Data Processing Agreement
Last updated: July 2026
This document is a draft prepared for Xperio3D and requires final review by qualified legal counsel before publication. It is provided for informational purposes and does not constitute legal advice.
1. Parties and Scope
This Data Processing Agreement ("DPA") forms part of the Xperio3D Terms of Service and applies to the processing of personal data by Xperio3D on behalf of business customers ("Customer" / "Controller"). Xperio3D acts as a Processor. This DPA reflects GDPR (EU 2016/679) and Thailand PDPA requirements.
2. Categories of Personal Data
- Visitor session and engagement data (anonymous session ids, sweep visits, interactions).
- Contact and lead information submitted through tour forms.
- Customer account data (name, email, role).
- Payment metadata (processed by Stripe; card data never stored by Xperio3D).
3. Subprocessors
Xperio3D engages the following subprocessors:
- Matterport Inc. — independent external platform hosting and rendering 3D tours. Matterport is an independent controller of its own processing; Xperio3D does not control Matterport's data practices.
- Stripe — payment processing.
- ElevenLabs — AI voice generation.
- Cloud hosting provider (Base44 / managed infrastructure) — application and database hosting.
- Analytics providers — Google Analytics, Meta Pixel, Google Tag Manager (when enabled by a brand).
- Email provider (Gmail) — transactional and support email delivery.
4. International Data Transfers
Personal data may be transferred to and maintained on servers located outside your country, including the United States and Thailand. Appropriate safeguards (Standard Contractual Clauses where applicable) are in place.
5. Data Retention and Deletion
Customer personal data is retained for the duration of the subscription plus any legally required period. On termination, customers may request a data export, after which data is deleted or anonymized per the Data Deletion Policy. See /data-deletion for the full workflow.
6. Customer Responsibilities
- Ensure lawful collection of visitor data and present appropriate consent notices.
- Provide privacy disclosures to end visitors where required.
- Respond to data-subject requests where Xperio3D does not have direct access.
7. Security Measures
Encryption in transit (TLS) and at rest, role-based access control, tenant isolation via row-level security, audit logging, and rate limiting on public ingestion endpoints.
8. Contact
For DPA inquiries: legal@xperio3d.com