Data Processing Addendum

Last updated September 30, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Xtag Inc., a Florida corporation ("Xtag"), and the customer using LINX ("Customer"). It applies whenever Xtag processes personal data contained in Customer Data on Customer's behalf ("Customer Personal Data"), and is designed to meet Article 28 of the EU General Data Protection Regulation and the UK GDPR ("GDPR"), and the service-provider requirements of the California Consumer Privacy Act ("CCPA"). Accepting the Terms accepts this DPA. No separate signature is needed. Customers who need a countersigned copy can ask at info@xtag.com.

1. Roles

Customer is the controller of Customer Personal Data, and Xtag is its processor, or "service provider" under the CCPA. Where Customer is itself a processor for another controller (for example, an organizer uploading attendee data on behalf of an event owner), Xtag is Customer's subprocessor. Customer is responsible for the lawfulness of its instructions and for having a lawful basis, and any required notices or consents, for the personal data it collects with LINX.

2. Details of processing

Subject matter and durationProviding the LINX service for the term of the Terms, plus the deletion period in Section 9.
Nature and purposeCapturing, storing, matching, scoring, enriching, exporting and syncing event leads and attendee lists, as instructed by Customer through the service.
Data subjectsEvent attendees and business contacts captured by Customer; Customer's users.
Categories of dataName, job title, company, business email and phone, badge identifiers, qualification answers, notes, follow-up status, lead scores, publicly available professional information (enrichment), capture records including IP address.
Special categoriesNone intended. Customer will not submit special-category or sensitive personal data.

3. Xtag's obligations

Xtag will:

4. Subprocessors

Customer authorizes Xtag to use the subprocessors listed below. Xtag binds each one by written terms that protect data at least as well as this DPA, and remains responsible for their performance.

SubprocessorPurposeLocation
Amazon Web Services, Inc.Hosting, database and backupsIreland (EU)
Anthropic, PBCAI lead scoring, research and card-reading fallbackUnited States
Mailchimp Transactional (Mandrill, an Intuit company)Emails such as lead exports, alerts and remindersUnited States

Integrations that Customer chooses to connect, such as HubSpot, Salesforce, Zapier, Make or webhooks, are Customer's own service providers, not Xtag's subprocessors. Xtag will announce a new subprocessor at least 15 days in advance, by email to account administrators or by updating this page. Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected service and receive a refund of prepaid fees for the remaining term.

5. International transfers

Customer Personal Data is stored in the EU. Where it is transferred to a country without an adequacy decision, including access by Xtag Inc. from the United States, the EU Standard Contractual Clauses (Commission Decision 2021/914) apply and are incorporated by reference, with Customer as data exporter and Xtag as data importer:

For UK data, the UK International Data Transfer Addendum applies. For Swiss data, the Clauses apply with references read as the Swiss Federal Act on Data Protection.

6. Security measures

7. Personal data breaches

Xtag will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting Customer Personal Data. The notice will include what Xtag knows about the nature of the breach, the data and people affected, likely consequences and the measures taken, updated as more becomes known. Xtag will take reasonable steps to contain and remedy the breach.

8. Audits

On request, and no more than once a year unless a breach or regulator requires otherwise, Xtag will answer Customer's reasonable security questionnaires and provide relevant documentation. If that is not enough to demonstrate compliance, Customer may conduct an audit, itself or through an independent auditor bound by confidentiality. The audit happens with at least 30 days' notice, during business hours, at Customer's cost, and without access to other customers' data.

9. Return and deletion

Customer can export and delete Customer Personal Data at any time using the service. When the Terms end, Xtag will delete Customer Personal Data within 30 days, and it expires from backups within a further 14 days, unless the law requires Xtag to keep it.

10. General

Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not allow that. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data. If the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.

Contact

Xtag Inc. · Privacy and legal: info@xtag.com