only. We process the data only to provide the service as you configure and use it, which together with the Terms and this addendum are your documented instructions, unless a law requires otherwise; in that case we tell you first unless the law forbids it. If we think an instruction breaks data protection law, we tell you.
  • Confidentiality. Everyone who can reach your data is bound to keep it confidential, and reaches it only when needed to run or support the service.
  • Security. We maintain the measures in section 5.
  • Helping you with requests. We help you answer requests from data subjects (access, correction, deletion, portability, objection) and pass on to you any request we receive directly about your data. The full export and workspace deletion under Your data in Workspace settings are there for this.
  • Helping you with compliance. We give you the information you reasonably need for a data protection impact assessment or a consultation with a regulator about the service.
5 · Security

Technical and organisational measures

  • The database and application are hosted in an EU region (Amsterdam), and media in EU-hosted storage.
  • All traffic to and from Hoxigen is encrypted with TLS.
  • Connector secrets — platform access tokens, API keys and webhook secrets — are encrypted at rest with AES-256-GCM, under a key kept separate from the one that signs sessions.
  • Passwords are stored only as bcrypt hashes, and repeated failed sign-ins are throttled.
  • Two-factor sign-in (authenticator app, passkeys, email fallback) is available to every user, and a workspace owner can require it for the whole team. Our own staff panel always requires it.
  • Role-based access inside each workspace: every action checks the member's role and permissions on the server.
  • Tenant isolation: every request is scoped to the workspace it belongs to, and automated tests check that boundary on each release.
  • Our staff enter a workspace only when its owner grants support access, for a window of 3 to 21 days, and staff actions are written to an audit log.
  • Webhooks we send to your site are signed with HMAC-SHA256 so it can verify them.
  • Location and camera metadata is stripped from images when they are stored.
  • Text, image and speech generation is routed only to AI endpoints that neither keep nor train on what we send.
  • Application logs are pruned after 14 days, and secrets are redacted from error reports.
6 · Sub-processors

Who else processes your data

You give us general authorisation to use the sub-processors on our sub-processors page. Each is bound by a written contract with data protection obligations at least as protective as this addendum, and we remain responsible to you for their work.

We email account owners at least 30 days before adding or replacing a sub-processor, except where a change is needed urgently to keep the service running or secure, in which case we tell you as soon as we can. If you object on reasonable data protection grounds, write to legal@hoxigen.app within that period. We will try to address the objection; if we cannot, you may end the affected service before the change takes effect and we refund any prepaid fees for the unused period.

7 · Breaches

If something goes wrong

If we become aware of a personal data breach affecting your data, we email the account owner without undue delay, and in any case within 48 hours of becoming aware of it. That leaves you time to meet your own 72-hour deadline to notify a regulator.

The notice describes what happened, the kinds and rough number of people and records involved, the likely consequences, and what we have done and will do about it. Where we do not yet know everything, we send what we know and follow up as we learn more.

8 · Transfers

Data leaving the EEA

Hoxigen operates from Israel, which the European Commission recognises as providing adequate protection. Your data is stored in the EU. Where a sub-processor handles it outside the EEA and Israel, the transfer is covered by the European Commission's Standard Contractual Clauses (processor-to-processor module) or by an adequacy decision, such as the EU-US Data Privacy Framework for a certified provider. The sub-processors page names the safeguard for each.

9 · Audits

Showing that we comply

On request we give you the information needed to show that we meet this addendum, including answers to a reasonable security questionnaire. If that is not enough, or a regulator asks, you may audit our compliance once a year, yourself or through an independent auditor bound by confidentiality, with 30 days' written notice, during business hours and at your own cost. Audits of our sub-processors rely on their own certifications and reports.

10 · The end

Deletion and return

Before you leave, a workspace owner can request a full export under Your data in Workspace settings: a ZIP file behind a private link we email to them, which expires after 7 days. The owner deletes the workspace from the same place. Anyone can also ask for either by writing to legal@hoxigen.app. A deleted workspace waits out a 30-day grace period; after that it and everything in it are permanently deleted. Backups roll off within about 30 days after that.

We keep only what the law requires: receipts and tax records, which our payment provider holds for as long as tax law requires. Cost records of AI usage survive without any of your content or personal data in them.

11 · General

Liability and changes

Each party's liability under this addendum is subject to the limits in the Terms, except where the law does not allow them. We may update this addendum as the law or the service changes; we tell account owners about material changes by email at least 30 days before they take effect, and never reduce the protection it gives your data.

Contact

Privacy and data requests: legal@hoxigen.app · General: support@hoxigen.app

Related: Privacy policy · Terms of service · Sub-processors · Cookie policy