Data Processing Addendum
Xanadu Technology Limited
Published at https://xanadu.co/dpa. Version 1.0. Last updated 1 January 2026.
This Data Processing Addendum (this “DPA”) supplements, and forms part of, the Xanadu Master Customer Terms published at https://xanadu.co/mct (the “Master Terms”) and each Order entered into under them between Xanadu Technology Limited (“Xanadu”) and the Customer. It applies where, and to the extent that, Xanadu Processes Customer Personal Data on behalf of the Customer in connection with the Supplies. Capitalised terms used but not defined in this DPA have the meaning given to them in the Master Terms.
1. Definitions and roles
1.1 Definitions. In this DPA:
- “Applicable Data Protection Law” means all data protection and privacy laws applicable to a party’s Processing of Customer Personal Data under the Master Terms and an Order, including, where applicable, the DIFC Data Protection Law (DIFC Law No. 5 of 2020) and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations.
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach” and “Processing” (and “Process”) have the meanings given to them in Applicable Data Protection Law.
- “Customer Personal Data” means the Personal Data that Xanadu Processes on behalf of the Customer under the Master Terms and an Order, as described in Annex 1.
- “Sub-processor” means any third party engaged by Xanadu to Process Customer Personal Data in the course of Xanadu’s own performance of the Supplies.
- “Vendor” and “Vendor Product” have the meanings given to them in the Master Terms (for Canva Campus, the Vendor is Canva).
1.2 Roles of the parties. For Customer Personal Data Processed by Xanadu under this DPA, the Customer is the Controller, and Xanadu is the Processor. Each party will comply with its obligations under Applicable Data Protection Law in respect of that Processing.
1.3 Vendor Processing is separate. The Customer acknowledges that the Vendor Processes Personal Data within the Vendor Product as a separate Processor under the Vendor’s own data processing terms. For Canva Business, Enterprise, and Campus, those terms are set forth in the Canva Data Processing Addendum available at https://www.canva.com/policies/data-processing-addendum/, which are flowed down to the Customer under the applicable Order. This DPA governs only Xanadu’s own Processing of Customer Personal Data and does not govern the Vendor’s Processing of Personal Data within the Vendor Product.
1.4 Scope. This DPA applies only to Xanadu’s Processing of Customer Personal Data described in Annex 1, which is limited to what is necessary to provision, administer, support and invoice the Supplies. Where there is any conflict between this DPA and the Master Terms in respect of the Processing of Customer Personal Data, this DPA prevails to the extent of the conflict.
2. Processing of Customer Personal Data
2.1 Documented instructions. Xanadu will Process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Master Terms, the applicable Order, this DPA and Annex 1, unless required to Process it otherwise by a law to which Xanadu is subject. In that case, Xanadu will inform the Customer of the legal requirement before Processing, unless that law prohibits it on important grounds of public interest.
2.2 Unlawful instructions. Xanadu will inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. This does not oblige Xanadu to provide legal advice or to monitor the Customer’s compliance with Applicable Data Protection Law.
2.3 Purpose limitation. Xanadu will Process Customer Personal Data only for the purposes set out in Annex 1. Xanadu will not sell Customer Personal Data and will not Process it for its own independent purposes.
2.4 Customer warranties. The Customer warrants that (a) it has a lawful basis for, and has made all disclosures and obtained all consents, authorisations and permissions required to enable Xanadu and any Sub-processor to Process Customer Personal Data as contemplated by the Master Terms, an Order and this DPA; and (b) its instructions comply with Applicable Data Protection Law.
3. Confidentiality of processing
Xanadu will ensure that persons it authorises to Process Customer Personal Data are subject to appropriate confidentiality obligations (whether contractual or statutory) and are aware of their responsibilities.
4. Security
4.1 Security measures. Xanadu will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing, and the risks to Data Subjects. A description of Xanadu’s current measures is set out in Annex 2.
4.2 Updates. Xanadu may update its measures from time to time, provided that the updated measures do not materially reduce the overall level of protection of Customer Personal Data.
5. Sub-processors
5.1 General authorisation. The Customer provides Xanadu with a general written authorisation to engage Sub-processors to Process Customer Personal Data. Xanadu’s current Sub-processors are listed in Annex 3.
5.2 Sub-processor obligations. Xanadu will impose on each Sub-processor data protection obligations that are no less protective than those set out in this DPA, and will remain liable to the Customer for the acts and omissions of its Sub-processors to the same extent as for its own acts and omissions.
5.3 Changes. Xanadu will give the Customer prior notice of the addition or replacement of any Sub-processor (including by updating Annex 3 or by other reasonable means). The Customer may object to a change on reasonable data protection grounds within a reasonable period after notice, and the parties will work together in good faith to address the objection.
5.4 Vendor is not a Sub-processor. Consistent with the Master Terms, where the Vendor Processes Personal Data within the Vendor Product as a separate Processor under its own data processing terms, the Vendor is not a Sub-processor of Xanadu in respect of that Processing.
6. Assistance to the Customer
6.1 Data Subject requests. Taking into account the nature of the Processing, Xanadu will provide reasonable assistance to the Customer, by appropriate technical and organisational measures and, insofar as possible, to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law. If Xanadu receives such a request directly, it will promptly forward it to the Customer and will not respond except in accordance with the Customer’s documented instructions or as required by law.
