Data Processing Addendum
- Introduction
- 1. Definitions
- 2. Applicability of DPA
- 3. Roles and Responsibilities
- 4. GDPR Obligations
- 5. Miscellaneous
- ANNEX A
- Details Of The Processing
- Nature and Purposes of Processing
- Categories of Data Subjects
- Special Categories of Data
- Duration of Processing
- Disclosures to Law Enforcement
- ANNEX B – LIST OF SUB-PROCESSORS AND CONDITIONS FOR SUB-PROCESSING
- General Requirements for Sub-processors
- Written Contract
- Same Level of Protection
- International Transfers
- Transfer Impact Assessments
- Sub-processor Categories
- Service Sub-processors
- Corporate/Marketing Processors (no processing of Customer Personal Data)
- Customer Notification and Right to Object
- Advance Notice.
- Right to Object.
- Emergency Replacement.
- Current List of Service Sub-processors
- 3CX Licensing & User Management – Service Sub-processors
- 3CX Communications System – Service Sub-processors
- 3CX Video Conferencing – Service Sub-processors
- Corporate/Marketing Processors (No Processing under the DPA)
- Access by Support Providers
- Standard Contractual Clauses
- See Also
Introduction
This Data Processing Addendum (“DPA”) is made as from the Effective Date by and between 3CX Limited and/or any other related company and/or affiliate of 3CX Group (“3CX”) and Customer (each a “party”, together the “parties”), pursuant to the Agreement for the provision of 3CX Services to the Customer. This DPA is incorporated by reference into the Agreement and sets out the terms that apply when Personal Data from the European Economic Area is processed by 3CX under the Agreement on behalf of the Customer. Other capitalised terms used but not defined in this DPA, have the same meanings as set out in the Agreement.
3CX main establishment address:
3CX Ltd 4, Markou Drakou, Engomi, 2409 Nicosia, Cyprus
1. Definitions
1.1 For the purposes of this DPA:
(a) “Agreement” means the electronic agreement or end-user license agreement (EULA) between the Customer and 3CX for the provision of any 3CX services (“Services”) to the Customer.
(b) "Affiliate" means an entity that directly or indirectly controls, is controlled by or is under common control with an entity.
(c) “Data Protection Laws” means all data protection and privacy laws and regulations applicable to a party's processing of Personal Data under the Agreement, including but not limited to: (i) EU Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; (iii) applicable national implementations of (i) and (ii); and (iv) in respect of the United Kingdom (“UK”) any applicable national legislation that replaces or converts in domestic law the GDPR or any other law relating to data and privacy that applies in the UK, and, for transfers from the UK, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable.
(d) “EEA” means the European Economic Area.
(e) “Controller” shall mean the entity which, alone or jointly with others, determines the purposes and means of the processing of Personal Data;
(f) “Processor” shall mean the entity which processes Personal Data on behalf of the Controller;
(g) “Personal Data” means any information that relates to an identified or identifiable natural person (as defined in Article 4 GDPR);
(h) “Security Incident” means accidental or unlawful destruction, loss, alteration and unauthorised disclosure of and/or access to Personal Data;
(i) “Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council issued by the Commission Implementing Decision (EU) 2021/914.
2. Applicability of DPA
2.1 Applicability of DPA: This DPA will apply only to the extent that 3CX processes Personal Data, originating from the EEA or UK on behalf of a Customer and/or a Customer Affiliate located in the EEA or UK. Further, this DPA extends the coverage of data processing activities under the Agreement to include Switzerland. The parties acknowledge and agree that the provisions of this DPA, including but not limited to those relating to the processing of Personal Data, Security, Data Transfers, GDPR-specific obligations, and any other relevant clauses, shall apply mutatis mutandis to the processing of Personal Data originating from Switzerland in addition to the European Economic Area (EEA) and the United Kingdom (UK). The term "Data Protection Laws" as defined in this DPA shall encompass the applicable data protection and privacy laws and regulations of Switzerland, including the Swiss Federal Data Protection Act (FADP) and any other relevant Swiss legislation governing the processing of Personal Data. Transfers from Switzerland shall rely on the EU SCCs as recognized by the FDPIC, with necessary Swiss-specific adaptations (e.g., references to Swiss FADP, competent authority, and governing law).
