Data Processing Addendum
Current summary · July 16, 2026
This page summarizes Excalium’s data-processing commitments for customers using the service in a business context. To request an executed DPA with the applicable entity details and annexes, please contact us.
Roles and instructions
Where Excalium processes personal data on a customer’s documented instructions to provide the service, the customer acts as controller and Excalium acts as processor, unless applicable law assigns different roles.
Processing
Processing may include hosting account identifiers, portfolio and preference data, Agent inputs and outputs, delivery records and security telemetry for the duration of the customer relationship and any required deletion or retention period.
Security and confidentiality
Excalium applies access controls, personnel and provider confidentiality obligations, encryption where appropriate, security monitoring and read-only controls for supported investment connections.
Subprocessors and transfers
Excalium may use infrastructure, authentication, analytics, AI, messaging, market-data and payment subprocessors. The executed DPA will address subprocessors, international-transfer safeguards and notification rights applicable to the customer.
Assistance and deletion
Excalium will provide reasonable assistance with data-subject requests, security incidents and compliance inquiries, and will delete or return customer personal data at the end of service subject to lawful retention requirements.
Request an executed DPA
Use Contact Us with the subject “DPA request” and your organization name.