Data Processing Addendum
How we process personal data we hold for a client.
This addendum applies when Xpancom processes personal data on a client's documented instructions as part of an engagement. It does not apply to Xpancom's own inquiry, account, and security records, where Xpancom is the controller.
01 / Section
Roles.
The client is the controller of personal data about its employees, customers, and suppliers that it provides to Xpancom or authorizes Xpancom to process. Xpancom is the processor of that data. Xpancom is the controller of marketing inquiries, operator-issued intake it originates, authentication identity, and security logs, as described in the Privacy Policy.
Xpancom is not a HIPAA business associate under these public terms. Do not send protected health information or payment card data to intake, email, or the workspace. If an engagement later requires a business associate agreement, that agreement must be signed separately and will name the systems in scope.
02 / Section
Instructions, confidentiality, and people.
We will process client-controlled personal data only on documented instructions, including in the statement of work, unless law requires otherwise. People who handle it are bound to confidentiality. We will not use it to train public foundation models.
03 / Section
Subprocessors.
Current subprocessors are listed on the Trust Center. We will give at least 30 days' notice of a material addition, except where an emergency security substitution is required. The client may object on reasonable data-protection grounds. If we cannot accommodate the objection, the client may terminate the affected services as described in the Professional Services Terms.
04 / Section
Security measures.
We apply the technical and organizational measures described in the security overview: invitation-only access, least privilege, encryption in transit and at rest, logging, backups, vendor review, and incident response. Those measures may evolve without reducing overall protection.
05 / Section
Assistance with rights requests and impact assessments.
If a person contacts Xpancom about client-controlled data, we will redirect them to the client unless law requires us to respond directly. We will assist the client with rights requests, security information, and data-protection impact assessments to the extent the information is available to us, at the client's reasonable expense if the work is not already in scope.
06 / Section
Personal-data breach notice.
We will notify the client without undue delay after becoming aware of a personal-data breach affecting client-controlled data we process, and will provide the information we reasonably have about the nature of the incident, the data concerned, and the steps we are taking. Notification is not an admission of fault.
07 / Section
Return, deletion, and audits.
At the end of processing we will, at the client's choice, return or delete client-controlled personal data, except where law or the published retention schedule requires a copy to remain. Deletion from backups follows the backup window.
The client's audit right is satisfied by a current SOC 2 report under non-disclosure when one exists, plus reasonable written answers to security questionnaires. On-site audits are available only if a report does not exist or does not cover the question, on 30 days' notice, during business hours, and at the client's expense.
08 / Section
International transfers.
Processing takes place in the United States. Where the client is in the EEA, United Kingdom, or Switzerland and a transfer mechanism is required, the parties incorporate the applicable Standard Contractual Clauses (controller-to-processor) on request, with Xpancom as data importer. The clauses prevail over this addendum on transfer issues.