Last updated: 8 October 2026
This Data Processing Agreement ("DPA") sets out how AI Vision ADS SRL processes personal data on behalf of its customers through XPI CRM, in line with Article 28 of the GDPR.
1. Parties, scope and definitions
The customer is the controller of the personal data it puts into XPI CRM. AI Vision ADS SRL, Splaiul Independenței 313B, Sector 6, 060042, Bucharest, Romania, Trade Register no. J2025/08/7555/4002, tax ID (CUI) 52901345, privacy contact adrian@minidigital.tech ("XPI CRM", "we") is the processor.
This DPA applies whenever we process personal data for the customer through the XPI CRM service at xpicrm.com, including the app, the API, imports, webhooks and support. It forms part of the Terms and Conditions and needs no separate signature, but a signed copy is available on request.
- GDPR: Regulation (EU) 2016/679, together with Romanian Law no. 190/2018.
- Customer data: personal data the customer or its users store in XPI CRM (clients, contacts, conversations, meetings, surveys, invoices, files, usage data, notes).
- Workspace: the customer's separate area in XPI CRM. Customer data is only accessible within its own workspace.
- Sub-processor: a third party we use that may process customer data (Annex 3).
- Other terms (personal data, processing, data subject, personal data breach) have their GDPR meaning.
2. Our obligations as processor
We process customer data only to provide XPI CRM and only on the customer's documented instructions. The Terms, this DPA and the customer's use of the app's features (including its settings, automations, API keys and webhooks) are those instructions.
- Instructions: if we believe an instruction breaks the GDPR, we tell the customer without delay.
- Confidentiality: everyone at XPI CRM who can access customer data is bound by confidentiality.
- Security: we apply the measures in Annex 2 and keep them appropriate to the risk.
- Sub-processors: we use them only as set out in section 3.
- Assistance: we help the customer meet its own GDPR duties, as set out in sections 5 and 6.
- No other use: we never sell customer data, use it for advertising, or use it to train AI models.
- Compliance: we make available the information needed to show we meet this DPA (section 8).
3. Sub-processors
The customer gives general authorisation for the sub-processors listed in Annex 3. We bind each one by contract to data protection terms at least as protective as this DPA, and we remain responsible for them.
- Changes: we announce any new or replaced sub-processor at least 30 days in advance, on this page and by email to workspace admins who subscribe.
- Objection: the customer may object on reasonable data protection grounds within that period. If we can't resolve it, the customer may end the service and get a pro-rata refund of any prepaid fees.
- Urgent replacement: if a sub-processor must be replaced at short notice for security or continuity, we tell customers as soon as possible afterwards, with the same right to object.
4. Where data is stored and international transfers
Customer data is stored in the European Union: the database, sign-in data and uploaded files are hosted in Ireland (AWS eu-west-1, through Lovable Cloud / Supabase). Encrypted weekly backups are stored in Cloudflare R2 within the EU jurisdiction.
Some sub-processors are US companies or run a global network (Annex 3). Where customer data may be accessed from or passed outside the EEA, we rely on the EU–US Data Privacy Framework where the provider is certified, or otherwise on the European Commission's Standard Contractual Clauses, with additional measures such as encryption in transit.
The app itself is delivered through Cloudflare's worldwide network, which handles requests (including IP addresses) at the location nearest each visitor to deliver the site and run bot checks. Customer records are stored only in the EU.
5. Assistance to the customer
Most data subject requests can be handled by the customer directly in XPI CRM: records can be viewed, exported (CSV and API), corrected and deleted, and the change history shows who changed what.
- Requests sent to us: if a data subject contacts us about customer data, we pass the request to the customer within 10 working days and don't answer it ourselves, unless the customer asks us to.
- Help beyond the app: where the app's own tools aren't enough, we help with reasonable requests for access, correction, deletion, restriction or portability.
- Impact assessments: we provide the information the customer reasonably needs for a data protection impact assessment or a consultation with a supervisory authority.
6. Personal data breaches
We notify the customer without undue delay, and at the latest within 72 hours of becoming aware of a breach affecting its customer data, so the customer can meet its own obligation to inform the supervisory authority.
The notice goes to the customer's workspace admins by email and includes, as far as known:
- what happened and when;
- the categories and approximate number of data subjects and records affected;
- the likely consequences;
- what we have done and propose to do to contain it;
- a contact for more information.
We add details as they become known and keep a record of every breach.
7. Return and deletion
The customer can export its data at any time (CSV export on every list, the API, and file downloads). When the customer deletes its workspace or account, we delete its customer data from the live service immediately.
Copies in our backups are deleted automatically when those backups expire: daily backups within 14 days, and encrypted weekly backups within 12 months. Until then they are kept secure and are not used. We keep data longer only where EU or Romanian law requires it, and then only for that purpose.
On request, we confirm the deletion in writing.
8. Audits and information
On request, we give the customer the information needed to show compliance with this DPA: this document, the security measures in Annex 2, the sub-processor list, and summaries of our security reviews.
If that isn't enough, the customer (or an independent auditor bound by confidentiality) may audit us once a year, with at least 30 days' notice, during working hours and without access to other customers' data. Each side bears its own costs, unless the audit finds a material breach of this DPA by us. Audits of sub-processors rely on their own certifications and reports (e.g. ISO 27001, SOC 2).
