Effective date: October 1, 2026
Version: 26a-2026-10-01
Last updated: October 1, 2026
Changelog: Initial general processor addendum draft. Counsel and transfer-annex review required; no existing contract is amended by this public draft.
Draft only. Not an executed DPA.
This text is a general draft for legal review. Posting or viewing it does not create an executed processing agreement. In-app acceptance records only an authorized workspace owner's/admin's assent to the exact version and document hash. Review and complete any customer-specific order, subprocessor notice/objection process, transfer assessment, SCC annexes, UK addendum, and other required contract documentation with counsel before relying on it. We do not claim any particular customer's record exists.
Processing addendum text
This general addendum is a draft for counsel and customer review. It applies to personal data a customer submits to Axiom Helm where the customer acts as controller and Mahlum Innovations LLC acts as processor. It supplements, and does not replace, the parties' signed order or other executed service terms. Viewing or accepting this document does not complete a restricted-transfer assessment, a required cover page, SCC module/annex, UK addendum, or customer-specific agreement.
1. Subject matter, duration, and purpose. The subject matter is the provision of Axiom Helm's business workspace, agent-assisted, connected-account, and support services configured by the customer. Processing lasts while the customer uses the applicable services and, thereafter, only as needed for documented return/deletion instructions, backups, security, legal duties, and the customer's chosen retention settings. The purpose is to host, maintain, secure, support, and perform the features the customer configures and directs.
2. Nature of processing. Processing may include receiving, recording, storing, organizing, retrieving, structuring, consulting, analyzing, transmitting to an instructed subprocessor, displaying, updating, exporting, and deleting personal data as required for the services and the customer's documented instructions.
3. Data subjects and data. Depending on the customer's use, data subjects may include its staff, customers, prospects, suppliers, representatives, and other people whose information the customer enters. Data may include business contact details, identifiers, account and connection details, messages, documents, workspace records, support records, financial or transaction details, task prompts and outputs, device and service-usage data, and other information the customer elects to submit. Sensitive data or government identifiers should not be submitted unless the feature and the parties' written instructions specifically support that use.
4. Customer instructions and responsibilities. The customer is responsible for the lawfulness, accuracy, permissions, and instructions relating to personal data it submits, for providing required notices and obtaining a legal basis, for limiting submitted data to what is necessary, and for controlling its users and connected accounts. Mahlum will process customer personal data only on documented instructions to provide the service, unless processing is required by law. Where law permits, Mahlum will inform the customer of such a requirement before processing.
5. Confidentiality. Mahlum will ensure that personnel authorized to handle customer personal data are subject to an appropriate duty of confidentiality and receive access only as needed to perform their role.
6. Security. Mahlum will maintain technical and organizational safeguards appropriate to the service and processing risk. These include application access control and security practices described in the current Security page and applicable service documentation. No particular certification, penetration-test report, encryption configuration, or security audit is represented by this general addendum unless the parties separately verify it in writing. Mahlum will provide reasonable assistance with security obligations, taking into account the processing and information available to it.
7. Subprocessors. The current, optional, and planned provider paths are distinguished in the public Subprocessors Register. A planned provider is not an active subprocessor solely because it appears on a roadmap. For an applicable customer processing path, Mahlum will require a subprocessor to undertake data-protection obligations appropriate to its processing, remain responsible for obligations it has agreed to perform, and provide notice of a material subprocessor change as required by the parties' executed service terms. A customer may raise a specific, reasoned objection at privacy@axiomhelm.com. The parties will work in good faith to address the objection; any suspension or termination right depends on the executed service terms.
8. Data-subject requests and assistance. Where the customer is responsible for responding to a data-subject request, Mahlum will, taking account of the processing, provide reasonable assistance through the available service controls and request channels. Mahlum will promptly direct to the customer a request that appears to relate to customer-controlled data unless applicable law prohibits referral. Mahlum will assist, as reasonably available, with a data-protection impact assessment or regulator consultation.
9. Personal-data incidents. Mahlum will notify the customer without undue delay after confirming a personal-data breach affecting customer personal data and provide material information reasonably available to support the customer's assessment and applicable notification duties. Notice is not an admission of fault or a determination that a regulator or individual must be notified.
10. Return, deletion, and retention. At the customer's choice, Mahlum will provide the available export or deletion controls for data within their inventoried scope, subject to identity and authority checks, shared-workspace rights, technical limitations, and applicable law. Some records must be retained by law or to protect security, billing, the rights of other users, or the integrity of the service. Third-party provider copies, infrastructure backups, authentication records, billing records, and security logs may follow separate provider or legal retention periods. Disconnecting an integration is not itself proof of provider-side data deletion. This addendum does not guarantee erasure from every subprocessor or backup on a fixed date.
11. Compliance information and audits. On reasonable written request, Mahlum will make available information reasonably necessary to demonstrate compliance with its processor obligations under the applicable executed terms. Any audit must be scoped, scheduled with reasonable notice, protect confidential and security-sensitive information, avoid access to another customer's data, and not unreasonably disrupt the services. Costs, frequency, and any independent audit-report reliance are subject to the parties' executed terms.
12. International transfers. Where a transfer restriction applies, the parties must identify and use a valid transfer mechanism and complete the information, transfer assessment, and annexes required for the actual transfer. The European Commission Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, may require the appropriate module and completed annexes. Any required UK addendum or other local transfer instrument must also be completed. A reference to SCCs in this general text is not an executed SCC, completed annex, approved transfer assessment, or representation that a transfer mechanism is already in force.
13. Assistance and conflicts. Where this addendum conflicts with a signed data-processing term between the parties, the signed term governs to the extent of the conflict. This addendum does not authorize processing outside the customer's documented instructions or supersede non-waivable law.
14. Contact and completion. Privacy contact: privacy@axiomhelm.com. The parties should complete any customer-specific order, accepted contract cover, processing details, subprocessor schedule, security schedule, SCC module/annex, UK addendum, and transfer assessment required for their relationship before relying on this text as a final agreement.
How authorized acceptance works
A workspace owner or active administrator can review the exact displayed version and, if authorized, accept it from Settings > Privacy & data for a selected workspace. The server binds an explicit acceptance receipt to the version and SHA-256 document hash and rejects a stale copy or unauthorized role. The acceptance record is evidence of that recorded click, not proof that all needed transfer annexes, custom terms, or outside provider contracts are complete.
Common Paper Data Processing Agreement Standard 1.1 is a separate published contract standard. This public Axiom Helm draft does not claim to reproduce that standard or to supply an accepted contract cover. If a party uses a Common Paper form or another contractual cover, it must be completed and accepted by the parties.
The European Commission's Standard Contractual Clauses require the applicable controller-to-processor (Module 2) or processor-to-processor (Module 3) terms, completed annexes, and transfer information; a link or reference alone does not complete them. Provider locations and accepted contractual terms remain subject to the verification described in our Subprocessors Register.
For a tailored agreement, transfer addendum, or annex, contact privacy@axiomhelm.com before sending restricted data.
Changelog
October 1, 2026: Initial general processor addendum draft. Counsel and transfer-annex review required; no existing contract is amended by this public draft.