Skip to content

Data Processing Agreement

XOXO Systems
effective September 3, 2026
english (en)

This Data Processing Agreement (the “DPA”) is incorporated into and forms part of the Consumer Terms of Service or the Enterprise Service Agreement (as applicable, the “Agreement”) between the customer identified in the Agreement (“Customer”) and XOXO Systems, Inc. (“XOXO”). It applies when XOXO processes Customer Personal Data on Customer’s behalf in providing the Services.

Capitalized terms not defined in this DPA have the meanings in the Agreement. If there is a conflict with respect to the processing of Customer Personal Data, the following order of precedence applies: (1) the Standard Contractual Clauses (including the UK Addendum and Swiss addendum, where they apply), (2) this DPA, (3) the Agreement, (4) the Privacy Policy. Product-specific terms control that product’s fees, plan structure, metering, and retention.

By using the Services, executing an Order Form, or otherwise agreeing to the Agreement, Customer agrees to this DPA.

1. Definitions

“Applicable Data Protection Laws” means privacy and data-protection laws that apply to the processing of Customer Personal Data under the Agreement, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA, the Texas Data Privacy and Security Act, and similar U.S. state laws, in each case as applicable.

“Customer Personal Data” means Personal Data that Customer or its Authorized Users submit to, or instruct XOXO to retrieve into, the Services, including Customer Content and Customer Data to the extent they include Personal Data.

“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as it forms part of UK law.

“Personal Data,” “data subject,” “processing,” “controller,” and “processor” have the meanings in Applicable Data Protection Laws or, if none, in the GDPR. “Controller” includes “business,” and “processor” includes “service provider” and “contractor,” as those terms are used in Applicable Data Protection Laws.

“Restricted Data” means protected health information under HIPAA, payment card data protected by PCI-DSS, “nonpublic personal information” under the Gramm-Leach-Bliley Act, and other data subject to a specialized statutory security framework XOXO has not agreed in writing to support.

“Security Incident” means a breach of XOXO’s security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in XOXO’s possession. It does not include unsuccessful attempts that do not compromise Customer Personal Data, including failed logins, pings, port scans, or denial-of-service attacks.

“Standard Contractual Clauses” or “SCCs” means Module Two (controller to processor) and/or Module Three (processor to processor) of the clauses approved by European Commission Implementing Decision (EU) 2021/914.

“Subprocessor” means a third party engaged by XOXO to process Customer Personal Data in providing the Services. It does not include XOXO personnel or Customer’s own Connected Systems, model keys, or MCP servers.

“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.

2. Scope and roles

2.1 Processor. With respect to Customer Personal Data, Customer is the controller (or a processor itself) and XOXO is Customer’s processor (or subprocessor). Each party will comply with Applicable Data Protection Laws that apply to its role.

2.2 Controller activities excluded. This DPA does not apply to personal information XOXO processes as an independent controller, such as account, billing, and Usage Data described in the Privacy Policy.

2.3 Details of processing. The subject matter, duration, nature, purpose, types of data, and categories of data subjects are described in Schedule 1 and determined by Customer’s use of the Services.

2.4 Customer responsibilities. Customer represents that it has provided all notices and obtained all consents and other lawful bases required for XOXO to process Customer Personal Data as described in the Agreement and this DPA, including processing by Subprocessors and model providers needed to generate Outputs and perform Actions. Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Data and for configuring the Services, Connected Systems, agents, and MCP tools in compliance with Applicable Data Protection Laws.

3. Customer instructions

3.1 Documented instructions. Customer instructs XOXO to process Customer Personal Data: (a) to provide, maintain, secure, and support the Services; (b) as specified in the Agreement, this DPA, an Order Form, and Customer’s use of in-product configuration, APIs, and MCP interfaces; and (c) as otherwise documented in writing.

3.2 Lawful instructions. XOXO will process Customer Personal Data only on those instructions, unless Applicable Data Protection Laws require otherwise. If law requires processing beyond the instructions, XOXO will inform Customer before processing if legally permitted.

3.3 Unlawful instructions. XOXO will promptly inform Customer if, in its opinion, an instruction violates Applicable Data Protection Laws. XOXO is not obligated to perform a legal analysis of Customer’s instructions.

