Data Processing Addendum
How XTK processes personal data on behalf of your practice, and the commitments we make as your processor.
Last updated:
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Sub-processor” have the meanings given in the GDPR / UK GDPR. “Applicable Data Protection Law” means the data protection laws that apply to your use of XTK.
2. Scope & roles
- You (the Practice) are the controller; we act only as your processor.
- We process personal data only to provide XTK and on your documented instructions, including as set out in the Terms and this DPA.
- We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
3. Details of processing
- Subject matter: provision of document management, e-signatures, client portal and template features.
- Duration: for the term of your subscription plus any retention period in the Terms.
- Nature & purpose: storing and moving documents, sending mail you initiate, and managing signature and request workflows.
- Types of personal data: names, email addresses, contact details, document contents, and e-signature records of your clients and signers.
- Categories of data subjects: your staff, clients and the signers you invite.
4. Our obligations
- Process personal data only on your documented instructions.
- Ensure persons authorised to process it are bound by confidentiality.
- Implement appropriate technical and organisational security measures (encryption in transit and at rest, encrypted OAuth tokens, restricted production access).
- Assist you, taking into account the nature of processing, with data subject requests and with your obligations on security, breach notification and impact assessments.
- Notify you without undue delay after becoming aware of a personal data breach.
5. Sub-processors
You provide general authorisation for us to engage the sub-processors listed on our Sub-processors page. We impose data protection terms on each and remain responsible for their performance. We will give notice of intended changes so you can object on reasonable data-protection grounds.
6. International transfers
Where processing involves transfers outside your jurisdiction, we rely on a lawful transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where applicable.
7. Data subject requests
XTK provides features that let you access, correct, export and delete data within your Practice. Where a data subject contacts us directly, we will refer them to you and assist you in responding.
8. Return & deletion
On termination, and at your choice, we will delete or return the personal data we process on your behalf, and delete existing copies unless law requires storage. Documents held in your connected storage provider remain under your control there. See Your data rights.
9. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable confidentiality and security safeguards.
10. Contact
To request a signed copy of this DPA or ask a question, contact support@octabyte.io.
Give Practice Manager its missing half
Install the extension, connect your Drive, and open your first client — your whole practice can be working in context today.
30-day free trial for your whole practice — no credit card required.