Legal
Data Processing Agreement
1. Scope and parties
This Data Processing Agreement (“DPA”) supplements the XAgent Terms of Service, master services agreement, Order Form or other agreement between Xinference Holdings Pte. Ltd., a Singapore private limited company (“Xinference”, “Processor”, “we” or “us”), and the customer identified in the applicable Order Form or agreement (“Customer” or “Controller”) (together, the “Agreement”).
This DPA applies only to the extent Xinference processes Customer Personal Data on Customer’s behalf in connection with XAgent. It forms part of the Agreement when incorporated by reference, signed, or otherwise accepted by the parties. If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls.
For a Self-Hosted Deployment, this DPA applies only to Customer Personal Data that Xinference actually receives or can access in providing support, maintenance, managed services, licensing, security, updates or optional telemetry. It does not apply to data that remains solely within infrastructure controlled by Customer and is not accessible to Xinference.
2. Definitions
“Applicable Data Protection Law” means any law or regulation governing the processing, privacy, security or protection of Customer Personal Data that applies to a party’s performance under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, Singapore Personal Data Protection Act 2012 (“PDPA”), the Australian Privacy Act 1988 (Cth), and U.S. state privacy laws.
“Customer Personal Data” means Personal Data contained in Customer Content that Xinference processes on behalf of Customer under the Agreement. Customer Personal Data excludes personal data for which Xinference independently determines the purposes and means of processing, such as business contact, billing, security and service-administration data handled under the XAgent Privacy Policy.
“Data Subject”, “Controller”, “Processor”, “Business”, “Service Provider”, “Sell”, “Share”, “Process” and “Personal Data” have the meanings given by Applicable Data Protection Law. “Personal Data Breach” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data processed by Xinference. Where the PDPA applies, references to a Processor include Xinference acting as a data intermediary to the extent it processes Personal Data on behalf of and for the purposes of Customer.
“Subprocessor” means a third party engaged by Xinference to process Customer Personal Data on Customer’s behalf. A third-party model provider, Connected Service or tool selected and contracted directly by Customer is not a Subprocessor merely because Customer configures XAgent to interact with it.
“XAgent” means Xinference’s agent platform for personal work, reusable team agents and enterprise AI systems. It can plan and execute multi-step tasks, use models and tools, work with files and knowledge bases, retain task context or memory, and interact with services that a user or customer connects.
Capitalised terms not defined in this DPA have the meanings given in the Agreement, including “Action”, “Agent”, “Connected Service”, “Customer Content”, “Deployment Model”, “Input”, “Model”, “Output”, “Self-Hosted Deployment”, “Third-Party Model Provider” and “Tool”.
3. Roles and compliance
Customer is the Controller or Business and Xinference is the Processor, service provider or data intermediary for Customer Personal Data, except where Applicable Data Protection Law assigns different terminology. Each party will comply with its obligations under Applicable Data Protection Law.
Customer is responsible for establishing a lawful basis, providing required notices, obtaining required consents or authorisations, and ensuring that its instructions, Agent configurations, Inputs, Connected Services and requested Actions comply with Applicable Data Protection Law. Customer will not instruct Xinference to process Customer Personal Data in violation of law.
If Customer acts as a Processor for another Controller, Customer appoints Xinference as a subprocessor, represents that it is authorised to do so, and will pass through all legally required instructions and restrictions.
4. Customer instructions and processing limits
Xinference will process Customer Personal Data only on documented instructions from Customer, including the Agreement, Order Form, Customer’s configuration and use of XAgent, prompts and Inputs, Agent workflows, enabled Models and Tools, support requests, and other written instructions consistent with the Agreement. Processing includes the operations described in Schedule 1.
Xinference will not process Customer Personal Data for its own independent purposes, sell or share it for cross-context behavioural advertising, or use it to train or fine-tune any Model unless Customer expressly agrees in writing. This restriction does not prevent processing necessary to provide, secure or support the contracted service, or use of aggregated or de-identified Usage Data to improve it.
Xinference will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited by law. Xinference may suspend the affected processing until the parties resolve the issue.
If law requires Xinference to process Customer Personal Data beyond Customer’s instructions, Xinference will notify Customer before processing unless that law prohibits notice on important grounds of public interest.
5. Confidentiality and personnel
Xinference will ensure that persons authorised to process Customer Personal Data are subject to contractual, statutory or professional confidentiality obligations and access it only as necessary for their duties. Xinference will provide appropriate privacy and security guidance to relevant personnel.
6. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as the risks to individuals, Xinference will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data. The measures applicable to the relevant Deployment Model are described in Schedule 2, the Order Form, and any security documentation incorporated into the Agreement.
Customer is responsible for securely configuring its environment, accounts, Agents, permissions, Connected Services, Models and Tools; limiting credentials and access scopes; reviewing high-impact Actions; maintaining supported software; and protecting systems and data under its control.
