Support & Downloads

Transforme los procesos de aprendizaje y construya equipos más capacitados para alcanzar el éxito empresarial

Contact Info

DATA PROCESSING AGREEMENT (DPA)

Data Processing Agreement

Version: 2.0
Last update: February 18, 2026
Data Processor: EXO ESEPLUS S.L. (alilo) – CIF B09870583
Headquarters: Calle Núñez de Balboa 120, Madrid, Spain
DPO Contact: privacidad@alilo.app


INTRODUCTION AND PURPOSE

This Data Processing Agreement (“DPA”) forms an integral part of the service contract entered into between alilo (EXO ESEPLUS S.L.) and the Customer (hereinafter “the Controller”), and governs the processing of personal data that alilo performs on behalf of the Customer in the context of the provision of its enterprise learning platform services.

This DPA complies with the requirements of Regulation (EU) 2016/679 (GDPR/GDPR), Article 28 in particular, and is compatible with the data protection regulations applicable in El Salvador, Mexico, Colombia, the United States (CCPA/CPRA) and other Latin American countries.

Acceptance of the commercial contract with alilo implies full acceptance of this DPA.


PART 1 – DEFINITIONS

For the purposes of this DPA, the following definitions shall apply:

  • “Personal Data”: Any information about an identified or identifiable natural person.
  • “Processing”: any operation performed on personal data (collection, recording, storage, consultation, use, communication, deletion, etc.).
  • “Data Controller / Controller”: The Client, who determines the purposes and means of the processing of personal data.
  • “Processor: alilo (EXO ESEPLUS S.L.), who processes personal data on behalf of the Controller.
  • “Sub-processor / Sub-processor”: Third-party provider contracted by alilo for the partial provision of services.
  • “Stakeholder Data”: personal data of employees, users or third parties processed within the framework of the services.
  • “Security Breach”: A breach of security that results in the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data.
  • “SCCs”: Standard Contractual Clauses approved by the European Commission for international data transfers.

PART 2 – ROLES AND RESPONSIBILITIES

2.1 The Client as Data Controller

The Client determines the purposes and means of the processing of personal data of its employees and users. The Client is responsible for:

  • To have an adequate legal basis for the processing and transfer of data to alilo.
  • To inform the interested parties about the processing of their data.
  • Respond to the rights of data subjects (access, rectification, deletion, etc.).
  • Ensure that personal data transferred to alilo is accurate and relevant.
  • Comply with the data protection regulations applicable in your jurisdiction.
2.2 alilo as Data Processor

alilo processes personal data only on the documented instruction of the Customer, in accordance with these T&Cs and the DPA, and not for its own purposes. alilo is responsible for:

  • To process the data in accordance with the Client’s instructions.
  • To guarantee the confidentiality and security of the data.
  • Notify the Customer without undue delay of any security breach affecting its data.
  • To facilitate the exercise of the rights of the interested parties.
  • Delete or return the data at the end of the contract.

PART 3 – TREATMENT DESCRIPTION

3.1 Purpose of treatment

The processing is carried out exclusively to provide the following services to the Client:

  • User account management (registration, cancellation, authentication).
  • Training delivery and learning follow-up (traceability).
  • Processing of documents uploaded by the Client for content generation through AI (LXD AI).
  • alilobot conversational agent responses based on the Client’s documents.
  • Analysis of the use of the Platform to improve the service.
  • Transactional communications (notifications, password recovery).
3.2 Categories of data processed
CategoryDataLegal Basis
Identification dataFirst name, last name, email, Employee IDContract execution
Training activity dataCompleted courses, scores, access time, badges, etc.Contract execution / Legitimate interest
Technical DataIP, device, operating system, access logsLegitimate interest (security)
Data contained in documentsIncidental data in LUPs, manuals or other Customer inputsContract execution
Communication dataMessages in platform communitiesUser consent

Note: alilo does not intentionally process special category data (health, racial origin, biometric data, etc.) unless the Customer includes them in the documents uploaded as inputs. In such a case, the Customer is responsible for having the appropriate legal basis.

