Legal

Data processing

How Xevrion processes customer data on customers' behalf, as a processor.

Last updated 30 September 2026

Roles

Each customer is the controller of the data it connects to Xevrion Ops. Xevrion processes that data only to provide the service and only on the customer's documented instructions, which include the connections, permissions and approval rules the customer sets.

Confidentiality and security

Access is limited to people who need it and are bound by confidentiality. Security measures are described on our security page, including tenant isolation, sealed credentials, two-factor sign-in, approvals and audit logging.

Subprocessors

We use the subprocessors listed on our subprocessors page and will give notice of changes in writing.

Assistance

We help customers respond to data subject requests, carry out assessments and meet their security obligations, using the export, deletion and audit features of the platform.

Incidents

We will notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, with the information they need.

End of service

On cancellation, customers can export their data. An owner can then complete deletion; operational data is deleted or anonymised, financial records follow retention rules and a minimal record of the deletion is kept.

Signed agreement

A signed data processing agreement is available on request: write to outreach@ops.xevrion.co.uk.

Contact

Questions about this page: outreach@ops.xevrion.co.uk. We reply in writing.