3.4 CCPA / U.S. state service-provider terms. XOXO will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data outside the direct business relationship or for any purpose other than the business purposes specified in this DPA and the Agreement, except as Applicable Data Protection Laws permit; or (c) combine Customer Personal Data with personal data from another person or from XOXO’s own interactions with a data subject, except as needed to provide the Services or as those laws permit. XOXO certifies that it understands these restrictions. If XOXO determines it can no longer meet its obligations, it will notify Customer, and Customer may take reasonable steps to stop or remediate unauthorized processing.

3.5 No training. Neither XOXO nor its Subprocessors will use Customer Personal Data to train, improve, or develop generally available AI models or services. This does not restrict processing Customer Personal Data to provide the Services to Customer, including generating Outputs and performing Actions, or a provider’s processing for safety, security, or legal compliance.

4. Confidentiality

XOXO will ensure that persons it authorizes to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.

5. Security

5.1 Measures. Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, XOXO will implement and maintain commercially reasonable administrative, technical, and physical measures designed to protect Customer Personal Data, as summarized in Schedule 2. XOXO may update those measures, provided the update does not materially reduce the overall security of the Services.

5.2 Customer controls. Customer is responsible for credentials, Connected System permissions, encryption of data before it is sent to the Services where Customer requires it, agent approvals, and MCP tool grants. XOXO is not liable for incidents resulting from Customer’s configuration or from Customer’s or its providers’ systems.

6. Subprocessors

6.1 General authorization. Customer generally authorizes XOXO to engage Subprocessors to process Customer Personal Data as needed to provide the Services. Current categories include:

  • cloud infrastructure and hosting;
  • content delivery and networking;
  • email, communications, and customer-support tooling;
  • payment and identity providers (to the extent they process Customer Personal Data);
  • observability, logging, and security tooling; and
  • AI, model, and inference providers used to generate Outputs and perform Actions.

Customer may request a then-current list of Subprocessors that process Customer Personal Data by emailing legal@xoxo.systems.

6.2 Requirements. XOXO will enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective than those in this DPA, to the extent applicable to the services provided. XOXO remains liable for Subprocessor acts and omissions to the same extent XOXO would be liable if it performed the services itself, subject to the limitations of liability in the Agreement.

6.3 Changes. Before appointing a new Subprocessor that will process Customer Personal Data, XOXO will give Customer reasonable notice by email or by posting an updated list. Customer may object on reasonable grounds relating to data protection by written notice to legal@xoxo.systems within fifteen (15) days of that notice. The parties will work in good faith to find a commercially reasonable resolution. If they cannot do so within fifteen (15) days after the objection, Customer may terminate the affected Services on written notice, and XOXO will refund prepaid fees for the unused remainder of the then-current term of those Services. If Customer does not object in time, Customer is deemed to have authorized the Subprocessor.

6.4 Customer-selected providers. Providers that Customer connects, brings its own keys for, or otherwise directs XOXO to use (including Customer-hosted MCP servers and third-party models Customer enables) are not XOXO Subprocessors. Customer is responsible for those providers.

7. Data subject requests

If XOXO receives a request from a data subject relating to Customer Personal Data, XOXO will, to the extent legally permitted, notify Customer without undue delay and may direct the data subject to Customer. Taking into account the nature of the processing, XOXO will provide reasonable assistance to Customer, through available product features where possible, to help Customer respond. XOXO will not respond to the data subject except to redirect the request, unless Applicable Data Protection Laws require otherwise.

8. Assistance; DPIAs

Taking into account the nature of processing and information available to XOXO, XOXO will provide reasonable assistance to Customer with: (a) data protection impact assessments; (b) prior consultation with supervisory authorities; and (c) Customer’s other obligations under Applicable Data Protection Laws relating to Customer Personal Data processed in the Services. XOXO may charge reasonable fees for assistance that goes beyond providing existing product features or documentation, unless the assistance is required because of a Security Incident caused by XOXO’s breach of Section 5.1.

9. International transfers

9.1 Transfers. Customer authorizes XOXO to transfer Customer Personal Data to the United States and other countries where XOXO or its Subprocessors operate, as needed to provide the Services.

9.2 SCCs. To the extent a transfer of Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a country that does not ensure an adequate level of protection requires a transfer mechanism, the SCCs (and the UK Addendum and Swiss addendum, as applicable) are incorporated by reference and completed as described in Schedule 3. They are deemed executed by the parties.

