Data Processing Addendum
A public summary of XMemo data-processing roles, controls, and DSAR support for enterprise evaluation.
- This page is an evaluation summary, not an executed Data Processing Addendum.
- XMemo can act as a processor for customer-provided memory data under an enterprise agreement.
- Customer administrators remain responsible for lawful instructions, retention policy, and user notices.
- Operators provide export/delete support through audited workflows and redacted evidence.
Current status
This page is a public summary provided for enterprise evaluation. It is not an executed Data Processing Addendum and does not by itself create processor obligations.
- The hosted service is currently free of charge, and no Business or paid plan is offered.
- DPA, Business, seat, and order-form obligations apply only under a separate signed agreement, as stated in the Terms of Service.
- To put a DPA in place, contact privacy@xmemo.dev.
Processing scope
Processing covers hosted memory storage, recall, reflection, account/session management, tenant administration, support diagnostics, and operational telemetry required to run and secure the service.
- Public discovery and installer metadata are secret-free.
- Data-plane writes require scoped credentials, and application authorization evaluates owner/team/tenant context. Database RLS requires deployment-specific target evidence.
- Control-plane administration requires admin key, console session, or user session with tenant RBAC permission.
Security measures
The enterprise posture requires HTTPS public URLs, secure cookies, token hash peppering, disabled plaintext fallback, production rate limits, private database/Redis networking, and production readiness gates.
- Production PostgreSQL must use certificate-validating TLS modes.
- MCP network access should use DB-backed bearer tokens instead of static production tokens.
- Support bundles and DSAR proofs exclude secrets and raw customer memory content.
Customer assistance
Operators assist with export, deletion, incident response, and audit evidence through documented runbooks. Completion evidence uses request IDs, counts, hashes, timestamps, and redacted references.
Aligned with DSAR export/delete workflows, application-authorization tests, deployment-specific RLS verification requirements, and operations runbooks.