Contractual Status. This Data Processing & Confidentiality Agreement (“Agreement”) forms an integral addendum to the Master Service Agreement, Terms of Service, subscription order form, or other principal commercial agreement in force between Xryzex AI (“Xryzex,” “Service Provider,” “Pr “Data Fiduciary,” “Controller,” “Receiving Party,” or “Disclosing Party,” as applicable).
/strong>,”Precedence. This Agreement supplements, and does not replace, the Master Service Agreement (“MSA”). In the event of direct conflict, this Agreement shall control only with respect to confidentiality, data processing, data security, data deletion, and sub-processor matters. All other commercial, billing, suspension, indemnity, and liability provisions remain governed by the MSA unless expressly overridden here.
1. Purpose and Scope
This Agreement governs:
- the processing of Client data by Xryzex in connection with Xryzex’s B2B AI SaaS services;
- the protection of mutual confidential information exchanged, uploaded, stored, accessed, or inferred during service delivery;
- the parties’ respective rights and obligations under applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000, together with applicable rules and directions; and
- the authorized use of sub-processors necessary to operate Xryzex’s hosted infrastructure, AI inference, telephony, messaging, and storage stack.
2. Roles of the Parties
For purposes of data protection compliance:
- the Client is the primary business principal determining the purpose of ingesting its Knowledge Base, Outbound Leads, and customer interaction logic into the platform;
- Xryzex acts as a service provider and processor for personal data processed on the Client’s behalf through the hosted application stack; and
- nothing in this Agreement transfers ownership of Client business data to Xryzex or ownership of Xryzex’s software, prompts, logic, or technical architecture to the Client.
3. Definitions
For this Agreement:
- “Knowledge Base” means Client-provided product catalogs, pricing rules, operational instructions, workflow mappings, commercial response logic, product notes, and related business data uploaded to or maintained within the Services.
- “Outbound Leads” means customer phone numbers, contact lists, lead lists, and related campaign or outreach data provided by the Client for outbound communication workflows.
- “WhatsApp Session Memory” means session-level WhatsApp conversation context, including recent message history used for operational continuity within the platform.
- “Confidential Information” has the meaning assigned in Section 4 below.
- “Personal Data” means any data relating to an identified or identifiable natural person processed by Xryzex on behalf of the Client through the Services.
- “Sub-Processor” means any third party engaged by Xryzex to assist in hosting, storage, messaging, inference, telephony, routing, or other processing operations necessary to perform the Services.
- “Security Incident” means confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or loss of Client data stored or processed within Xryzex-controlled systems, excluding unsuccessful attempts, blocked scans, generalized internet noise, or incidents confined solely to the Client’s own systems.
4. Mutual Confidential Information
4.1 Mutual Treatment
Each party acknowledges that, in the course of the relationship, it may receive or access non-public information of the other party that is commercially sensitive, proprietary, operationally material, or legally protected. Such information shall be treated as Confidential Information whether disclosed orally, visually, electronically, by system access, or in written form.
4.2 Client Confidential Information
The following shall be deemed the Client’s Confidential Information, whether or not marked confidential:
- inventory data;
- product catalogs;
- pricing rules and pricing logic;
- sales terms, commercial response rules, and fulfillment instructions;
- Outbound Leads and customer phone numbers;
- WhatsApp message histories and session-level conversation content;
- call-related business instructions, route logic, or escalation rules configured by the Client; and
- all derived datasets, structured exports, and database records representing the Client’s trade secrets, customer relationships, or operating methods.
4.3 Xryzex Confidential Information
The following shall be deemed Xryzex’s Confidential Information, whether or not marked confidential:
- source code, Python architecture, internal frameworks, and implementation methods;
- AI system prompts, LLM instructions, prompt engineering methods, agent policies, and response orchestration layers;
- telephony routing logic, message routing logic, workflow engines, automations, and failure-handling methods;
- database schemas, relational structures, indexing strategies, security architecture, and application design;
- internal APIs, model selection logic, optimization methods, cost controls, and deployment configurations; and
- all non-public technical, commercial, product, and infrastructure materials of Xryzex.
4.4 Reverse Engineering Prohibition
The Client shall not, and shall not permit any third party to, reverse-engineer, decompile, disassemble, scrape, derive, infer, extract, map, or attempt to replicate Xryzex’s prompts, system instructions, orchestration logic, routing behavior, schema design, AI control layers, or software business logic, except to the limited extent such restriction is prohibited by non-waivable law. The Client shall not use outputs, logs, interface behavior, latency patterns, or prompt responses to build a competing system or derivative logic library.
4.5 Confidentiality Standard
Each party shall protect the other party’s Confidential Information using at least the same degree of care it uses to protect its own confidential information of similar importance, and in no event less than reasonable care. Confidential Information shall be used solely for performance, receipt, administration, security, compliance, or enforcement of the Services and the MSA.
