1. Background

This Data Processing Agreement ("DPA") supplements the Xinference Terms of Service, Order Form or other agreement between Xinference Holdings Pte. Ltd. ("Xinference") and the customer identified in the applicable agreement ("Customer") (together, the "Agreement"). This DPA applies where Xinference processes Personal Data on Customer's behalf in connection with Xinference. If this DPA conflicts with the Agreement regarding the processing of Personal Data, this DPA controls for that processing.

2. Definitions

"Applicable Data Protection Laws" means all data-protection and privacy laws applicable to the processing of Personal Data under this DPA, including, where applicable, the Singapore Personal Data Protection Act 2012 ("PDPA"), the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the Australian Privacy Act 1988 (Cth), and other applicable privacy or data-protection laws.

"Customer Content" has the meaning given in the Agreement and includes Personal Data to the extent Customer or its users submit, generate or otherwise make that Personal Data available through Xinference.

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" have the meanings given by Applicable Data Protection Laws. Where the PDPA applies, references to a Processor include Xinference acting as a data intermediary to the extent it processes Personal Data on behalf of and for the purposes of Customer.

"Subprocessor" means a third party engaged by Xinference to process Customer Personal Data on Xinference's behalf in order to provide the applicable Xinference-managed service or Model API.

3. Roles and documented instructions

As between the parties, Customer is the Controller or business for Customer Personal Data and Xinference is the Processor, service provider or data intermediary to the extent Xinference processes that Personal Data on Customer's behalf. If Customer processes Personal Data on behalf of another controller, Customer represents that it has authority to appoint Xinference and give the instructions contemplated by the Agreement and this DPA.

Xinference will process Customer Personal Data only on Customer's documented instructions as set out in the Agreement, this DPA, Customer's configuration and use of Xinference, and other written instructions accepted by Xinference, unless processing is required by applicable law. Where legally permitted, Xinference will inform Customer before processing required by law that is outside Customer's instructions.

Customer is responsible for ensuring that its instructions, Customer Content and use of Xinference comply with Applicable Data Protection Laws, including providing required notices and obtaining any required consents, permissions or other lawful bases.

Where Xinference processes account, commercial, website, security or other Personal Data as an independent Controller rather than on Customer's behalf, that processing is governed by the Xinference Privacy Policy and not this DPA.

4. Scope and purpose of processing

The subject matter, duration, nature, purpose and categories of processing are described in Annex 1.

Xinference does not use Customer Content, Inputs or Outputs to train or fine-tune foundation models unless Customer expressly agrees in writing. Xinference may use service and Usage Data, feedback, and aggregated or de-identified information to secure, operate and improve Xinference. If Customer selects or configures a third-party model provider, that provider's handling of data is governed by Customer's configuration and the provider's applicable terms and privacy policy.

5. Confidentiality

Xinference will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as necessary to perform their responsibilities.

6. Security measures

Xinference will maintain reasonable administrative, technical and organisational measures designed to protect Customer Personal Data against unauthorised access, loss, misuse, alteration or disclosure, taking into account the nature of the processing, the deployment model and the risks involved. The categories of measures are summarised in Annex 2. Specific security commitments, where applicable, may also be stated in an Order Form or other security documentation expressly incorporated into the Agreement.

For a Self-Hosted Deployment, Customer is responsible for the infrastructure, network, identity, access controls, credentials, backups, models, third-party services and other configuration choices under Customer's control. Xinference remains responsible for protecting Customer Personal Data that it actually receives and processes on Customer's behalf, for example through agreed support or service operations.

7. Subprocessors

Customer gives Xinference general authorisation to engage Subprocessors where reasonably necessary to provide a Xinference-managed service or Model API. Xinference will require each Subprocessor that processes Customer Personal Data on its behalf to be bound by data-protection and confidentiality obligations appropriate to the processing.

