Data Processing Agreement (DPA) and Generative AI Policy
Effective Date: 23 April 2025
Entity: X18agency by Headson, LLC ("X18agency", "Headson", "we", "our", "us")
EIN: 35‑2834563
Registered Address: 651 N Broad St, Suite 201, Middletown, DE 19709 USA
This Data Processing Agreement ("DPA") is part of the Terms of Service ("Agreement") between [Customer Name] ("Customer," "you," "your") and X18agency ("the Software," "Processor," "we," "our," "us"). This DPA governs the processing of personal data that we perform on behalf of the Customer in connection with the provision of the Software, in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Definitions
- Data Controller: The entity that determines the purposes and means of the processing of personal data.
- Data Processor: The entity that processes personal data on behalf of the Data Controller.
- Data Subject: Any identified or identifiable individual whose personal data is processed.
- Personal Data: Any information relating to an identified or identifiable individual.
- Processing: Any operation or set of operations performed on personal data, such as collection, storage, use, disclosure, or erasure.
- Sub-Processor: Any third party appointed by the Processor to process personal data on behalf of the Customer.
2. Roles and Responsibilities
- Customer as Data Controller: The Customer acts as the Data Controller for all personal data processed through the Software. As Data Controller, the Customer is responsible for determining the legal basis for processing and ensuring compliance with applicable data protection laws.
- X18agency as Data Processor: X18agency acts as the Data Processor and processes personal data on behalf of the Customer in accordance with this DPA and the Customer's instructions.
3. Types of Personal Data Processed
X18agency processes the following types of personal data on behalf of the Customer:
- End-user data: Names, email addresses, reviews, feedback, video testimonials, and other information submitted through review requests or landing pages.
- Customer data: Names, email addresses, contact information, login credentials, and other business-related data.
- Usage data: IP addresses, device information, and data related to the usage of the Software.
The scope of the data processed may change based on the services provided by X18agency, and the Customer will be informed accordingly.
4. Purpose of Processing
X18agency processes personal data for the following purposes:
- Aggregating reviews from third-party platforms (e.g., Trustpilot, Google, Facebook).
- Responding to reviews via artificial intelligence on behalf of the Customer.
- Sending review request campaigns and processing feedback.
- Sharing reviews through widgets and social media platforms.
- Performing analytics to track and enhance reputation management.
- Automating processes such as the sending of review requests.
5. Duration of Processing
The processing of personal data will continue for the duration of the Agreement, unless otherwise required by law or requested by the Customer for data deletion.
6. Processor Obligations
X18agency agrees to:
- Process data only under instructions from the Customer: We will process personal data only as necessary to provide the Software and in accordance with the Customer's documented instructions.
- Ensure confidentiality: We will ensure that all employees or contractors involved in processing personal data are subject to a duty of confidentiality.
- Implement security measures: We will implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, alteration, or disclosure.
- Assist the Customer: We will assist the Customer in fulfilling its obligations to respond to data subject requests (e.g., requests for access, rectification, deletion, or portability) and in ensuring compliance with applicable laws, including performing data protection impact assessments when required.
- Data breach notification: In the event of a personal data breach, we will notify the Customer without undue delay after becoming aware of the breach and provide reasonable information and assistance.
7. Customer Obligations
As Data Controller, the Customer agrees to:
- Provide lawful instructions: The Customer will ensure that all instructions provided to X18agency are lawful and comply with applicable data protection laws.
- Inform data subjects: The Customer is responsible for providing data subjects with any necessary privacy notices and obtaining the required consents where applicable.
- Ensure legal basis for processing: The Customer must ensure that there is a valid legal basis for processing personal data (e.g., consent, legitimate interest, contract performance).
- Respond to data subject requests: The Customer will handle all data subject requests related to the personal data processed through the Software. X18agency will assist upon request.
8. Sub-Processors
X18agency may engage Sub-Processors to process personal data on behalf of the Customer. We will:
- Ensure that any Sub-Processor we engage provides the same level of data protection and security as required by this DPA.
- Remain fully liable for the performance of our Sub-Processors.
