Skip to content

Data Processing Addendum

This is a plain-language draft reflecting the move to an on-prem-only product. It has not been reviewed by counsel — treat it as a starting point until it has been.

This Data Processing Addendum ("DPA") supplements the XHR Software Inc. License Agreement and Privacy Policy (together, the "Agreement") and is incorporated by reference. It is between XHR Software Inc., a Delaware C-Corp ("XHR Software"), and the Customer.

1. Why this DPA is narrow

XHR Software's product is on-prem software: it runs inside the Customer's own infrastructure, and the Customer's application traffic, target-site data, and end-user Personal Data never pass through any system operated by XHR Software. For that data, XHR Software does not act as a Data Processor or Sub-processor, because it never processes it at all.

This DPA therefore governs only the limited Personal Data XHR Software does handle:

  1. Business contact data (name, email, company, billing details) that Customer provides to purchase, administer, and receive support for a licence — for this, XHR Software acts as an independent Data Controller, as described in the Privacy Policy.
  2. Any data the Customer voluntarily shares with XHR Software for support purposes (e.g. logs or reproduction data sent when requesting help debugging a deployment) — for this narrow, opt-in category, XHR Software acts as a Data Processor on the Customer's instructions, per the terms below.

2. Definitions

Terms not defined here have the meaning given in the Agreement.

  • "Data Protection Laws" — applicable privacy/data-protection laws, including EU/UK GDPR and US state laws (e.g. CCPA).
  • "Personal Data" — data processed by XHR Software as described in Section 1(2) above that is defined as personal data under applicable Data Protection Laws.
  • "Processing," "Controller," "Processor," "Data Subject," "Supervisory Authority" — as defined in the GDPR/UK GDPR.

3. Obligations for support data (Section 1(2))

Where Customer shares Personal Data with XHR Software for support purposes, XHR Software will:

  • Process it only to provide the requested support, per Customer's instructions in the Agreement or the support request itself.
  • Apply appropriate technical and organizational safeguards, consistent with Security.
  • Ensure personnel accessing it are bound by confidentiality obligations.
  • Notify Customer within 24 hours of any breach affecting that data.
  • Delete or return it once the support request is resolved, unless retention is required by law.
  • Not sell it, or use it for any purpose other than the support request.

4. Sub-processors

XHR Software's sub-processors are limited to the general business tooling listed on the Subprocessors page (billing, code hosting, support tooling) — none of which receive Customer's application or end-user data, since XHR Software itself never receives it.

5. Customer responsibility

Because XHR Software's software runs inside Customer's own infrastructure, Customer is the Data Controller (and, where applicable, the Data Processor to its own end users) for all Personal Data processed by the Software. XHR Software has no visibility into, and cannot fulfill Data Subject requests regarding, that data — Customer is responsible for its own compliance obligations with respect to it, including any data protection impact assessment or Data Subject rights processes.

6. Contact

legal@xhr.dev