Xinference will inform Customer before adding or replacing a Subprocessor that will process Customer Personal Data, giving Customer a reasonable opportunity to object on legitimate data-protection grounds. If the parties cannot reasonably resolve an objection, they will work in good faith on an appropriate alternative, which may include modification or termination of the affected service where no reasonable alternative is available.

The applicable current Subprocessor list may be provided through Xinference's contractual, trust or support channels. For Customer Content that remains solely within a Self-Hosted Deployment, Xinference does not appoint a Subprocessor to process that Customer Content. A cloud, infrastructure or model provider selected and contracted directly by Customer is governed by Customer's relationship with that provider rather than by Xinference's Subprocessor appointment.

8. Assistance with Data Subject rights

Taking into account the nature of the processing and the information available to Xinference, Xinference will provide reasonable assistance to Customer in responding to requests by Data Subjects to exercise rights under Applicable Data Protection Laws. If Xinference receives a request relating primarily to Customer Personal Data processed on Customer's behalf, Xinference may direct the requester to Customer unless applicable law requires Xinference to respond directly.

9. Personal Data Breach notification

Xinference will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by Xinference on Customer's behalf. The notice will include information reasonably available to Xinference that Customer may need to assess the breach and meet its own legal obligations, and additional information may be provided in phases as it becomes available.

Where the PDPA applies and Xinference acts as a data intermediary, Xinference will notify Customer without undue delay from the time it has credible grounds to believe that a relevant data breach has occurred. Customer remains responsible for determining whether notification to the Personal Data Protection Commission or affected individuals is required, unless the parties agree otherwise or applicable law requires a different allocation.

10. Data protection impact assessments and regulatory assistance

Taking into account the nature of the processing and information available to Xinference, Xinference will provide reasonable information and assistance requested by Customer for data-protection impact assessments, prior consultations or similar obligations under Applicable Data Protection Laws.

11. International data transfers

11.1 Self-Hosted Deployments

For a Self-Hosted Deployment, Customer selects the infrastructure and region in which Customer Content is processed. Customer Personal Data that remains solely within that environment is not transferred by Xinference. If Customer sends Personal Data to Xinference for support, licensing, security, updates or other agreed service operations, that Personal Data may be processed in locations used by Xinference and its service providers in accordance with this DPA and the Xinference Privacy Policy.

11.2 Xinference-managed deployments and Model API

For a Xinference-managed deployment or Model API, Customer Personal Data may be processed in the selected deployment region and in other countries where Xinference or its applicable Subprocessors operate, depending on the service, support arrangements and providers used.

Where Applicable Data Protection Laws require safeguards for an international transfer, the parties will use an appropriate legally recognised transfer mechanism. For transfers subject to the Singapore PDPA, Xinference will take steps intended to ensure that transferred Personal Data receives a standard of protection comparable to that required under the PDPA. Where EU or UK data-protection law requires a transfer mechanism, the parties will apply the applicable standard contractual clauses, UK transfer mechanism or other legally recognised safeguard as required for the relevant transfer.

12. Audit and compliance information

On reasonable prior written notice, Customer may request information reasonably necessary to demonstrate Xinference's compliance with this DPA. Xinference may satisfy such requests through relevant policies, security or trust materials, independent reports where available, written questionnaire responses or other appropriate evidence.

Unless required by a regulator, Applicable Data Protection Laws or following a material Personal Data Breach affecting Customer Personal Data, Customer will not request an audit more than once in any twelve-month period. The parties will first seek to address the request through remote documentation and reasonable written responses before considering any on-site review. Any audit must protect the confidentiality and security of other customers and Xinference systems and must not unreasonably disrupt operations.

13. Return and deletion of Personal Data

During the term, Customer is responsible for exporting Customer Content using available product functionality or other agreed methods. On termination or expiry of the Agreement, Xinference will return, delete or de-identify Customer Personal Data under its control in accordance with the Agreement, Customer's documented instructions and Applicable Data Protection Laws, subject to information that Xinference must retain for legal, security, fraud-prevention, dispute-resolution or similar legitimate purposes.

