Data Processing Addendum (DPA)
Last updated July 29, 2026
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Master Subscription Agreement between your organization and XIMA USA LLC (“XIMA”). It sets out the terms under which XIMA processes personal data contained in Customer Data to provide PostalView. It reflects and elaborates Section 10 of that Agreement; in case of conflict on data protection, this DPA controls.
Read together with our Privacy Policy and our list of subprocessors.
1. Roles
As between the parties, your organization is the controller / business and XIMA is the processor / service provider with respect to Customer Data. XIMA processes Customer Data only to provide the Service, on your documented instructions, and does not “sell” or “share” it (as those terms are defined by applicable privacy laws) or use it for its own purposes.
2. Nature and Purpose of Processing
XIMA processes Customer Data to operate the mail, mailbox, and point-of-sale features of the Service — including logging packages and mail, managing mailboxes and subscriptions, notifying recipients, taking payments, and storing identity documents where you upload them. The data subjects are your staff and your end customers; the categories include contact and account details, operational records, financial metadata, and — where you collect them — government-identity documents.
3. Security Measures
XIMA maintains commercially reasonable technical and organizational measures, including:
- strict tenant isolation between organizations;
- encryption in transit;
- a private storage bucket for identity documents, accessed only through short-lived signed URLs — document bytes never pass through the application API;
- role-based access controls; and
- append-only audit logging of significant actions.
4. Subprocessors
XIMA may engage the subprocessors listed at /legal/subprocessors and remains responsible for their performance. XIMA will give notice of new subprocessors where required before they begin processing Customer Data.
5. Your Responsibilities
You warrant that you have a lawful basis and all necessary consents and notices to collect and process Customer Data — including your end customers’ identity documents — and to have XIMA process it on your behalf. Where your end customers are in Mexico, this includes providing them a compliant aviso de privacidad under the LFPDPPP and honoring their ARCO rights; XIMA acts only as your processor for that data.
6. International Transfers
XIMA and its subprocessors may process Customer Data in the United States and other countries, as indicated on the subprocessors page. Where required, the parties rely on appropriate safeguards for cross-border transfers.
7. Security Incidents
Each party will reasonably cooperate on security-incident notifications required by law. XIMA will notify you without undue delay after becoming aware of a personal-data breach affecting your Customer Data and provide the information you reasonably need to meet your own notification obligations.
8. Return and Deletion
On termination, and on your request during the term, XIMA will make Customer Data available for export and will delete or return it in accordance with the Agreement, subject to retention required by law and to append-only integrity records that cannot be edited individually.
9. Contact and Signed Copy
A countersigned copy of this DPA is available on request. To request one, or to raise a data-protection question, contact XIMA USA LLC at legal@postalview.com.
This document is provided for general information and does not constitute legal advice.