9.3 Transfer impact assessments. Upon reasonable written request, XOXO will provide information reasonably necessary for Customer to complete a transfer impact assessment.

9.4 Conflict. If the SCCs conflict with this DPA, the SCCs control for that transfer.

10. Security Incidents

10.1 Notice. XOXO will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident. Notice will be sent to the email associated with Customer’s account or as specified in an Order Form. XOXO’s notice or response is not an admission of fault or liability.

10.2 Content and cooperation. The notice will include, to the extent reasonably available: the nature of the Security Incident; the categories and approximate number of data subjects and records concerned; likely consequences; and measures taken or proposed to mitigate effects. XOXO will investigate and reasonably cooperate with Customer’s investigation, taking into account the nature of processing and information available to XOXO.

10.3 Customer incidents. Customer will promptly notify XOXO if it becomes aware of unauthorized access originating from Customer’s environment, credentials, agents, or Connected Systems, and will cooperate with investigation and response.

11. Audits

11.1 Information. Upon written request, and no more than once per twelve (12) month period (unless required by a supervisory authority or following a Security Incident caused by XOXO’s breach of Section 5.1), XOXO will make available information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of security practices, responses to security questionnaires, or third-party audit reports or certifications to the extent XOXO maintains them.

11.2 On-site audits. If Applicable Data Protection Laws give Customer a right to audit that cannot reasonably be satisfied under Section 11.1, Customer may conduct an audit of controls relevant to Customer Personal Data, at Customer’s expense, provided: (a) Customer or its auditor executes an appropriate confidentiality agreement; (b) the parties agree in advance on scope, timing, duration, and security controls; (c) the audit is conducted during business hours in a manner that minimizes disruption; and (d) a similar audit has not occurred in the prior twelve (12) months except as stated in Section 11.1. Customer may use audit results only to confirm compliance with this DPA and to meet Customer’s regulatory obligations.

11.3 No SOC claim. This DPA does not represent that XOXO currently maintains any particular certification. Availability of reports depends on what XOXO has in place at the time of the request.

12. Return and deletion

During the term, Customer may export Customer Personal Data using available product features, subject to applicable Plan Limits and retention periods. Within thirty (30) days after termination or expiration of the Agreement, Customer may request return or deletion of Customer Personal Data. XOXO will delete Customer Personal Data within thirty (30) days after that request (or after the thirty-day window if no request is made), except for copies retained in backups until they cycle, or as required by law, to resolve a dispute, or to prevent abuse or security threats. Residual copies remain subject to confidentiality and this DPA until deleted.

Retention periods during the term, including for logs, telemetry, and stored files, are product-specific Plan Limits. After those periods, XOXO may delete the affected data even if the Agreement remains in effect. XOXO is not an archival provider.

13. Restricted Data

Customer will not submit Restricted Data to the Services. XOXO does not offer a HIPAA business associate agreement and has no obligations under this DPA for Restricted Data beyond the security measures in Section 5 that apply to Customer Personal Data generally. Customer assumes all risk if it submits biometric identifiers, precise geolocation, genetic data, data of individuals under 13, or health-related data.

14. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent Applicable Data Protection Laws or the SCCs require otherwise. For enterprise customers, claims arising out of a Data Breach or this DPA are subject to the Data Breach Claims Cap in the Enterprise Service Agreement. XOXO’s notification of a Security Incident is not an admission of liability.

15. Term and changes

This DPA remains in effect for as long as XOXO processes Customer Personal Data under the Agreement. XOXO may update this DPA on reasonable notice to the extent required by changes in Applicable Data Protection Laws, or otherwise by posting a revised version and updating the effective date. Material changes that are not required by law will follow the change process in the Agreement. If Customer objects to a material change that is not required by law and the parties cannot agree, Customer’s exclusive remedy is to stop using the affected Services (and, for an Order Form, to decline to renew).

16. General

16.1 Governing law. This DPA is governed by the governing law and dispute-resolution provisions of the Agreement, except that the SCCs are governed as they provide.

16.2 Survival. Sections that by their nature should survive (including confidentiality, security of retained copies, liability, and this Section 16) survive termination.

16.3 Entire addendum. This DPA is the entire data-processing agreement between the parties regarding Customer Personal Data and supersedes prior data-processing terms on that subject.

