Skip to content
xenzee xenzee
Apps
The xenzee suite

Seven Apps. One Login. One Source of Truth.

Delta Social Plan, schedule and publish across every channel. Atlas SEO Track rankings and turn research into growth. Haven HR Hiring, onboarding and the whole team lifecycle. Nexus CRM Leads to cash, with deals and invoices connected. Forge Projects Deliver client work and prove the profit. Campaigns Paid ads Launch and track ads across every network. Pulse Reporting Every number from every app, in one live report.
Explore the full suite
Platform Pulse About FAQ
Sign in Get started
Legal

Data Processing Agreement

Last updated: 30 June 2026 · xenzee is a brand of Loyus Solutions Pvt. Ltd.

How Loyus Solutions Pvt. Ltd. processes personal data on your behalf when you use the xenzee suite.

Terms Privacy DPA Sub-processors

On this page

  1. About this agreement
  2. Definitions
  3. Roles of the parties
  4. Subject matter and details of processing
  5. Processing instructions
  6. Confidentiality
  7. Security measures
  8. Sub-processors
  9. Assisting with data-subject rights
  10. Personal data breaches
  11. Impact assessments
  12. International transfers
  13. Return and deletion
  14. Audits and information
  15. Liability
  16. Governing law
  17. How to reach us
This document is written in plain language so it is easy to follow. It forms a binding agreement. If anything is unclear, you can reach us through the support options inside your xenzee account dashboard.

About this agreement

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between you ("Customer", "Controller") and Loyus Solutions Pvt. Ltd. ("Loyus", "Processor") for the xenzee Services. It applies where, in providing the Services, Loyus processes Personal Data on the Customer’s behalf, for example through Haven (HR), Nexus (CRM), Forge, Campaigns, Pulse and the other Apps. It takes effect when you accept the Terms or begin using the Services.

Where this DPA conflicts with the Terms in relation to the processing of Personal Data, this DPA controls.

Definitions

  • Applicable Data Protection Law means all privacy and data protection laws that apply to the processing, which may include the EU and UK GDPR and India’s Digital Personal Data Protection Act, 2023.
  • Personal Data, Controller, Processor, Data Subject and Processing have the meanings given in Applicable Data Protection Law.
  • Customer Personal Data means Personal Data that Loyus processes on the Customer’s behalf under the Services.
  • Sub-processor means a third party engaged by Loyus to process Customer Personal Data.

Roles of the parties

For Customer Personal Data, the Customer is the Controller and Loyus is the Processor. The Customer determines the purposes and means of processing; Loyus processes only as described in this DPA and on the Customer’s documented instructions. The Customer is responsible for the lawfulness of the Personal Data it provides and the instructions it gives, including having a valid legal basis and providing any required notices to Data Subjects.

Subject matter and details of processing

The subject matter is the provision of the Services. The duration is the term of the Terms plus any wind-down period described below.

  • Nature and purpose: hosting, storing, organising, analysing, transmitting and otherwise processing Customer Personal Data to provide the Apps and the functions the Customer asks them to perform.
  • Types of Personal Data: as determined by the Customer, which may include identifiers and contact details, employment and HR data (Haven), customer and contact records (Nexus), project, time and cost data (Forge), advertising and engagement data (Campaigns, Delta), and related records across the suite.
  • Categories of Data Subjects: as determined by the Customer, which may include the Customer’s employees, candidates, customers, contacts, leads and end users.

Processing instructions

Loyus will process Customer Personal Data only on the Customer’s documented instructions, including those given through the configuration and use of the Services, unless required to act otherwise by law (in which case Loyus will inform the Customer where legally permitted). Loyus will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

Confidentiality

Loyus ensures that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and access the data only as needed to provide the Services.

Security measures

Loyus implements appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art and the risks involved. These include encryption of data in transit, access controls and role-based permissions, keeping sensitive financial figures need-to-know, storing third-party credentials as protected references, network and application safeguards on our AWS infrastructure, logging and monitoring, and maintaining audit trails of changes. Loyus reviews and updates these measures over time.

Sub-processors

The Customer provides a general authorisation for Loyus to engage Sub-processors to process Customer Personal Data, including the cloud infrastructure provider Amazon Web Services (United States) and the providers listed on our Sub-processors page. Loyus imposes data protection obligations on its Sub-processors that are no less protective than those in this DPA, and remains responsible for their performance.

Loyus will keep the Sub-processors page current and will provide a mechanism to be notified of intended changes. The Customer may object to a new Sub-processor on reasonable data-protection grounds, in which case the parties will work in good faith to address the concern.

Assisting with data-subject rights

Taking into account the nature of the processing, Loyus will provide reasonable assistance, including appropriate technical and organisational measures and the self-service controls within the Services, to help the Customer respond to requests from Data Subjects to exercise their rights. If Loyus receives such a request directly relating to Customer Personal Data, it will, where permitted, direct the Data Subject to the Customer.

Personal data breaches

Loyus will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations. Loyus will take reasonable steps to mitigate and, where possible, remedy the breach.

Impact assessments

Taking into account the nature of processing and the information available, Loyus will provide the Customer reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority that Applicable Data Protection Law requires.

International transfers

The Services are hosted on Amazon Web Services in the United States, and Customer Personal Data is processed and stored primarily in the US. Where the provision of the Services involves transferring Customer Personal Data across borders, Loyus will ensure an appropriate transfer mechanism or safeguard recognised under Applicable Data Protection Law (such as standard contractual clauses) is in place with the relevant recipients.

Return and deletion

On termination or expiry of the Services, and at the Customer’s choice, Loyus will make Customer Personal Data available for export for a limited period where reasonably practicable, and will then delete or anonymise it, except to the extent retention is required by law. Our standard retention timelines are described in our Privacy Policy.

Audits and information

Loyus will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, security, scheduling and scope limitations so as not to disrupt the Services or other customers.

Liability

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms.

Governing law

This DPA is governed by the same law as the Terms, namely the laws of India, except where Applicable Data Protection Law requires otherwise for specific transfers or rights.

How to reach us

For questions about this DPA, or to make data-protection requests, you can reach us, including the Grievance Officer where applicable, through the support and grievance options inside your xenzee account dashboard.

xenzee xenzee

The All-in-One Business Suite.

Company

About us

Legal

Terms Privacy

Compliance

DPA Sub-processors
© 2026 xenzee. All rights reserved. xenzee- One Platform for Your Whole Business.