Data may remain for a limited period in backups or restricted records before being overwritten or deleted in accordance with applicable retention practices. For a Self-Hosted Deployment, Customer is responsible for deletion of Customer Content that remains solely in Customer's environment.

14. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent such limitations or exclusions are prohibited by Applicable Data Protection Laws.

15. Term

This DPA takes effect when the Agreement becomes effective and continues for as long as Xinference processes Customer Personal Data on Customer's behalf. Provisions that by their nature must continue after termination, including confidentiality, return or deletion and liability provisions, will survive for the period necessary to give them effect.

16. Contact

Questions about this DPA may be sent to legal@xinference.co.

Annex 1 — Details of Processing

Subject matter

Provision, operation, security and support of the Xinference model inference and serving platform and related services ordered by Customer.

Duration

For the term of the Agreement and any limited period after termination reasonably necessary to return, delete or de-identify Customer Personal Data or comply with applicable legal obligations.

Deployment model

The processing depends on the deployment identified in the Agreement or Order Form, which may include a Xinference-managed deployment, Model API, Marketplace deployment or Self-Hosted Deployment.

Nature and purpose of processing

Processing may include receiving, hosting, storing, organising, retrieving, transmitting, serving, displaying, securing, troubleshooting, supporting and deleting Customer Personal Data as necessary to provide Xinference in accordance with Customer's instructions and the Agreement.

Categories of Personal Data

Customer Personal Data may include account and business-contact details of Customer's authorised users; identifiers and authentication-related information; support communications; and any Personal Data Customer chooses to include in prompts, instructions, documents, datasets, embeddings, model inputs or outputs, model configurations, retrieval results or other Customer Content. Depending on the deployment and support context, technical logs may also contain user identifiers, IP addresses, authentication events or other Personal Data.

Categories of Data Subjects

Customer's employees, contractors, authorised users, business contacts, end users, customers or other individuals whose Personal Data Customer chooses to include in Customer Content or whose information is otherwise processed through Xinference on Customer's behalf.

Special or sensitive categories

Customer is responsible for determining whether it is permitted to submit special-category, sensitive or regulated Personal Data to Xinference and for applying any additional safeguards required by Applicable Data Protection Laws or the Agreement.

Annex 2 — Categories of Technical and Organisational Measures

Xinference's measures are selected according to the deployment and risk and may include, as appropriate to the parts of the service Xinference operates:

  • identity, authentication and access controls;
  • encryption in transit and other transport-security measures;
  • logging, monitoring and security-event controls;
  • backup, recovery and resilience measures for systems operated by Xinference;
  • confidentiality and access restrictions for personnel;
  • vulnerability, patch and change-management practices appropriate to the relevant systems;
  • incident detection, response and escalation procedures;
  • logical separation and access boundaries appropriate to the deployment model;
  • vendor and Subprocessor due diligence and contractual controls; and
  • retention and deletion practices designed to limit Personal Data to what is reasonably necessary.

For Self-Hosted Deployments, Customer is responsible for security measures within the infrastructure and configuration it controls. Specific measures or service commitments apply only where expressly agreed in the Agreement or incorporated security documentation.

Annex 3 — Subprocessors and customer-selected providers

For Xinference-managed deployments and Model API, the applicable current Subprocessor list is maintained separately and may be provided through Xinference's contractual, trust or support channels. That list should identify the provider, purpose and relevant processing-location information for the applicable service.

For Self-Hosted Deployments, Customer Content that remains solely in Customer's environment is not processed by Xinference Subprocessors. Customer-selected cloud, infrastructure or model providers used through Customer's own account, credentials or contractual relationship are governed by Customer's relationship with those providers and are not appointed by Xinference merely because Customer configures Xinference to use them.

Public model repositories may be used to obtain model software or weights. Customer Content is not sent to such a repository solely because a model is downloaded from it.