This Data Processing Agreement ("DPA") describes how Xyloid Technologies LLC ("Xyloid," "we," "us," or "our") processes personal data on behalf of a client when performing professional services. This DPA is a template intended to be executed with, or incorporated by reference into, the written services agreement between Xyloid and the client (the "Services Agreement"). It applies only when, and to the extent that, Xyloid processes personal data on behalf of the client in the course of providing services. It does not apply to Xyloid's own informational website, which is addressed by our Privacy Policy and Cookie Policy.
1. Definitions
The following terms are used in this DPA with the meanings below, consistent with common usage under the General Data Protection Regulation (GDPR) and comparable United States privacy laws:
- Controller: the party that determines the purposes and means of processing personal data. For processing under this DPA, the client is the Controller.
- Processor: the party that processes personal data on behalf of the Controller. For processing under this DPA, Xyloid is the Processor or service provider.
- Personal Data: any information relating to an identified or identifiable natural person that Xyloid processes on behalf of the client under the Services Agreement.
- Processing: any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Sub-processor: a third party engaged by Xyloid to process personal data on the client's behalf.
- Data Subject: the individual to whom the personal data relates.
2. Scope and Roles
This DPA applies to Xyloid's processing of personal data on behalf of the client as necessary to provide the services described in the Services Agreement. The client acts as the Controller, and Xyloid acts as the Processor. Each party is responsible for complying with the data protection laws applicable to it. This DPA is incorporated into the Services Agreement, and in the event of a conflict regarding the processing of personal data, this DPA controls.
3. Processing Instructions and Purpose
Xyloid will process personal data only on the client's documented instructions and only for the purpose of providing the services, unless required to act otherwise by applicable law, in which case Xyloid will inform the client of that legal requirement unless the law prohibits such notice. The Services Agreement and any related statements of work or task orders constitute the client's documented instructions. Xyloid will not sell personal data and will not process personal data for its own independent commercial purposes.
4. Confidentiality of Personnel
Xyloid will ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations and are informed of the confidential nature of the personal data. Xyloid will limit access to personal data to personnel who need access to perform the services.
5. Security Measures
Xyloid will implement and maintain appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures take into account the nature of the processing and the risks presented, and may include access controls, encryption where appropriate, logging and monitoring, and secure configuration practices consistent with the requirements of the Services Agreement.
6. Sub-processors
The client authorizes Xyloid to engage sub-processors to process personal data in connection with the services, subject to this DPA. Where Xyloid engages a sub-processor, Xyloid will impose data protection obligations on the sub-processor that are substantially similar to those set out in this DPA, through a written agreement (flow-down obligations). Xyloid remains responsible to the client for the performance of its sub-processors' obligations. Xyloid will make available information about its sub-processors and any intended changes as provided in the Services Agreement, so that the client has an opportunity to object on reasonable data protection grounds.
7. Assistance with Data Subject Requests
Taking into account the nature of the processing, Xyloid will provide reasonable assistance to the client, through appropriate technical and organizational measures, to help the client respond to requests from Data Subjects to exercise their rights, such as access, correction, deletion, and objection. If Xyloid receives a request directly from a Data Subject relating to personal data processed on behalf of the client, Xyloid will, unless prohibited by law, direct the Data Subject to the client rather than responding directly.
8. Personal Data Breach Notification
Xyloid will notify the client without undue delay after becoming aware of a personal data breach affecting personal data processed on the client's behalf. The notification will include the information reasonably available to Xyloid to assist the client in meeting its own notification and reporting obligations. Xyloid will take reasonable steps to mitigate and remediate the effects of the breach.
9. Assistance with Compliance Obligations
Xyloid will provide reasonable assistance to the client, taking into account the nature of the processing and the information available to Xyloid, in relation to the client's obligations regarding security of processing, breach notification, data protection impact assessments, and consultations with supervisory authorities, to the extent applicable to the services.
10. Return or Deletion of Personal Data
Upon termination or expiration of the services, or upon the client's earlier written request, Xyloid will, at the client's choice, return or delete the personal data processed on the client's behalf, and delete existing copies, unless applicable law requires continued retention. This obligation is subject to any transition or wind-down terms in the Services Agreement.
11. Records and Audits
Xyloid will maintain reasonable records of its processing activities relating to the services and will make available to the client information reasonably necessary to demonstrate compliance with this DPA. Xyloid will provide reasonable assistance in connection with audits or assessments as set out in the Services Agreement, subject to appropriate confidentiality, security, and scheduling arrangements, and in a manner that does not compromise the security or confidentiality of other clients or systems.
12. International Data Transfers
Where personal data is transferred across borders in connection with the services, the parties will put in place appropriate safeguards required by applicable law, such as standard contractual clauses or another recognized transfer mechanism, to the extent applicable. Xyloid operates primarily from the United States, and the client acknowledges that processing may occur there or in other locations described in the Services Agreement.
13. Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Services Agreement. This DPA does not create liability beyond what is provided in the Services Agreement, except as required by applicable law.
14. Term
This DPA takes effect when it is incorporated into or executed with the Services Agreement and remains in effect for as long as Xyloid processes personal data on behalf of the client under the Services Agreement. Provisions that by their nature should survive termination, such as those relating to confidentiality and return or deletion of personal data, will survive.
15. Governing Law
This DPA is governed by the laws of the Commonwealth of Virginia, United States, without regard to its conflict-of-laws principles, except where a mandatory data protection law requires otherwise. Venue and dispute resolution are as set out in the Services Agreement.
16. Contact
For questions about this DPA or to discuss incorporating it into a Services Agreement, please contact us at privacy@xyloidtechnologies.com.