Data Processing Addendum
Last updated September 30, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Xtag Inc., a Florida corporation ("Xtag"), and the customer using LINX ("Customer"). It applies whenever Xtag processes personal data contained in Customer Data on Customer's behalf ("Customer Personal Data"), and is designed to meet Article 28 of the EU General Data Protection Regulation and the UK GDPR ("GDPR"), and the service-provider requirements of the California Consumer Privacy Act ("CCPA"). Accepting the Terms accepts this DPA. No separate signature is needed. Customers who need a countersigned copy can ask at info@xtag.com.
1. Roles
Customer is the controller of Customer Personal Data, and Xtag is its processor, or "service provider" under the CCPA. Where Customer is itself a processor for another controller (for example, an organizer uploading attendee data on behalf of an event owner), Xtag is Customer's subprocessor. Customer is responsible for the lawfulness of its instructions and for having a lawful basis, and any required notices or consents, for the personal data it collects with LINX.
2. Details of processing
| Subject matter and duration | Providing the LINX service for the term of the Terms, plus the deletion period in Section 9. |
|---|---|
| Nature and purpose | Capturing, storing, matching, scoring, enriching, exporting and syncing event leads and attendee lists, as instructed by Customer through the service. |
| Data subjects | Event attendees and business contacts captured by Customer; Customer's users. |
| Categories of data | Name, job title, company, business email and phone, badge identifiers, qualification answers, notes, follow-up status, lead scores, publicly available professional information (enrichment), capture records including IP address. |
| Special categories | None intended. Customer will not submit special-category or sensitive personal data. |
3. Xtag's obligations
Xtag will:
- process Customer Personal Data only on Customer's documented instructions, which are the Terms, this DPA and Customer's use and configuration of the service, unless required otherwise by law. In that case Xtag will inform Customer first unless the law prohibits it. Xtag will tell Customer if it believes an instruction infringes data protection law;
- ensure that people authorized to process Customer Personal Data are bound by confidentiality;
- implement the security measures in Section 6;
- not sell or share Customer Personal Data. It will not retain, use or disclose it for any purpose other than providing the service, nor combine it with other data except as the CCPA permits. Xtag certifies that it understands these restrictions;
- not use Customer Personal Data to train AI models;
- help Customer, taking into account the nature of the processing, respond to data subject requests (the service provides export, correction and deletion tools), and with security, breach notification, impact assessments and prior consultations under GDPR Articles 32 to 36;
- make available the information necessary to demonstrate compliance with this DPA, as described in Section 8.
4. Subprocessors
Customer authorizes Xtag to use the subprocessors listed below. Xtag binds each one by written terms that protect data at least as well as this DPA, and remains responsible for their performance.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database and backups | Ireland (EU) |
| Anthropic, PBC | AI lead scoring, research and card-reading fallback | United States |
| Mailchimp Transactional (Mandrill, an Intuit company) | Emails such as lead exports, alerts and reminders | United States |
Integrations that Customer chooses to connect, such as HubSpot, Salesforce, Zapier, Make or webhooks, are Customer's own service providers, not Xtag's subprocessors. Xtag will announce a new subprocessor at least 15 days in advance, by email to account administrators or by updating this page. Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected service and receive a refund of prepaid fees for the remaining term.
5. International transfers
Customer Personal Data is stored in the EU. Where it is transferred to a country without an adequacy decision, including access by Xtag Inc. from the United States, the EU Standard Contractual Clauses (Commission Decision 2021/914) apply and are incorporated by reference, with Customer as data exporter and Xtag as data importer:
- Module 2 (controller to processor) or Module 3 (processor to processor) applies, as appropriate;
- Clause 7 (docking) applies;
- Clause 9 uses option 2 (general authorization), with the notice period in Section 4;
- the optional language in Clause 11 does not apply;
- Clauses 17 and 18 select the law and courts of Ireland;
- Annexes I and II are completed by Sections 2 and 6 of this DPA.
For UK data, the UK International Data Transfer Addendum applies. For Swiss data, the Clauses apply with references read as the Swiss Federal Act on Data Protection.
6. Security measures
- Encryption in transit (TLS 1.2+, HSTS). Integration credentials and secrets are encrypted at rest. Mobile session tokens are kept in the device's secure storage.
- Strict tenant isolation: every request is scoped to the customer's own event memberships, and this is covered by automated tests.
- Role-based access for customer users (admin, manager, scanner, viewer), with sign-in by one-time email links or codes. Codes are rate-limited against guessing.
- Production access limited to authorized Xtag staff, using SSH keys from restricted networks. There is a host firewall, and the database and cache are not reachable from the internet.
- Automatic security updates, nightly database backups kept for 14 days, and a tested restore procedure.
- Webhook deliveries are signed, and outbound requests are protected against server-side request forgery.
- Error monitoring with alerts to the operations team.
7. Personal data breaches
Xtag will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting Customer Personal Data. The notice will include what Xtag knows about the nature of the breach, the data and people affected, likely consequences and the measures taken, updated as more becomes known. Xtag will take reasonable steps to contain and remedy the breach.
8. Audits
On request, and no more than once a year unless a breach or regulator requires otherwise, Xtag will answer Customer's reasonable security questionnaires and provide relevant documentation. If that is not enough to demonstrate compliance, Customer may conduct an audit, itself or through an independent auditor bound by confidentiality. The audit happens with at least 30 days' notice, during business hours, at Customer's cost, and without access to other customers' data.
9. Return and deletion
Customer can export and delete Customer Personal Data at any time using the service. When the Terms end, Xtag will delete Customer Personal Data within 30 days, and it expires from backups within a further 14 days, unless the law requires Xtag to keep it.
10. General
Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not allow that. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data. If the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.
Contact
Xtag Inc. · Privacy and legal: info@xtag.com