Draft — under legal review
This is a working draft published ahead of launch. It will be replaced by the final text approved by our lawyer before any sale is made.
This addendum applies where we process personal data on your behalf as a processor, under the GDPR or similar laws, and forms part of your agreement with INTELLIENS INFOCOM LLP.
1. What we do not process
Xtic runs on your infrastructure. We do not receive, store or process your backup data or anything inside it. You are the controller (data fiduciary) for that data and Xtic is software you operate.
2. What we process
The personal data of your users and contacts in the customer portal: names, work e-mail addresses, roles, sign-in records, support tickets and the licence and usage counts your installations send (which you can switch off).
3. Our commitments
We process this data only to provide the portal, licensing, billing and support; keep it confidential; protect it with appropriate technical and organisational measures (encryption in transit and at rest, multi-factor authentication for staff, least privilege, audit logging); use only the sub-processors we list, with notice of changes; help you answer requests from individuals; tell you without undue delay about a personal-data breach; and delete or return the data at the end of the service, except where the law requires us to keep it (for example invoices).
4. Transfers
The portal is hosted in India. Where a transfer needs a safeguard, we use the Standard Contractual Clauses or an equivalent mechanism.
5. Signing
Write to privacy@xtic.in for a countersigned copy.