About this DPA
This Data Processing Agreement ("DPA") reflects the standard data-protection terms Xlines ("Processor", "we") incorporates into its services agreement with each client ("Controller", "you") for whom we provide outsourced customer-experience (CX) or back-office services involving personal data. It is published here for transparency and vendor-diligence review. A copy specific to your engagement, referencing your services agreement, is available on request and can be countersigned as an addendum to that agreement.
Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR (and, where applicable, the UK GDPR and other applicable data protection laws such as the CCPA/CPRA, under which the equivalent terms are "Business" and "Service Provider").
Subject matter, duration & purpose
Xlines processes Personal Data on the Controller's behalf solely to deliver the services described in the applicable services agreement (for example, customer support, sales/outbound, order management, or quality/reporting), for the duration of that agreement, and strictly on the Controller's documented instructions.
Xlines' obligations as processor
- Process Personal Data only on the Controller's documented instructions, unless required otherwise by law (in which case we will inform the Controller, unless prohibited from doing so).
- Ensure personnel authorized to process Personal Data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures (see "Security measures" below and our Security & Data Protection page).
- Not engage a sub-processor without the Controller's prior general or specific authorization (see "Sub-processing").
- Assist the Controller in responding to data subject requests and regulatory obligations.
- Notify the Controller of a Personal Data Breach without undue delay.
- At the Controller's choice, delete or return Personal Data at the end of the engagement, and delete existing copies unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described below.
Sub-processing
The Controller grants Xlines general authorization to engage sub-processors necessary to deliver the services (for example, hosting or communication-infrastructure providers), provided Xlines imposes data-protection obligations on them substantially equivalent to those in this DPA and remains responsible for their performance. Our current, honest list of sub-processors is published on our Subprocessors page and updated whenever it changes; clients may request advance notice of new sub-processors and an opportunity to object.
Security measures
Xlines implements measures appropriate to the nature and risk of the processing, described in full on our Security & Data Protection page — including encrypted connections, access restricted to authorized personnel, and nonce-protected form handling. As a small, growing company, we do not currently hold formal certifications such as ISO 27001 or SOC 2, and we say so plainly rather than imply otherwise; we describe our actual practices honestly on that page and will pursue formal certification as we scale.
Assistance with data subject requests
Xlines will, taking into account the nature of the processing, reasonably assist the Controller in fulfilling its obligation to respond to data subject requests (access, deletion, correction, portability, etc.) received in relation to Personal Data processed under the services agreement.
Personal data breach notification
Xlines will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's data, and will provide reasonably available information to help the Controller meet its own breach-notification obligations under applicable law.
International transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland to Egypt (or any other country without an applicable adequacy decision), the transfer is made subject to the European Commission's Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum), incorporated by reference into the client-specific DPA.
Audit rights
On reasonable prior notice, and no more than once per year (or following a significant Personal Data Breach), the Controller may request information demonstrating Xlines' compliance with this DPA, and — for enterprise engagements — a mutually scheduled audit, subject to reasonable confidentiality and scope limitations appropriate to a company of our size.
Return or deletion of data
At the end of the services agreement, and at the Controller's written request, Xlines will delete or return all Personal Data processed on the Controller's behalf, except where retention is required by applicable law.
Liability & term
This DPA remains in effect for as long as Xlines processes Personal Data on the Controller's behalf under the services agreement. Liability under this DPA is subject to the limitation-of-liability terms in the underlying services agreement, unless applicable law requires otherwise.
Requesting a countersigned copy
Enterprise clients and prospects can request a client-specific, countersigned copy of this DPA — including annexes listing the specific categories of data, data subjects, and sub-processors relevant to that engagement — by emailing info@xlinescx.com.
This page reflects Xlines' standard DPA terms and is provided for transparency and general information; it does not itself constitute an executed agreement and does not substitute for legal advice. Enterprise clients should have their own counsel review the client-specific, countersigned version before relying on it.