Last updated: August 1, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between X Enterprises, LLC ("X Enterprises," "we," "us," "our," or "Processor") and the customer that accepts the Agreement ("Customer" or "Controller"). It applies to the extent we process Personal Data contained in Customer Data on Customer's behalf in providing the Products.
This DPA does not apply to personal data we process as a controller for our own purposes (such as account, billing, and usage data), which is described in our Privacy Policy.
Customer is the controller (or a processor acting on behalf of another controller) of Personal Data; we are a processor (or sub-processor). We will process Personal Data only: (a) to provide, secure, and support the Products; (b) on Customer's documented instructions, including those given through the Product's settings and features; and (c) as required by law, in which case we will notify Customer unless legally prohibited.
Details of processing. Subject matter: provision of the Products. Duration: the term of the Agreement plus the retention period in the Agreement. Nature and purpose: hosting, storage, transmission, and display of Customer Data as directed by Customer through the Products. Categories of data subjects and Personal Data: determined by Customer through its use of the Products (typically end users, customers, employees, or contacts of Customer, and identifiers, contact details, and content they submit). Customer agrees not to submit sensitive or special categories of data unless the applicable Product and a Product Addendum expressly support it.
Customer is responsible for: the accuracy and lawfulness of Personal Data submitted to the Products; providing all required notices to, and obtaining all required consents from, data subjects; and ensuring its instructions to us comply with Data Protection Laws.
We ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
We implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the data and the risks of processing. These measures include access controls, encryption of data in transit, credential management, vendor due diligence, and personnel security practices as described in our Privacy Policy.
Customer provides general authorization for us to engage Sub-processors (including hosting, storage, payment, communications, authentication, monitoring, and analytics providers). We will: (a) impose data-protection obligations on Sub-processors that are no less protective than those in this DPA; (b) remain responsible for their performance; and (c) make a current list of Sub-processors available upon request to legal@x.enterprises. We will provide notice of new Sub-processors upon request mechanisms being in place or by updating that list; Customer may object on reasonable data-protection grounds, and if we cannot address the objection, Customer may terminate the affected subscription and receive a refund of prepaid, unused fees.
Taking into account the nature of the processing, we will provide reasonable assistance (including through the Products' features) to enable Customer to respond to data subject requests to exercise rights under Data Protection Laws (such as access, correction, deletion, and portability). If a data subject contacts us directly regarding Personal Data we process on Customer's behalf, we will direct them to Customer where identifiable.
We will notify Customer without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data, and will provide information reasonably available to us to assist Customer in meeting its breach-notification obligations. Our notice is not an acknowledgement of fault or liability.
We will provide reasonable assistance to Customer with data protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the information available to us.
Personal Data is processed in the United States. Where Data Protection Laws require a transfer mechanism for Personal Data originating from the EEA, UK, or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Module 2: controller-to-processor, or Module 3: processor-to-processor, as applicable), and the UK Addendum where applicable, are incorporated by reference into this DPA, with Customer as data exporter and X Enterprises as data importer, and with the details of processing set out in Section 2 above.
To the extent U.S. state privacy laws apply, we act as a "service provider" or "processor" with respect to Personal Data. We will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than providing the Products (including not using it for cross-context behavioral advertising); or combine it with personal information from other sources except as permitted for service providers. We certify that we understand and will comply with these restrictions, and we will notify Customer if we determine we can no longer meet them, in which case Customer may take reasonable steps to stop and remediate unauthorized use.
Upon reasonable written request no more than once per year, we will make available information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of security practices or third-party audit reports where available. Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by such documentation, an audit may be conducted at Customer's expense, during business hours, with reasonable advance notice, and subject to our confidentiality and security requirements.
Upon termination of the Agreement, we will make Customer Data (including Personal Data) available for export for 30 days as described in the Agreement, after which we will delete it, except where retention is required by law. Deletion from backups occurs in the ordinary course of backup rotation.
The liability of each party under this DPA is subject to the limitations of liability in the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls; the Standard Contractual Clauses, where they apply, control over this DPA.
Questions about this DPA or requests for the current Sub-processor list can be sent to legal@x.enterprises.