Last updated: 8 October 2026

This Data Processing Agreement ("DPA") sets out how AI Vision ADS SRL processes personal data on behalf of its customers through XPI CRM, in line with Article 28 of the GDPR.

1. Parties, scope and definitions

The customer is the controller of the personal data it puts into XPI CRM. AI Vision ADS SRL, Splaiul Independenței 313B, Sector 6, 060042, Bucharest, Romania, Trade Register no. J2025/08/7555/4002, tax ID (CUI) 52901345, privacy contact adrian@minidigital.tech ("XPI CRM", "we") is the processor.

This DPA applies whenever we process personal data for the customer through the XPI CRM service at xpicrm.com, including the app, the API, imports, webhooks and support. It forms part of the Terms and Conditions and needs no separate signature, but a signed copy is available on request.

  • GDPR: Regulation (EU) 2016/679, together with Romanian Law no. 190/2018.
  • Customer data: personal data the customer or its users store in XPI CRM (clients, contacts, conversations, meetings, surveys, invoices, files, usage data, notes).
  • Workspace: the customer's separate area in XPI CRM. Customer data is only accessible within its own workspace.
  • Sub-processor: a third party we use that may process customer data (Annex 3).
  • Other terms (personal data, processing, data subject, personal data breach) have their GDPR meaning.

2. Our obligations as processor

We process customer data only to provide XPI CRM and only on the customer's documented instructions. The Terms, this DPA and the customer's use of the app's features (including its settings, automations, API keys and webhooks) are those instructions.

  1. Instructions: if we believe an instruction breaks the GDPR, we tell the customer without delay.
  2. Confidentiality: everyone at XPI CRM who can access customer data is bound by confidentiality.
  3. Security: we apply the measures in Annex 2 and keep them appropriate to the risk.
  4. Sub-processors: we use them only as set out in section 3.
  5. Assistance: we help the customer meet its own GDPR duties, as set out in sections 5 and 6.
  6. No other use: we never sell customer data, use it for advertising, or use it to train AI models.
  7. Compliance: we make available the information needed to show we meet this DPA (section 8).

3. Sub-processors

The customer gives general authorisation for the sub-processors listed in Annex 3. We bind each one by contract to data protection terms at least as protective as this DPA, and we remain responsible for them.

  • Changes: we announce any new or replaced sub-processor at least 30 days in advance, on this page and by email to workspace admins who subscribe.
  • Objection: the customer may object on reasonable data protection grounds within that period. If we can't resolve it, the customer may end the service and get a pro-rata refund of any prepaid fees.
  • Urgent replacement: if a sub-processor must be replaced at short notice for security or continuity, we tell customers as soon as possible afterwards, with the same right to object.

4. Where data is stored and international transfers

Customer data is stored in the European Union: the database, sign-in data and uploaded files are hosted in Ireland (AWS eu-west-1, through Lovable Cloud / Supabase). Encrypted weekly backups are stored in Cloudflare R2 within the EU jurisdiction.

Some sub-processors are US companies or run a global network (Annex 3). Where customer data may be accessed from or passed outside the EEA, we rely on the EU–US Data Privacy Framework where the provider is certified, or otherwise on the European Commission's Standard Contractual Clauses, with additional measures such as encryption in transit.

The app itself is delivered through Cloudflare's worldwide network, which handles requests (including IP addresses) at the location nearest each visitor to deliver the site and run bot checks. Customer records are stored only in the EU.

5. Assistance to the customer

Most data subject requests can be handled by the customer directly in XPI CRM: records can be viewed, exported (CSV and API), corrected and deleted, and the change history shows who changed what.

  • Requests sent to us: if a data subject contacts us about customer data, we pass the request to the customer within 10 working days and don't answer it ourselves, unless the customer asks us to.
  • Help beyond the app: where the app's own tools aren't enough, we help with reasonable requests for access, correction, deletion, restriction or portability.
  • Impact assessments: we provide the information the customer reasonably needs for a data protection impact assessment or a consultation with a supervisory authority.

6. Personal data breaches

We notify the customer without undue delay, and at the latest within 72 hours of becoming aware of a breach affecting its customer data, so the customer can meet its own obligation to inform the supervisory authority.

The notice goes to the customer's workspace admins by email and includes, as far as known:

  • what happened and when;
  • the categories and approximate number of data subjects and records affected;
  • the likely consequences;
  • what we have done and propose to do to contain it;
  • a contact for more information.

We add details as they become known and keep a record of every breach.

7. Return and deletion

The customer can export its data at any time (CSV export on every list, the API, and file downloads). When the customer deletes its workspace or account, we delete its customer data from the live service immediately.

Copies in our backups are deleted automatically when those backups expire: daily backups within 14 days, and encrypted weekly backups within 12 months. Until then they are kept secure and are not used. We keep data longer only where EU or Romanian law requires it, and then only for that purpose.

On request, we confirm the deletion in writing.

8. Audits and information

On request, we give the customer the information needed to show compliance with this DPA: this document, the security measures in Annex 2, the sub-processor list, and summaries of our security reviews.

