Security & Legal
Data Processing Addendum (DPA)
Last updated:
This Data Processing Addendum ("DPA") forms part of the Xelp Terms of Service or other written agreement (the "Agreement") between Blaze Technologies Inc, a Delaware corporation with offices at 651 N Broad St., Ste 024, Middletown, DE 19709, USA ("Xelp", the "Processor") and the customer entity that has entered into the Agreement ("Customer", the "Controller"), and governs Xelp's Processing of Personal Data on behalf of the Customer in connection with the Xelp omnichannel support and commerce platform (the "Service").
By using the Service, the Customer agrees to this DPA on behalf of itself and its Authorized Affiliates. This DPA is effective as of the date the Customer accepts the Agreement.
1. Definitions
- "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, which may include, as applicable: (a) the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR; (b) India's Digital Personal Data Protection Act, 2023 ("DPDP Act"); (c) the Seychelles Data Protection Act; (d) the Law of the Republic of Azerbaijan "On Personal Data"; and (e) any other applicable data protection or privacy laws.
- "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by Xelp on behalf of the Customer in connection with the Service ("Service Data" as described in the Xelp Privacy Policy).
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates, including the Customer's End Users, contacts, and customers.
- "Processing" means any operation performed on Personal Data, whether or not by automated means, such as collection, recording, organization, storage, adaptation, retrieval, use, disclosure, restriction, erasure, or destruction.
- "Sub-processor" means any third party engaged by Xelp to Process Personal Data on behalf of the Customer.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Xelp.
- "SCCs" means the Standard Contractual Clauses approved by the European Commission (Decision (EU) 2021/914) for the transfer of personal data to third countries, and, where applicable, the UK International Data Transfer Addendum.
2. Roles and Scope
2.1 Roles. The parties acknowledge that, with respect to the Processing of Service Data, the Customer is the Controller (or, where the Customer itself acts as a processor for a third-party controller, the Customer is a processor and Xelp is a sub-processor), and Xelp is the Processor.
2.2 Customer Instructions. Xelp shall Process Personal Data only on documented instructions from the Customer, including as set out in the Agreement, this DPA, and the Customer's configuration and use of the Service, unless required to do otherwise by applicable law (in which case Xelp shall inform the Customer of that legal requirement before Processing, unless prohibited by law). The Customer's instructions shall be lawful.
2.3 Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.
3. Customer Responsibilities
3.1 The Customer is solely responsible for: (a) the accuracy, quality, and lawfulness of Personal Data submitted to the Service; (b) establishing and maintaining a valid legal basis (including obtaining any required consents from End Users) for the collection and Processing of Personal Data through the Service; (c) providing all required privacy notices to Data Subjects, including regarding the use of messaging channels, automated or AI-assisted responses, and commerce features; (d) complying with all messaging platform requirements applicable to the Customer, including the WhatsApp Business Terms, Meta Platform Terms, and channel-specific opt-in and anti-spam requirements; and (e) responding to Data Subject requests, as Controller.
3.2 The Customer shall not submit to the Service any sensitive or special categories of Personal Data (e.g., health data, biometric data, government identification numbers, data revealing racial or ethnic origin, political opinions, or religious beliefs) unless expressly agreed in writing with Xelp.
3.3 The Customer represents that its instructions to Xelp comply with Applicable Data Protection Law.
4. Xelp Obligations
4.1 Confidentiality. Xelp shall ensure that all personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
4.2 Security. Xelp shall implement and maintain appropriate technical and organizational measures to protect Personal Data against Security Incidents, as described in Annex 2. Xelp may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.
4.3 Data Subject Requests. Taking into account the nature of the Processing, Xelp shall assist the Customer through appropriate technical and organizational measures (including in-app data access, export, and deletion capabilities) in fulfilling the Customer's obligation to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, objection, and grievance redressal). If a Data Subject contacts Xelp directly regarding Service Data, Xelp shall promptly refer the Data Subject to the Customer and shall not respond substantively except as instructed by the Customer or required by law.
4.4 Assistance. Xelp shall provide reasonable assistance to the Customer with data protection impact assessments, consultations with supervisory authorities, and compliance with the Customer's security and breach notification obligations, taking into account the nature of the Processing and information available to Xelp.
4.5 Security Incident Notification. Xelp shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting the Customer's Personal Data. The notification shall include, to the extent known: the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate its effects. Xelp shall cooperate with the Customer and take reasonable steps to mitigate the effects of the Security Incident.
4.6 Deletion and Return. Upon termination or expiry of the Agreement, or upon deletion of the Customer's account, Xelp shall, at the Customer's choice, delete or return all Personal Data, and delete existing copies from its production systems, unless retention is required by applicable law. Absent a contrary instruction, Personal Data is permanently deleted upon account termination or deletion, consistent with the Xelp Privacy Policy. The Customer may export its data (contacts, conversations, commerce data) prior to termination using the Service's export features. For inactive accounts, Xelp may delete data following at least 90 days of inactivity after warning notice, as described in the Agreement and Privacy Policy.
4.7 Records and Audits. Xelp shall maintain records of its Processing activities as required by Applicable Data Protection Law. Xelp shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or its mandated auditor, provided that: (a) audits are limited to once per 12-month period (except following a Security Incident or where required by a supervisory authority); (b) the Customer gives at least 30 days' written notice; (c) audits are conducted during business hours, do not unreasonably interfere with Xelp's operations, and are subject to confidentiality obligations; and (d) Xelp may first satisfy the audit request by providing recent third-party audit reports, certifications, or security documentation.
