Trust & Security

Data Processing Agreement (DPA)

This DPA sets out how Amox processes data on behalf of the Tenant. It forms part of the Terms of Service.

Nature of Processing

Amox acts as a Data Processor. The Tenant acts as the Data Controller. Amox's processing is limited to collecting, analyzing, and summarizing publicly available market information (OSINT) to produce competitive intelligence reports for the Tenant.

Data Isolation

Amox does not access your internal business systems, customer databases, or financial transactions. The only Tenant data we process is your business profile (e.g., your listed entity URL) and the reports we generate from it. This data is kept separate per Tenant and is never used to train models for other Tenants.

Authorized Sub-Processors

Amox relies on SOC2-compliant infrastructure and data-collection providers to deliver the service. By using Amox, the Tenant authorizes the use of these sub-processors, limited strictly to the following functions:

Infrastructure

Hosting and database services.

Data Collection

Automated collection of public (OSINT) data.

Report Generation (LLM)

Language models used only to generate your reports. These providers are not permitted to retain Amox Tenant data for their own model training.

Data Retention & Incident Response

Raw competitor data is deleted once it has been processed into a report. Tenant data is encrypted in transit and at rest through our infrastructure providers. If we confirm a security incident affecting Tenant data, Amox will notify the Tenant through their primary contact within 72 hours of verification.

Last Updated: September 2026. To request a signed copy of this agreement for your compliance records, please contact the Amox support team.