NoteX
← Back to Home

GDPR Compliance

Our commitment to data protection under the General Data Protection Regulation

1. Our Commitment to GDPR

NoteX is fully committed to complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). We recognize the importance of data privacy and have implemented comprehensive measures to ensure the rights and freedoms of data subjects are protected.

This page outlines how NoteX processes personal data in compliance with GDPR requirements and describes the rights available to individuals within the European Economic Area (EEA) and United Kingdom.

2. Roles and Responsibilities

2.1 NoteX as Data Controller

NoteX acts as the Data Controller for personal data collected directly from users of our platform, including:

  • Account registration and profile information
  • Payment and billing data
  • Website usage and analytics data
  • Customer support communications

2.2 NoteX as Data Processor

When businesses use NoteX to send notifications to their clients, NoteX acts as the Data Processor. In this capacity:

  • The business (our customer) is the Data Controller
  • We process data solely on their instructions
  • We provide a Data Processing Agreement (DPA) to all business customers
  • We do not use client data for our own purposes

3. Lawful Basis for Processing

We process personal data under the following legal bases as defined by Article 6 of the GDPR:

Contractual Necessity (Art. 6(1)(b))

Processing necessary for the performance of a contract, such as account creation, service delivery, and payment processing.

Legitimate Interest (Art. 6(1)(f))

Processing necessary for our legitimate interests, including service improvement, security measures, and fraud prevention, balanced against the rights of data subjects.

Consent (Art. 6(1)(a))

Processing based on freely given, specific, informed, and unambiguous consent, such as marketing communications and optional analytics.

Legal Obligation (Art. 6(1)(c))

Processing necessary for compliance with a legal obligation, such as tax reporting and regulatory requirements.

4. Data Subject Rights

Under the GDPR, individuals have the following rights regarding their personal data:

4.1 Right of Access (Art. 15)

You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data. We will respond to access requests within 30 days.

4.2 Right to Rectification (Art. 16)

You have the right to request correction of inaccurate personal data. You can update most information directly through your account settings.

4.3 Right to Erasure (Art. 17)

You have the right to request deletion of your personal data ("right to be forgotten") when the data is no longer necessary, you withdraw consent, or you object to processing. Certain exceptions apply, such as legal obligations.

4.4 Right to Restriction (Art. 18)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or object to processing.

4.5 Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV) and to transmit it to another controller.

4.6 Right to Object (Art. 21)

You have the right to object to processing based on legitimate interests or direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds.

4.7 Rights Related to Automated Decision-Making (Art. 22)

NoteX does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

To exercise any of these rights, contact our Data Protection Officer at dpo@notex.io. We will respond within 30 days of receiving your request.

5. Data Processing Agreement (DPA)

We provide a comprehensive Data Processing Agreement to all business customers in accordance with Article 28 of the GDPR. Our DPA covers:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Categories of data subjects and personal data
  • Obligations and rights of the controller
  • Sub-processor management and notification
  • Data breach notification procedures
  • Data deletion and return upon termination
  • Audit and inspection rights

To request a DPA, contact legal@notex.io.

6. International Data Transfers

When personal data is transferred outside the EEA, we ensure adequate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU Commission-approved SCCs for data transfers to third countries
  • Adequacy Decisions: We rely on EU adequacy decisions where applicable
  • Transfer Impact Assessments: We conduct assessments to evaluate the data protection regime of recipient countries
  • Supplementary Measures: We implement additional technical and organizational safeguards as needed

7. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to data subjects, including:

  • Introduction of new data processing technologies
  • Large-scale processing of personal data
  • Changes to notification delivery mechanisms
  • New third-party integrations that process personal data

8. Data Breach Notification

In the event of a personal data breach, we comply with the GDPR notification requirements:

  • Supervisory Authority: We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to data subjects
  • Data Subjects: We will notify affected individuals without undue delay when a breach is likely to result in a high risk to their rights and freedoms
  • Business Customers: We will notify affected business customers promptly so they can fulfill their own notification obligations

9. Sub-Processors

We use the following categories of sub-processors to deliver the Service:

  • Cloud Infrastructure: Hosting and data storage providers
  • Payment Processing: Secure payment gateway providers
  • Analytics: Privacy-focused analytics tools
  • Email Delivery: Transactional email service providers
  • Customer Support: Support ticket management platforms

We maintain an up-to-date list of sub-processors and notify business customers of any changes. All sub-processors are bound by data processing agreements that meet GDPR requirements.

10. Data Protection Officer

NoteX has appointed a Data Protection Officer (DPO) who can be contacted for any questions regarding our GDPR compliance:

  • Email: dpo@notex.io
  • Address: NoteX Inc., Data Protection Officer, 100 Innovation Drive, San Francisco, CA 94105

11. Supervisory Authority

If you are unsatisfied with our handling of your personal data, you have the right to lodge a complaint with your local supervisory authority. A list of EU/EEA supervisory authorities can be found on the European Data Protection Board website.

© 2026 NoteX. All rights reserved.