3. Roles and Responsibilities
3.1 Parties’ Roles: If Data Protection Laws apply to either party's processing of Personal Data, the parties acknowledge and agree that with regard to the processing of Personal Data, Customer is the Controller and 3CX is a Processor acting on behalf of the Customer, as further described in the Agreement, and both parties shall comply with their obligations under the Data Protection Laws, based on recognised industry standards.
3.2 Purpose Limitation: 3CX shall process the Personal Data for the purposes described in Annex A, except where otherwise required by the applicable law.
3.3 Security. 3CX will maintain appropriate technical and organizational measures to safeguard the security of Personal Data. 3CX will maintain an information security and risk management program based on commercial best practices to preserve the confidentiality, integrity and accessibility of Personal Data with administrative, technical and physical measures conforming to generally recognised industry standards and practices. 3CX shall implement appropriate technical and organisational measures to protect the Personal Data from an accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
3.4. Updates to Security: Customer is responsible for reviewing the information made available by 3CX relating to data security and making an independent determination as to whether the Service meets Customer’s requirements and legal obligations under Data Protection Laws. Customer acknowledges that Security is subject to technical progress and development and that 3CX may update or modify Security from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Service provided to Customer. 3CX shall notify Customer of any material reductions in security measures.
3.5. Transferring Personal Data Outside of the EEA or UK: To the extent that 3CX processes (or causes to be processed) any Personal Data originating from the EEA or UK in a country that has not been designated by the European Commission as providing an adequate level of protection for Personal Data, such Personal Data shall have adequate protection (within the meaning of Data Protection Laws). To the extent that 3CX processes (or causes to be processed) any such Personal Data outside of the EEA or UK, it shall commit to apply a transfer mechanism in compliance with the Data Protection Laws such as, but not limited to, Standard Contractual Clauses (SCC). Sub-processors located outside of the EEA or UK are required to have a GDPR statement of their own. 3CX shall conduct transfer impact assessments where required by law and make such assessments available to Customer upon request (subject to redactions).
3.6. Compliance: Customer, as Controller, shall be responsible for ensuring that:
(a) it has complied, and will continue to comply, with all Data Protection Laws, including in any instructions it issued to 3CX under this Agreement and DPA; and
(b) it has, and will continue to have, the right to transfer, or provide access to, the Personal Data to 3CX for processing in accordance with the terms of the Agreement and this DPA. 3CX shall promptly inform the Customer if an instruction is unlawful or infringes Data Protection Laws.4. GDPR Obligations4.1 Applicability of Section: This Section 4 shall apply to the processing of Personal Data that is within the scope of the GDPR / that originates from the EEA or UK.4.2 Confidentiality of processing: 3CX shall ensure that any person with the authorisation to process Personal Data, shall be subject to a duty of confidentiality (whether a contractual or statutory duty).4.3 Sub-processors. The Customer agrees that 3CX may engage 3CX affiliates and third-party sub-processors (collectively, “Sub-processors”) to process the Personal Data on 3CX’s behalf. 3CX shall impose on such Sub-processors data protection terms that protect the Personal Data to the same standard provided for by this DPA and shall remain liable for any breach of the DPA caused by a Sub-processor. The Sub-Processors engaged by 3CX are listed on the 3CX Sub-processor List and are available in Annex B. 3CX shall notify Customer at least 30 days before adding a Sub-processor.4.4 Changes to Sub-processors. 3CX may add or make changes to the Sub-processors. If the Customer objects to the appointment of an additional Sub-processor, then the Customer will be entitled to suspend or terminate the affected 3CX service in accordance with the termination provisions of the Agreement.4.5 Security Incidents. Upon becoming aware of a Security Incident, 3CX shall notify the Customer without undue delay and make every effort to notify the Customer within 48 hours of becoming aware of a Security Incident, at the contact information that the Customer has provided in the Customer Portal and shall provide such timely information as the Customer may reasonably require, including to enable the Customer to fulfil any data breach reporting obligations under Data Protection Laws.4.6 Cooperation and data subjects’ rights. 