Data Processing Addendum
Last updated 15 July 2026
This page summarizes, in plain language, how xbackupman acts as a data processor for the personal data you entrust to the Service. If your organization requires a countersigned DPA (for example, to satisfy GDPR Article 28), contact [email protected] and we will provide an executable version.
1. Roles
For personal data contained in your account and connection settings that we process to run the Service, you are the “controller” and xbackupman is the “processor”. For personal data inside your backups, that data is encrypted before it leaves the worker and is written to your own storage — we do not access it in readable form.
2. Scope & purpose of processing
- Subject matter: provision of the backup scheduling, encryption, verification and restore Service.
- Duration: for the term of your account, plus limited retention as described in the Privacy Policy.
- Categories of data subjects: your team members and any individuals whose data appears in your configured sources.
- Types of personal data: account identifiers (name, email, organization) and any personal data within your backups (which remains encrypted and inaccessible to us).
3. Our obligations as processor
- Process personal data only on your documented instructions.
- Ensure personnel who access personal data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see Section 5).
- Assist you, taking into account the nature of processing, with data subject requests and with your security, breach-notification and impact-assessment obligations.
- Delete or return personal data at the end of the service, subject to legal retention requirements.
- Make available information reasonably necessary to demonstrate compliance.
4. Subprocessors
You authorize us to engage subprocessors to provide the Service. We impose data-protection obligations on them substantially similar to those in this addendum and remain responsible for their performance. Current subprocessors:
- Stripe — payment processing and subscription billing.
- Cloud hosting & CDN (e.g. Cloudflare) — application and worker hosting, network delivery and protection.
Your chosen backup storage provider is controlled by you and is not our subprocessor. We will provide notice of intended changes to the subprocessor list so you can object where you have the right to do so.
5. Security measures
We maintain measures including: AES-256-GCM encryption of backups performed inside the worker before upload; TLS in transit; encryption at rest for sensitive fields; salted password hashing; tenant isolation scoped to your organization; least-privilege access; and audit logging of job activity. Because backups are encrypted with keys not stored in your bucket, exposure of your storage alone does not reveal backup contents.
6. Data subject requests
Taking into account the nature of the processing, we will assist you with responding to requests from data subjects to exercise their rights. Many of these can be handled directly by you within the dashboard.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide information reasonably available to help you meet your notification obligations.
8. International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or an equivalent lawful transfer mechanism.
9. Deletion & return
On termination, we will delete or, at your request, return the personal data we process on your behalf, subject to limited legal retention. Backups themselves remain in your own storage under your control.
10. Contact
To request a countersigned DPA or ask a question, email [email protected]. See also our Privacy Policy and Terms of Service.