Data Processing Addendum
GDPR Art. 28 agreement governing processing of personal data in ISO 20022 message traffic on behalf of institutional customers.
Legal Contact / DPO
compliance@xvilan.com
XVILAN SYSTEMIC INFRASTRUCTURES LLC
ISO 20022 Data Router
Processor
Obligations.
The binding Art. 28 terms governing how XVILAN processes personal data on behalf of its institutional customers.
1. Roles & Scope (GDPR Art. 28)
This Data Processing Addendum ('DPA') forms part of the Master Service Agreement between XVILAN SYSTEMIC INFRASTRUCTURES LLC ('Processor') and the customer ('Controller'). To the extent the Controller transmits personal data — including personal data embedded in ISO 20022 payment messages — to the Platform, the Controller is the Data Controller and XVILAN is the Data Processor. This DPA sets out the subject-matter, duration, nature, and purpose of processing, the categories of data subjects, and the Controller's rights and obligations.
2. Instructions & Lawfulness
The Processor processes personal data only on documented instructions from the Controller, unless required to do so by EU or Member State law (in which case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest). Processing is limited to what is strictly necessary to provide the ISO 20022 scan, cleanse, translate, and harmonize services, and to bill for tolled usage.
3. Confidentiality & Staff
The Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is granted on a least-privilege basis, and under the Zero-Payload mandate, message payload content is never persisted, logged, or exposed to personnel.
4. Security of Processing (Art. 32)
Taking into account the state of the art, the Processor implements appropriate technical and organizational measures: AES-256 encryption at rest and TLS 1.3 in transit; HSM-backed secrets; hardware-isolated confidential computing (AMD SEV-SNP); logical and physical access controls; audit logging of operational metadata (never payloads); and routine security testing. These measures ensure a level of security appropriate to the risk.
5. Subprocessors
The Controller gives general authorization for engagement of subprocessors. The Processor maintains a list of subprocessors, including: Stripe, Inc. (payment processing) and Neon (managed Postgres for metadata). The Processor imposes on each subprocessor the same data-protection obligations as set out in this DPA, particularly Art. 28(3) requirements. The Processor notifies the Controller of any intended changes to the subprocessor list and provides an opportunity to object.
6. Breach Notification (Art. 33–34)
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Controller data, and provides timely information required by the Controller to comply with its Art. 33 and Art. 34 notification obligations. The Processor cooperates with the Controller in investigating and remediating the breach. Notification to data subjects remains the Controller's responsibility.
7. Data Subject Rights (Art. 15–22)
The Processor assists the Controller, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Controller's obligation to respond to requests for the exercise of data subject rights under Art. 15–22 (access, rectification, erasure, restriction, portability, objection). Given the Zero-Payload mandate, in most cases no payload data will exist to be returned, and only operational metadata will be subject to such requests.
8. International Transfers
Primary institutional compute resides in the European Union (OCI Confidential Enclaves, Frankfurt). Where any transfer of personal data from the EEA/UK to a third country occurs, the Processor relies on European Commission Standard Contractual Clauses (SCCs 2021/914) or the UK International Data Transfer Addendum, as applicable, and ensures that subprocessors are bound accordingly.
9. Audit & Records
The Processor makes available to the Controller all information necessary to demonstrate compliance with its obligations under Art. 28, and allows for and contributes to audits and inspections conducted by the Controller or its mandated auditor, subject to reasonable notice, confidentiality, and no more than once per calendar year unless a breach or regulatory request requires otherwise.
10. Deletion & Return (Art. 28(3)(g))
At the choice of the Controller, the Processor deletes or returns all personal data to the Controller after the end of the provision of services and deletes existing copies unless EU or Member State law requires storage. Under the Zero-Payload mandate, payload data is not stored at all; operational metadata is deleted within the retention windows described in the Privacy Policy. This DPA survives termination of the MSA until all data is deleted or returned.