Data Processing Agreement
Last updated: July 19, 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between Xpitro, operated byXalterra Ltd (“Xpitro”, “Processor”) and the customer entity that subscribes to or otherwise uses the Services (“Customer”, “Controller”) for the provision of Xpitro’s security and compliance platform.
This DPA applies where Xpitro processes Personal Data on behalf of the Customer as part of providing the Services. It is intended to meet the requirements of the UK GDPR and EU GDPR (as applicable), including Article 28.
2. Definitions
- “Personal Data”: any information relating to an identified or identifiable natural person.
- “Processing”: any operation performed on Personal Data (e.g., collection, storage, use, disclosure, deletion).
- “Data Subject”: the identified or identifiable natural person to whom Personal Data relates.
- “Sub-processor”: any processor engaged by Xpitro to Process Personal Data on behalf of the Customer.
- “Customer Content”: content submitted to the Services by or on behalf of the Customer, which may include Personal Data.
- “Security Incident” / “Personal Data Breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
3. Roles and Scope
The Customer is the Controller of Personal Data contained in Customer Content and determines the purposes and means of Processing. Xpitro Processes Personal Data only on documented instructions from the Customer and only as necessary to provide the Services.
Xpitro may Process Personal Data to comply with applicable law. In such cases, Xpitro will inform the Customer of the legal requirement unless prohibited by law.
4. Details of Processing
Subject matter
Provision of security, compliance, audit, risk, and governance functionality, including platform administration, evidence collection workflows, audit trails, reporting, and support.
Duration
For the duration of the Customer’s subscription and any applicable retention period required by law, contract, or reasonable backup practices.
Categories of Data Subjects
- Customer employees, workers, and contractors
- Users authorised by the Customer to access the Services
- Customer’s end users, clients, or third parties whose data may be included in Customer Content
Types of Personal Data
- Contact and professional details (name, email, role, department)
- Account and authentication data (user ID, access tokens, login events)
- Usage data and activity logs (audit logs, user actions, device/IP metadata)
- Customer Content that may include compliance evidence, policies, audit artifacts, and attachments
Special category data
The Services are not designed to require special category data (e.g., health data) by default. If the Customer chooses to upload special category data, the Customer is responsible for ensuring a lawful basis and appropriate safeguards.
5. Processor Obligations
Xpitro shall:
- Process Personal Data only on documented instructions from the Customer
- Ensure persons authorised to Process Personal Data are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Assist the Customer with Data Subject requests (as described below)
- Notify the Customer of Personal Data Breaches as described in this DPA
- Make available information reasonably necessary to demonstrate compliance
6. Security Measures
Xpitro implements technical and organisational measures appropriate to the risk, which may include:
- Encrypted transport
- Role-based access control and least-privilege permissions
- Audit logging and monitoring
- Vulnerability management and regular security assessments
- Incident response procedures and security training
- Physical and infrastructure security controls (where applicable)
7. Sub-processors
The Customer authorises Xpitro to use Sub-processors to deliver the Services, provided that:
- Xpitro imposes equivalent data protection obligations on Sub-processors
- Xpitro remains responsible for Sub-processor performance of its obligations
- Xpitro provides notice of material Sub-processor changes where contractually or legally required
A current list of Sub-processors may be made available on request. Please contact us using the details in the “Contact” section.
8. International Transfers
Transfers of Personal Data outside the UK or EEA will be subject to appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU SCCs, EU Standard Contractual Clauses (SCCs), and/or adequacy decisions, as applicable.
9. Data Subject Rights Assistance
Taking into account the nature of the Processing, Xpitro will provide reasonable assistance to the Customer to fulfil obligations to respond to Data Subject requests (including access, rectification, erasure, restriction, objection, and portability).
If Xpitro receives a request directly from a Data Subject relating to Customer Personal Data, Xpitro will, where legally permitted, direct the Data Subject to the Customer.
10. Personal Data Breach
Xpitro will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Xpitro will provide information reasonably necessary for the Customer to comply with its breach notification obligations.
11. Audits and Compliance
Xpitro will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and proportionality controls.
12. Return/Deletion of Data
Upon termination or expiry of the Services, Xpitro will return or delete Customer Personal Data in accordance with the agreement, operational constraints, backup integrity, and applicable law. Any retained data will remain protected under this DPA until deleted.
13. Confidentiality
Xpitro will ensure that all persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations (contractual or statutory).
14. Contact
For questions about this DPA, please contact:
Email: privacy@xpitro.com or legal@xpitro.com