3CX, taking into account the nature of the processing, shall provide reasonable assistance and tools, where available, to the Customer insofar as this is possible, to enable the Customer to respond to requests from a data subject seeking to exercise their rights under the Data Protection Laws. In the event that such a request is made directly to 3CX, 3CX shall promptly inform the data subject to contact the Customer of the same. It is the Customer’s sole responsibility to ensure that any administrator identified for the Customer’s 3CX account to manage and carry out data subject requests has appropriate authority to fulfill the data subject requests.4.7 Data Protection Impact Assessments: 3CX, to the extent required by the Data Protection Laws, upon Customer’s request and at Customer’s expense, shall provide the Customer with reasonable assistance with data protection impact assessments or prior consultations with data protection authorities that the Customer is required to carry out under the Data Protection Laws.4.8 Deletion or return of data: Upon termination or expiration of the Agreement, 3CX shall (at Customer's election) delete or return to Customer all Personal Data (including copies) in its possession or control, except that this requirement shall not apply to the extent 3CX is required by applicable law to retain some or all of the Personal Data, or to Personal Data it has archived on back-up systems, which Personal Data 3CX shall securely isolate, protect from any further processing and eventually delete in accordance with 3CX’s deletion policies, except to the extent required by applicable law.4.9 Audits / inspections: 3CX shall make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. This obligation is limited to one audit per Customer per year provided a reasonable notice of 30 days is provided by the Customer in advance.5. Miscellaneous5.1 Except as amended by this DPA, the Agreement will remain in full force and effect.5.2 If there is a conflict between the Agreement and this DPA, the terms of this DPA shall prevail.5.3 Any claims brought under this DPA shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement. Nothing in this DPA limits liability under the Standard Contractual Clauses.5.4 Any clarifications on this DPA or other enquiries relating to data protection shall be addressed to the main establishment addresses referred to above or via email to [email protected] ADetails Of The ProcessingNature and Purposes of Processing3CX is an open standards communications solution that offers complete Unified Communications.3CX provides software, instance hosting, and cloud services.Purposes of the Processing are:Accounts registration and management through the 3CX Customer Portal.Identification of the customer for ordering, licensing, and email communication.Identification of the Communications System administrator for email communication.Identification of the Communications System machine for licensing.Identification of the Communications System users for personalized experience in Video Conferencing.Issuance of 3CX academy certificates.Lead processing of end-users with free licenses for potential sales.Review of usage data for general quality control, reporting and troubleshooting of the 3CX Services.Sending email notifications to Communications System users when the 3CX SMTP is used.Troubleshooting and assistance by 3CX staff.Categories of Data SubjectsCustomer and End Users who use the Services, and any data subject who uses the 3CX Services at the request of and in connection with the business of the Customer.Type(s) of Personal Data Processed:The personal data transfer concerns the following categories of data for the data subjects:Identification information for Customer, contact information (address, telephone number, email address, fax number), company name.Identification information for each Extension of the 3CX Communications System as part of the Video Conferencing feature, including extension number, first and last names, email address, meeting friendly names in Click2Meet URL.Identification information for each Participant of a Video Conferencing including name, email address and IP address. Participant’s telephone number will also be processed for those joining through the Video Conferencing Dial-In audio bridge.Any other personal data that the Customer or users choose to include in the content of the communications that are sent and received using the 3CX Services including but not limited to support bundles, logs, crash reports, through emails, tickets, calls or any other means.The personal data transferred to 3CX for processing is determined and controlled by the Customer in its sole discretion. As such, 3CX has no control over the volume and sensitivity of personal data processed through its Services by the Customer or users. 