DATA PROCESSING AGREEMENT (DPA)
Data Processing Agreement
Version: 2.0
Last update: February 18, 2026
Data Processor: EXO ESEPLUS S.L. (alilo) – CIF B09870583
Headquarters: Calle Núñez de Balboa 120, Madrid, Spain
DPO Contact: privacidad@alilo.app
INTRODUCTION AND PURPOSE
This Data Processing Agreement (“DPA”) forms an integral part of the service contract entered into between alilo (EXO ESEPLUS S.L.) and the Customer (hereinafter “the Controller”), and governs the processing of personal data that alilo performs on behalf of the Customer in the context of the provision of its enterprise learning platform services.
This DPA complies with the requirements of Regulation (EU) 2016/679 (GDPR/GDPR), Article 28 in particular, and is compatible with the data protection regulations applicable in El Salvador, Mexico, Colombia, the United States (CCPA/CPRA) and other Latin American countries.
Acceptance of the commercial contract with alilo implies full acceptance of this DPA.
PART 1 – DEFINITIONS
For the purposes of this DPA, the following definitions shall apply:
- “Personal Data”: Any information about an identified or identifiable natural person.
- “Processing”: any operation performed on personal data (collection, recording, storage, consultation, use, communication, deletion, etc.).
- “Data Controller / Controller”: The Client, who determines the purposes and means of the processing of personal data.
- “Processor: alilo (EXO ESEPLUS S.L.), who processes personal data on behalf of the Controller.
- “Sub-processor / Sub-processor”: Third-party provider contracted by alilo for the partial provision of services.
- “Stakeholder Data”: personal data of employees, users or third parties processed within the framework of the services.
- “Security Breach”: A breach of security that results in the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data.
- “SCCs”: Standard Contractual Clauses approved by the European Commission for international data transfers.
PART 2 – ROLES AND RESPONSIBILITIES
2.1 The Client as Data Controller
The Client determines the purposes and means of the processing of personal data of its employees and users. The Client is responsible for:
- To have an adequate legal basis for the processing and transfer of data to alilo.
- To inform the interested parties about the processing of their data.
- Respond to the rights of data subjects (access, rectification, deletion, etc.).
- Ensure that personal data transferred to alilo is accurate and relevant.
- Comply with the data protection regulations applicable in your jurisdiction.
2.2 alilo as Data Processor
alilo processes personal data only on the documented instruction of the Customer, in accordance with these T&Cs and the DPA, and not for its own purposes. alilo is responsible for:
- To process the data in accordance with the Client’s instructions.
- To guarantee the confidentiality and security of the data.
- Notify the Customer without undue delay of any security breach affecting its data.
- To facilitate the exercise of the rights of the interested parties.
- Delete or return the data at the end of the contract.
PART 3 – TREATMENT DESCRIPTION
3.1 Purpose of treatment
The processing is carried out exclusively to provide the following services to the Client:
- User account management (registration, cancellation, authentication).
- Training delivery and learning follow-up (traceability).
- Processing of documents uploaded by the Client for content generation through AI (LXD AI).
- alilobot conversational agent responses based on the Client’s documents.
- Analysis of the use of the Platform to improve the service.
- Transactional communications (notifications, password recovery).
3.2 Categories of data processed
| Category | Data | Legal Basis |
|---|---|---|
| Identification data | First name, last name, email, Employee ID | Contract execution |
| Training activity data | Completed courses, scores, access time, badges, etc. | Contract execution / Legitimate interest |
| Technical Data | IP, device, operating system, access logs | Legitimate interest (security) |
| Data contained in documents | Incidental data in LUPs, manuals or other Customer inputs | Contract execution |
| Communication data | Messages in platform communities | User consent |
Note: alilo does not intentionally process special category data (health, racial origin, biometric data, etc.) unless the Customer includes them in the documents uploaded as inputs. In such a case, the Customer is responsible for having the appropriate legal basis.
3.3 Stakeholder categories
- Employees and collaborators of the Client.
- Platform administrators and managers designated by the Client.
