Q: Where is customer data stored, and what policies govern its security?
Xoxoday stores customer data in secure AWS / Azure / Oracle / or client-preferred data centers, aligned with regional data residency and compliance requirements.
Key policies include:
Data Residency: Data stored (including backups) in regions chosen by the client, ensuring compliance with local regulations.
Encryption: AES-256 at rest and TLS 1.3+ in transit.
Access Controls: Strict role-based access with MFA for all authorized personnel.
Backups & Retention: Automated daily backups with defined retention and disaster recovery protocols.
Compliance: Supports GDPR and other major data protection frameworks.
Monitoring & Audits: Continuous monitoring, logging, and periodic security audits.
Q: Are physical backups taken off-site?
No, Xoxoday does not take physical backups off-site. Instead, the platform relies on the built-in, fully managed backup and disaster recovery mechanisms of its cloud service providers (AWS and Azure). These providers maintain redundant data backups within their data centers to ensure durability, availability, and compliance. Xoxoday does not maintain or transport physical backup media, which mitigates risks related to physical loss or theft of sensitive data(Answer: No)
Q: Are off-site backups performed?
Yes. Xoxoday performs regular off-site backups as part of its business continuity and disaster recovery strategy.
Key practices include:
Daily automated backups transferred securely to off-site locations.
Geographically redundant storage in compliant data centers.
End-to-end encryption (AES-256 at rest, encrypted transfer channels).
Continuous monitoring & integrity checks to ensure data can be restored.
Defined retention and rotation policies aligned with compliance needs.
This ensures data remains protected, resilient, and recoverable even if the primary site becomes unavailable.
