Xano TRUST CENTER
Xano
Loading…

Certifications

Attestation

GDPR

Overview

GDPR is the European Union’s core data protection law governing how personal data is collected, used, stored, shared, and otherwise processed. For Xano as a SaaS platform and data processor, GDPR alignment means maintaining policies, processes, and technical safeguards that support lawful processing, data security, processor obligations, and the responsible handling of personal data. For our customers, as data controllers, this helps demonstrate that the processor they rely on is structured to support key GDPR requirements, including privacy governance, data protection expectations, and the secure processing of EU-related personal data in support of their own compliance responsibilities.

How Xano Aligns With Criteria

Xano maintains a range of contractual documents, policies, procedures, and operational controls to support its alignment and overall security posture. The examples below highlight key elements of our program in relation to GDPR requirements, and do not represent a complete list:

  • Data Processing Addendum (DPA) - available to all paid plans (excluding Free plan); please request a DPA by emailing us at security@xano.com
    • Standard Contractual Clauses (SCCs) are included in Xano’s DPA
  • Record of Processing Activities (RoPA)
  • Subprocessor list - available here (https://docs.xano.com/legal/xano-subprocessors)
  • Privacy Notice - available here (https://docs.xano.com/legal/privacy-notice)
  • Information Security Policy
  • Privacy & Data Protection Policy
  • Data Deletion Policy & Procedure
  • Access Control Policy
  • Incident Response Procedure
  • Data Subject Access, Correction, & Erasure Request Procedure
  • Disaster Recovery Plan
  • Internal Audit Program
  • InfoSec Management Review Meetings

Files

100%