3.3 Stakeholder categories
  • Employees and collaborators of the Client.
  • Platform administrators and managers designated by the Client.
  • Any third parties whose data appear incidentally in uploaded documents.
3.4 Duration of treatment

Processing will be carried out for the duration of the subscription contract. Upon termination:

  • alilo will delete inputs and drafts within 60 days from the date of termination.
  • Traceability data and SCORM exports must be downloaded by the Client prior to closing.
  • Rotating backups are retained for a maximum of 30 additional days before final deletion.

PART 4 – ALILO’S DUTIES AS MANAGER

4.1 Instructions from the person in charge

alilo will process personal data only in accordance with the Customer’s documented instructions. If alilo considers that an instruction violates the GDPR or other applicable regulations, it will notify the Customer immediately.

4.2 Confidentiality

alilo ensures that the persons authorized to process the Customer’s personal data are subject to confidentiality obligations, whether contractual or legal. Role-based access controls (RBAC) have been implemented to ensure that only personnel who need to access the data can do so.

4.3 Technical and organizational safety

alilo implements the following security measures:

  • Encryption in transit: TLS 1.2+ for all communications.
  • Encryption at rest: AES-256 for data stored in databases and backups.
  • Access control: Multi-factor authentication (MFA) for administrators, RBAC for all users.
  • Backups: Automatic daily backups with 30-day rolling retention.
  • Monitoring: Intrusion detection and continuous monitoring systems.
  • Audits: Periodic security reviews.
4.4 Security Breach Notification

In the event of a security breach involving Customer data, alilo shall notify the Customer without undue delay and, in any event, within 72 hours of detection. The notification shall include:

  • Description of the nature of the violation.
  • Categories and approximate number of affected stakeholders.
  • Categories and approximate number of records affected.
  • Probable consequences of the violation.
  • Actions taken or proposed.
4.5 Assistance to the Responsible

alilo will assist the Customer, to the extent possible, to:

  • Respond to requests for data subjects’ rights (access, rectification, deletion, portability, limitation, opposition).
  • Comply with the obligations of Article 32 RGPD (security of processing).
  • Conduct impact assessments (DPIA) when necessary.
  • Notifying security breaches to the control authorities.

PART 5 – SUB-PROCESSORS

5.1 General authorization

The Customer authorizes alilo to engage subcontractors for the provision of the services. alilo shall ensure that the subcontractors are subject to data protection obligations equivalent to those of this DPA.

5.2 List of Authorized Sub-processors
SupplierFunctionHeadquarters / Legal guarantee
Google Cloud PlatformCloud infrastructure, databases, storage, hostingEU (Europe-west region) / SCCs
Google Vertex AILanguage models (LLM), content generation by AIGlobal / SCCs + Enterprise Measures
ElevenLabs (and equivalents)On-demand speech synthesis (TTS), synthetic image generationUSA / SCCs
MailgunSending transactional emails (notifications, password recovery)EU / SCCs
Firebase (Google)User authenticationUE / SCCs
OsanoCookie consent management and GDPR representation in EU/UKEU/UK
5.3 Changes in subcontractors

alilo shall notify the Customer at least 14 days in advance of any change in the list of subcontractors (addition or substitution), giving the Customer the possibility to justifiably object. If the Customer objects and alilo is unable to provide the service without the new subcontractor, either party may terminate the contract without penalty.


PART 6 – INTERNATIONAL DATA TRANSFERS

6.1 General principle

alilo guarantees that any transfer of personal data outside the European Economic Area (EEA) is carried out under valid legal mechanisms in accordance with Chapter V of the GDPR.

6.2 Transfer Mechanisms Applied
  • Standard Contractual Clauses (SCCs): The SCCs approved by the European Commission (Implementing Decision 2021/914) for transfers to the USA and other third countries, including the UK Addendum, apply.
  • Adequacy decisions: For countries recognized by the European Commission as adequate.
  • Complementary measures: End-to-end encryption, pseudonymization and additional access controls for high-risk transfers.
6.3 Transparency

At the Customer’s request, alilo will provide copies of the applicable SCCs and any transfer impact assessment (TIA) performed. Contact: legal@alilo.app.


