Data processing addendum
Effective 25 June 2026 · version 1.0 (draft)
When you use the regulation10.com platform, you (the customer) are the controller of the personal data you bring into scope and Exec X AI Ltd (DIFC commercial licence 10474) acts as your processor. This addendum summarises the written processing terms we enter into under Article 28 of the GDPR. It forms part of the master subscription agreement; the executed addendum prevails over this summary.
1. Roles and scope
We process customer personal data only to provide the platform and only on your documented instructions (the agreement, the product configuration, and your in-app actions), unless a law we are subject to requires otherwise, in which case we tell you first unless legally prohibited.
2. Our processor obligations (Article 28 of the GDPR)
- process only on documented instructions, and only for the agreed purposes;
- ensure personnel are bound by confidentiality;
- apply the technical and organisational security measures required by Article 32 of the GDPR;
- engage sub-processors only under written terms no less protective than this addendum, and maintain the current list on our sub-processors page, with prior notice of changes and a right to object;
- assist you with data-subject requests and with your accountability duties;
- notify you of a personal-data breach without undue delay and support your notification duties to your supervisory authority and to affected data subjects under Articles 33 and 34 of the GDPR;
- on termination, delete or return customer personal data, save where retention is legally required. Immutable WORM audit records are retained for their lawful period.
3. Residency and international transfers (Chapter V of the GDPR, Articles 44 to 49)
Tenant data is resident in the Azure Sweden Central region, inside the EU data boundary. AI inference for the platform runs in the same region.
Any transfer to a jurisdiction that is not the subject of an adequacy decision relies on the European Commission standard contractual clauses under Article 46 of the GDPR, supported by a transfer impact assessment. The mechanism relied on for each provider is listed on the sub-processors page.
The at-rest commitment above is a residency statement about stored data. Where inference runs is stated separately in the same clause and on our trust and evidence page, so the two are never conflated.
4. Audit and assistance
We make available the information needed to demonstrate compliance with Article 28 of the GDPR and allow for and contribute to audits, including through the platform's read-only auditor evidence room and signed evidence packs.
5. Requesting the executed addendum
To execute the full addendum, including the applicable standard contractual clause modules, for your organisation, email privacy@regulation10.com.