Excalium

Data Processing Addendum

Current summary · July 16, 2026

This page summarizes Excalium’s data-processing commitments for customers using the service in a business context. To request an executed DPA with the applicable entity details and annexes, please contact us.

Roles and instructions

Where Excalium processes personal data on a customer’s documented instructions to provide the service, the customer acts as controller and Excalium acts as processor, unless applicable law assigns different roles.

Processing

Processing may include hosting account identifiers, portfolio and preference data, Agent inputs and outputs, delivery records and security telemetry for the duration of the customer relationship and any required deletion or retention period.

Security and confidentiality

Excalium applies access controls, personnel and provider confidentiality obligations, encryption where appropriate, security monitoring and read-only controls for supported investment connections.

Subprocessors and transfers

Excalium may use infrastructure, authentication, analytics, AI, messaging, market-data and payment subprocessors. The executed DPA will address subprocessors, international-transfer safeguards and notification rights applicable to the customer.

Assistance and deletion

Excalium will provide reasonable assistance with data-subject requests, security incidents and compliance inquiries, and will delete or return customer personal data at the end of service subject to lawful retention requirements.

Request an executed DPA

Use Contact Us with the subject “DPA request” and your organization name.