Version scout-dpa-2026-09-17-v1.1 · Effective September 17, 2026
This Data Processing Addendum ("DPA") forms part of the Scout Terms of Service between Maxis Technology Inc. ("Processor" / "Maxis") and Customer ("Controller" / "Customer") when Maxis processes personal data on Customer's behalf in providing Scout.
Customer is controller (or business). Maxis is processor (or service provider). Each party complies with applicable data-protection law for its role.
Processing of personal data contained in Customer Data and account/usage data as needed to provide Scout, for the term of the Service and the retention periods in the Privacy Policy / Customer settings.
Hosting, analysis, Report generation, AI-assisted features, support, security, and billing entitlement enforcement — solely to provide the Service to Customer.
May include identifiers, employment/role data, system usernames, and other personal data present in Customer systems Customer chooses to upload or connect. Data subjects: Customer's employees, contractors, and other individuals reflected in those systems.
Maxis processes personal data only on documented instructions from Customer (including the Terms, this DPA, and in-product configuration), unless required by law.
Maxis ensures persons authorized to process personal data are bound to confidentiality and implements appropriate technical and organizational measures as described in the Privacy Policy (encryption in transit/at rest, access control, logging).
Customer authorizes Maxis to use subprocessors listed at scout.alchemize.io/subprocessors. Maxis will impose data-protection terms no less protective than this DPA, including prohibiting AI subprocessors from training models on Customer Data. Maxis remains responsible for subprocessors' performance of delegated obligations.
Where personal data is transferred internationally, Maxis will use appropriate safeguards (including standard contractual clauses where required).
Maxis will assist Customer, insofar as reasonable and taking into account the nature of processing, with data-subject requests, security incident notification, and DPIAs. Security incidents involving personal data will be notified to Customer without undue delay after Maxis confirms a breach affecting Customer personal data (target: within 72 hours of confirmation, unless law requires sooner).
On termination, Maxis will delete or return personal data per the Terms / Privacy Policy / Customer deletion controls, except where retention is required by law.
Upon reasonable written request, Maxis will provide information reasonably necessary to demonstrate compliance with this DPA (e.g., security summaries). On-site audits only if required by law or a supervisory authority and on reasonable notice, subject to confidentiality and scheduling.
If this DPA conflicts with the Terms on data-protection obligations, this DPA controls for that conflict. Negotiated enterprise DPAs supersede this standard form when signed.
Questions: use the contact form on scout.alchemize.io.