Data Processing Agreement (DPA) #

Effective Date: July 2026
Version: 1.0


1. Purpose #

This Data Processing Agreement ("DPA") forms part of the agreement between XAR Hub and its customers. It governs the processing of Personal Data where XAR Hub processes Personal Data on behalf of the Customer in accordance with Article 28 of the General Data Protection Regulation (GDPR).


2. Parties #

This Agreement is entered into between:

Customer The individual or legal entity using XAR Hub services.

and

XAR Hub The provider of the XAR Hub platform.


3. Definitions #

For the purposes of this Agreement:

Controller The entity determining the purposes and means of processing Personal Data.

Processor The entity processing Personal Data on behalf of the Controller.

Personal Data Any information relating to an identified or identifiable natural person.

Processing Any operation performed on Personal Data including collection, storage, organization, transmission, modification or deletion.

Capitalized terms not defined here shall have the meaning assigned under the GDPR.


4. Scope of Processing #

XAR Hub processes Personal Data solely for the purpose of providing the services requested by the Customer. Processing activities may include:

  • Hosting business information
  • User authentication
  • Secure storage
  • Dashboard functionality
  • Customer support
  • Analytics related to service performance
  • Security monitoring

5. Categories of Personal Data #

Depending on Customer usage, Personal Data may include:

  • Name
  • Email Address
  • Username
  • Business Contact Information
  • Device Information
  • IP Address
  • Login Records
  • Uploaded Content

6. Categories of Data Subjects #

Personal Data may relate to:

  • Customers
  • Employees
  • Business Owners
  • Authorized Users
  • Visitors of Customer Business Pages
  • Support Contacts

7. Customer Responsibilities #

The Customer agrees to:

  • Ensure lawful collection of Personal Data.
  • Provide required privacy notices.
  • Obtain any necessary consents.
  • Use XAR Hub in compliance with applicable law.
  • Ensure submitted data is accurate where reasonably possible.

The Customer remains responsible for determining the purposes and legal basis for processing.


8. XAR Hub Responsibilities #

XAR Hub agrees to:

  • Process Personal Data only on documented instructions from the Customer, unless otherwise required by law.
  • Maintain appropriate technical and organizational security measures.
  • Ensure personnel are subject to confidentiality obligations.
  • Assist Customers in fulfilling GDPR obligations where reasonably possible.
  • Notify Customers of legally required disclosures unless prohibited by law.

9. Confidentiality #

All personnel authorized to process Personal Data are subject to appropriate confidentiality obligations. Confidentiality obligations continue after employment or contractual relationships end.


10. Security Measures #

XAR Hub implements appropriate safeguards, including:

  • Encryption in transit
  • Secure authentication
  • Password hashing
  • Access controls
  • Logging and monitoring
  • Backup procedures
  • Vulnerability management

Security controls are reviewed periodically.


11. Subprocessors #

XAR Hub may engage trusted subprocessors to support service delivery. Subprocessors may provide:

  • Cloud infrastructure
  • Email delivery
  • Authentication services
  • Payment processing
  • Monitoring
  • Customer support tools

A current list of subprocessors is maintained separately.


12. International Transfers #

Where Personal Data is transferred outside the European Economic Area, XAR Hub implements appropriate safeguards in accordance with applicable law. Safeguards may include:

  • Standard Contractual Clauses (SCCs)
  • Adequacy Decisions
  • Other lawful transfer mechanisms

13. Data Subject Requests #

Where appropriate, XAR Hub will assist Customers in responding to requests involving:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Portability
  • Objection

The Customer remains responsible for responding to Data Subjects.


14. Personal Data Breaches #

If XAR Hub becomes aware of a confirmed Personal Data Breach affecting Customer data, it will:

  • Investigate the incident.
  • Contain the issue.
  • Notify the Customer without undue delay where required.
  • Cooperate in mitigation efforts.
  • Maintain records of the incident.

15. Audits #

Where legally required and subject to appropriate confidentiality obligations, XAR Hub may provide reasonable information demonstrating compliance with this Agreement. Requests must not unreasonably interfere with business operations or compromise the security of other customers.


16. Deletion or Return of Data #

Upon termination of the services, Personal Data will be deleted or returned where applicable, unless retention is required by law. Backups may remain until their normal retention period expires.


17. Liability #

Liability under this Agreement is governed by the applicable Terms of Service unless mandatory law provides otherwise.


18. Changes #

This DPA may be updated to reflect:

  • Regulatory changes
  • Platform improvements
  • Operational requirements

The latest version will always be published by XAR Hub.


19. Governing Law #

This Agreement shall be governed by applicable data protection legislation together with the governing law specified in the Terms of Service.


20. Contact #

Questions regarding this Agreement may be submitted through the official XAR Hub legal contact channels.


This Agreement should be read together with:


Conclusion #

XAR Hub is committed to processing Personal Data responsibly, securely and transparently while supporting Customers in meeting their own data protection obligations.


End of Document