Data Processing Agreement
Last updated: 3 October 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between X Enterprises, LLC ("X Enterprises," "we," "us," "our," or "Processor") and the customer that accepts the Agreement ("Customer" or "Controller"). It applies to the extent we process Personal Data contained in Customer Data on Customer's behalf in providing the Products.
This DPA does not apply to personal data we process as a controller for our own purposes (such as account, billing, and usage data), which is described in our Privacy Policy.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Data and processed by us on Customer's behalf.
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, which may include U.S. state privacy laws (such as the California Consumer Privacy Act as amended), the EU/UK General Data Protection Regulation ("GDPR"), and Canada's PIPEDA, in each case to the extent applicable.
- "Sub-processor" means a third party we engage to process Personal Data on Customer's behalf.
- "Customer Data", "Products", and other capitalized terms not defined here have the meanings given in the Agreement.
2. Roles and scope of processing
Customer is the controller (or a processor acting on behalf of another controller) of Personal Data; we are a processor (or sub-processor). We will process Personal Data only: (a) to provide, secure, and support the Products; (b) on Customer's documented instructions, including those given through the Product's settings and features; and (c) as required by law, in which case we will notify Customer unless legally prohibited.
Details of processing. Subject matter: provision of the Products. Duration: the term of the Agreement plus the retention period in the Agreement. Nature and purpose: hosting, storage, transmission, and display of Customer Data as directed by Customer through the Products. Categories of data subjects and Personal Data: determined by Customer through its use of the Products (typically end users, customers, employees, or contacts of Customer, and identifiers, contact details, and content they submit). Customer agrees not to submit sensitive or special categories of data unless the applicable Product and a Product Addendum expressly support it.
3. Customer responsibilities
Customer is responsible for: the accuracy and lawfulness of Personal Data submitted to the Products; providing all required notices to, and obtaining all required consents from, data subjects; and ensuring its instructions to us comply with Data Protection Laws.
4. Confidentiality
We ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
5. Security
We implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the data and the risks of processing. These measures include access controls, encryption of data in transit, credential management, vendor due diligence, and personnel security practices as described in our Privacy Policy.
6. Sub-processors
Customer provides general authorization for us to engage Sub-processors (including hosting, storage, payment, communications, authentication, monitoring, analytics, and consent-management providers). We will: (a) impose data-protection obligations on Sub-processors that are no less protective than those in this DPA; (b) remain responsible for their performance under this DPA; and (c) maintain a current list of Sub-processors used to process Personal Data in Customer Data.
List availability. Until a complete Sub-processor inventory is ready to publish, the current list is available only by email request to legal@x.enterprises. We will not publish an incomplete list as Annex A. When the inventory is ready, we will publish it as Annex A (Sub-processors) on this legal hub (on this page, or at /legal/sub-processors) and later changes will follow the notice rules in this Section 6. We may also provide the list through the Product admin or documentation when available.
Notice of changes. We will give Customer notice of any intended addition or replacement of a Sub-processor that will process Personal Data in Customer Data at least fifteen (15) days before the new Sub-processor begins processing that Personal Data (thirty (30) days where feasible for material infrastructure changes). Notice may be provided by email to Customer's designated admin or legal contact on file, by in-product or account notification, and/or by updating the Sub-processor list and noting the change date. Emergency replacements strictly necessary for security, availability, or legal compliance may proceed with shorter notice; we will notify Customer as soon as reasonably practicable and the objection process below will still apply.
Objection. Customer may object to a new Sub-processor on reasonable data-protection grounds by emailing legal@x.enterprises within fifteen (15) days after notice (or within fifteen (15) days after Customer receives notice of an emergency replacement). The parties will cooperate in good faith to address the objection, including by offering a commercially reasonable alternative configuration that avoids the objected-to Sub-processor where available. If we cannot accommodate the objection within a reasonable period, Customer may terminate the Processor services (or the affected Product subscription) for the processing that would use that Sub-processor, by written notice to legal@x.enterprises, and receive a refund of prepaid, unused fees for the terminated portion. This termination right is Customer's sole and exclusive remedy for an unresolved Sub-processor objection under this DPA.
7. Data subject requests
Taking into account the nature of the processing, we will provide reasonable assistance (including through the Products' features) to enable Customer to respond to data subject requests to exercise rights under Data Protection Laws (such as access, correction, deletion, and portability). If a data subject contacts us directly regarding Personal Data we process on Customer's behalf, we will direct them to Customer where identifiable.
8. Personal data breach
We will notify Customer without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data, and will provide information reasonably available to us to assist Customer in meeting its breach-notification obligations. Our notice is not an acknowledgement of fault or liability.
9. Assistance
We will provide reasonable assistance to Customer with data protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the information available to us.
10. International transfers
Personal Data is processed in the United States. Where Data Protection Laws require a transfer mechanism for Personal Data originating from the EEA, UK, or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Module 2: controller-to-processor, or Module 3: processor-to-processor, as applicable), and the UK Addendum where applicable, are incorporated by reference into this DPA, with Customer as data exporter and X Enterprises as data importer, and with the details of processing set out in Section 2 above.
11. U.S. state privacy laws
To the extent U.S. state privacy laws apply, we act as a "service provider" or "processor" with respect to Personal Data. We will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than providing the Products (including not using it for cross-context behavioral advertising); or combine it with personal information from other sources except as permitted for service providers. We certify that we understand and will comply with these restrictions, and we will notify Customer if we determine we can no longer meet them, in which case Customer may take reasonable steps to stop and remediate unauthorized use.
12. Audit
Upon reasonable written request no more than once per year, we will make available information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of security practices or third-party audit reports where available. Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by such documentation, an audit may be conducted at Customer's expense, during business hours, with reasonable advance notice, and subject to our confidentiality and security requirements.
13. Return and deletion
Upon termination of the Agreement, we will make Customer Data (including Personal Data) available for export for 30 days as described in the Agreement, after which we will delete it, except where retention is required by law. Deletion from backups occurs in the ordinary course of backup rotation.
14. Liability and order of precedence
The liability of each party under this DPA is subject to the limitations of liability in the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls; the Standard Contractual Clauses, where they apply, control over this DPA.
Annex A: Sub-processors
Not published on this page yet. Email legal@x.enterprises to request the current Sub-processor list. A public Annex A will be added here when the inventory is ready. This page does not list individual Sub-processors.
Contact us
Questions about this DPA, Sub-processor notices or objections, or requests for the current Sub-processor list can be sent to legal@x.enterprises.
