小xiaoquiz

Data Processing Agreement

Last updated 1 October 2026

This Data Processing Agreement (“DPA”) applies when an organization using xiaoquiz collects personal data from players — nicknames, answers, and any lead-capture fields it enables — and is therefore the controller of that data. In that case Hexcraft AB (reg. 559396-5576, Sweden) acts as the controller’s processor, and xiaoquiz may in turn be a subprocessor where the organization is itself acting for its own client (for example an agency running a game for a brand).

It is based on the controller-to-processor Standard Contractual Clauses in EU Commission Implementing Decision (EU) 2021/915. It supplements, and is governed by, our Terms and Privacy Policy.

Subject matter and roles

We process personal data only on the controller’s documented instructions, for the sole purpose of providing xiaoquiz. We do not use player or lead data for our own purposes.

Our commitments

  • Process personal data only on your documented instructions.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Apply the technical and organisational measures in Annex II.
  • Notify you of a personal-data breach affecting your data within 48 hours of becoming aware.
  • Assist you with data-subject requests and with your security/DPIA obligations.
  • Delete or return the data at the end of the service, subject to legal retention.
  • Make available the information needed to demonstrate compliance, and allow audits.

Annex I — Description of processing

  • Categories of data subjects: players who join a game, and (if lead capture is enabled) people who submit their details.
  • Categories of personal data: nicknames, answers and scores; where lead capture is enabled, the fields the controller configures (e.g. name, email, company).
  • Nature and purpose: hosting a live interactive game, computing results, and (where enabled) collecting leads on the controller’s behalf.
  • Duration: for the lifetime of the game and the retention windows set out in the Privacy Policy, unless the controller instructs earlier deletion.

Annex II — Technical and organisational measures

  • Data stored and processed in the EU.
  • Encryption in transit (TLS); passwords stored only as salted hashes.
  • Access control and least-privilege access to production data.
  • Isolation of each organization’s data (multi-tenant scoping).
  • Automated anonymisation of player data after its retention window.
  • Security logging and rate limiting against abuse.

A fuller summary of our security controls is available on request (see our internal security overview).

Annex III — Subprocessors

The subprocessors we engage, with purpose and data location, are listed on our Subprocessors page. We give at least 30 days’ notice before adding or replacing a subprocessor, and you may object.

Entering into this DPA

If your organization needs a signed copy, or acts for a client as described above, contact privacy@xiaoquiz.com. A click-through acceptance will be presented in-product when you first enable lead capture.

Privacy · Terms · Subprocessors

© 2026 xiaoquiz