3CX does not monitor or access the Customer’s content unless required for support and such processing is on-demand, limited, and logged.Special Categories of Data3CX does not intentionally collect or process any special categories of data in the provision of its Services.Duration of ProcessingThe personal data will be processed for the term of the Agreement, or as otherwise required by law or agreed between the parties.Disclosures to Law EnforcementThe Processor shall not disclose Personal Data to any law-enforcement or governmental authority unless required to do so under applicable law binding upon the Processor.Where a request is received directly by the Processor, the Processor shall:(a) verify whether the request is legally valid and properly addressed to the relevant 3CX entity;(b) notify the Controller (unless prohibited by law); and(c) disclose only the minimum Personal Data required by law.The Processor is not obliged to act upon informal notifications or unsubstantiated allegations from third parties and may request that such parties redirect their concerns to the appropriate law-enforcement channels.ANNEX B – LIST OF SUB-PROCESSORS AND CONDITIONS FOR SUB-PROCESSINGGeneral Requirements for Sub-processorsWritten Contract3CX shall only engage Sub-processors under a written agreement imposing data protection obligations no less protective than those set out in this DPA, as required by Article 28 GDPR.Same Level of Protection3CX remains fully liable for the acts and omissions of its Sub-processors and shall ensure that each Sub-processor implements appropriate technical and organisational measures in accordance with Article 28 and 32 GDPR.International TransfersWhere a Sub-processor is located outside the EEA, UK or Switzerland, 3CX shall ensure that a lawful transfer mechanism is implemented, including:EU Standard Contractual ClausesUK Addendum or IDTASwiss-adapted SCCsor any successor or alternative mechanism recognised by the competent authority.Transfer Impact AssessmentsFor non-EEA/UK transfers, 3CX shall conduct transfer impact assessments (where required by law) and make a summary available to Customer upon request.Sub-processor CategoriesFor transparency, 3CX distinguishes between the following categories of Sub-processors:Service Sub-processorsSub-processors that process Customer Personal Data strictly for the provision of the 3CX Services (e.g., hosting, push notifications, email delivery).Corporate/Marketing Processors (no processing of Customer Personal Data)
Processors used for analytics and marketing on 3CX websites (e.g., Google Analytics, Facebook Pixel) do not process any Customer Personal Data under this DPA.
They are listed for transparency only and do not form part of the Customer’s supply chain for the provision of Services. Customer Personal Data, as defined in this DPA, is never shared with Corporate/Marketing Processors.
Customer Notification and Right to Object
Advance Notice.
3CX shall notify Customer at least 30 days in advance of adding or replacing a Service Sub-processor. Notification shall be made via the Customer Portal or by email.
Right to Object.
Customers may object to a new Service Sub-processor on reasonable data protection grounds within 30 days of notification.
3CX will work with Customers in good faith to address such objections. If the parties cannot reach a mutually acceptable solution, Customer may suspend or terminate the affected Service and receive a pro-rated refund for prepaid, unused fees.
Emergency Replacement.
In urgent circumstances (e.g., service failure), 3CX may temporarily appoint a replacement Sub-processor. 3CX will notify Customer as soon as reasonably practicable.
Current List of Service Sub-processors
The following entities are authorised Service Sub-processors engaged by 3CX to support the provision of the Services.
Each listed Sub-processor processes Customer Personal Data only for the purposes described and subject to the transfer mechanisms indicated.
3CX Ltd
3CX Development Ltd
3CX GmbH
3CX USA Corp
3CX Licensing & User Management – Service Sub-processors
Sub-processor | Country of Processing | Service Description | Personal Data Involvement | Transfer Mechanism |
Google Cloud (Alphabet Inc.) | EU / USA | Cloud hosting services | Storage & processing of Customer Personal Data | SCCs + UK Addendum (if applicable) |
Google GSuite (Alphabet Inc.) | EU / USA | Email provider | Email transmission of support/license communications | SCCs + UK Addendum |
Google OAuth (Alphabet Inc.) | EU / USA | Email authentication login | User authentication data | SCCs + UK Addendum |
Checkout.com LLC | EU / UK / USA | Payment processor | Customer billing data | SCCs + UK Addendum |
Cloudflare, Inc. | EU / USA | CDN & security protection | Network traffic data | SCCs + UK Addendum |
