Data Processing Agreement
How we process personal data on your behalf when you use the xonPlus Platform
Data Processing Agreement (DPA)
TL;DR
When you use xonPlus, you are the data controller and we (Jejo InfoSec Private Limited, the company behind XposedOrNot and xonPlus) are your data processor. This DPA is part of our Terms of Service and is automatically accepted when you subscribe. We only process data on your instructions, never collect or store passwords (sign-in uses magic links), do not retain the identifiers you look up through the API, keep everything encrypted and access-controlled, use vetted sub-processors (listed in Annex 3) with 30 days' notice before changes, notify you of any breach within 72 hours, support EU/UK transfers via the Standard Contractual Clauses, and return or delete your data when you leave. The public breach index itself is ours, not yours: we maintain it as an independent controller, and it is not covered by this DPA.
How this DPA applies
This DPA is entered into between you (the “Customer”) and Jejo InfoSec Private Limited (CIN: U72900TN2019PTC126682), a private limited company incorporated under the Companies Act, 2013 in India (“we”, “us”, “our”), which owns and operates the XposedOrNot and xonPlus platforms.
By subscribing to or using the xonPlus Platform, you agree to this Data Processing Agreement (“DPA”). It forms part of and supplements the xonPlus Terms of Service (the “Agreement”) and should be read together with our Privacy Policy. If there is any conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.
1. Background and Purpose
This DPA governs our processing of personal data on your behalf in connection with your subscription to and use of the xonPlus Platform (xonEnterprise+, xonConsumer+, xonAPI+, and xonThreatIntel+). It is intended to ensure that such processing complies with applicable data protection laws, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act (“CCPA”) as amended, the Digital Personal Data Protection Act of India, the Personal Information Protection and Electronic Documents Act of Canada (“PIPEDA”), and any other applicable privacy or data protection legislation (“Applicable Data Protection Laws”).
2. Definitions
Capitalised terms not defined here have the meaning given in the Agreement or in Applicable Data Protection Laws. In particular:
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Special Categories of Personal Data” have the meanings given in the GDPR (or equivalent terms under other Applicable Data Protection Laws).
- “Customer Personal Data” means personal data that you submit to the Platform, or that the Platform generates for you, namely: identifiers you submit for monitoring or lookup (email addresses and domain names, including those of your executives, employees, and end-users); account and contact details of your Platform users; and the monitoring results and exposure alerts generated for you. Customer Personal Data does not include the Breach Index.
- “Breach Index” means the corpus of publicly available breach data that we collect, verify, and maintain independently of any Customer, as described at plus.xposedornot.com/our-data. We process the Breach Index as an independent Controller on the basis of our legitimate interests. It exists before and after your subscription, is not processed on your instructions, and is not subject to the return, deletion, or audit provisions of this DPA.
- “SCCs” means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.
- “Sub-processor” means any third party we engage to process Customer Personal Data on our behalf in connection with the Services.
3. Roles of the Parties
- For the processing of Customer Personal Data, you act as the Controller (or, where you process personal data on behalf of your own end-users or clients, as a Processor), and we act as the Processor (or Sub-processor, as applicable).
- Where you act as a Processor on behalf of a third-party Controller, you warrant that you have obtained all necessary authorisations to engage us as a Sub-processor on the terms of this DPA.
- We act as an independent Controller, and not as your Processor, for the Breach Index and for personal data of visitors to our public marketing pages. That processing is governed by our Privacy Policy, not by this DPA.
- Each party is individually responsible for compliance with its own obligations under Applicable Data Protection Laws.
4. Details of Processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex 1 (Processing Details) below.
5. Customer Obligations
You shall:
- Ensure Customer Personal Data is collected and submitted to the Platform in compliance with Applicable Data Protection Laws and with all required notices, consents, and lawful bases.
- Be solely responsible for the accuracy, quality, and legality of Customer Personal Data and how you acquired it.
- Be responsible for your documented instructions to us. Your use of the Platform in accordance with the Agreement and our documentation constitutes your documented instructions.
