DATA PROCESSING ADDENDUM

A processor framework for customer personal data handled through XZMargin.

This public DPA is a standard contractual framework. It becomes binding only when incorporated into a signed order form, master agreement or other written agreement between XZ BYTECORE PRIVATE LIMITED and the customer.

Document status

Effective date: 16 September 2026
Operator: XZ BYTECORE PRIVATE LIMITED
If a signed customer agreement conflicts with this public policy, the signed agreement controls to the extent of that conflict.

1. Roles and scope

For personal data contained in customer-uploaded business records, the customer generally determines why the data is processed and XZ BYTECORE processes that data to provide XZMargin under the customer’s instructions. The exact legal role may vary by dataset, jurisdiction and contract. For XZMargin account, billing, security and direct business-contact data, XZ BYTECORE may act independently for its own legitimate service-administration purposes as permitted by applicable law.

2. Processing instructions

XZ BYTECORE will process customer personal data to provide, secure, support and maintain XZMargin, to follow documented customer instructions, and as otherwise required by applicable law. If an instruction appears unlawful, XZ BYTECORE may pause the affected processing while the parties clarify the instruction.

3. Confidentiality

Persons authorised to process customer personal data should be subject to appropriate confidentiality obligations and should access data only to the extent required for their role.

4. Security measures

XZ BYTECORE will maintain technical and organisational measures appropriate to the service and risk, including authenticated workspace access, company-scoped data controls, import validation and operational security practices described on the Security page. The DPA does not claim certifications that have not actually been obtained.

5. Subprocessors

The customer authorises XZ BYTECORE to use subprocessors necessary to provide the service, subject to appropriate contractual protections. The current list is published on the Subprocessors page. Where a customer contract requires advance notice of a material new subprocessor, XZ BYTECORE will follow that contractual notice process.

6. Assistance

Taking into account the nature of processing and information available, XZ BYTECORE will provide reasonable assistance for data-subject or data-principal requests, security obligations, impact assessments and regulator enquiries where the request relates to customer data processed through XZMargin and the applicable law or contract requires such assistance.

7. Security incidents

XZ BYTECORE will investigate confirmed security incidents involving customer personal data and will notify the customer without undue delay where notification is required by applicable law or the governing commercial agreement. The notice may be updated as facts become available.

8. International processing

Infrastructure and subprocessors may process data in jurisdictions different from the customer’s location. Where a law requires contractual or other safeguards for a transfer, the parties will use the applicable mechanism required by that law and the governing commercial agreement.

9. Return and deletion

At termination or on a valid deletion instruction, XZ BYTECORE will delete or return customer personal data as required by the applicable agreement, subject to legal retention obligations, security records, backups and technical limitations described in the Data Retention & Deletion Policy.

10. Information and audits

XZ BYTECORE will make reasonably necessary information about its processing and security practices available to support customer due diligence. Formal audits, on-site reviews, penetration-test reports or certification evidence are subject to availability, confidentiality, security restrictions and any applicable commercial agreement.

Schedule — processing details

Related documents

Privacy Policy · Terms of Service · Security · Legal & Trust Center