Data Processing Agreement (DPA)

Last updated: November 6, 2025

This Data Processing Agreement ("DPA") forms part of the Terms of Service between XProduct and you (the "Client") for use of the Digital Product Passport platform (the "Platform"). This DPA ensures compliance with EU General Data Protection Regulation ("GDPR") where applicable.

1. Purpose

This DPA governs the processing of personal data provided by the Client to XProduct in the context of using the Platform services.

2. Roles

Client is the Data Controller. XProduct is the Data Processor.

3. Processing Details

  • Nature and Purpose: To provide DPP creation, storage, display, and management tools.
  • Data Subjects: Employees, customers, and partners of the Client.
  • Types of Data: Names, emails, product ownership data, and uploaded documentation.

4. Processor Obligations

  • Process data only on documented Client instructions.
  • Ensure personnel confidentiality.
  • Implement appropriate technical and organizational security measures.
  • Assist Client with GDPR compliance for rights of data subjects.

5. Sub-Processors

Client agrees to XProduct’s use of third-party sub-processors (e.g., cloud infrastructure providers). A list of sub-processors is available upon request.

6. Data Transfers

Where data is transferred outside the EU, XProduct shall ensure appropriate safeguards such as Standard Contractual Clauses (SCCs).

7. Retention & Deletion

Upon contract termination, XProduct shall delete or return personal data to the Client, unless required by law to retain it.

8. Contact

Questions about this DPA can be directed to: support@xproduct.co.uk