7. Personal Data Breach
Xinference will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available to Xinference about the nature of the breach, likely consequences, affected data and individuals, mitigation taken or proposed, and a contact point. Xinference may provide information in phases as it becomes available.
Where the PDPA applies and Xinference acts as a data intermediary, Xinference will notify Customer without undue delay from the time it has credible grounds to believe that a relevant data breach has occurred. Customer remains responsible for determining whether notification to the Personal Data Protection Commission or affected individuals is required, unless the parties agree otherwise or applicable law requires a different allocation.
Xinference will take reasonable steps to contain, investigate and mitigate a Personal Data Breach and will reasonably assist Customer with legally required notifications. Notification does not constitute an admission of fault or liability. Unsuccessful attempts or events that do not result in a confirmed compromise of Customer Personal Data are not Personal Data Breaches under this DPA.
8. Data-subject requests
Taking into account the nature of processing, Xinference will provide reasonable assistance through appropriate technical and organisational measures to help Customer respond to requests from individuals to exercise rights under Applicable Data Protection Law. If Xinference receives a request relating to Customer Personal Data, it will refer the requester to Customer and will not respond substantively unless authorised by Customer or required by law.
9. Regulatory assistance and impact assessments
Xinference will provide information reasonably necessary to help Customer demonstrate compliance with applicable security, breach-notification, data-protection-impact-assessment and regulator-consultation obligations, taking into account the nature of processing and information available to Xinference. Customer remains responsible for determining whether an assessment or consultation is required.
10. Subprocessors
Customer gives Xinference general written authorisation to engage Subprocessors to provide XAgent. Xinference will impose written data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to Xinference under this DPA, to the extent relevant to the services performed. Xinference remains responsible for its Subprocessors’ performance of those obligations as required by Applicable Data Protection Law.
Xinference will make available its current Subprocessor list through the location or process identified in the Agreement or Order Form. Xinference will provide reasonable advance notice of a new Subprocessor that will process Customer Personal Data. Customer may object on reasonable, documented data-protection grounds within the notice period stated in the notice, or fourteen days if no period is stated. The parties will work in good faith on a commercially reasonable resolution. If no resolution is available, Customer may terminate only the affected service without penalty, and its sole remedy for the objection is a refund of prepaid fees for the unused terminated period.
Customer acknowledges that Customer-selected Third-Party Model Providers, Connected Services and Tools may process data under Customer’s separate agreement with those providers. Customer is responsible for reviewing and authorising those providers. They are Subprocessors of Xinference only where Xinference, rather than Customer, engages them to process Customer Personal Data on Customer’s behalf.
11. International transfers
Xinference will ensure that international transfers of Customer Personal Data use a lawful transfer mechanism where required. For transfers subject to the EU GDPR that are not covered by an adequacy decision, the parties incorporate the European Commission’s 2021 Standard Contractual Clauses (“EU SCCs”) as described in Schedule 3. For restricted transfers subject to the UK GDPR, the EU SCCs are supplemented by the then-current UK International Data Transfer Addendum unless the parties use another lawful mechanism. For Swiss transfers, references in the EU SCCs will be interpreted to include applicable Swiss law and the competent Swiss authority as required.
For transfers governed by Singapore’s PDPA, Xinference will take steps required by the PDPA to ensure that transferred personal data receives a standard of protection comparable to the protection under the PDPA. The parties will cooperate on reasonable transfer-risk information and supplementary safeguards where legally required.
12. Return and deletion
Upon termination or expiry of the applicable services, and at Customer’s written choice where required by law, Xinference will delete or return Customer Personal Data within the period specified in the Agreement or Order Form. If no period is specified, Xinference will act within a commercially reasonable period, subject to normal backup cycles and legal retention requirements. Xinference may retain data where required by law, provided it remains protected and is processed only for that retention purpose.
Customer is responsible for exporting Customer Personal Data before access to the service ends and for deleting data within systems, Connected Services, Models and Tools controlled by Customer or its chosen third parties.
13. Information and audits
Xinference will make available information reasonably necessary to demonstrate compliance with this DPA. Customer will first use current independent audit reports, certifications, security documentation and written responses made available by Xinference, if any.
If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may conduct one audit in any twelve-month period, unless a regulator requires more frequent review or a Personal Data Breach reasonably justifies an additional audit. Audits require reasonable advance written notice, must occur during normal business hours, must avoid disruption and access to other customers’ data, and must be subject to confidentiality and security requirements. Customer will bear its audit costs and reimburse Xinference’s reasonable costs unless the audit identifies a material breach by Xinference.