5. Permitted Processing and Processing Instructions
Xryzex shall process Client data only:
- to provide the Services described in the MSA or applicable order form;
- on the documented or platform-configured instructions of the Client;
- to store, retrieve, structure, query, transmit, and secure the Knowledge Base, Outbound Leads, and WhatsApp Session Memory necessary for service operation;
- to maintain service integrity, logging, fraud prevention, diagnostics, and abuse prevention; and
- to comply with applicable law, court order, lawful governmental request, or mandatory incident response duty.
Xryzex shall not sell Client Confidential Information and shall not use Client Confidential Information for advertising profiling or unrelated commercial exploitation.
6. Database Security Architecture and Row Level Security (RLS)
6.1 Segregated Multi-Tenant Controls
Xryzex operates a secure hosted cloud environment designed to segregate Client datasets at the application, identity, and database-access layers. Xryzex uses PostgreSQL Row Level Security (RLS) hosted on Supabase to enforce tenant-level isolation.
6.2 Cryptographic and Logical Walling-Off
The parties acknowledge and agree that Client data is designed to be cryptographically and logically walled off from other tenants. One factory owner is not permitted to query, view, join, enumerate, export, or otherwise access another factory owner’s rows, records, or tenant-specific datasets through the application, database, or ordinary API behavior.
6.3 RLS Enforcement Principle
RLS policies are intended to ensure that row visibility and row operations are constrained by tenant identity and platform authorization controls, such that database operations are evaluated against tenant-specific access rules before data is returned or mutated.
6.4 Encryption
Xryzex maintains encryption safeguards including:
- encryption in transit using TLS/SSL for network communications between clients, application services, APIs, and hosted infrastructure; and
- encryption at rest for hosted storage layers as provided by the underlying infrastructure stack and associated configuration controls.
6.5 Administrative Access Controls
Xryzex shall maintain reasonable administrative access restrictions, credential controls, and environment separation practices designed to limit internal access to authorized personnel with legitimate operational need.
7. Authorized Sub-Processors and Client Authorization
The Client expressly authorizes Xryzex to engage the following Sub-Processors to the extent reasonably necessary to deliver the Services:
| Sub-Processor | Primary Function | Typical Data Scope |
|---|---|---|
| Google Cloud Platform / Vertex AI | LLM reasoning, inference workloads, application hosting, and AI-related processing | Prompt inputs, Knowledge Base query context, temporary inference payloads, operational response context |
| Supabase | PostgreSQL database hosting and related application data storage | Knowledge Base records, Outbound Leads, WhatsApp Session Memory, account-linked structured datasets |
| ChakraHQ / Meta | WhatsApp message routing, delivery, and platform messaging infrastructure | WhatsApp numbers, message payloads, message metadata, operational conversation context |
| LiveKit / Sarvam AI / Azure | Voice routing, live media transport, speech processing, and related voice AI functions | Ephemeral voice-processing payloads, speech segments, transcription inputs/outputs as required for runtime handling |
7.1 Authorization Effect
The Client’s use of the Services constitutes legal authorization for Xryzex to transfer, disclose, transmit, or make available relevant Client data to the foregoing Sub-Processors solely to the extent necessary for the contracted service to function.
7.2 No Public Model Training Commitment
Xryzex uses enterprise-grade AI processing arrangements and requires that Client Confidential Information processed through Google Vertex AI / Azure OpenAI is not used to train public foundation models. Xryzex does not intentionally submit Client Knowledge Base content, WhatsApp histories, or other Client Confidential Information for public model training purposes.
7.3 Sub-Processor Responsibility Standard
Xryzex shall use commercially reasonable care in selecting Sub-Processors appropriate for enterprise infrastructure functions. However, the Client acknowledges that Xryzex does not own or control the internal systems of independent Sub-Processors and cannot warrant absolute immunity from external compromise, service outage, or infrastructure-level attack affecting those providers.
8. Client Obligations and Data Legitimacy
The Client represents, warrants, and undertakes that:
- it has all necessary rights, notices, permissions, and legal bases to provide the Knowledge Base, Outbound Leads, and WhatsApp-related data to Xryzex for processing;
- it will not provide unlawfully obtained data or data prohibited by applicable law;
- it remains responsible for the legality of customer lists, lead lists, and message or outreach content uploaded to the platform; and
- it will not use the Services to store or route data beyond what is operationally necessary for its legitimate business workflows.
9. Security Incident and Data Breach Notification
9.1 Notification Timeline
If Xryzex confirms a Security Incident affecting Client data within Xryzex-controlled systems, Xryzex shall notify the Client within 72 hours of confirming the breach, consistent with the incident response posture expected under applicable Indian cyber incident reporting frameworks, including reference alignment with CERT-In guidance.
9.2 Notification Content
Such notice may include, to the extent then known and legally disclosable:
- the general nature of the incident;
- the categories of affected data;
- the known or reasonably suspected impact on the Client;
- containment or remediation measures initiated by Xryzex; and
- recommended steps, if any, for Client-side mitigation.