- Not submit Special Categories of Personal Data, payment card data, or government-issued identifiers to the Platform unless we expressly agree in writing as part of the service configuration.
- Promptly notify us if you believe any instruction or processing may infringe Applicable Data Protection Laws.
6. Our Obligations as Processor
We shall:
- Process Customer Personal Data only on your documented instructions (including for international transfers), unless required by law to which we are subject, in which case we will inform you first, unless the law prohibits this on important grounds of public interest.
- Ensure personnel authorised to process Customer Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational measures, as described in Annex 2.
- Engage Sub-processors only in accordance with Section 9.
- Assist you, by appropriate technical and organisational measures and insofar as possible, in responding to data subject rights requests, in securing processing, in breach notification, in data protection impact assessments, and in prior consultation with supervisory authorities.
- At your choice, delete or return all Customer Personal Data after the end of the Services, in accordance with Section 15.
- Make available the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR (or equivalent provisions).
7. Confidentiality of Personnel
We ensure that any personnel authorised to process Customer Personal Data are subject to written confidentiality obligations no less restrictive than the confidentiality provisions of our Terms of Service, and receive appropriate training on their data protection responsibilities.
8. Security of Processing
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls and the principle of least privilege
- Network segmentation, logging, and monitoring
- Regular vulnerability assessments and incident response procedures
We regularly review and, where appropriate, update these measures to maintain a level of security appropriate to the risk, taking into account the state of the art and the nature, scope, and purposes of processing. Full details are in Annex 2.
9. Sub-processors
- You provide general written authorisation for us to engage Sub-processors, subject to this Section. The current list is in Annex 3.
- We will give you at least 30 days' prior notice of any addition or replacement of a Sub-processor (the “Change Notice”), so that you can object.
- If you reasonably object on legitimate data protection grounds, notify us in writing within 15 days of the Change Notice. We will discuss a resolution in good faith. If none is reached, we will either (i) not appoint the proposed Sub-processor, or (ii) let you terminate the affected Services without penalty, with a pro-rata refund of any prepaid fees for the unused portion (notwithstanding the no-refund provisions of our Terms of Service).
- We enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than this DPA, and we remain fully liable for their performance.
10. Data Subject Rights
Taking into account the nature of the processing, we will provide reasonable assistance, by appropriate technical and organisational measures and insofar as possible, to help you fulfil your obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, and objection).
If we receive a request directly from a data subject relating to Customer Personal Data, we will, where legally permitted, promptly forward it to you and will not respond directly except on your instructions or as required by law.
11. Personal Data Breach Notification
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent available, the notification will include:
- the nature of the breach, including categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address and mitigate it; and
- a point of contact where more information can be obtained.
We will cooperate and provide reasonable assistance in investigating, mitigating, and remedying the breach, and in fulfilling any notification obligations to authorities or data subjects. Notification is not an acknowledgement of fault or liability.
12. Data Protection Impact Assessments
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities where required by Applicable Data Protection Laws. We may charge a reasonable fee where the requested assistance goes beyond the standard documentation made available to subscribers.
13. International Data Transfers
We (Jejo InfoSec Private Limited) are established in India, and we and our Sub-processors may process Customer Personal Data outside the European Economic Area (“EEA”), the UK, Canada, or your country of establishment.
Where processing involves a transfer of personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties comply with the SCCs, incorporated by reference, with the following selections:
- Module Two (Controller to Processor) where you are a Controller; Module Three (Processor to Sub-processor) where you are a Processor.
- Clause 7 (Docking clause): does not apply.
- Clause 9 (Sub-processors): Option 2 (general written authorisation), with a 30-day notice period as in Section 9.
- Clause 11 (Redress): the optional independent dispute resolution language does not apply.
- Clause 17 (Governing law): the law of the Republic of Ireland.
- Clause 18 (Forum and jurisdiction): the courts of Ireland.
- Annexes I, II and III to the SCCs are completed by Annexes 1, 2, and 3 to this DPA.
