Legal & Policies
This Data Processing Agreement (DPA) governs how XILA processes personal data on your behalf in full compliance with the General Data Protection Regulation (EU) 2016/679. It applies to all users whose personal data is processed in connection with the XILA marketplace platform.
To ensure clarity and transparency, the following definitions apply throughout this agreement:
Data Controller: The entity (you) that determines the purposes and means of processing personal data.
Data Processor: XILA — the entity that securely processes personal data on behalf of the Data Controller.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing: Any operation performed on personal data, including collection, storage, adaption, retrieval, use, disclosure, or destruction.
Sub-Processor: Any third party engaged by XILA to assist in processing data on the Data Controller's behalf.
This DPA applies to all personal data processed by XILA in connection with the Services, including data of EEA/UK Data Subjects. It seamlessly supplements our Terms and Conditions and Privacy Policy. In the event of any conflict regarding data protection matters, the terms of this DPA shall prevail.
Determine the purposes and means of processing.
Ensure a lawful basis for processing personal data.
Obtain necessary consents directly from Data Subjects.
Comply with all applicable data protection laws.
Processes data strictly per your documented instructions.
Implements robust, enterprise-grade security measures.
Notifies you of data breaches within 72 hours.
Maintains comprehensive records of processing activities.
To provide our services efficiently, we process specific categories of personal data:
Account Info: Names, emails, phones, usernames.
Profile Data: Bios, photos, user preferences.
Communications: Messages, chat history, calls.
Transactions: Purchase history, payment details.
Usage Data: Platform activity and analytics.
Technical Data: IP addresses, device & browser info.
TLS/SSL encryption in transit.
Strong encryption at rest.
Strict access controls & authentication.
Network security & firewalls.
Advanced intrusion detection systems.
Reliable data backup & recovery systems.
Staff data protection training.
Enforced confidentiality obligations.
Rapid incident response procedures.
Regular security audits and reviews.
Comprehensive business continuity plans.
Compliance Certifications Maintained: ISO 27001, SOC 2 Type II, PCI DSS.
You authorize XILA to engage trusted sub-processors to facilitate service provision. All sub-processors are bound by stringent data protection obligations equivalent to those established in this DPA.
| Category | Provider | Purpose |
|---|---|---|
| Cloud Infrastructure | [Cloud Provider] | Data hosting and storage |
| Chat / Messaging | Agora Chat SDK | Real-time chat and messaging |
| Voice / Video Calls | Agora RTC SDK | Audio and video calling |
| Payment Processing | Stripe | Secure payment processing |
| Analytics | [Analytics Provider] | Usage analytics and monitoring |
| Email Delivery | [Email Provider] | Transactional and marketing emails |
We will provide a 30-day advance notice before introducing any new sub-processors or replacing existing ones. You reserve the right to object to such changes.
XILA is fully committed to assisting you in fulfilling Data Subject Rights requests. We aim to acknowledge requests within 5 business days and complete them within 30 days:
Right of Access: Provide comprehensive access to stored data.
Right to Rectification: Swiftly correct inaccurate or incomplete data.
Right to Erasure: Delete personal data seamlessly upon legitimate request.
Right to Restriction: Halt or limit processing activities when contested.
Data Portability: Export data in a structured, machine-readable format.
Right to Object: Respect objections to specific data processing operations.
In the rare event of a personal data breach, XILA is obligated to notify you without undue delay and, where feasible, within 72 hours. Our comprehensive notification will detail the nature of the breach, categories and approximate numbers of affected Data Subjects, potential consequences, robust measures taken to address and mitigate the issue, and a dedicated contact point for further coordination.
Personal data may occasionally be transferred outside the European Economic Area (EEA) to deliver our global services. We guarantee full compliance by strictly employing EU Standard Contractual Clauses (SCCs), leveraging adequacy decisions, and utilizing other officially approved legal mechanisms. Official documentation demonstrating our transfer safeguards is available upon request.
We retain personal data solely for the duration of our service agreement, or as strictly mandated by statutory laws. Upon contract termination or expiration, all relevant personal data is systematically deleted or securely returned to you within 30 days, unless longer retention is legally required. Formal certification of deletion will be provided upon your request.
You maintain the explicit right to request detailed information regarding our data processing practices and to formally audit our compliance. Audits require a minimum of 30 days' advance notice, are conducted exclusively during standard business hours, remain subject to confidentiality obligations, and are performed at your expense (unless a material security breach is uncovered). Our latest ISO 27001 and SOC 2 Type II audit reports are readily available for your review.
We meticulously maintain comprehensive and up-to-date records of all processing activities performed on your behalf. These detailed records outline the exact categories of data processed, authorized recipients, geographical data locations, and defined retention schedules, fully conforming to GDPR Article 30 requirements.
All personal data processed through our platform is treated as strictly confidential. We ensure that our personnel, contractors, and sub-processors authorized to process personal data have committed themselves to stringent confidentiality agreements or are under an appropriate statutory obligation of professional secrecy.
Each party's liability arising out of or related to this Data Processing Agreement, whether in contract, tort, or under any other theory of liability, is subject to the limitations of liability set forth in the overarching Terms and Conditions between you and XILA, unless explicitly prohibited by applicable data protection legislation.
This Data Processing Agreement becomes effective concurrently with the overarching service agreement and remains in full force for the entire duration of your use of the XILA platform. Vital provisions, including confidentiality, data retention, audit rights, and liability, shall perpetually survive the termination of this agreement.
Without prejudice to mandatory rights afforded to data subjects under the GDPR, this agreement and any disputes arising from it shall be governed by and construed in accordance with the exact jurisdiction and governing law stipulated in the primary Terms and Conditions.
XILA reserves the right to dynamically update this Data Processing Agreement to reflect changes in legal, regulatory, or operational requirements. Any material changes will be communicated prominently via email or platform notification. Continued use of the platform after updates signifies your ongoing acceptance.
This DPA, together with our Terms and Conditions and Privacy Policy, constitutes the complete and exclusive understanding between you and XILA regarding the processing of personal data, effectively superseding all prior verbal or written negotiations and agreements on this subject matter.
By registering for an account, accessing, or actively utilizing the XILA platform, you formally acknowledge that you have read, understood, and unequivocally agree to be bound by all the terms and conditions set forth in this comprehensive Data Processing Agreement.
For any inquiries regarding your data protection rights, to submit a data access or deletion request, or to raise a concern about how your personal data is being processed, please contact our Data Protection Officer. We take all data privacy matters seriously and will respond to your request within the timeframes required by applicable law.