- Any third parties whose data appear incidentally in uploaded documents.
3.4 Duration of treatment
Processing will be carried out for the duration of the subscription contract. Upon termination:
- alilo will delete inputs and drafts within 60 days from the date of termination.
- Traceability data and SCORM exports must be downloaded by the Client prior to closing.
- Rotating backups are retained for a maximum of 30 additional days before final deletion.
PART 4 – ALILO’S DUTIES AS MANAGER
4.1 Instructions from the person in charge
alilo will process personal data only in accordance with the Customer’s documented instructions. If alilo considers that an instruction violates the GDPR or other applicable regulations, it will notify the Customer immediately.
4.2 Confidentiality
alilo ensures that the persons authorized to process the Customer’s personal data are subject to confidentiality obligations, whether contractual or legal. Role-based access controls (RBAC) have been implemented to ensure that only personnel who need to access the data can do so.
4.3 Technical and organizational safety
alilo implements the following security measures:
- Encryption in transit: TLS 1.2+ for all communications.
- Encryption at rest: AES-256 for data stored in databases and backups.
- Access control: Multi-factor authentication (MFA) for administrators, RBAC for all users.
- Backups: Automatic daily backups with 30-day rolling retention.
- Monitoring: Intrusion detection and continuous monitoring systems.
- Audits: Periodic security reviews.
4.4 Security Breach Notification
In the event of a security breach involving Customer data, alilo shall notify the Customer without undue delay and, in any event, within 72 hours of detection. The notification shall include:
- Description of the nature of the violation.
- Categories and approximate number of affected stakeholders.
- Categories and approximate number of records affected.
- Probable consequences of the violation.
- Actions taken or proposed.
4.5 Assistance to the Responsible
alilo will assist the Customer, to the extent possible, to:
- Respond to requests for data subjects’ rights (access, rectification, deletion, portability, limitation, opposition).
- Comply with the obligations of Article 32 RGPD (security of processing).
- Conduct impact assessments (DPIA) when necessary.
- Notifying security breaches to the control authorities.
PART 5 – SUB-PROCESSORS
5.1 General authorization
The Customer authorizes alilo to engage subcontractors for the provision of the services. alilo shall ensure that the subcontractors are subject to data protection obligations equivalent to those of this DPA.
5.2 List of Authorized Sub-processors
| Supplier | Function | Headquarters / Legal guarantee |
|---|---|---|
| Google Cloud Platform | Cloud infrastructure, databases, storage, hosting | EU (Europe-west region) / SCCs |
| Google Vertex AI | Language models (LLM), content generation by AI | Global / SCCs + Enterprise Measures |
| ElevenLabs (and equivalents) | On-demand speech synthesis (TTS), synthetic image generation | USA / SCCs |
| Mailgun | Sending transactional emails (notifications, password recovery) | EU / SCCs |
| Firebase (Google) | User authentication | UE / SCCs |
| Osano | Cookie consent management and GDPR representation in EU/UK | EU/UK |
5.3 Changes in subcontractors
alilo shall notify the Customer at least 14 days in advance of any change in the list of subcontractors (addition or substitution), giving the Customer the possibility to justifiably object. If the Customer objects and alilo is unable to provide the service without the new subcontractor, either party may terminate the contract without penalty.
PART 6 – INTERNATIONAL DATA TRANSFERS
6.1 General principle
alilo guarantees that any transfer of personal data outside the European Economic Area (EEA) is carried out under valid legal mechanisms in accordance with Chapter V of the GDPR.
6.2 Transfer Mechanisms Applied
- Standard Contractual Clauses (SCCs): The SCCs approved by the European Commission (Implementing Decision 2021/914) for transfers to the USA and other third countries, including the UK Addendum, apply.
- Adequacy decisions: For countries recognized by the European Commission as adequate.
- Complementary measures: End-to-end encryption, pseudonymization and additional access controls for high-risk transfers.
6.3 Transparency
At the Customer’s request, alilo will provide copies of the applicable SCCs and any transfer impact assessment (TIA) performed. Contact: legal@alilo.app.