14. U.S. state privacy requirements
Where Customer Personal Data is subject to a U.S. state privacy law and Customer is a Business, Xinference acts as a Service Provider or Processor. Xinference will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it outside the direct business relationship with Customer or for a commercial purpose other than the limited purposes specified in the Agreement; or (c) combine it with personal data received from another person or collected from Xinference’s own interaction with an individual, except as permitted by law. Customer may take reasonable and appropriate steps to help ensure processing is consistent with these obligations and to stop and remediate unauthorised use.
15. Liability, term and general provisions
This DPA remains in effect while Xinference processes Customer Personal Data. The exclusions and limitations of liability in the Agreement apply to this DPA to the maximum extent permitted by law. Nothing in this DPA limits liability that cannot lawfully be limited.
The governing law and dispute-resolution provisions in the Agreement apply to this DPA, except where Applicable Data Protection Law or the EU SCCs require otherwise. Amendments must be in writing, except that Xinference may update this DPA where reasonably necessary to comply with law, provided the update does not materially reduce protection for Customer Personal Data.
Schedule 1 — Details of processing
| Item | Description |
| :—- | :—- |
| Subject matter | Provision, operation, security, support and maintenance of XAgent under the Agreement. |
| Duration | For the term of the applicable services and any limited post-termination period required for return, deletion, backup cycling, dispute handling or legal compliance. |
| Nature and purpose | Hosting, receiving, storing, organising, indexing, retrieving, analysing, transforming, transmitting and deleting Customer Personal Data; executing Customer-configured Agent workflows; generating Outputs; invoking authorised Models, Tools and Connected Services; providing support, security and service administration. |
| Frequency | Continuous, intermittent or ad hoc, depending on Customer’s configuration and use. |
| Data subjects | Customer personnel, authorised users, contractors, customers, prospects, suppliers, business contacts and other individuals whose Personal Data Customer submits or makes accessible through XAgent. |
| Personal Data | Account and identity data; contact and professional data; prompts, instructions and communications; files and document content; knowledge-base content, embeddings and retrieval results; Agent memory and task state; model Inputs and Outputs; tool calls and Action results; connected-service records; logs and technical identifiers. |
| Special or sensitive data | Only if Customer chooses to submit or make such data accessible. Customer must ensure that processing is lawful, necessary and appropriately configured. XAgent is not intended for regulated data categories unless the Agreement or Order Form expressly authorises them. |
| Customer instructions | The Agreement, Order Form, documented configurations, authorised-user activity, support requests and other written instructions consistent with the Agreement. |
| Deletion period | As stated in Section 12 and any more specific retention or deletion term in the Agreement or Order Form. |
Schedule 2 — Technical and organisational measures
The measures below are baseline contractual commitments. Specific controls may vary by Deployment Model and will be described in incorporated security documentation or the Order Form. This Schedule does not promise a certification, encryption method, recovery objective or control that Xinference has not expressly confirmed in writing.
- Access controls designed to restrict production and support access to authorised personnel based on role and business need.
- Authentication and account-security measures appropriate to the relevant service and Deployment Model.
- Encryption or equivalent safeguards for Customer Personal Data in transit and at rest where appropriate to the service architecture and risk.
- Logging, monitoring, vulnerability management and incident-response processes appropriate to the service.
- Secure development, change-management and dependency-management practices appropriate to XAgent components operated by Xinference.
- Backup, recovery, availability and resilience measures appropriate to the contracted service, without creating a service-level commitment unless stated in an SLA or Order Form.
- Personnel confidentiality, security awareness and access-review processes.
- Subprocessor due diligence and written data-protection commitments.
- Processes supporting data retention, deletion, privacy requests and incident notification.
- Customer-configurable controls for permissions, connectors, credentials, Agents, Models, Tools and high-impact Actions, where supported by the applicable Deployment Model.
Schedule 3 — International-transfer terms
EU SCCs. For a restricted transfer from Customer subject to the EU GDPR to Xinference in a country not recognised as adequate, Commission Implementing Decision (EU) 2021/914 is incorporated by reference. Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is a Processor. Clause 7 (docking) applies; Option 2 in Clause 9 applies with the notice period in Section 10; the optional wording in Clause 11 does not apply; and the competent supervisory authority and governing law are determined under Clauses 13 and 17 based on the exporter’s establishment or otherwise as permitted by the EU SCCs. The courts under Clause 18 are the courts of the corresponding EU Member State.
Annex I to the EU SCCs. The parties and contact details are those in the Agreement and Order Form. The transfer description is Schedule 1. The frequency is continuous, intermittent or ad hoc. The purpose and retention period are stated in Schedule 1. The competent authority is determined under Clause 13.
Annex II to the EU SCCs. The technical and organisational measures are those in Schedule 2 and any incorporated security documentation.
Annex III to the EU SCCs. The authorised Subprocessors are those disclosed through the process described in Section 10.
UK and Switzerland. Where applicable, the UK International Data Transfer Addendum is incorporated with the information in this DPA populating its tables, and the EU SCCs are adapted for Swiss law as described in Section 11.