This English translation is provided for information. The French version is the only legally binding one.
Annex — processing of data on behalf of the Client
Annex to the Soluax terms, version of 2 October 2026. Parties: the Client identified when its account was created, acting as controller or as processor for its own customers, and the Publisher, AXIIZ, a French single-shareholder simplified joint-stock company with a share capital of €100, registered with the Montpellier Trade and Companies Register under number 881 813 174, whose registered office is at 222 place Ernest Granier, 34000 Montpellier, France (EU VAT number FR50881813174). This annex applies from the Client's acceptance of the Soluax terms.
1. Instructions and description
The Client entrusts the Publisher with processing the backup reports and metadata strictly necessary for the service. Operations: native reception by email through Mailgun in the EU region, text/CSV import or webhook, redaction, deterministic classification, limited retention, display, export and deletion. Native reception does not require n8n; an n8n workflow remains an optional legacy option under the Client's control. The AI explanation is optional: at the user's express request, the Publisher sends the status and the first 2,000 filtered characters of the report only to the provider chosen by that user among Mistral AI, OpenAI and Anthropic.
Purpose: to make the operational checking of received reports easier. Duration: that of the contract and of the planned deletion operations. Possible data subjects: the Client's users, senders of the reports and, if present in a log, users of its end customers. Possible data: sender/recipient addresses, email subject and headers, report body before redaction during its reception, any attachments while in transit, machine aliases/labels, residual business identifiers, timestamps, task states and error messages. Attachments are neither analyzed nor archived in the Soluax database. No sensitive data or access secret is required.
The Client documents its instructions and holds the necessary authorizations. The Publisher processes the data only on these instructions, including for transfers, unless a legal obligation applies, of which it informs the Client where the law allows. It promptly reports any instruction that it believes infringes data protection law.
2. Confidentiality and security
Authorized persons are bound by confidentiality and trained for their scope. The Publisher applies proportionate measures: access rights, account isolation, server-side storage of secrets, HTTPS, minimization, no report bodies in technical logs, export and deletion, request rate limiting and incident management. The details of the measures in place and the date of the latest checks are provided to the Client on request.
Report text is filtered and limited to 20,000 characters; this operation does not guarantee anonymization. For an incoming email, the message passes raw through Mailgun and up to the reception server before this filtering. Direct forwarding is preferred, with no application-level archiving of the raw message; the technical retention periods of the reception provider are set out in the policy. History is limited to 90 days; expired items are deleted during the daily retention pass run by the scheduled task, normally within 24 hours of their expiry. Messages received on a client address that cannot be assigned to a task are deleted after 30 days, whether or not they have been assigned since. The AI explanation requires a user action and only sends the first 2,000 filtered characters. Resolved tickets are deleted 36 months after their resolution and the alert delivery log after 90 days; open tickets are kept until they are resolved. The Client remains responsible for minimizing the data it sends, including in the notes it enters.
3. Sub-processors and transfers
The Client authorizes the sub-processors named in the privacy policy, in the version in force on the date the terms were accepted, within their scope. Any addition or replacement likely to process its data is announced at least thirty days in advance, except in a justified emergency. The Client may raise a reasoned objection relating to data protection; the parties then seek a solution, followed by termination of the scope concerned if no reasonable solution is possible.
The Publisher imposes substantially equivalent protection obligations and remains liable for the performance of its sub-processors' obligations. Transfers outside the EEA are governed by the appropriate legal mechanism, documented with its required safeguards and assessments. Choosing Ireland (EU) for the database and Mailgun EU for incoming messages is not a commitment that no international transfer takes place, in particular for some account data, metadata, billing and support operations.
Slack or Microsoft Teams destinations are chosen and provided by the Client, who uses them under its own contract with these services. They are not sub-processors of the Publisher: on the Client's instruction, the Publisher only sends them the alert title, the client and task names, their state and a link to the dashboard, with no report content. The location, retention and transfers of the messages received fall under the Client's contract with that service.
4. Assistance and incidents
The Publisher helps the Client respond to requests to exercise rights, assess and carry out the required impact assessments and meet its security and notification obligations, according to the nature of the processing and the information available.
In the event of a breach affecting the entrusted data, it notifies the Client without undue delay after becoming aware of it, at the email address of the Client's account or at any incident contact the Client has designated in writing. The Publisher's incident contact: support@soluax.ai. It gradually provides the available information on the facts, the data/persons affected, the consequences, the measures taken and the follow-up contact. It does not notify an authority or individuals on the Client's behalf without an instruction or a legal obligation.
5. End of processing
The Client may export its data before deletion. At its choice, the data is returned or deleted at the end of the service, unless a legal retention obligation applies. Backup copies expire within the period stated in the policy, are isolated from day-to-day use and serve only for recovery; any restore reapplies the deletions. This period depends on the backup cycle of the Supabase plan subscribed and is provided to the Client on request.
6. Evidence and audit
The Publisher makes available the information needed to demonstrate its obligations and allows reasonable audits by the Client or its auditor, under confidentiality, with appropriate notice except in an incident/emergency, and while protecting the data of other customers. The practical arrangements and proportionate costs are agreed without preventing the effective exercise of the audit right.
The Client accepts this annex at the same time as the Soluax terms, when creating its account or subscribing.