PART 7 – RIGHTS OF INTERESTED PARTIES
7.1 Procedure
The Customer is primarily responsible for responding to the rights of data subjects. When a data subject addresses his request directly to alilo, alilo will forward it to the Customer within 5 working days.
7.2 Technical assistance
alilo will provide the Customer with the necessary technical tools to:
- Export the data of a specific user (portability).
- Delete a user’s account and data (deletion / right to be forgotten).
- Anonymize a user’s activity data.
7.3 Deadlines
The assistance ofilo al Cliente in resolving requests for rights will be provided within a maximum of 15 working days from receipt of the request.
PART 8 – AUDITS AND INSPECTIONS
The Customer has the right to verify alilo’s compliance with this DPA. Audits shall be carried out:
- Through review of safety and compliance documentation provided by alilo (certifications, internal audit reports).
- In case of on-site audit, prior written notice at least 30 days in advance, with a maximum of one audit per year.
- At the Client’s expense or at the expense of an independent third party auditor subject to confidentiality.
The costs of the on-site audit shall be borne by the Customer, unless the audit reveals a material non-compliance on the part of alilo.
PART 9 – JURISDICTION-SPECIFIC REGIMES
9.1 Customers in the European Union (GDPR)
This DPA fully complies with Article 28 of the GDPR. The representative of alilo with the EU supervisory authorities is Osano International Compliance Services Limited, 3 Dublin Landings, North Wall Quay, Dublin 1, D01C4E0, Ireland.
9.2 Customers in El Salvador (LATAM)
The processing of data is carried out in accordance with the current Salvadoran regulations on data protection. This specific agreement with Salvadoran customers is governed by the laws of the Republic of El Salvador, with submission to the courts of San Salvador.
9.3 Customers in Mexico
Data processing complies with the Federal Law for the Protection of Personal Data in Possession of Private Parties (LFPDPPP) and its Regulations. The specific privacy notice for Mexican customers is available at: privacidad@alilo.app.
9.4 Customers in Colombia
Data processing complies with Law 1581 of 2012 and its regulatory decrees. The responsible for the treatment before the Superintendence of Industry and Commerce (SIC) is the Client.
9.5 Customers in California and the U.S. (CCPA/CPRA)
For California residents, alilo acts as a “Service Provider” under the CCPA. alilo does not sell or share personal data with third parties for their own marketing purposes. The data is processed solely for the provision of the contracted services. California residents may exercise their rights under the CCPA by contacting: privacidad@alilo.app.
9.6 Customers in Brazil (LGPD)
Data processing complies with the Lei Geral de Proteção de Dados (LGPD) – Lei nº 13.709/2018. alilo acts as “Operator” and the Client as “Controller” in accordance with the LGPD.
PART 10 – DELETION AND RETURN OF DATA
Upon termination of the contract:
- alilo will delete all of the Customer’s personal data, including backup copies, no later than 60 days from the effective date of termination.
- If the Customer requests the return of data prior to deletion, alilo will provide them in standard exportable format (CSV, JSON or equivalent).
- Once deleted, alilo will issue a certificate of deletion at the Customer’s request.
- It is the Client’s responsibility to download their SCORM exports and traceability reports prior to service closure.
PART 11 – MODIFICATIONS AND VALIDITY
This DPA shall remain in effect as long as the subscription contract between the parties is in force. Amendments to the DPA shall follow the same procedure as amendments to the T&C. In case of contradiction between the DPA and the commercial contract, the DPA shall prevail as regards the processing of personal data.
CONTACT AND EXERCISE OF RIGHTS
Data Protection Officer (DPO):
privacidad@alilo.app
EU Representative:
Osano International Compliance Services Limited
3 Dublin Landings, North Wall Quay, Dublin 1, D01C4E0, Ireland
UK Representative:
Osano UK Compliance LTD
42-46 Fountain Street, Belfast, Antrim BT1 5EF
For customers in the Americas:
ese Corp – 66 West Flagler Street, Miami, FL 33130, USA
Email: privacidad@alilo.app