GDPR Privacy Shield

EU General Data Protection Regulation (EU) 2016/679 compliant policy for the institutional ISO 20022 grid.

Zero-Payload Verified
Art. 6 · 15–22 · SCC 2021/914

Legal Contact / DPO

compliance@xvilan.com
XVILAN SYSTEMIC INFRASTRUCTURES LLC
Financial Technology Software Provider
ISO 20022 Data Router

GDPR Privacy Policy v3.0

Message Data
Privacy Shield.

Your data rights under the GDPR, our legal bases for processing, retention limits, and how to exercise your rights.

1. Data Controller & Processor Roles

XVILAN SYSTEMIC INFRASTRUCTURES LLC ('XVILAN', 'we', 'us') is the Data Controller for account, billing, and platform-usage data collected from customers who access the platform directly. Where we process ISO 20022 payment message payloads on behalf of a customer (a financial institution, payment service provider, or other enterprise), XVILAN acts as a Data Processor under the customer's instruction, governed by our Data Processing Addendum (DPA) and the Master Service Agreement. This policy describes both roles. Our EU Representative and Data Protection Officer contact: compliance@xvilan.com.

2. Personal Data We Process

Account data (name, email, organization, billing address, role); payment data (Stripe transaction identifiers, amounts, card metadata — never raw card numbers, which are stored only by Stripe); API usage metadata (timestamps, endpoints, message counts, license keys — never message payloads); support and audit communications. Under our Zero-Payload mandate, message payloads containing names, account numbers, addresses, or transaction content are processed in volatile memory within confidential enclaves and are not persisted, logged, or stored by XVILAN.

3. Legal Basis for Processing (GDPR Art. 6)

We process personal data under the following legal bases: (a) Performance of a contract — operating your account, delivering the tolled services, and enforcing the MSA (Art. 6(1)(b)); (b) Legal obligation — regulatory compliance, fraud prevention, audit, and tax record-keeping (Art. 6(1)(c)); (c) Legitimate interests — security monitoring, abuse prevention, service improvement, and business analytics where our interests are not overridden by your rights (Art. 6(1)(f)). Consent (Art. 6(1)(a)) is used only for optional analytics and marketing communications, which you may withdraw at any time.

4. Purposes of Processing

Providing and operating the ISO 20022 routing, scanning, cleansing, translation, and harmonization services; processing payments and credits via Stripe; authenticating users and API keys; enforcing usage ceilings, rate limits, and fraud controls; generating and sending invoices; providing customer support; complying with legal and regulatory obligations; and improving service reliability and security. We do not sell personal data, and we do not use message payloads for any purpose other than executing the customer's instruction.

5. Your Data Subject Rights (GDPR Art. 15–22)

You have the right to: access (Art. 15) — obtain a copy of the personal data we hold about you; rectification (Art. 16); erasure / right to be forgotten (Art. 17), subject to legal retention obligations; restriction of processing (Art. 18); data portability (Art. 20) — receive your data in a structured, machine-readable format; and object to processing (Art. 21), including objection to legitimate-interest processing. You may withdraw consent (Art. 7(3)) at any time without affecting the lawfulness of processing before withdrawal. Submit requests to compliance@xvilan.com; we respond within one month, extendable by two further months for complex requests.

6. Data Retention

Account and billing records are retained for the duration of the contractual relationship plus the statutory tax and audit retention period (generally 7 years). API usage metadata is retained for 24 months for fraud, abuse, and capacity analysis, then aggregated or deleted. Message payloads are not retained — they are processed ephemerally and shredded after engine execution. Upon termination of the MSA, we delete or return all personal data per the DPA and Art. 17, unless applicable law requires retention.

7. International Data Transfers

Primary institutional compute is hosted in the European Union (OCI Confidential Enclaves, Frankfurt). Where personal data is transferred from the EEA/UK to third countries, we rely on European Commission Standard Contractual Clauses (SCCs 2021/914), the UK International Data Transfer Addendum, or an adequacy decision, as applicable. Subprocessors (including Stripe for payments and Neon/Prisma for metadata storage) are bound by DPA or SCC terms and are listed in the Data Processing Addendum.

8. Security & Zero-Payload Safeguards

We implement administrative, physical, and technical safeguards: AES-256 encryption at rest and TLS 1.3 in transit; HSM-backed secrets; hardware-isolated confidential computing (AMD SEV-SNP); least-privilege access with audit logging; and a Zero-Payload mandate under which message content is never written to logs, stdout, stderr, telemetry, or analytics. Our security architecture is described in the MSA and the Data Processing Addendum.

9. Cookies & Tracking

We use strictly necessary cookies and storage for authentication, session integrity, and security (these cannot be disabled without affecting the service). Optional analytics (via Vercel Analytics/Speed Insights) and marketing cookies are loaded only with your consent through our cookie banner, which you may accept or decline. You may withdraw or change consent at any time via your browser settings or the banner.

10. Supervisory Authority & Contact

If you are in the EEA, you have the right to lodge a complaint with your local supervisory authority (e.g., the CNIL in France or the data protection authority of your Member State). For all privacy questions, data subject requests, or DPO contact: compliance@xvilan.com, or XVILAN SYSTEMIC INFRASTRUCTURES LLC, US Corporate Headquarters — Institutional Desk. This policy was last updated 2026-08-29 and takes effect immediately.