Data Processing Addendum

Version 2.0 · Effective 2026-07-15. This DPA is incorporated by reference into the Terms of Service and applies whenever we process personal data on behalf of a customer. It reflects Articles 28 and 32 of Regulation (EU) 2016/679 (GDPR) and equivalent UK and Swiss law.

1. Definitions

Controller, Processor, Personal Data, Processing, Data Subject and Personal Data Breach have the meanings given in Article 4 of the GDPR. Customer is the entity accepting the Terms of Service. X-com refers to the platform operator.

2. Roles & scope

The Customer is the Controller of Customer Personal Data; X-com is the Processor. Where X-com engages sub-processors, they act as sub-processors of X-com. The subject matter, nature, purpose, categories of data and data subjects are described in Annex I.

3. Duration of processing

Processing continues for the term of the Terms of Service, plus any additional period during which we are required or permitted to retain Customer Personal Data under applicable law (see Section 11).

4. Instructions

We process Customer Personal Data only per documented Customer instructions — including the Terms of Service, this DPA, in-product configuration, and any subsequent written instructions — and applicable law. We inform the Customer if we believe an instruction infringes data protection law.

5. Confidentiality

Personnel authorised to process Customer Personal Data are bound by written confidentiality obligations that survive termination of their engagement.

6. Security (Art. 32)

We implement the technical and organisational measures listed in Annex II, taking into account the state of the art, cost of implementation, the nature, scope, context and purposes of processing, and the risks to data subjects.

7. Sub-processors (Art. 28(2), 28(4))

The Customer grants X-com general written authorisation to engage the sub-processors listed at /trust/subprocessors (current version 2026-07-15, with 8 entries). We give at least 30 days' notice before adding or replacing a sub-processor by updating that page and its JSON feed. The Customer may object on reasonable data protection grounds; if we cannot accommodate the objection, the Customer may terminate the affected services with a pro-rata refund of pre-paid fees.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA and remain liable to the Customer for their performance.

8. Assistance obligations (Art. 28(3)(e)–(f))

Taking into account the nature of processing and information available to us, we assist the Customer with: (a) responses to data subject requests under Articles 15–22; (b) security of processing under Article 32; (c) breach notification under Articles 33–34; (d) data protection impact assessments under Article 35; and (e) prior consultation under Article 36.

9. Personal data breach notification (Art. 33)

We notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 72 hours. Notification is sent to the workspace owner email on record and includes the information required by Article 33(3) to the extent then available.

10. Data subject rights

In-product tooling lets workspace admins export Customer data (Art. 20) and delete Customer data (Art. 17) within statutory deadlines. For requests we receive directly, we forward them to the Customer without responding to the data subject except as legally required.

11. Deletion & return

Upon termination or on written Customer request, we delete or return all Customer Personal Data within 30 days, subject to legal retention obligations (e.g. tax, dispute resolution, ongoing legal holds). Backups age out per the retention window in Annex II.

12. Audit rights (Art. 28(3)(h))

Once per year and on 30 days' notice, or more frequently for cause following a substantiated breach, the Customer may (a) review our latest independent audit report (e.g. SOC 2) under NDA, or (b) conduct a documentary audit at their own expense. On-site audits are available for cause following a substantiated Personal Data Breach.

13. International transfers (Art. 44 et seq.)

Transfers of Customer Personal Data outside the EEA rely on:

Where an adequacy decision applies, no additional mechanism is required. We complete a Transfer Impact Assessment for material US destinations post-Schrems II; a summary is available on request.

14. Liability & governing law

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Governing law and venue follow the Terms of Service; nothing in this DPA deprives a data subject of mandatory protections under the GDPR.

15. Precedence & changes

In case of conflict, this DPA prevails over the Terms of Service on data protection matters, and the SCCs (where incorporated) prevail over this DPA. We may update this DPA to reflect changes in law or the platform; material changes are announced at least 30 days in advance via the workspace owner email on record.


Annex I — Description of processing

Subject matterProvision of the X-com collaboration platform (channels, huddles, tasks, integrations, admin console).
DurationTerm of the Terms of Service, plus retention windows in Section 11.
Nature & purposeHosting, transmitting, indexing and displaying Customer content; delivering notifications; enabling third-party channel bridging chosen by the Customer.
Categories of data subjectsWorkspace members, workspace admins, client users, collaborator members, invited recipients, end users of connected channels.
Categories of personal dataAccount identifiers (user ID, email, display name); authentication metadata (hashed password, session, MFA state); workspace and role metadata; message content and attachments; call-quality telemetry; audit and interaction events; billing contact when billing is enabled. No special-category data is required by the platform; Customers must not upload it without a separate written agreement.
FrequencyContinuous, on-demand.

Annex II — Technical & organisational measures

The measures below are also published at /trust and are the same list rendered from a single source.

Annex III — Sub-processors

The authoritative list, transfer mechanisms per vendor, and the change-notification feed are published at /trust/subprocessors. The machine-readable version is at /subprocessors.json.

To sign the executable version, email legal@connectandflow.app.