Data Processing Addendum
Version 2.0 · Effective 2026-07-15. This DPA is incorporated by reference into the Terms of Service and applies whenever we process personal data on behalf of a customer. It reflects Articles 28 and 32 of Regulation (EU) 2016/679 (GDPR) and equivalent UK and Swiss law.
1. Definitions
Controller, Processor, Personal Data, Processing, Data Subject and Personal Data Breach have the meanings given in Article 4 of the GDPR. Customer is the entity accepting the Terms of Service. X-com refers to the platform operator.
2. Roles & scope
The Customer is the Controller of Customer Personal Data; X-com is the Processor. Where X-com engages sub-processors, they act as sub-processors of X-com. The subject matter, nature, purpose, categories of data and data subjects are described in Annex I.
3. Duration of processing
Processing continues for the term of the Terms of Service, plus any additional period during which we are required or permitted to retain Customer Personal Data under applicable law (see Section 11).
4. Instructions
We process Customer Personal Data only per documented Customer instructions — including the Terms of Service, this DPA, in-product configuration, and any subsequent written instructions — and applicable law. We inform the Customer if we believe an instruction infringes data protection law.
5. Confidentiality
Personnel authorised to process Customer Personal Data are bound by written confidentiality obligations that survive termination of their engagement.
6. Security (Art. 32)
We implement the technical and organisational measures listed in Annex II, taking into account the state of the art, cost of implementation, the nature, scope, context and purposes of processing, and the risks to data subjects.
7. Sub-processors (Art. 28(2), 28(4))
The Customer grants X-com general written authorisation to engage the sub-processors listed at /trust/subprocessors (current version 2026-07-15, with 8 entries). We give at least 30 days' notice before adding or replacing a sub-processor by updating that page and its JSON feed. The Customer may object on reasonable data protection grounds; if we cannot accommodate the objection, the Customer may terminate the affected services with a pro-rata refund of pre-paid fees.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA and remain liable to the Customer for their performance.
8. Assistance obligations (Art. 28(3)(e)–(f))
Taking into account the nature of processing and information available to us, we assist the Customer with: (a) responses to data subject requests under Articles 15–22; (b) security of processing under Article 32; (c) breach notification under Articles 33–34; (d) data protection impact assessments under Article 35; and (e) prior consultation under Article 36.
9. Personal data breach notification (Art. 33)
We notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 72 hours. Notification is sent to the workspace owner email on record and includes the information required by Article 33(3) to the extent then available.
10. Data subject rights
In-product tooling lets workspace admins export Customer data (Art. 20) and delete Customer data (Art. 17) within statutory deadlines. For requests we receive directly, we forward them to the Customer without responding to the data subject except as legally required.
11. Deletion & return
Upon termination or on written Customer request, we delete or return all Customer Personal Data within 30 days, subject to legal retention obligations (e.g. tax, dispute resolution, ongoing legal holds). Backups age out per the retention window in Annex II.
12. Audit rights (Art. 28(3)(h))
Once per year and on 30 days' notice, or more frequently for cause following a substantiated breach, the Customer may (a) review our latest independent audit report (e.g. SOC 2) under NDA, or (b) conduct a documentary audit at their own expense. On-site audits are available for cause following a substantiated Personal Data Breach.
13. International transfers (Art. 44 et seq.)
Transfers of Customer Personal Data outside the EEA rely on:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller → Processor) between the Customer and X-com and Module Three (Processor → Processor) between X-com and its sub-processors, with Annexes I & II populated per this DPA;
- the UK International Data Transfer Addendum (Version B1.0) for UK-origin transfers; and
- the Swiss addendum issued by the FDPIC for Swiss-origin transfers.
Where an adequacy decision applies, no additional mechanism is required. We complete a Transfer Impact Assessment for material US destinations post-Schrems II; a summary is available on request.
14. Liability & governing law
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Governing law and venue follow the Terms of Service; nothing in this DPA deprives a data subject of mandatory protections under the GDPR.
15. Precedence & changes
In case of conflict, this DPA prevails over the Terms of Service on data protection matters, and the SCCs (where incorporated) prevail over this DPA. We may update this DPA to reflect changes in law or the platform; material changes are announced at least 30 days in advance via the workspace owner email on record.
Annex I — Description of processing
| Subject matter | Provision of the X-com collaboration platform (channels, huddles, tasks, integrations, admin console). |
| Duration | Term of the Terms of Service, plus retention windows in Section 11. |
| Nature & purpose | Hosting, transmitting, indexing and displaying Customer content; delivering notifications; enabling third-party channel bridging chosen by the Customer. |
| Categories of data subjects | Workspace members, workspace admins, client users, collaborator members, invited recipients, end users of connected channels. |
| Categories of personal data | Account identifiers (user ID, email, display name); authentication metadata (hashed password, session, MFA state); workspace and role metadata; message content and attachments; call-quality telemetry; audit and interaction events; billing contact when billing is enabled. No special-category data is required by the platform; Customers must not upload it without a separate written agreement. |
| Frequency | Continuous, on-demand. |
Annex II — Technical & organisational measures
The measures below are also published at /trust and are the same list rendered from a single source.
- Encryption in transit. TLS 1.2+ enforced on all endpoints, webhooks, and inter-service calls.
- Managed disk encryption at rest. AES-256 provider-managed encryption on all database volumes and object storage. Backups are encrypted with the same standard.
- Column-level encryption. Not currently applied to message bodies or attachment content. Passwords are bcrypt-hashed; API tokens are stored as SHA-256 hashes.
- Row-level security (RLS). RLS enabled on every table containing customer data; policies enforce workspace scoping.
- Least-privilege access. Service-role credentials are never exposed to browsers or application code. Admin access requires MFA and is time-boxed.
- Signed webhook verification. HMAC verification on every inbound channel (Slack, Postmark, helpdesks, payment providers).
- Append-only audit log. Auditable actions are written to a log that no application role can modify or delete.
- Rate limiting & abuse controls. Per-workspace and per-integration token buckets protect outbound quota, cost, and integrity.
- Configurable retention. Per-workspace message retention with legal-hold override; deletions are irreversible after grace period.
- Backups & restore. Point-in-time recovery covering the last 7 days on the primary database. Restore procedures are documented and tested at least annually.
- Access reviews. Production-access list is reviewed quarterly by an engineering lead; departures trigger same-day revocation.
- Vulnerability management. Automated dependency scans, periodic application security scans, and a public disclosure channel at /trust#reporting.
- Data export & erasure. GDPR Article 20 export and Article 17 erasure endpoints available to workspace admins from the Data & plan section.
- Incident response. Documented playbook with a 72-hour breach notification target under GDPR Art. 33. Customer contacts are notified via the workspace owner email on record.
Annex III — Sub-processors
The authoritative list, transfer mechanisms per vendor, and the change-notification feed are published at /trust/subprocessors. The machine-readable version is at /subprocessors.json.
To sign the executable version, email legal@connectandflow.app.