For transfers subject to the UK GDPR, the parties comply with the UK International Data Transfer Addendum to the EU SCCs issued by the UK ICO, incorporated by reference.
For transfers subject to other Applicable Data Protection Laws, the parties implement such other transfer mechanisms as those laws require.
14. Audits and Inspections
- On reasonable prior written request and not more than once per calendar year, we will make available the information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and our reasonable security protocols. This includes a description of the measures in Annex 2, the certifications and attestations published by our Sub-processors (such as the ISO 27001 and SOC 2 reports for Google Cloud), and written responses to a reasonable security questionnaire.
- You agree that this documentation is the primary means of exercising your audit rights, and that it satisfies them to the extent it demonstrates compliance. You may request an inspection only where (i) that documentation is insufficient to demonstrate compliance, (ii) a supervisory authority requires it, or (iii) a confirmed Personal Data Breach has affected your Customer Personal Data.
- Any inspection is at your cost, on at least 30 days' written notice, limited to once per calendar year, conducted remotely where feasible and otherwise during normal business hours, by you or an independent auditor bound by confidentiality, and scoped to the processing of your Customer Personal Data. It must not unreasonably interfere with our operations or compromise the security or confidentiality of other customers. We may charge a reasonable fee for time spent supporting an inspection beyond the standard documentation. Inspections do not extend to Sub-processor facilities; Sub-processor compliance is demonstrated through their own certifications and audit reports.
15. Return or Deletion of Data
- Within 30 days of termination or expiry of the Agreement, we will, at your choice, return or delete all Customer Personal Data in our production systems, instruct Sub-processors to do the same, and provide written certification on request. Copies held in encrypted backups are deleted as those backups expire under our standard rotation cycle, and are not accessed or processed in the meantime other than for disaster recovery, in which case this Section applies to any restored data.
- Identifiers submitted through Stateless Lookups (see Annex 1) are never retained, so there is nothing to return or delete for them. Associated request metadata is deleted in accordance with our data retention policy.
- We may retain Customer Personal Data where required by applicable law, keeping it confidential and not processing it further except for the purpose for which it must be retained.
- Aggregated, anonymised, or de-identified data that no longer constitutes personal data may be retained and used for legitimate business purposes, including service improvement and threat intelligence research.
16. Liability
- Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where mandatory provisions of Applicable Data Protection Laws (including Article 82 of the GDPR) provide otherwise.
- Any administrative fines or penalties imposed directly on a party by a supervisory authority are borne by that party, except where they result from the other party's breach of this DPA.
17. Term, Precedence, and General
- Term: This DPA takes effect with the Agreement and remains in force for as long as we process Customer Personal Data on your behalf. Sections on confidentiality, breach notification, return/deletion, and liability survive termination as required.
- Order of precedence: in the event of conflict, the order is (1) the SCCs (where applicable); (2) this DPA; (3) the Agreement.
- Governing law: without prejudice to Section 13 (which governs the law and forum for the SCCs), this DPA is governed by the laws of India, and disputes are resolved in accordance with the dispute resolution provisions of our Terms of Service.
- Amendments: we may amend this DPA where required to comply with changes in Applicable Data Protection Laws by giving 30 days' notice; other changes will be communicated in accordance with our Terms of Service.
- Severability: if any provision is held invalid or unenforceable, the remaining provisions continue in full force and effect.
Annex 1: Processing Details
Subject matter
Our processing of Customer Personal Data to provide the xonPlus Platform (xonEnterprise+, xonConsumer+, xonAPI+, xonThreatIntel+) and related breach monitoring and threat intelligence services.
Duration
For the term of your subscription, plus any retention or deletion period set out in Section 15.
Nature and purpose
Matching identifiers you submit against the Breach Index; monitoring registered domains and email addresses for new exposures; generating and delivering exposure alerts; providing dashboards, reporting, and API access; and providing related threat intelligence, all on your behalf and on your instructions. The Platform operates in two modes, and the processing differs between them:
- Stateless Lookups (xonAPI+, the community API, and the free exposure check): the email address or domain you submit is matched against the Breach Index in memory and the result is returned. The submitted identifier is not written to disk, logged, or retained. We retain request metadata (such as API key identifier, timestamp, source IP address, endpoint, and response status) for billing, rate limiting, security, and abuse prevention, in accordance with our data retention policy.