9. Liability, precedence, law and term
- Liability: XPI CRM is currently offered free of charge. To the fullest extent permitted by law, we accept no liability towards the customer for any loss or damage arising from the free service or this DPA. This does not exclude liability that cannot be excluded by law, in particular for intent or gross negligence, towards data subjects under GDPR Article 82, or for fines imposed directly on us. Paid plans, if introduced, will set their own limits in the Terms.
- Precedence: if this DPA and the Terms conflict on personal data, this DPA applies.
- Governing law and courts: Romanian law; the courts of Bucharest, unless the GDPR requires otherwise.
- Term: this DPA lasts as long as we process customer data for the customer, including the backup periods in section 7.
- Changes: we may update this DPA to reflect changes in law or in the service, with 30 days' notice, never lowering the level of protection.
Annex 1 – Description of the processing
| Item | Details |
|---|---|
| Purpose | Providing XPI CRM, a customer success CRM: storing and organising the customer's client relationships, automations, reports, health scores, imports, API and webhooks, and support. |
| Nature | Storage, organisation, retrieval, calculation (health scores, reports), transmission (API, webhooks to addresses the customer sets), deletion. |
| Data subjects | The customer's own users; contacts at the customer's clients; other people the customer records (e.g. survey respondents). |
| Categories of data | Names, business email addresses, phone numbers, job titles; conversation and meeting notes; survey answers and scores; invoice details; product usage records (which may include user IDs); uploaded files; sign-in data and change history for the customer's users. |
| Special category data | Not intended. Customers should not store health, biometric or similar data in XPI CRM. |
| Duration | For the term of the service, plus the backup periods in section 7. |
| Location | EU (Ireland), see section 4. |
Annex 2 – Security measures
| Area | Measures in place |
|---|---|
| Separation between customers | Each workspace's data is isolated by row-level security enforced in the database itself, tested automatically (cross-workspace reads, writes and file downloads are refused). |
| Access control | Roles (admin, standard, view-only) enforced in the database; admin-only setup, API keys and webhooks; sign-in with email and password, Google or Microsoft; email confirmation. |
| API keys | Shown once, stored only as a SHA-256 fingerprint, limited to chosen objects and read-only or read & write, revocable, rate-limited (600 per minute, 10,000 per hour per key). |
| Encryption | HTTPS (TLS) for all traffic with HSTS; data encrypted at rest by the hosting provider; weekly backups encrypted before upload with a key only we hold. |
| Abuse protection | Bot checks (Cloudflare Turnstile) on sign-up, password reset, contact form and repeated failed sign-ins; rate limits on sign-in, sign-up, password reset and forms. |
| Webhooks | HMAC-SHA256 signed; private and internal addresses refused when saved and before every send; redirects not followed. |
| Audit trail | Every create, change and delete is recorded by the database with who, when and the source (app, import, API, automation). |
| Secrets | Server keys stored only as server-side secrets, never in the browser or the code repository; the build fails if one appears. |
| Browser security | Content security policy, HSTS, no embedding in other websites, no content-type guessing, restricted browser permissions. |
| Monitoring | Error monitoring (Sentry, EU region) with personal data removed before sending; uptime monitoring every 5 minutes; a daily check alerts us if scheduled jobs or backups fail. |
| Backups | Daily database backups kept 14 days; encrypted weekly full backups (database and uploaded files) kept up to 12 months in the EU; restores tested. |
| People | Access to production is limited to the company's administrators, who are bound by confidentiality; a security review is carried out before each major release. |
Annex 3 – Sub-processors
| Sub-processor | What it does | Customer data involved | Where | Transfer safeguard |
|---|---|---|---|---|
| Lovable Labs Incorporated (with Lovable Labs AB, Sweden) | App platform and hosting operator (Lovable Cloud) | All customer data | EU (Ireland) | Lovable Data Processing Agreement; EU–US Data Privacy Framework / Standard Contractual Clauses |
| Supabase Inc. (via Lovable Cloud) | Database, sign-in and file storage | All customer data | EU – Ireland (AWS eu-west-1) | Data stored in the EU; Standard Contractual Clauses for any support access |
| Amazon Web Services EMEA SARL | Underlying servers for the database | All customer data (encrypted at rest) | EU – Ireland | Within the EU |
| Cloudflare Inc. | Delivers the app worldwide; bot checks (Turnstile); encrypted backup storage (R2) | Request data passing through, IP addresses; encrypted backups | Global network; R2 backups in the EU jurisdiction | EU–US Data Privacy Framework / Standard Contractual Clauses |
| Mailgun Technologies, Inc. (via Lovable Emails) | Sends account and notification emails from notify.xpicrm.com (transactional email, email domain management) | Users' names and email addresses, email content | US | Lovable's DPA (EU–US Data Privacy Framework / Standard Contractual Clauses) |
| Functional Software Inc. (Sentry) | Error monitoring, with personal data removed before sending | None intended (scrubbed) | EU (Germany) | Data stored in the EU |
| Google LLC / Microsoft | Optional sign-in (only if a user chooses it) | Name, email address, profile picture of that user | US / global | EU–US Data Privacy Framework |
Not sub-processors, because they never receive customer data: GitHub (stores the app's code) and the uptime monitoring service (checks only that the site responds).