Data Processing Addendum
Effective date: 23 June 2026·Version: 1.0
← All policiesDraft for review — not yet legally verified.
This Data Processing Addendum ("DPA") supplements our Terms of Service and Instructing Party Terms.
1. When this DPA applies
This DPA applies only where ExQlo processes personal data as a processor on the documented instructions of an Instructing Party ("Controller") — for example, third-party personal data that the Controller inserts or uploads into a case on the Service. For our own activities, ExQlo is a controller and our Privacy Policy applies.
2. Roles
ExQlo is the controller for account administration, billing, security, directory operation and matching. ExQlo is a processor only for third-party personal data that the Controller inserts into the Service and that we process on the Controller's instructions.
3. Processing details (Article 28)
- Subject matter — hosting and transmitting personal data inserted into the Service by the Controller.
- Duration — until deletion or return under section 7.
- Nature and purpose — providing the Service's messaging and storage, strictly to operate the Service.
- Types of data — identifiers and contact information, and any data the Controller chooses to insert.
- Data subjects — individuals referenced by the Controller.
4. Processor obligations
ExQlo will: process Controller data only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational measures; assist the Controller, so far as reasonably possible, with data-subject requests and data-protection impact assessments; maintain records as required; and permit reasonable, proportionate audits subject to confidentiality.
5. Sub-processors
The Controller authorises ExQlo to use the sub-processors below. We will give at least 14 days' notice of any material change, during which the Controller may reasonably object.
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication and file storage (EU region) | UK/EEA |
| Vercel | Application hosting and compute (London) | UK/EEA |
| Stripe | Payments, Connect accounts and payouts | US (SCCs/IDTA) |
| Anthropic | AI suitability matching and enrichment via its commercial API; inputs and outputs are not used to train any AI model | US (SCCs/IDTA) |
| Twilio | SMS notifications | US (SCCs/IDTA) |
| Postmark | Transactional email | US (SCCs/IDTA) |
| Slack | Internal operational notifications | US (SCCs/IDTA) |
6. International transfers
Core processing takes place within the UK/EEA. Where a sub-processor processes data outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards such as the UK IDTA or EU Standard Contractual Clauses. Anthropic processes data via its commercial API and does not use it to train any AI model.
7. Deletion or return
Within 30 days of account closure, ExQlo will delete or return Controller data processed as a processor, unless retention is required by law.
8. Breach notification
ExQlo will notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware of a personal-data breach affecting Controller data processed under this DPA.
9. Contact
Data Protection Lead: tom@exqlo.com.