- Persistent Monitoring (xonEnterprise+, xonThreatIntel+, and xonConsumer+): the domains and email addresses you register, your alert configuration, and the monitoring results and exposure alerts generated for you are retained for the term of your subscription so that we can monitor continuously and alert you to new exposures.
Frequency
Stateless Lookups: per request, with no persistence of the submitted identifier. Persistent Monitoring: continuous and ongoing for the duration of the subscription.
Types of personal data
- Email addresses and domain names submitted for monitoring or lookup, including those of your executives, employees, contractors, and end-users
- Account and contact details for Customer users of the Platform (name, work email address, organisation, and billing contact details)
- IP addresses and technical/usage data generated through use of the Platform, including API request metadata
- Monitoring results and exposure alerts generated by the Platform
The Platform does not collect or store passwords. Platform sign-in uses passwordless magic links, and we never ask for, receive, or store the passwords or other credentials of your users or of the individuals you monitor. Where a password exposure check is used, only a partial one-way hash prefix is submitted under a k-anonymity scheme, so no password or full hash reaches the Platform. Monitoring is keyed on email addresses and domain names only; we do not require or process names, job titles, or other identity attributes of the individuals you monitor.
The Platform is not intended for Special Categories of Personal Data, payment card data, or government-issued identifiers, which should not be submitted unless expressly agreed in writing (see Section 5).
Categories of data subjects
- Your employees, executives, and contractors
- Your end-users, customers, or clients whose identifiers you submit for monitoring
- Other individuals whose personal data is contained in the identifiers you choose to monitor
Annex 2: Technical and Organisational Measures
We implement and maintain the following measures to ensure a level of security appropriate to the risk:
Encryption in transit
All data transmitted between you and the Platform, and between Platform components, is encrypted using TLS 1.3 or equivalent industry-standard protocols.
Encryption at rest
Customer Personal Data stored in databases, object storage, and backups is encrypted using AES-256 or equivalent.
Access controls
Role-based access controls, principle of least privilege, multi-factor authentication for administrative and cloud-console access, and periodic access reviews.
Authentication
Passwordless magic-link authentication for Platform users, so no customer passwords are stored on the Platform. MFA for privileged and cloud-console access. API access is authenticated with per-customer API keys.
Network security
Cloudflare web application firewall and DDoS protection in front of the Platform, Google Cloud network controls with restricted ingress and egress, and separation between production and non-production environments.
Logging and monitoring
Centralised logging of access and administrative actions on Google Cloud, with automated alerting on critical events.
Vulnerability management
Regular vulnerability scanning, dependency and patch management, and periodic third-party penetration testing, with findings tracked to remediation.
Incident response
Documented incident response plan, defined roles and responsibilities, breach notification procedures aligned with Section 11, and post-incident review.
Backup and recovery
Encrypted backups with periodic restore testing and documented disaster recovery procedures.
Data minimisation
Collection limited to data necessary for the purposes in Annex 1; pseudonymisation and hashing applied where feasible (e.g. credential matching).
Pseudonymisation and non-persistence
Stateless Lookups are processed in memory without persisting the submitted identifier. Password exposure checks, where used, operate on partial one-way hash prefixes under a k-anonymity scheme, so no password or full hash reaches the Platform.
Personnel security
Written confidentiality undertakings and regular data protection and security awareness training for all personnel with access to Customer Personal Data.
Sub-processor management
Due diligence on all Sub-processors, back-to-back contractual data protection terms, and ongoing monitoring of performance and compliance.
Physical security
Hosting in data centres operated by reputable cloud providers with industry-standard physical security controls. We do not operate our own physical data centres.
Business continuity
Documented business continuity and disaster recovery plans, periodically tested, covering loss of key personnel, infrastructure, or third-party services.