PART 7 – RIGHTS OF INTERESTED PARTIES

7.1 Procedure

The Customer is primarily responsible for responding to the rights of data subjects. When a data subject addresses his request directly to alilo, alilo will forward it to the Customer within 5 working days.

7.2 Technical assistance

alilo will provide the Customer with the necessary technical tools to:

  • Export the data of a specific user (portability).
  • Delete a user’s account and data (deletion / right to be forgotten).
  • Anonymize a user’s activity data.
7.3 Deadlines

The assistance ofilo al Cliente in resolving requests for rights will be provided within a maximum of 15 working days from receipt of the request.


PART 8 – AUDITS AND INSPECTIONS

The Customer has the right to verify alilo’s compliance with this DPA. Audits shall be carried out:

  • Through review of safety and compliance documentation provided by alilo (certifications, internal audit reports).
  • In case of on-site audit, prior written notice at least 30 days in advance, with a maximum of one audit per year.
  • At the Client’s expense or at the expense of an independent third party auditor subject to confidentiality.

The costs of the on-site audit shall be borne by the Customer, unless the audit reveals a material non-compliance on the part of alilo.


PART 9 – JURISDICTION-SPECIFIC REGIMES

9.1 Customers in the European Union (GDPR)

This DPA fully complies with Article 28 of the GDPR. The representative of alilo with the EU supervisory authorities is Osano International Compliance Services Limited, 3 Dublin Landings, North Wall Quay, Dublin 1, D01C4E0, Ireland.

9.2 Customers in El Salvador (LATAM)

The processing of data is carried out in accordance with the current Salvadoran regulations on data protection. This specific agreement with Salvadoran customers is governed by the laws of the Republic of El Salvador, with submission to the courts of San Salvador.

9.3 Customers in Mexico

Data processing complies with the Federal Law for the Protection of Personal Data in Possession of Private Parties (LFPDPPP) and its Regulations. The specific privacy notice for Mexican customers is available at: privacidad@alilo.app.

9.4 Customers in Colombia

Data processing complies with Law 1581 of 2012 and its regulatory decrees. The responsible for the treatment before the Superintendence of Industry and Commerce (SIC) is the Client.

9.5 Customers in California and the U.S. (CCPA/CPRA)

For California residents, alilo acts as a “Service Provider” under the CCPA. alilo does not sell or share personal data with third parties for their own marketing purposes. The data is processed solely for the provision of the contracted services. California residents may exercise their rights under the CCPA by contacting: privacidad@alilo.app.

9.6 Customers in Brazil (LGPD)

Data processing complies with the Lei Geral de Proteção de Dados (LGPD) – Lei nº 13.709/2018. alilo acts as “Operator” and the Client as “Controller” in accordance with the LGPD.


PART 10 – DELETION AND RETURN OF DATA

Upon termination of the contract:

  • alilo will delete all of the Customer’s personal data, including backup copies, no later than 60 days from the effective date of termination.
  • If the Customer requests the return of data prior to deletion, alilo will provide them in standard exportable format (CSV, JSON or equivalent).
  • Once deleted, alilo will issue a certificate of deletion at the Customer’s request.
  • It is the Client’s responsibility to download their SCORM exports and traceability reports prior to service closure.

PART 11 – MODIFICATIONS AND VALIDITY

This DPA shall remain in effect as long as the subscription contract between the parties is in force. Amendments to the DPA shall follow the same procedure as amendments to the T&C. In case of contradiction between the DPA and the commercial contract, the DPA shall prevail as regards the processing of personal data.


CONTACT AND EXERCISE OF RIGHTS

Data Protection Officer (DPO):
privacidad@alilo.app

EU Representative:
Osano International Compliance Services Limited
3 Dublin Landings, North Wall Quay, Dublin 1, D01C4E0, Ireland

UK Representative:
Osano UK Compliance LTD
42-46 Fountain Street, Belfast, Antrim BT1 5EF

For customers in the Americas:
ese Corp – 66 West Flagler Street, Miami, FL 33130, USA
Email: privacidad@alilo.app