Skip to content
Compliance

How we meet our obligations

Where we stand on data privacy regulations, industry standards, and financial compliance requirements.

GDPR compliance

  • Right to access (data export via support request)
  • Right to deletion (automated deletion with cascading)
  • Right to portability (JSON export format)
  • Cookie consent management (granular preferences)
  • Data processing agreements (DPAs) available on request

CCPA & state privacy laws

  • Sensitive data opt-out rights
  • Data portability
  • Non-discrimination for exercising rights

Industry standards

  • SOC 2-aligned controls (we follow SOC 2-type controls; not certified)
  • NIST Cybersecurity Framework-aligned practices
  • CIS Controls-aligned practices
  • ISO 27001-aligned controls (roadmap for certification)
  • PCI DSS-aligned practices (card data via Stripe; we do not store card data)
  • NACHA compliance for ACH payments
  • 10DLC SMS compliance (opt-out via STOP/HELP)

Financial compliance

  • Card data handled exclusively by Stripe (a PCI DSS Level 1 certified provider)
  • ACH authorization with NACHA-compliant consent
  • Bank account verification (Plaid + microdeposits)
  • Audit trails for all financial transactions

Third-party data processors

We use the following processors for operation. All act as Data Processors per GDPR.

ProviderPurpose
VercelApplication hosting
NeonPostgreSQL database hosting
StripePayment processing
PlaidBank verification
PostmarkTransactional email
TelnyxSMS notifications
AnthropicAI document drafting and assistant
OpenAIAI document processing
PineconeDocument search embeddings
Backblaze B2Document storage
StatusPageStatus monitoring

Legal documentation

Compliance FAQs

We support GDPR data-subject rights: access (data export), deletion (automated, cascading), portability (JSON export), and granular cookie consent. Data processing agreements (DPAs) are available on request. Our data is stored in the United States, so EU customers should contact us at support@xclause.com to discuss data-transfer terms before onboarding.

Email support@xclause.com (or open a ticket from your dashboard) to request a data export. Exports include three scopes: user only, user + company, or user + company + clients. All data is exported in JSON format including contracts, signatures, comments, and settings (excluding sensitive credentials).

Email support@xclause.com (or open a ticket from your dashboard) to request deletion. We offer three deletion levels matching our export scopes. Deletion is cascading and transaction-safe, so your data is removed completely and referential integrity stays intact.

All data is stored in the United States on secure servers. We use PostgreSQL for structured data and Backblaze B2 (S3-compatible) for document storage. EU customers should contact us to discuss data-transfer terms; further data-location detail is available on request for compliance purposes.

We only share data with service providers necessary for operation: Vercel (hosting), Neon (database hosting), Stripe (payment processing), Plaid (bank verification), Postmark (transactional email), Telnyx (SMS), Anthropic and OpenAI (AI document processing), Pinecone (document search), Backblaze B2 (storage), and StatusPage (monitoring). All processors act as Data Processors per GDPR. We never share data with third parties for marketing.

We are not SOC 2 certified. We follow SOC 2-aligned controls including encryption, access controls, audit logging, and incident response.

Need a DPA or running a security review?

Email support@xclause.com to request a data processing agreement or send us your security questionnaire. We'll route it to the right people.

Start running your contracts the modern way.

Build, send, e-sign, and manage every MSA and SOW in one platform. Start today, no demo required.

Free trialCancel anytimeNo long-term contract