Compliance
How we meet our obligations
Where we stand on data privacy regulations, industry standards, and financial compliance requirements.
GDPR compliance
- Right to access (data export via support request)
- Right to deletion (automated deletion with cascading)
- Right to portability (JSON export format)
- Cookie consent management (granular preferences)
- Data processing agreements (DPAs) available on request
CCPA & state privacy laws
- Sensitive data opt-out rights
- Data portability
- Non-discrimination for exercising rights
Industry standards
- SOC 2–aligned controls (we follow SOC 2–type controls; not certified)
- NIST Cybersecurity Framework–aligned practices
- CIS Controls–aligned practices
- ISO 27001–aligned controls (roadmap for certification)
- PCI DSS–aligned practices (card data via Stripe; we do not store card data)
- NACHA compliance for ACH payments
- 10DLC SMS compliance (opt-out via STOP/HELP)
Financial compliance
- Card data handled exclusively by Stripe (a PCI DSS Level 1 certified provider)
- ACH authorization with NACHA-compliant consent
- Bank account verification (Plaid + microdeposits)
- Audit trails for all financial transactions
Third-party data processors
We use the following processors for operation. All act as Data Processors per GDPR.
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Neon | PostgreSQL database hosting |
| Stripe | Payment processing |
| Plaid | Bank verification |
| Postmark | Transactional email |
| Telnyx | SMS notifications |
| Anthropic | AI document drafting and assistant |
| OpenAI | AI document processing |
| Pinecone | Document search embeddings |
| Backblaze B2 | Document storage |
| StatusPage | Status monitoring |
Legal documentation
- Terms of Service (includes arbitration clause)
- Privacy Policy
- Cookie Policy (covered in Privacy Policy)
Compliance FAQs
Need a DPA or running a security review?
Email support@xclause.com to request a data processing agreement or send us your security questionnaire — we'll route it to the right people.
Start running your contracts the modern way.
Build, send, e-sign, and manage every MSA and SOW in one platform — start today, no demo required.
Free trial • Cancel anytime • No long-term contract