The short version
You are the controller; we are the processor. We process only on your instructions, protect the data, tell you about incidents without undue delay, use vetted subprocessors, and help you meet your obligations.
- Applies whenever Xcelocloud processes personal data on your behalf under a SOW, in any jurisdiction with data-protection law (including GDPR, UK GDPR, US state privacy laws, PIPEDA and others).
- For partners: where a partner processes end-customer data, the partner is typically a processor and Xcelocloud a subprocessor; the obligations below then run from Xcelocloud to the partner, and the partner is responsible for its own flow-down to end customers.
- If this DPA conflicts with the Services Terms or a SOW on personal data, this DPA prevails.
Definitions and roles
"Personal Data" means information relating to an identified or identifiable natural person that Xcelocloud processes on Customer's behalf under a SOW. "Controller," "Processor," "Processing," "Data Subject," "Supervisory Authority" and "Personal Data Breach" have the meanings given in applicable Data Protection Law, with equivalents such as "business," "service provider" and "consumer" under US state law read accordingly. "Data Protection Law" means all laws applicable to the Processing of Personal Data under the SOW. "Subprocessor" means a third party engaged by Xcelocloud to Process Personal Data on Customer's behalf.
Customer is the Controller (or, as a Partner, a Processor acting for its End Customer) and Xcelocloud is the Processor (or Subprocessor). Each party will comply with Data Protection Law applicable to its role. Customer is responsible for the lawfulness of the Personal Data it provides, for having a lawful basis and any required notices or consents, and for the accuracy of its instructions.
Scope and details of processing
Typical IT-services processing: contact and account data of your users, identity and device data, logs and tickets. Nothing more than the Services require.
- Subject matter and purpose: provision of the Services described in the SOW, including monitoring, support, security operations, project and field work, service desk, reporting and the operation of XceloHub.
- Duration: the term of the SOW plus the deletion period in section 9.
- Nature: collection, storage, access, analysis, correlation, transmission, correction and deletion as necessary to deliver and support the Services.
- Categories of Data Subjects: Customer's employees, contractors and end users; for Partners, End Customers' personnel and end users; Customer's suppliers and other contacts whose details appear in in-scope systems.
- Categories of Personal Data: names, business contact details, user and account identifiers, job titles, device and network identifiers, authentication metadata, log and telemetry data, ticket and communication content, and any other Personal Data Customer places in in-scope systems.
- Sensitive data: not intended to be processed. If a SOW brings regulated data (for example PHI, payment card data or government-restricted data) into scope, the SOW will state the applicable requirements and any additional agreement (such as a HIPAA Business Associate Agreement) will be signed before Processing begins.
Processing on instructions
Xcelocloud will Process Personal Data only on Customer's documented instructions, which are the Services Terms, the SOW, this DPA and reasonable written instructions consistent with them, unless required otherwise by law, in which case Xcelocloud will inform Customer before Processing where legally permitted. Xcelocloud will inform Customer promptly if, in its opinion, an instruction infringes Data Protection Law, and may suspend the instruction until resolved. Xcelocloud will not sell or share Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than the Services, or combine it with Personal Data from other sources except as permitted by law for the Services.
Personnel and confidentiality
Xcelocloud limits access to Personal Data to personnel who need it to perform the Services, binds them to written confidentiality obligations, provides data-protection and security training, and applies background screening consistent with applicable law and the SOW.
Security measures
Risk-appropriate technical and organizational controls across access, encryption, monitoring, vulnerability management, continuity and vendor management.
Xcelocloud maintains a written information-security program with administrative, technical and physical measures appropriate to the risk, including at minimum:
- Access control: role-based least-privilege access, named accounts, multi-factor authentication for administrative and remote access, periodic access reviews and prompt deprovisioning.
- Encryption: industry-standard encryption of Personal Data in transit over public networks and at rest within Xcelocloud-managed systems.
- Logging and monitoring: centralized logging of administrative and security-relevant events, retained and reviewed to detect and investigate incidents.
- Vulnerability and change management: patching and configuration management for Xcelocloud-managed systems, controlled change processes, and periodic independent security assessment.
- Business continuity: backups, redundancy and tested recovery procedures for the Platform.
- Physical security: Xcelocloud-managed infrastructure is hosted in data centers maintaining independent security certifications; Xcelocloud offices restrict physical access.
- Secure development: security requirements, code review and testing for Platform changes.
- Vendor management: due diligence and contractual controls for Subprocessors.
Xcelocloud may update these measures provided overall protection is not materially reduced. Where Xcelocloud operates within Customer's environment, Customer remains responsible for the security of systems, accounts and data outside Xcelocloud's contracted scope.
Subprocessors
We use vetted subprocessors (hosting, productivity, security tooling, affiliated delivery centers). We publish the list, give notice of changes, and stay responsible for them.
