Xlines Xlines lines Excellence Across All Lines
Home Services Pricing About Insights Contact
Book a strategy call
Legal

Data Processing Agreement (DPA)

Last updated: September 6, 2026

On this page
  • About this DPA
  • Definitions
  • Subject matter, duration & purpose
  • Xlines' obligations as processor
  • Sub-processing
  • Security measures
  • Assistance with data subject requests
  • Personal data breach notification
  • International transfers
  • Audit rights
  • Return or deletion of data
  • Liability & term
  • Requesting a countersigned copy

About this DPA

This Data Processing Agreement ("DPA") reflects the standard data-protection terms Xlines ("Processor", "we") incorporates into its services agreement with each client ("Controller", "you") for whom we provide outsourced customer-experience (CX) or back-office services involving personal data. It is published here for transparency and vendor-diligence review. A copy specific to your engagement, referencing your services agreement, is available on request and can be countersigned as an addendum to that agreement.

Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR (and, where applicable, the UK GDPR and other applicable data protection laws such as the CCPA/CPRA, under which the equivalent terms are "Business" and "Service Provider").

Subject matter, duration & purpose

Xlines processes Personal Data on the Controller's behalf solely to deliver the services described in the applicable services agreement (for example, customer support, sales/outbound, order management, or quality/reporting), for the duration of that agreement, and strictly on the Controller's documented instructions.

Xlines' obligations as processor

  • Process Personal Data only on the Controller's documented instructions, unless required otherwise by law (in which case we will inform the Controller, unless prohibited from doing so).
  • Ensure personnel authorized to process Personal Data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see "Security measures" below and our Security & Data Protection page).
  • Not engage a sub-processor without the Controller's prior general or specific authorization (see "Sub-processing").
  • Assist the Controller in responding to data subject requests and regulatory obligations.
  • Notify the Controller of a Personal Data Breach without undue delay.
  • At the Controller's choice, delete or return Personal Data at the end of the engagement, and delete existing copies unless retention is required by law.
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described below.

Sub-processing

The Controller grants Xlines general authorization to engage sub-processors necessary to deliver the services (for example, hosting or communication-infrastructure providers), provided Xlines imposes data-protection obligations on them substantially equivalent to those in this DPA and remains responsible for their performance. Our current, honest list of sub-processors is published on our Subprocessors page and updated whenever it changes; clients may request advance notice of new sub-processors and an opportunity to object.

Security measures

Xlines implements measures appropriate to the nature and risk of the processing, described in full on our Security & Data Protection page — including encrypted connections, access restricted to authorized personnel, and nonce-protected form handling. As a small, growing company, we do not currently hold formal certifications such as ISO 27001 or SOC 2, and we say so plainly rather than imply otherwise; we describe our actual practices honestly on that page and will pursue formal certification as we scale.

Assistance with data subject requests

Xlines will, taking into account the nature of the processing, reasonably assist the Controller in fulfilling its obligation to respond to data subject requests (access, deletion, correction, portability, etc.) received in relation to Personal Data processed under the services agreement.

Personal data breach notification

Xlines will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's data, and will provide reasonably available information to help the Controller meet its own breach-notification obligations under applicable law.

International transfers

Where Personal Data is transferred from the EEA, UK, or Switzerland to Egypt (or any other country without an applicable adequacy decision), the transfer is made subject to the European Commission's Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum), incorporated by reference into the client-specific DPA.

Audit rights

On reasonable prior notice, and no more than once per year (or following a significant Personal Data Breach), the Controller may request information demonstrating Xlines' compliance with this DPA, and — for enterprise engagements — a mutually scheduled audit, subject to reasonable confidentiality and scope limitations appropriate to a company of our size.

Return or deletion of data

At the end of the services agreement, and at the Controller's written request, Xlines will delete or return all Personal Data processed on the Controller's behalf, except where retention is required by applicable law.

Liability & term

This DPA remains in effect for as long as Xlines processes Personal Data on the Controller's behalf under the services agreement. Liability under this DPA is subject to the limitation-of-liability terms in the underlying services agreement, unless applicable law requires otherwise.

Requesting a countersigned copy

Enterprise clients and prospects can request a client-specific, countersigned copy of this DPA — including annexes listing the specific categories of data, data subjects, and sub-processors relevant to that engagement — by emailing info@xlinescx.com.

This page reflects Xlines' standard DPA terms and is provided for transparency and general information; it does not itself constitute an executed agreement and does not substitute for legal advice. Enterprise clients should have their own counsel review the client-specific, countersigned version before relying on it.

Related: GDPR & EU Privacy · Subprocessors · Security & Data Protection · Terms of Use · Legal Information
Xlines lines

The managed CX and back-office partner for growing US and European businesses. Cairo, Egypt — serving the US & Europe.

in

Company

  • About
  • Why Xlines
  • Industries
  • Analytics & Insights

Services

  • Customer Support
  • Sales & Outbound
  • Order Management
  • Quality & Reporting

Legal

  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • Accessibility
  • All policies

Contact

  • info@xlinescx.com

Get CX insights in your inbox

One email a month. No spam, unsubscribe anytime.

© 2026 Xlines CX Solutions & BPO
Privacy Policy Terms of Use
Powered by PrimeOpex

We currently use only essential technology on this site — no analytics or advertising cookies are set. If that ever changes, this lets you choose. See our Cookie Policy for details.