Freshworks, Inc. – Freshdesk | EU / USA / India | Ticketing system for support | Support-related customer data | SCCs + UK Addendum |
Microsoft Azure (Microsoft Corp.) | EU / USA | Cloud hosting services | Storage & processing of Customer Personal Data | SCCs + UK Addendum |
Microsoft Online OAuth | EU / USA | Email authentication login | Authentication data | SCCs + UK Addendum |
Microsoft Power BI | EU | Reporting & analytics | Metadata / usage data | No transfer required (EU data centres) |
OVH SAS | EU | Cloud hosting services | Storage & processing of Customer Personal Data | No transfer required |
PayPal Holdings – Braintree | EU / USA | Payment processor | Customer billing data | SCCs + UK Addendum |
TeamViewer Germany GmbH | EU | Remote assistance sessions | Access to Customer system during support sessions | No transfer required |
Twilio Inc. – SendGrid | EU / USA | Email delivery services | Email metadata | SCCs + UK Addendum |
3CX Communications System – Service Sub-processors
Sub-processor | Country of Processing | Service Description | Personal Data Involvement | Transfer Mechanism |
Google Cloud | EU / USA | Cloud hosting | Processing of Customer Personal Data | SCCs + UK Addendum |
Google FCM (Firebase Cloud Messaging) | USA | Push notifications (Android) | Device IDs / push tokens | SCCs + UK Addendum |
Google Firebase Crashlytics | USA | Crash reporting (Android client) | Device metadata, logs | SCCs + UK Addendum |
Google Marketplace | USA | Distribution of app downloads | Download metadata | SCCs + UK Addendum |
Amazon Marketplace | EU / USA | Distribution of app downloads | Download metadata | SCCs + UK Addendum |
Apple APNS | USA | Push notifications (iOS) | Device IDs / push tokens | SCCs + UK Addendum |
DigitalOcean LLC | EU / USA | Cloud hosting services | Storage & processing of Customer Personal Data | SCCs + UK Addendum |
Microsoft Azure Marketplace | EU / USA | Distribution of app downloads | Download metadata | SCCs + UK Addendum |
OVH SAS | EU | Cloud hosting services | Storage & processing of Customer Personal Data | No transfer required |
Twilio Inc. – SendGrid | EU / USA | Email provider | Email metadata | SCCs + UK Addendum |
3CX Video Conferencing – Service Sub-processors
Sub-processor | Country of Processing | Service Description | Personal Data Involvement | Transfer Mechanism |
Google Cloud | EU / USA | Cloud hosting & user sync | User profile data, conferencing metadata | SCCs + UK Addendum |
YouTube (Alphabet Inc.) | USA | Streaming & playback | Video URLs, IP addresses | SCCs + UK Addendum |
Amazon AWS | EU / USA | Cloud hosting | Storage & processing of conferencing data | SCCs + UK Addendum |
DigitalOcean LLC | EU / USA | Cloud hosting | Storage & processing of Customer Personal Data | SCCs + UK Addendum |
Host Africa (Pty) Ltd | South Africa | Cloud hosting | Storage & processing of Customer Personal Data | SCCs + UK Addendum (if SA → EU/UK) |
Vultr (The Constant Company LLC) | EU / USA | Cloud hosting | Storage & processing of Customer Personal Data | SCCs + UK Addendum |
Corporate/Marketing Processors (No Processing under the DPA)
The following providers are used exclusively for 3CX website analytics, advertising optimisation or corporate marketing purposes.
They do not process Customer Personal Data provided under this DPA. Their inclusion is for transparency only.
Provider | Purpose | Nature of Activity | Customer Data Processed |
Google Analytics | Website analytics | Tracks website usage | None under this DPA |
Google Ads | Advertising optimisation | Conversion and campaign tracking | None under this DPA |
Meta Pixel | Advertising optimisation | Tracks website activity | None under this DPA |
X Pixel | Advertising optimisation | Tracks website conversions and ad performance | None under this DPA |
LinkedIn Analytics | Marketing analytics | Website interaction tracking | None under this DPA |
Reddit Analytics | Marketing analytics | Campaign tracking | None under this DPA |
Access by Support Providers
Where a Support Sub-processor (e.g., TeamViewer) has potential access to Personal Data:
- Access is occasional, limited, and logged.
- Access occurs only when Customer requests support.
- The Sub-processor is bound by confidentiality and processor-level data protection obligations.
- Sub-processor may only access data strictly necessary to fulfil the support function.
Standard Contractual Clauses
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32021D0914
See Also
- https://www.3cx.com/company/eula/
- https://www.3cx.com/company/ai-transcription-services/
- https://www.3cx.com/company/gdpr-statement/
- https://www.3cx.com/company/privacy/
- https://www.3cx.com/company/privacy-policy/
- https://www.3cx.com/company/terms-and-conditions/
- https://www.3cx.com/company/hipaa-policy/
- https://www.3cx.com/company/refund-cancellation-policy/
Last Updated
This document was last updated 26 June 2026