5. Sub-processors
5.1 Authorization. The Customer provides general written authorization for Xelp to engage Sub-processors to Process Personal Data, including those listed in Annex 3.
5.2 Obligations. Xelp shall: (a) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA; and (b) remain liable to the Customer for the performance of each Sub-processor's obligations.
5.3 Changes. Xelp shall notify the Customer (via the Service, email, or its website) of any intended addition or replacement of Sub-processors at least 15 days in advance. The Customer may object on reasonable data protection grounds within 15 days of the notice. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid, unused fees.
6. International Transfers
6.1 The Customer acknowledges that Xelp and its Sub-processors (including Cloudflare, Railway, Stripe, and Meta) may Process Personal Data in the United States and other countries outside the Customer's jurisdiction, as described in the Xelp Privacy Policy.
6.2 Where the Processing involves a transfer of Personal Data subject to the GDPR or UK GDPR to a country without an adequacy decision, the parties agree that the SCCs (Module Two: Controller-to-Processor, or Module Three: Processor-to-Processor, as applicable) are hereby incorporated by reference into this DPA, with the Customer as data exporter and Xelp as data importer, completed with the details set out in the Annexes to this DPA. For UK transfers, the UK International Data Transfer Addendum applies. In case of conflict, the SCCs prevail over this DPA.
6.3 Where the DPDP Act, Seychelles Data Protection Act, Azerbaijani law, or other Applicable Data Protection Law imposes conditions on cross-border transfer, Xelp shall Process and transfer Personal Data in accordance with such conditions, including any restrictions on transfers to countries notified as restricted by the relevant government.
7. Liability and Order of Precedence
7.1 Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement, except where prohibited by Applicable Data Protection Law.
7.2 In the event of conflict, the order of precedence is: (a) the SCCs (where applicable); (b) this DPA; (c) the Agreement.
8. Term
This DPA remains in effect for as long as Xelp Processes Personal Data on behalf of the Customer.
Annex 1 — Details of Processing
Subject matter: Provision of the Xelp omnichannel customer support and commerce platform, enabling the Customer to receive, manage, and respond to End User communications across connected channels and to operate commerce workflows.
Duration: The term of the Agreement, plus the period until deletion of all Personal Data in accordance with this DPA.
Nature and purpose of Processing: Receipt, transmission, storage, organization, display, analysis (including AI-assisted features such as reply suggestions and summarization), export, and deletion of communications and related data; operation of commerce features (catalogs, carts, orders, shipping, tracking); provision of support and security.
Categories of Data Subjects:
- End Users of the Customer (the Customer's customers, contacts, and prospects who communicate via WhatsApp, Instagram, Facebook Messenger, SMS, Email, Telegram, TikTok, or other supported channels);
- The Customer's Agents and authorized users.
Types of Personal Data:
- Identifiers and contact details: name, phone / WhatsApp number, email address, Telegram handle, Instagram username, TikTok username, Messenger ID, and similar channel identifiers;
- Content of messages and conversations, including attachments and media;
- Commerce data (where the Commerce Module is used): orders, cart contents, catalog interactions, shipping addresses, order tracking data;
- Labels, notes, and attributes assigned by the Customer;
- Technical and usage metadata related to message delivery.
Sensitive data: Not intended to be Processed; the Customer is instructed not to submit sensitive data (Section 3.2).
Frequency: Continuous, for the duration of the Agreement.
Annex 2 — Technical and Organizational Measures
Xelp implements and maintains, at minimum, the following measures:
- Encryption: TLS encryption for data in transit; encryption at rest provided through infrastructure providers.
- Access control: Role-based access controls; unique user accounts; least-privilege access for Xelp personnel; multi-factor authentication for administrative access.
- Tenant isolation: Logical separation of Customer data within the Service.
- Network and application security: Web application firewall, DDoS protection, and edge security via Cloudflare; secure software development practices; dependency and vulnerability management.
- Logging and monitoring: Security logging, monitoring, and alerting for anomalous activity.
- Backups and resilience: Regular backups and recovery procedures to protect against accidental loss.
- Personnel: Confidentiality obligations for all personnel; security awareness practices.
- Sub-processor management: Written data processing agreements and due diligence for all Sub-processors.
- Incident response: Documented incident response procedures, including Customer notification per Section 4.5.
- Data lifecycle: In-app tools for data access, export, and deletion; permanent deletion upon account termination.
Annex 3 — Authorized Sub-processors
| Sub-processor | Purpose | Location | |---|---|---| | Cloudflare, Inc. | Frontend hosting, CDN, security, AI infrastructure (Workers AI / AI Gateway) | United States (global network) | | Railway Corp. | Backend application hosting and data storage | United States | | Stripe, Inc. | Payment processing (Customer billing data only) | United States | | Meta Platforms, Inc. / Meta Platforms Ireland Ltd | WhatsApp Cloud API, Instagram, Messenger, Facebook Login (message transmission) | United States / Ireland |
Channel platforms connected at the Customer's direction (e.g., Telegram, TikTok, SMS/email providers) act as independent services or separate controllers under their own terms and are not Sub-processors of Xelp except to the extent they process data on Xelp's instructions.
A current list of Sub-processors is available at any time on request to privacy@xelp.io.
Contact for this DPA: Blaze Technologies Inc — Data Protection Officer: Renuka Vivek, renuka@xelp.io | privacy@xelp.io