If that isn't enough, the customer (or an independent auditor bound by confidentiality) may audit us once a year, with at least 30 days' notice, during working hours and without access to other customers' data. Each side bears its own costs, unless the audit finds a material breach of this DPA by us. Audits of sub-processors rely on their own certifications and reports (e.g. ISO 27001, SOC 2).

9. Liability, precedence, law and term

  • Liability: XPI CRM is currently offered free of charge. To the fullest extent permitted by law, we accept no liability towards the customer for any loss or damage arising from the free service or this DPA. This does not exclude liability that cannot be excluded by law, in particular for intent or gross negligence, towards data subjects under GDPR Article 82, or for fines imposed directly on us. Paid plans, if introduced, will set their own limits in the Terms.
  • Precedence: if this DPA and the Terms conflict on personal data, this DPA applies.
  • Governing law and courts: Romanian law; the courts of Bucharest, unless the GDPR requires otherwise.
  • Term: this DPA lasts as long as we process customer data for the customer, including the backup periods in section 7.
  • Changes: we may update this DPA to reflect changes in law or in the service, with 30 days' notice, never lowering the level of protection.

Annex 1 – Description of the processing

ItemDetails
PurposeProviding XPI CRM, a customer success CRM: storing and organising the customer's client relationships, automations, reports, health scores, imports, API and webhooks, and support.
NatureStorage, organisation, retrieval, calculation (health scores, reports), transmission (API, webhooks to addresses the customer sets), deletion.
Data subjectsThe customer's own users; contacts at the customer's clients; other people the customer records (e.g. survey respondents).
Categories of dataNames, business email addresses, phone numbers, job titles; conversation and meeting notes; survey answers and scores; invoice details; product usage records (which may include user IDs); uploaded files; sign-in data and change history for the customer's users.
Special category dataNot intended. Customers should not store health, biometric or similar data in XPI CRM.
DurationFor the term of the service, plus the backup periods in section 7.
LocationEU (Ireland), see section 4.

Annex 2 – Security measures

AreaMeasures in place
Separation between customersEach workspace's data is isolated by row-level security enforced in the database itself, tested automatically (cross-workspace reads, writes and file downloads are refused).
Access controlRoles (admin, standard, view-only) enforced in the database; admin-only setup, API keys and webhooks; sign-in with email and password, Google or Microsoft; email confirmation.
API keysShown once, stored only as a SHA-256 fingerprint, limited to chosen objects and read-only or read & write, revocable, rate-limited (600 per minute, 10,000 per hour per key).
EncryptionHTTPS (TLS) for all traffic with HSTS; data encrypted at rest by the hosting provider; weekly backups encrypted before upload with a key only we hold.
Abuse protectionBot checks (Cloudflare Turnstile) on sign-up, password reset, contact form and repeated failed sign-ins; rate limits on sign-in, sign-up, password reset and forms.
WebhooksHMAC-SHA256 signed; private and internal addresses refused when saved and before every send; redirects not followed.
Audit trailEvery create, change and delete is recorded by the database with who, when and the source (app, import, API, automation).
SecretsServer keys stored only as server-side secrets, never in the browser or the code repository; the build fails if one appears.
Browser securityContent security policy, HSTS, no embedding in other websites, no content-type guessing, restricted browser permissions.
MonitoringError monitoring (Sentry, EU region) with personal data removed before sending; uptime monitoring every 5 minutes; a daily check alerts us if scheduled jobs or backups fail.
BackupsDaily database backups kept 14 days; encrypted weekly full backups (database and uploaded files) kept up to 12 months in the EU; restores tested.
PeopleAccess to production is limited to the company's administrators, who are bound by confidentiality; a security review is carried out before each major release.

Annex 3 – Sub-processors

Sub-processorWhat it doesCustomer data involvedWhereTransfer safeguard
Lovable Labs Incorporated (with Lovable Labs AB, Sweden)App platform and hosting operator (Lovable Cloud)All customer dataEU (Ireland)Lovable Data Processing Agreement; EU–US Data Privacy Framework / Standard Contractual Clauses
Supabase Inc. (via Lovable Cloud)Database, sign-in and file storageAll customer dataEU – Ireland (AWS eu-west-1)Data stored in the EU; Standard Contractual Clauses for any support access
Amazon Web Services EMEA SARLUnderlying servers for the databaseAll customer data (encrypted at rest)EU – IrelandWithin the EU
Cloudflare Inc.Delivers the app worldwide; bot checks (Turnstile); encrypted backup storage (R2)Request data passing through, IP addresses; encrypted backupsGlobal network; R2 backups in the EU jurisdictionEU–US Data Privacy Framework / Standard Contractual Clauses
Mailgun Technologies, Inc. (via Lovable Emails)Sends account and notification emails from notify.xpicrm.com (transactional email, email domain management)Users' names and email addresses, email contentUSLovable's DPA (EU–US Data Privacy Framework / Standard Contractual Clauses)
Functional Software Inc. (Sentry)Error monitoring, with personal data removed before sendingNone intended (scrubbed)EU (Germany)Data stored in the EU
Google LLC / MicrosoftOptional sign-in (only if a user chooses it)Name, email address, profile picture of that userUS / globalEU–US Data Privacy Framework

Not sub-processors, because they never receive customer data: GitHub (stores the app's code) and the uptime monitoring service (checks only that the site responds).