XPLG DATA PROCESSING AGREEMENT
This Data Processing Agreement (“DPA”) forms part of the agreement or Terms and Conditions (the “Agreement”) entered between XPLG Ltd. (“XPLG”, “We”, “Us”) and the customer identified in the Agreement (“Customer”, “You”).
Effective date. This DPA takes effect on the date the Customer downloads, installs, or uses the Software, or the date of the Agreement, whichever is earlier.
Deployment model. The Software is installed and operated in Customer’s own environment. XPLG does not host or access Customer’s production data. XPLG may Process limited Personal Data only for license management, account administration, and optional technical support as described herein.
1. INTERPRETATION AND DEFINITIONS
1.1 Headings are for convenience only and do not affect interpretation.
1.2 References to clauses are references to clauses of this DPA.
1.3 Words in the singular include the plural and vice versa.
1.4 Capitalized terms not defined herein have the meaning given in the Agreement.
1.5 Definitions
- “Controller” means the entity that determines the purposes and means of Processing Personal Data.
- “Processor” means the entity that Processes Personal Data on behalf of the Controller.
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on Personal Data (collection, storage, use, disclosure, etc.).
- “GDPR” means Regulation (EU) 2016/679.
- “UK GDPR” has the meaning given in section 3(10) of the UK Data Protection Act 2018.
- “Data Protection Laws” means, collectively, the GDPR, the UK GDPR, and any applicable laws implementing or supplementing them.
- “Security Documentation” means the technical and organizational security measures described in Schedule 2 (as updated from time to time).
- “Standard Contractual Clauses (SCCs)” means the EU Commission’s standard contractual clauses for the transfer of Personal Data to third countries (Decision (EU) 2021/914, Module 2).
- “UK Transfer Addendum” means the UK ICO’s International Data Transfer Addendum to the EU SCCs (or, where elected by XPLG, the UK International Data Transfer Agreement (IDTA)).
2. PROCESSING OF PERSONAL DATA
2.1 Roles of the Parties.
Customer is the Controller for all Personal Data it Processes using the Software. XPLG acts as a Processor only with respect to limited Personal Data necessary for license activation, account administration, or support requests initiated by Customer.
2.2 Customer Responsibilities.
Customer is responsible for ensuring its Processing complies with Data Protection Laws and for determining the lawful basis for any Personal Data shared with XPLG.
2.3 XPLG Processing Activities.
XPLG will Process Personal Data only:
(i) to perform its contractual obligations under the Agreement;
(ii) to provide license, account, or support services requested by Customer; or
(iii) as required by law.
If XPLG cannot comply with an instruction, it will notify Customer and may suspend the affected Processing. If no resolution is possible, either party may terminate the affected Processing, and Customer shall pay for Services provided up to termination.
2.4 Details of Processing.
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Schedule 1.
3. DATA SUBJECT RIGHTS
Where XPLG Processes Personal Data on Customer’s behalf, it shall assist Customer, to the extent reasonably possible, in responding to requests to exercise rights under the GDPR or UK GDPR. Customer remains responsible for handling requests related to data it Processes within its own environment.
4. CONFIDENTIALITY AND PERSONNEL
XPLG ensures that persons authorized to Process Personal Data are bound by confidentiality obligations and receive appropriate privacy and security training.
5. SECURITY OF PROCESSING
5.1 Measures.
XPLG maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Schedule 2.
5.2 Assistance.
Taking into account the nature of Processing and information available to XPLG, XPLG shall reasonably assist Customer, at Customer’s cost, in fulfilling the obligations under Articles 32–36 GDPR and corresponding UK GDPR provisions.
- PERSONAL DATA INCIDENT MANAGEMENT
If XPLG becomes aware of a Personal Data Breach involving Personal Data Processed by XPLG, it shall notify Customer without undue delay and provide information reasonably available to assist Customer in meeting any notification obligations. Customer is responsible for breaches occurring within its own systems.
- RETURN AND DELETION OF PERSONAL DATA
Upon termination of the Agreement or upon Customer’s request, XPLG shall delete or return any Personal Data Processed by XPLG, unless retention is required by law or necessary to establish, exercise, or defend legal claims.
8. AUDIT AND VERIFICATION
Upon reasonable written request, XPLG will make available documentation or third-party certifications demonstrating compliance with this DPA. Such information is Confidential Information of XPLG and satisfies Customer’s audit rights under Article 28(3)(h) GDPR and equivalent UK GDPR provisions.
9. INTERNATIONAL TRANSFERS
9.1 General.
This DPA is designed for on-premise deployments where XPLG does not host Customer data.
If XPLG transfers Personal Data internationally (for example, via license or support systems), it will implement a valid transfer mechanism under applicable Data Protection Laws.
9.2 EU Transfers.
For transfers from the EEA to countries lacking an adequacy decision, the SCCs (Module 2) are incorporated by reference. Schedules 1–2 serve as the SCCs’ Annexes.
9.3 UK Transfers.
For transfers from the UK to countries lacking adequacy, the UK Transfer Addendum (or, at XPLG’s option, the IDTA) is incorporated by reference alongside the SCCs or as a standalone instrument.
9.4 In case of conflict between this DPA and the SCCs or UK Transfer Addendum/IDTA, those instruments prevail for the relevant transfer only.
- CHANGES IN LAW
XPLG may update this DPA to reflect changes in Data Protection Laws. Any materially adverse changes will be communicated via reasonable means and will apply prospectively.
- TERM AND TERMINATION
This DPA remains in effect for the duration of the Agreement and thereafter as necessary for XPLG to meet its obligations under this DPA.
- RELATIONSHIP WITH THE AGREEMENT
In case of conflict between this DPA and the Agreement, this DPA prevails with respect to data-protection matters.
- GOVERNING LAW AND JURISDICTION
This DPA is governed by the law and jurisdiction stated in the Agreement.
For the SCCs, EU law applies per Clause 17 thereof. For the UK Transfer Addendum/IDTA, the governing law is the law of England and Wales.
- ACCEPTANCE
By downloading, installing, or using the Software, or executing the Agreement, Customer acknowledges and accepts this DPA.
Schedule 1 – Details of Processing
Subject Matter
Limited Processing of Personal Data necessary for license, account, and optional support operations.
Nature and Purpose of Processing
- License activation and entitlement management
- Account administration and billing
- Technical support (including optional diagnostics/logs voluntarily provided by Customer)
- Compliance with legal obligations
Duration
For the term of the Agreement and any legally required retention period.
Types of Personal Data
Business contact details (name, email, company, role, phone – optional); license identifiers; support artifacts provided by Customer.
Categories of Data Subjects
Customer personnel and authorized users.
Processing Location
Primarily within XPLG’s own business systems; any cross-border transfer follows Clause 9.
Schedule 2 – Security Measures
XPLG maintains technical and organizational security measures, including:
- Access-control and authentication management
- Network and endpoint protection (firewalls, anti-malware, patching)
- Encryption of data in transit and at rest where applicable
- Segregation of systems and environments
- Logging, monitoring, and incident-response procedures
- Personnel confidentiality and security training
- Secure handling of support materials and deletion upon case closure
- Business-continuity and backup controls
Signature (optional)
Customer
Signature: _ Name/Title: _ Date: __
XPLG Ltd.
Signature: _ Name/Title: _ Date: __
Last update April 2025