Data segregation
Logical separation of Customer data within multi-tenant environments, with controls to prevent unauthorised cross-tenant access.
Secure deletion
Documented procedures for deletion of Customer Personal Data on termination or request: from production systems within the period in Section 15, and from encrypted backups as they expire under the standard rotation cycle.
Annex 3: Approved Sub-processors
The following Sub-processors are authorised at the date of this DPA. We maintain an up-to-date list and notify you of any additions or replacements in accordance with Section 9. Entries marked marketing website only do not process Customer Personal Data; they operate on visitors to our public marketing pages, where we act as Controller in our own right rather than as your Processor. They are listed here for transparency.
Google LLC / Google Cloud EMEA Limited (Google Cloud Platform)
Purpose: Cloud infrastructure hosting, database storage, and compute for the Platform; storage of Customer Personal Data submitted for monitoring.
Location: United States (Google Cloud US regions); may be replicated to additional regions for redundancy and disaster recovery.
Safeguards: EU SCCs in the Google Cloud Data Processing Addendum; encryption in transit and at rest by default.
Cloudflare, Inc.
Purpose: CDN, TLS termination, DDoS protection, and web application firewall for traffic to and from the Platform (Customer Personal Data in transit only).
Location: Cloudflare global edge network (no persistent storage of Customer Personal Data).
Safeguards: EU SCCs in the Cloudflare Data Processing Addendum; data processed in transit only.
Mailjet SAS (a Sinch company)
Purpose: Delivery of transactional emails, account notifications, and breach alerts to Customer users.
Location: France / European Union.
Safeguards: EU SCCs in the Mailjet Data Processing Addendum; data hosted within the EU.
Lemon Squeezy, LLC
Purpose: Subscription billing and payment processing as Merchant of Record (checkout, payment authorisation, sales tax, and invoicing).
Location: United States.
Safeguards: PCI-DSS compliance; EU SCCs in the Lemon Squeezy Data Processing Addendum.
PayPal, Inc. / PayPal (Europe) S.à r.l. et Cie, S.C.A.
Purpose: Payment processing for subscription fees where PayPal is selected as the payment method.
Location: United States and Luxembourg.
Safeguards: PCI-DSS compliance; EU SCCs applied by PayPal for EEA-originating transactions.
Google LLC (Google Analytics)
Purpose: Usage analytics on our marketing site and inside the Platform dashboard; understanding aggregate user behaviour and Service performance.
Location: United States.
Safeguards: EU SCCs in the Google Ads Data Processing Terms; IP anonymisation enabled; configured to avoid collecting identifiable Customer Personal Data where reasonably possible.
PostHog, Inc.
Purpose: Product analytics and feature usage tracking inside the Platform dashboard to operate and improve the Platform.
Location: United States (PostHog US Cloud).
Safeguards: EU SCCs in the PostHog Data Processing Addendum; configured to minimise capture of identifiable Customer Personal Data.
RB2B, Inc. (Retention.com), marketing website only
Purpose: Business visitor identification on our public marketing pages: resolving anonymous website traffic to company and professional contact details for our own sales and marketing. Does not run within the Platform and does not process Customer Personal Data submitted to or generated by the Platform.
Location: United States.
Safeguards: Engaged under RB2B's standard data processing terms. Because this processing concerns marketing website visitors rather than Customer Personal Data, we act as Controller and not as your Processor. Visitors may opt out at app.retention.com/optout, and under GDPR at rb2b.com/rb2b-gdpr-opt-out.
Contact
For any questions about this DPA, data protection, or to exercise the rights and processes described above:
Jejo InfoSec Private Limited
CIN: U72900TN2019PTC126682 · Chennai, Tamil Nadu, India
Email: deva [at] xposedornot [dot] com
GitHub: github.com/xposedornot
Twitter: @xposedornot
Last Updated: October 2026. This DPA forms part of the xonPlus Terms of Service and is accepted when you subscribe to or use the Platform. We encourage you to review it periodically for any updates.