9.3 No Admission
Any incident notification provided under this Section shall not constitute an admission of fault, liability, negligence, or legal responsibility by Xryzex.
10. Liability Cap and Third-Party Compromise Limitation
10.1 Specific Breach Liability Cap
Notwithstanding anything to the contrary in this Agreement or the MSA, Xryzex’s total aggregate liability arising out of or relating to any Security Incident, data breach, unauthorized database access event, or confidentiality claim under this Agreement shall be strictly capped at the total amount paid by the Client to Xryzex during the three (3) calendar months immediately preceding the confirmed breach.
10.2 Exclusion of Disproportionate Exposure
Under no circumstances shall Xryzex be liable for speculative, punitive, exemplary, indirect, incidental, special, or consequential damages, including lost profits, reputational loss, lost business opportunity, downstream customer claims, or multi-party exposure measured in amounts grossly disproportionate to the fees actually paid by the Client.
10.3 Third-Party Infrastructure Events
To the maximum extent permitted by law, Xryzex shall not be liable for claimed “millions in damages” or comparable extraordinary exposure resulting from an external compromise, infrastructure attack, platform vulnerability, or security failure occurring within the independent systems of third-party Sub-Processors such as Google Cloud Platform, Supabase, Meta, ChakraHQ, LiveKit, Azure, except to the limited extent directly caused by Xryzex’s own proven willful misconduct in configuring or transmitting data to such provider.
11. Mutual Restrictions on Use and Disclosure
Neither party shall disclose the other party’s Confidential Information to third parties except:
- to its employees, advisers, auditors, legal counsel, or contractors with a strict need to know and confidentiality obligations no less protective than those in this Agreement;
- to Sub-Processors or service providers as expressly authorized hereunder;
- as required by law, regulation, court order, or lawful governmental process; or
- with the prior written consent of the Disclosing Party.
12. Data Retention, 90-Day Purge, and Data Minimization
12.1 Retention Principle
Xryzex shall not retain Client data indefinitely where no continuing service, legal, or security purpose justifies retention. The parties acknowledge that controlled deletion is part of Xryzex’s compliance posture and supports the data minimization principle under the DPDP Act.
12.2 Termination or Extended Non-Payment
Upon termination of the contract, or where the Client account remains suspended for non-payment for 90 consecutive days, Xryzex may execute an automated data purge.
12.3 Purged Data Categories
The purge may include destruction of:
- the Client’s Knowledge Base;
- Outbound Leads;
- WhatsApp Session Memory;
- session-linked operational records stored solely for active service continuity; and
- other Client-specific hosted data no longer required for limited legal retention, fraud prevention, or dispute preservation.
12.4 No Hostage Retention
Xryzex does not hold Client data hostage after commercial termination, and it does not undertake indefinite storage of dormant account datasets absent a specific paid retention arrangement or legal preservation duty.
13. Return or Export of Data
Where technically available within the product and commercially applicable under the MSA, the Client may export or retrieve certain account data prior to termination or purge. Unless otherwise agreed in writing, Xryzex has no obligation to build custom extraction tooling, forensic exports, or long-term archival services after termination or purge has been triggered.
14. Intellectual Property Reservation
Nothing in this Agreement grants the Client ownership of Xryzex’s software, prompts, agent logic, APIs, routing logic, schemas, methods, or platform architecture. Nothing in this Agreement grants Xryzex ownership of the Client’s pre-existing business records, product catalogs, pricing rules, lead lists, or message histories beyond the limited processing rights necessary to perform the Services.
15. Audit, Inquiry, and Cooperation
Upon reasonable written request, and subject to confidentiality and security limitations, Xryzex may provide high-level information about its security posture, sub-processor structure, or incident response measures sufficient for enterprise diligence. Xryzex shall not be required to disclose source code, live prompts, exploit-sensitive architecture, penetration test details, customer-specific configurations of other tenants, or materials that would create security risk or expose proprietary trade secrets.
16. Term and Survival
This Agreement shall commence upon the effective date of the MSA or the Client’s use of the Services, whichever occurs first, and shall remain in effect for so long as Xryzex processes Client data or retains Confidential Information subject to this Agreement. The confidentiality, liability, deletion, intellectual property, and dispute-related provisions shall survive termination for so long as applicable by their nature.
17. Governing Law
This Agreement shall be governed by and construed in accordance with the laws of the Republic of India. Any disputes arising out of or in connection with this Agreement shall be governed by the dispute resolution and jurisdiction provisions stated in the MSA, unless the parties agree otherwise in writing.
18. Entire Addendum
This Agreement constitutes the entire understanding of the parties with respect to confidentiality and data processing subject matter addressed herein and supersedes prior inconsistent understandings on those subjects, but only as an addendum to and not as a replacement of the MSA.