01
Scope and roles
This Data Processing Addendum ("DPA") forms part of the Eucalyptus Terms of Service between X-QDO OÜ ("X-QDO") and Customer. It applies where X-QDO processes personal data contained in Customer Content on Customer’s behalf.
For such personal data, Customer is the controller (or a processor acting for its own controllers) and X-QDO is the processor. X-QDO processes account and billing data about Customer’s users as an independent controller.
02
Subject matter and duration
The subject matter of processing is the provision of the Eucalyptus platform: hosting, validating, compiling, versioning, executing, and observing Excel-based calculation models submitted by Customer. Processing lasts for the term of the agreement plus the export and deletion periods described below.
03
Nature and purpose of processing
Processing consists of storing workbooks and compiled artifacts, executing calculation requests, recording execution telemetry and audit events, and producing aggregate usage reports. The sole purpose is to provide and support the Service as instructed by Customer through its configuration and use of the platform.
04
Categories of data and data subjects
Customer determines what data its workbooks and API calls contain. Depending on Customer’s models, calculation inputs and outputs may include personal data of Customer’s own customers, policyholders, applicants, or employees (for example rating factors such as age or region).
Usage exports contain allocation data only — model, version, label, and volume aggregates. They do not contain calculation inputs, calculation outputs, tokens, IP addresses, or pricing information.
05
Instructions
X-QDO processes Customer Content only on documented instructions from Customer — given through the agreement, the dashboard, the API, and workspace configuration — unless processing is required by European Union or member-state law. In that case X-QDO informs Customer of the legal requirement before processing, unless the law prohibits doing so. X-QDO will inform Customer if, in its opinion, an instruction infringes applicable data-protection law.
06
Confidentiality
X-QDO ensures that persons authorised to process Customer Content are bound by confidentiality obligations and access Customer Content only to the extent required to operate and support the Service.
07
Security measures
X-QDO implements appropriate technical and organisational measures, including: encryption of data in transit and at rest; workspace and token isolation scoped to model, version, and environment; content-addressed, signed compiled bytecode; role-based access control with OIDC SSO and SCIM support; and immutable audit logging of executions, deployments, and credential rotations.
Security documentation and penetration-test reports are available under NDA on request.
08
Subprocessors
Customer authorises X-QDO to engage the following subprocessors to provide the Service: Amazon Web Services EMEA SARL (cloud hosting, EU regions; managed SaaS runs in eu-central-1) and Cloudflare, Inc. (edge network: DNS, TLS termination, content delivery, and request routing). X-QDO will maintain an up-to-date subprocessor list, provide notice of intended changes, and give Customer the opportunity to object on reasonable data-protection grounds. X-QDO remains responsible for its subprocessors’ performance.
Where Customer runs a private execution destination in its own AWS account, calculation traffic, workbooks, compiled models, tokens, and execution history remain in Customer’s environment and under Customer’s control.
09
Assistance and data subject rights
Taking into account the nature of processing, X-QDO assists Customer with appropriate technical and organisational measures in fulfilling Customer’s obligations to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection), and with Customer’s obligations regarding security, breach notification, and data-protection impact assessments, insofar as information is available to X-QDO.
10
Personal data breach
X-QDO notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and provides information reasonably required for Customer to meet its own notification obligations, including the nature of the breach, affected categories, likely consequences, and measures taken.
11
International transfers
The managed Service is hosted in the European Union. X-QDO does not transfer Customer Content outside the EU/EEA unless the transfer is subject to appropriate safeguards under Chapter V GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses.
12
Return and deletion
During the term, Customer can export workbooks and configuration through the Service. For 30 days after termination, X-QDO makes Customer Content available for export; thereafter X-QDO deletes Customer Content, except where retention is required by law. Aggregate usage records that contain no calculation data may be retained for billing and audit purposes.
13
Audits
X-QDO makes available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party assessments and penetration-test reports under NDA. Where these are insufficient, Customer may conduct an audit — at most once annually, on reasonable notice, without disrupting operations, and subject to confidentiality obligations.
14
Contact
Data-protection enquiries: [email protected]. X-QDO OÜ, Tallinn, Estonia.