9. International Data Transfers
X18agency operates a distributed cloud infrastructure and, as a result, personal data may be transferred to-or accessed from countries outside the jurisdiction in which it was collected, including but not limited to the EEA, the United Kingdom, the United States, Australia, and various Asian jurisdictions (e.g., Singapore, Israel, Thailand).
Whenever such transfers occur, we will ensure they comply with all relevant cross-border‐transfer rules in each originating region.
10. Security Measures
X18agency implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data during transmission.
- Access controls to prevent unauthorized access to data.
- Regular security assessments and audits.
- Incident response plans to handle data breaches.
11. Data Subject Rights
X18agency will assist the Customer in ensuring compliance with data subjects' rights under applicable data protection laws, including the rights to:
- Access their personal data.
- Rectify inaccurate or incomplete data.
- Request erasure of their data ("right to be forgotten").
- Restrict or object to the processing of their data.
- Receive their data in a portable format (where applicable).
Requests from data subjects will be forwarded to the Customer for handling, and X18agency will provide assistance as necessary.
12. Data Retention and Deletion
Upon termination or expiration of the Agreement, X18agency will, at the Customer's request:
- Return all personal data processed on behalf of the Customer, or
- Delete all personal data, unless retention is required by law.
13. Liability
Both parties agree that their liability under this DPA will be subject to the limitations and exclusions set out in the Agreement, except where such limitations are prohibited by applicable data protection laws.
14. Governing Law
This DPA shall be governed by and construed in accordance with the laws of USA, without regard to its conflict of laws principles.
15. Termination
This DPA shall remain in effect as long as X18agency processes personal data on behalf of the Customer. Upon termination of the Agreement, the terms of this DPA will continue to apply for as long as X18agency retains personal data.
16. Generative AI Policy
16.1 Feature Scope
- The AI Review Response feature is optional and user-initiated.
- When invoked, the text of an incoming private or public review is sent to a Large Language Model (“LLM”) to draft a suggested reply.
- No current other product functionality uses Generative AI.
16.2 Data Minimisation & Prompt Design
Before transmission to the LLM we automatically strip or pseudonymise: email, customer identifiers, phone numbers and precise locations.
Data sent consists of:
- Review text and star rating.
- Your business tone preferences (if configured).
No persistent personal identifiers are included. - name of reviewer
16.3 Purpose & Legal Basis
Processing occurs solely to generate a draft response on your behalf. No profiling, automated decision-making, or further enrichment is performed.
17. Sub-Processor for AI
17.1 Provider
The current LLM provider is OpenAI, L.L.C. (or its Azure OpenAI equivalent)
17.2 Contractual Safeguards
- Data is processed transiently and never used to train or fine-tune provider models.
- Provider is bound to equal or stronger security and confidentiality obligations than those in this DPA.
- Standard Contractual Clauses govern any international transfer.
18. Security & Retention for AI Prompts
18.1 Transit & Storage – TLS 1.2+ encryption in transit; prompts are kept only in volatile memory by the provider and are not stored by the LLM.
18.2 Internal Logs – We retain minimal audit metadata (timestamp, prompt hash, success flag) for 30 days, then securely delete.
18.3 Access Controls – Only vetted engineering staff with least-privilege roles may access AI-related logs.
19. Human Oversight & Customer Responsibilities
19.1 Draft-Only Output – AI text is returned to your dashboard as a draft. It is never auto-published.
19.2 Review & Edit – You (or your authorised users) must review, modify if needed, and approve the content before posting.
19.3 Content Standards – You must not publish AI-generated text that is unlawful, defamatory, or infringes third-party rights.
21. Accuracy & Disclaimers
While we use state-of-the-art LLMs, AI output may occasionally be factually incorrect or reflect unintended bias. We provide no warranty as to the factual accuracy of AI-generated drafts. Sections 14 (Liability) and 15 (Governing Law) apply equally to the AI feature.
22. Audit & Transparency
Upon reasonable request, we will:
- Disclose current LLM providers and architectural diagrams relevant to the feature.
23. Changes to the Generative AI Policy
We may update Sections 18–23 to reflect new laws or material feature changes. We will notify you 30 days in advance via email and in-app banner. Continued use after the effective date constitutes acceptance.
24. Contact
Questions about the Generative AI Policy? Email info@x18agency.com