Customer authorizes Xcelocloud to engage Subprocessors, including Xcelocloud affiliates and delivery centers, for the categories of service described in the current Subprocessor List available from Xcelocloud on request or at the location referenced in the SOW. Xcelocloud will impose data-protection obligations on each Subprocessor no less protective than this DPA and remains liable for their performance. Xcelocloud will give Customer at least 30 days' notice before adding or replacing a Subprocessor; Customer may object in writing on reasonable data-protection grounds within that period, and the parties will work in good faith to resolve the objection. If it cannot be resolved, Customer may terminate the affected Services on written notice without early-termination charges for the terminated portion.
Data subject requests and assistance
Xcelocloud will, taking into account the nature of the Processing, assist Customer with appropriate technical and organizational measures to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection), data-protection impact assessments and consultations with Supervisory Authorities. If Xcelocloud receives a request directly from a Data Subject or an authority relating to Customer's Personal Data, it will redirect the Data Subject to Customer, or notify Customer of the authority request where legally permitted, and will not respond substantively without Customer's instruction except where legally required. Assistance beyond what the Services include may be chargeable at the rates in the SOW.
Personal Data Breach notification
Notice without undue delay and no later than 72 hours after confirmation, with what we know, what we are doing, and a named contact.
Xcelocloud will notify Customer without undue delay, and in any event within 72 hours, after confirming a Personal Data Breach affecting Customer's Personal Data. The notice will describe the nature of the breach, categories and approximate numbers of Data Subjects and records, likely consequences, measures taken or proposed, and a point of contact, with updates as information becomes available. Xcelocloud will cooperate reasonably in Customer's investigation, mitigation and any notifications Customer must make, and will not notify Data Subjects, regulators or the public on Customer's behalf unless Customer instructs it or law requires. Notification is not an admission of fault.
Return and deletion
On expiry or termination of a SOW, and at any time on Customer's written request, Xcelocloud will return Personal Data in a commonly used format or delete it, at Customer's choice, and delete remaining copies within 90 days, except to the extent retention is required by law or the data persists in encrypted backups, which are isolated and deleted on the normal backup cycle. On request Xcelocloud will certify deletion in writing.
Audits and compliance information
Independent reports and security questionnaires first; on-site audit once a year or after an incident, on notice, under confidentiality.
Xcelocloud will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of independent assessments and completed security questionnaires. Where that information is insufficient to satisfy a legal requirement, Customer or an independent auditor bound by confidentiality may audit Xcelocloud's relevant controls no more than once in any 12-month period, or following a Personal Data Breach, on at least 30 days' notice, during business hours, in a manner that does not disrupt operations or expose other customers' data. Each party bears its own costs; Xcelocloud may charge for time beyond one business day per audit.
International transfers
Xcelocloud is headquartered in the United States and may Process Personal Data in the United States and in other countries where Xcelocloud, its affiliates or Subprocessors operate, as disclosed in the Subprocessor List or SOW. Where Data Protection Law restricts transfers, the parties rely on an appropriate transfer mechanism: for EEA data, the European Commission's Standard Contractual Clauses (Module 2 controller-to-processor or Module 3 processor-to-processor, as applicable) which are incorporated by reference with Customer as data exporter and Xcelocloud as data importer, the optional docking clause enabled, Irish law and courts for clause 17/18, and Annexes completed by this DPA; for UK data, the UK International Data Transfer Addendum to those Clauses; for Swiss data, the Clauses as adapted for the FADP. Customer may request a US-only delivery location in the SOW where Xcelocloud offers it for the relevant Services.
United States state law terms
To the extent US state privacy laws apply, Xcelocloud acts as a service provider or processor; will not sell or share Personal Data; will not retain, use or disclose it outside the direct business relationship or for purposes other than the Services; will comply with applicable obligations and provide the same level of privacy protection as required of Customer; will notify Customer if it can no longer meet those obligations; and grants Customer the right to take reasonable steps to stop and remediate unauthorized use. Customer may use the audit rights above to confirm compliance.
Liability and precedence
Each party's liability under this DPA is subject to the limitation of liability in the Services Terms, except that the aggregate cap for breach of this DPA is two times the fees paid or payable under the affected SOW in the twelve months preceding the claim, and the exclusion of consequential damages does not apply to regulatory fines finally imposed on a party to the extent caused by the other party's breach of this DPA. This DPA prevails over the Services Terms and the SOW in respect of Personal Data. This DPA is governed by the governing-law and dispute-resolution provisions of the Services Terms, except where the Standard Contractual Clauses require otherwise.
Contact
Data-protection inquiries, Subprocessor List requests and breach notices: privacy@xcelocloud.com. Xcelocloud, Inc., 5331 East Mockingbird Lane, Suite 411, Dallas, TX 75206, United States.