Schedule 1 — Details of processing

A. Parties. Data exporter: Customer (and Customer Affiliates using the Services under the Agreement). Data importer: XOXO Systems, Inc., 801 International Pkwy STE 550143, Flower Mound, TX 75022, USA. Contact: legal@xoxo.systems.

B. Subject matter and nature. Providing the Services, which may include hosting, storage, retrieval, organization, analysis, visualization, transmission, deletion, and other processing of Customer Personal Data in software products that unify data, support operational workflows, and run agentic workflows. Processing includes generating Outputs and performing Actions through AI, agents, APIs, and MCP interfaces.

C. Purpose. To provide, maintain, secure, and support the Services for Customer pursuant to the Agreement; to prevent abuse; and to comply with law.

D. Duration. The term of the Agreement, plus any post-termination retention described in Section 12, and any shorter product-specific retention periods that apply during the term.

E. Categories of data subjects. Determined by Customer. May include Customer’s employees, contractors, customers, end users, suppliers, and other individuals whose Personal Data Customer submits or connects.

F. Categories of personal data. Determined by Customer. May include identifiers, contact details, professional information, device and usage information, and any other Personal Data Customer chooses to submit or connect, including content of Inputs, files, connected-system records, and Outputs that reproduce that information.

G. Special categories. None, unless Customer elects to submit them. The Services are not designed for special-category data or Restricted Data. Customer is instructed not to submit them.

H. Frequency. Continuous, as determined by Customer’s use and configuration of the Services.

I. Subprocessors. Categories listed in Section 6.1, as updated under Section 6.3.

Schedule 2 — Technical and organizational measures

XOXO maintains commercially reasonable measures designed to protect Customer Personal Data, which may include:

  • access control, unique user credentials, and least-privilege access for personnel;
  • encryption of data in transit over public networks, and encryption at rest where the product architecture provides it;
  • network segmentation, firewalls, and monitoring designed to detect unauthorized access;
  • logging and alerting for security-relevant events, subject to product-specific retention;
  • personnel confidentiality obligations and access only as needed to provide the Services;
  • vulnerability management and secure-development practices appropriate to the Services;
  • incident-response procedures consistent with Section 10; and
  • vendor review before engaging Subprocessors that will process Customer Personal Data.

XOXO may update these measures without materially reducing the overall security of the Services. Customer is responsible for configuring product-level controls available to it.

Schedule 3 — International transfer mechanisms

A. SCCs. Where Section 9.2 applies:

  • Module Two applies when Customer is a controller. Module Three applies when Customer is a processor.
  • Clause 7 (docking) is included.
  • Clause 9(a) Option 2 (general written authorization) applies. The time period for notice of Subprocessor changes is as in Section 6.3.
  • Clause 11 (optional redress) is not included.
  • Clause 13: the competent supervisory authority is determined as the SCCs provide. If the data exporter is not established in an EU Member State and has not appointed an Article 27 representative, the reference authority is the Irish Data Protection Commission.
  • Clause 17 Option 1: the law of the Republic of Ireland, or, where required by the SCCs, the law of the Member State where the data exporter is established.
  • Clause 18: the courts of the Republic of Ireland, or as otherwise required by the SCCs.
  • Annex I is completed by Schedule 1 and the Agreement. Annex II is completed by Schedule 2. Annex III is completed by the Subprocessor information described in Section 6.
  • The importer’s contact is legal@xoxo.systems.

B. UK. For transfers subject to the UK GDPR, the UK Addendum is incorporated. Table 1 is completed by the parties’ details in the Agreement and Schedule 1. Table 2: the version of the SCCs described above. Table 3: Annexes as above. Table 4: either party may end the Addendum as the UK Addendum provides.

C. Switzerland. For transfers subject to Swiss data-protection law, the SCCs are interpreted to refer to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner is a competent authority, and references to EU Member States include Switzerland, in each case to the extent required for the SCCs to be valid under Swiss law.

Contact

XOXO Systems, Inc.
Attn: Legal / Data Protection
801 International Pkwy STE 550143
Flower Mound, TX 75022
United States

Email: legal@xoxo.systems


xoxo systems

ⓒ 2026 XOXO Systems, Inc.
All rights reserved.

Privacy Policy Terms of Service: Consumer Terms of Service: Enterprise Data Processing Agreement