← Back to almxpp.com

Data Processing Agreement

Article 28 GDPR · Last updated: 16 August 2026 · Public reference version

This page is the reference text, published so that you can review it before signing anything. A countersignable version personalised to your organisation — naming your entity, your data residency region and the sub-processors actually engaged for your account — can be generated from your dashboard, or requested at alim@almxpp.com.

1. Roles of the parties

Where you use ALM XPP MCP to process data relating to your own personnel, customers or projects (for example by uploading a custom model or connecting an Azure DevOps repository), you are the controller and we are the processor. We process that data only on your documented instructions, which comprise these terms and your use of the service's features.

For the account and metering data described in our Privacy Policy, we act as controller in our own right.

2. Subject matter, duration, nature and purpose

Subject matterIndexing, search, analysis and code generation over material you submit
DurationFor as long as your account is active, plus the deletion period in clause 8
NatureStorage, indexing, semantic retrieval, static analysis, generation of derived artefacts
PurposeProviding the contracted service to you

3. Categories of data and data subjects

The service is designed for source code and technical metadata, not for personal data. Personal data nevertheless reaches it incidentally, principally as:

  • identifiers of your developers embedded in source code, commits, work items and pull requests (names, corporate email addresses, account identifiers);
  • any personal data present in code comments, test fixtures or documents you choose to upload;
  • the first argument of tool calls, captured for metering as described in the Privacy Policy.

Data subjects are therefore primarily your employees and contractors. You must not upload special-category data (Article 9 GDPR) or production data containing personal data of your own customers; the service is not designed for it and we do not warrant it as suitable.

4. Our obligations

  • Process personal data only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we inform you before processing, unless the law forbids it.
  • Ensure that persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures in clause 6.
  • Respect the conditions in clause 5 for engaging sub-processors.
  • Assist you, by appropriate measures, in responding to data subject requests.
  • Assist you with security, breach notification, impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.
  • Delete or return the data at the end of the service, per clause 8.
  • Make available the information necessary to demonstrate compliance, and allow audits per clause 9.

5. Sub-processors

You give general authorisation to the sub-processors listed below. We will inform you of any intended addition or replacement at least 30 days in advance, during which you may object on reasonable data protection grounds; if the objection cannot be resolved, you may terminate the affected service without penalty.

Sub-processorPurposeLocationTransfer mechanism
Microsoft AzureHosting, storage, container registryWest Europe (EU)No transfer
BrevoTransactional emailEuropean UnionNo transfer
GroqFallback language model, optional AgentFlow feature onlyUnited StatesStandard Contractual Clauses

AgentFlow can be disabled for your account, in which case no data leaves the European Union.

6. Technical and organisational measures

We state these as implemented, not as aspirations:

  • In transit: TLS 1.2 or higher enforced, HSTS, strict Content Security Policy.
  • At rest: platform-level encryption; the account store additionally encrypted with AES-GCM.
  • Access control: role-based, deny-by-default; access to another organisation's data requires an explicit grant; credentials stored as salted hashes; API tokens stored as hashes only.
  • Traceability: append-only audit log of administrative and security-relevant actions, retained 90 days.
  • Segregation: each customer's uploaded models are indexed in a separate namespace and are not returned to other customers.
  • Resilience: backups of persistent state, with a documented and exercised restore procedure; the last measured recovery time was under ten minutes.
  • Secure development: automated test suite executed on every change; dependency vulnerability scanning in the build pipeline.

We do not currently hold ISO 27001 or SOC 2 certification, and we do not represent otherwise.

7. Personal data breach

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting data processed on your behalf, giving the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken. This allows you to meet your own 72-hour obligation to your supervisory authority.

8. Deletion and return

You may delete uploaded models and documents at any time from the interface; deletion removes both the source and its index entries. On termination, data processed on your behalf is deleted within 30 days, except where retention is required by law. Backups are overwritten in the normal rotation. A copy of your data can be exported before termination on request.

9. Audit

We will provide, on reasonable written request and no more than once a year, the documentation needed to demonstrate compliance with this agreement. Where that is insufficient for your regulator, an on-site or remote audit may be arranged with reasonable notice, during business hours, subject to confidentiality and without disrupting the service or exposing other customers' data.

10. Order of precedence

This agreement supplements the Terms of Service. In the event of a conflict concerning the processing of personal data, this agreement prevails.

ALM XPP MCP · Privacy Policy · Terms of Service · Security & Compliance · alim@almxpp.com