This Data Processing Addendum ("DPA") forms part of the agreement between xMatix Private Limited ("Xmatix", the "Processor") and the Customer (the "Controller" / data fiduciary) for the Xmatix platform, and applies to personal data contained in Customer Content.
1. Roles and scope
The Customer determines the purposes and means of processing personal data in Customer Content; Xmatix processes it solely to provide and support the Service. Categories of data subjects and personal data are determined by what the Customer stores in the Service (typically employees, customers, dealers, and suppliers of the Customer, with business contact and transactional data, and — where the Customer enables field features — location data of its consenting field staff).
2. Instructions
Xmatix processes personal data only on the Customer's documented instructions, which comprise the agreement, this DPA, and the Customer's configuration of the Service. Xmatix will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.
3. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations and receive appropriate data protection training. Access is limited to what is necessary to operate and support the Service.
4. Security
Xmatix implements appropriate technical and organisational measures, including: encryption of data in transit and at rest; logical per-tenant isolation with tenant-scoped access enforcement at the data layer; role-based access control and least-privilege administration; audit logging of data access and changes; segregated development, test, and production environments; and backup and recovery procedures.
5. Sub-processors
The Customer authorises the following categories of sub-processors: cloud infrastructure, communication, and AI services provided by Microsoft Azure (hosting, storage, messaging, email delivery, and — where enabled by the Customer — AI model hosting), and any AI model provider the Customer itself configures for its tenant. Xmatix will notify the Customer of intended changes to sub-processors and give the Customer the opportunity to object on reasonable data-protection grounds. Xmatix remains responsible for its sub-processors' performance.
6. Data subject requests
Taking into account the nature of the processing, Xmatix will assist the Customer with appropriate technical and organisational measures to fulfil requests from data subjects (access, correction, erasure, portability). Requests received directly by Xmatix relating to Customer Content will be forwarded to the Customer without undue delay.
7. Personal data breach
Xmatix will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, providing information reasonably required for the Customer to meet its own notification obligations, and will take reasonable steps to contain and remediate the breach.
8. Data location and transfers
Customer Content is hosted in the Azure region(s) applicable to the Customer's tenant (India regions by default). Xmatix will not transfer Customer Content to another jurisdiction except as needed to provide the Service and in compliance with applicable data protection law.
9. Return and deletion
Upon termination or expiry of the agreement, Xmatix will make Customer Content available for export for thirty (30) days and thereafter delete it from active systems, with residual copies removed from backups in the ordinary rotation cycle, unless retention is required by law.
10. Audit
Xmatix will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits by the Customer or its appointed auditor, not more than once annually, on reasonable notice, and without disruption to other tenants — normally satisfied through documentation, security summaries, and third-party attestations where available.
11. Contact
Data protection enquiries: info@xmatix.com.
