XAG

Data Processing Addendum

1. About this addendum

1.1 This Data Processing Addendum ("DPA") is part of the Terms of Use between you ("Customer", "you") and XAGlobal, registered in Thailand (business registration number 8006069000003), of 108/1 Moo. 2, Umphur Chawang, Thambon NaGaCha, Nakorn Sri Thammarat, Thailand, 80150 ("XAG", "we", "us"). Words such as "Services" and "Your Data" have the meaning they have in the Terms.

1.2 In this DPA you are the "controller" and we are the "processor", as those words are used in the data protection law that applies, including Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). This DPA covers the personal data in Your Data that we process for you.

1.3 It applies automatically once you use the Services. You do not need to sign it. If you want a signed copy, email hello@xaglobal.stream and we will countersign it.

1.4 If this DPA and the Terms disagree about personal data, this DPA applies.

2. What we process and why

2.1 We process Your Data to provide, secure and fix the Services, as set out in the Terms. That means storing, hosting, showing, sending, backing up and deleting it and, where you use those features, sending emails or texts and drafting text with an AI provider.

2.2 We process Your Data while you use the Services, and until it is deleted or returned under section 10. Annex 1 lists the people and the data involved.

2.3 We do not sell Your Data or use it for our own purposes, except as needed to run, secure and fix the Services.

3. Your instructions

3.1 We process personal data only on your documented instructions: the Terms, this DPA, your settings, your use of the Services' features, and any written instruction you send to hello@xaglobal.stream.

3.2 If we think an instruction breaks data protection law, we will tell you and may pause it until you confirm or change it.

3.3 You are responsible for having a lawful basis to put personal data into the Services, for giving the notices the law requires, and for following clause 4.1 of the Terms, which does not allow sensitive data such as medical records.

4. Confidentiality

4.1 People who handle Your Data for us must keep it confidential. We limit access to the people who need it to run the Services.

5. Security

5.1 We use appropriate technical and organisational measures to protect Your Data. At the moment these include:

5.2 Section 7 of our Privacy Policy describes more. We do not claim any security certification. We may change our measures, but we will not lower the overall level of protection.

6. Sub-processors

6.1 You agree that we may use the sub-processors in Annex 2. We remain responsible to you for how they handle Your Data, as set out in the Terms.

6.2 We will give you at least 30 days' notice before we add or replace a sub-processor, by email to the account owner or by a notice in the Service.

6.3 You may object, on reasonable data protection grounds, by writing to us within that time. We will work with you in good faith to solve it. If we cannot, you may cancel the affected Service under the Terms before the change takes effect.

7. Moving data between countries

7.1 Our sub-processors run servers in several countries, so Your Data may be processed outside Thailand and outside your own country. We send only what is needed, use encrypted connections, and aim to have contractual safeguards that meet the PDPA's rules on sending data abroad. If your law needs a specific transfer mechanism, tell us and we will work with you.

8. Helping you

8.1 Where a Service provides self-service tools such as "Export my data" and "Delete my account", you can use them to answer requests from people. Otherwise, write to us and we will help you within 30 days of your written request.

8.2 If a person contacts us directly about Your Data, we will pass the request to you and will not answer it ourselves, unless the law requires us to.

9. Personal data breaches

9.1 If we become aware of a personal data breach that affects Your Data, we will tell you without undue delay and in any case within 72 hours of becoming aware.

9.2 We will email the account owner what we know about what happened, the data and people affected, the likely effects and what we are doing, and we will update you as we learn more. You are responsible for any notice to authorities or people, and we will help you with it.

10. When the Services end

10.1 When you ask us in writing, at any time including after the Services end, we will delete Your Data or return it to you, as you choose, within 30 days of your request. If you do not choose, we will delete it.

10.2 Copies in our backups are deleted as the backups expire, which is up to 30 days later.

10.3 We may keep data that the law requires us to keep.

11. Audits

11.1 We will give you the information reasonably needed to show that we meet this DPA, and we will answer reasonable written requests about how we process Your Data. You may make such a request no more than once a year. Any inspection of our systems or premises needs our agreement.

12. Liability, law and disputes

12.1 Our liability under this DPA follows the Terms, including the limits in section 11 of the Terms.

12.2 This DPA is governed by the laws of Thailand. The courts of Nakorn Sri Thammarat, Thailand, will decide disputes about it, as set out in section 14 of the Terms.

13. Contact

Questions and requests: hello@xaglobal.stream.

Annex 1. Processing details

Annex 2. Sub-processors

The leaked-password check and browser connection test named in the Privacy Policy do not receive Your Data.