6.2 Assessments and consultations. Xanadu will provide the Customer with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, in each case only to the extent they relate to Xanadu’s Processing of Customer Personal Data and taking into account the information available to Xanadu.
7. Personal Data Breach
Xanadu will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data Processed by Xanadu, and will provide the Customer with reasonable information and cooperation to enable the Customer to meet its own breach notification obligations under Applicable Data Protection Law. Where a Personal Data Breach occurs within the Vendor Product, the Vendor’s breach obligations under the Vendor Terms apply, and Xanadu will pass through to the Customer the relevant notifications it receives from the Vendor.
8. Deletion or return of Customer Personal Data
On expiry or termination of the relevant Order (or earlier on the Customer’s written request), Xanadu will, at the Customer’s choice, delete or return the Customer Personal Data Processed under that Order and delete existing copies, except to the extent that retention is required by a law to which Xanadu is subject or is reasonably necessary for the establishment, exercise or defence of legal claims. Any Customer Personal Data so retained will continue to be protected in accordance with this DPA.
9. Audit and information
9.1 Information. Xanadu will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA.
9.2 Audits. The Customer, or an independent auditor it mandates (who must not be a competitor of Xanadu and must be bound by confidentiality), may audit Xanadu’s compliance with this DPA on at least thirty (30) days’ prior written notice, no more than once in any twelve (12) month period, except where an audit is required by a supervisory authority or follows a Personal Data Breach affecting Customer Personal Data. Audits will be conducted during business hours, in a manner that minimises disruption, subject to Xanadu’s reasonable security and confidentiality requirements, and at the Customer’s cost. Xanadu may satisfy an audit request by providing relevant third-party certifications or reports, or the audit materials of its Sub-processors or the Vendor, where these reasonably address the request.
10. International transfers
Xanadu and its Sub-processors may Process and transfer Customer Personal Data outside the jurisdiction in which it was collected only where a transfer mechanism or safeguard required by Applicable Data Protection Law is in place (for example, a finding of adequacy, standard contractual clauses, or another lawful transfer mechanism). The Customer authorises such transfers undertaken in accordance with this Section, including transfers to the Vendor and to the Sub-processors listed in Annex 3.
11. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in Section 9 of the Master Terms. This DPA does not increase, and is not intended to increase, either party’s aggregate liability beyond the limits set out in the Master Terms.
12. General
12.1 Relationship with the Master Terms. This DPA forms part of, and is governed by, the Master Terms. Except as expressly varied by this DPA, the Master Terms remain in full force and effect.
12.2 Governing law. This DPA is governed by the laws of the Dubai International Financial Centre (DIFC) and is subject to the jurisdiction and dispute resolution provisions in Section 14.6 of the Master Terms.
12.3 Term. This DPA takes effect on the effective date of the first Order to which it relates and continues for as long as Xanadu Processes Customer Personal Data under the Master Terms and any Order. It is effective as part of the relevant Order without the need for a separate signature.
Annex 1. Details of the Processing
This Annex describes the categories of Xanadu’s Processing of Customer Personal Data in connection with the Supplies. The specific Vendor Products and the Customer are identified in the relevant Order.
Annex 2. Technical and organisational measures
Xanadu maintains the following technical and organisational measures in respect of its own Processing of Customer Personal Data. Xanadu relies on the security measures of its underlying cloud and software providers (including the Vendor) for the platforms on which it operates.
- Access control. Role-based, least-privilege access to systems holding Customer Personal Data, granted on a need-to-know basis and revoked promptly on role change or departure.
- Authentication. Multi-factor authentication is enforced on key business systems and administrative access.
- Encryption. Customer Personal Data is encrypted in transit using TLS, and at rest using the encryption provided by Xanadu’s underlying cloud and software providers.
- Personnel. Personnel with access are bound by written confidentiality obligations and receive guidance on data protection awareness.
- Sub-processor management. Due diligence on, and data protection terms with, Sub-processors, and reliance on their certifications and security measures (including the Vendor’s Statement of Technical and Organisational Measures).
- Operational security. Use of reputable, industry-standard SaaS and cloud platforms, secure configuration of administrative tools, and separation of customer information where practicable.
- Incident management. A documented process to identify, escalate, respond to and record security incidents and Personal Data Breaches, and to notify affected Controllers without undue delay.
- Resilience. Reliance on the backup, availability and resilience measures of Xanadu’s underlying platform providers.
Annex 3. Sub-processors
The following Sub-processors are engaged by Xanadu to process Customer Personal Data in the course of Xanadu’s own performance of the Supplies. An up-to-date list is available on request.
Xanadu may use other reputable SaaS providers to administer and support customer accounts; any additions or replacements are handled under Section 5.3.
Note: Canva appears above only in respect of Xanadu’s own use of Canva to prepare customer materials. Separately, where Canva is supplied to the Customer as the Vendor Product (for example, Canva Campus), Canva processes the Customer’s platform data as a separate Processor under the Canva Data Processing Addendum, and in that capacity is not a Sub-processor of Xanadu (Section 5.4).