Data
Where is customer data stored geographically?
Where is customer data stored geographically?
- Primary Data Centers in the United States: All customer data is stored on AWS cloud infrastructure, with primary hosting facilities located within the United States.
- High Availability and Redundancy: The platform leverages AWS’s geographically distributed data centers to ensure business continuity, high availability, and disaster recovery.
- ISO 27001 and SOC 2 Compliance: All hosting infrastructure complies with globally recognized data protection and security standards.
- Data Encryption: Customer data is encrypted both in transit (via TLS 1.2) and at rest (via AES-256 encryption), ensuring maximum security.
- Optional Regional Hosting: For enterprise clients, data can also be hosted in other jurisdictions such as Singapore or the European Union, based on compliance and data residency requirements.
Data, Policy and Privacy
What are Xoxoday's data security practices?
What are Xoxoday's data security practices?
- Certifications: ISO 27001, SOC 2 Type II, GDPR-compliant
- Encryption: AES-256 for data at rest; TLS 1.2+ for data in transit
- Access Management: Role-based access control (RBAC), Multi-factor authentication (MFA), Least privilege principle, Regular access reviews and logs
- Cloud Infrastructure: Hosted on AWS with VPC isolation and auto-scaling; Monitored using real-time security event tracking and anomaly detection
- Data Retention & Deletion: Aligned with client contracts, GDPR, and PIPL retention requirements
- Audits & Testing: Periodic internal audits, Annual third-party vulnerability assessments, Penetration testing and risk remediation workflows
- Incident Management: Structured incident response plan with SLA-bound notification and containment steps
- Ensures high availability, confidentiality, and integrity of data across all geographies and client use cases
Does the customer retain copyright on customizations made to the platform?
Does the customer retain copyright on customizations made to the platform?
How does the platform maintain detailed records of transactions for audit and compliance purposes?
How does the platform maintain detailed records of transactions for audit and compliance purposes?
Where can I find the privacy policy or product/service privacy notice for the platform?
Where can I find the privacy policy or product/service privacy notice for the platform?
- The types of personal data collected across services.
- Purposes for data processing (e.g., reward fulfillment, communication, analytics).
- Legal basis under GDPR, CCPA, and other applicable frameworks.
- User rights and instructions for submitting access or deletion requests.
- Contact details for privacy and data protection queries.
AI Data Security
Can sensitive data be removed from your solution's AI model upon request?
Can sensitive data be removed from your solution's AI model upon request?
- Xoxoday Rewards, Incentives, and Payout Platform: Data deletion upon request: The platform supports data subject rights under regulations like GDPR and CCPA, including the right to erasure (“right to be forgotten”), which applies to both structured and unstructured data—including inputs processed by AI systems. Model behavior isolation: LLM-based AI features do not persist user-specific training data beyond a session scope. Multi-tenant architecture ensures each client’s data is logically segregated with encryption keys per tenant.
- Employee Engagement Platform: PII sanitization via content moderation: Em’s AI scans and blocks the ingestion of personally identifiable information before it’s processed by internal models. Consent-based AI processing allows user or admin-led revocation of processed data. Data control APIs allow admins to raise requests to remove engagement logs and user-generated content used in AI training.
- Sales Incentives Platform: Custom dashboards and reports built through natural language queries do not permanently train AI models on client data. These are temporarily cached and can be purged or redacted based on user role or admin request.
- Loyalty Platform: All customer data used in AI-driven segmentation or CLTV prediction models can be excluded or deleted upon request, thanks to configurable segmentation rules and data access policies.
- Merchant Offer Platform: AI modules that use personalization logic operate within secure, tenant-specific boundaries. Sensitive user or partner data involved in offer targeting can be excluded or wiped via admin-level operations or customer success support.
Is user input data used to influence or train the AI model within your platform?
Is user input data used to influence or train the AI model within your platform?
- Purpose: Data is leveraged for smart recommendations, sentiment analysis, predictive analytics, and engagement insights.
- Patterns used: Recognition activity, reward redemptions, and survey feedback inform contextual outputs.
- Personalization focus: Inputs are applied to improve user-specific experiences within the platform.
- Examples: Skill mapping from recognition messages, reward suggestions based on behavior, and predictive trends for retention and engagement.
Does your platform provide logging for AI features, including user actions, dates, and timestamps?
Does your platform provide logging for AI features, including user actions, dates, and timestamps?
- AI Co-pilot tracks active users, pending nominations, award givers/receivers, budget utilization, and engagement reports
- Logs are time-bound and actionable, helping admins monitor AI usage over time
- Supports auditability and transparency, with timestamped logs available for compliance needs
Do you have documented technical and procedural processes to address potential negative impacts of AI as described by the AI Risk Management Framework (RMF)?
Do you have documented technical and procedural processes to address potential negative impacts of AI as described by the AI Risk Management Framework (RMF)?
- Safety checks are built into AI features for content moderation, fraud detection, and decision transparency
- Technical safeguards include anomaly detection, rule-based overrides, and configurable escalation protocols
- Procedural controls allow workflows to be flagged, paused, or escalated for manual oversight
- AI outputs are designed for explainability, ensuring interpretability and auditability
Does the platform process protected health information (PHI) or any data under HIPAA compliance?
Does the platform process protected health information (PHI) or any data under HIPAA compliance?
- HIPAA compliance framework – implemented controls and processes aligned with HIPAA’s Privacy, Security, and Breach Notification Rules.
- Data encryption – PHI is encrypted both in transit (using TLS protocols) and at rest (using AES-256 encryption) to prevent unauthorized access.
- Access control measures – role-based access controls (RBAC) and multi-factor authentication (MFA) restrict PHI access to authorized personnel only.
- Audit logging and monitoring – comprehensive logging of system access, data interactions, and administrative actions for accountability and traceability.
- Secure hosting environment – cloud infrastructure hosted on ISO 27001 and SOC 2 Type 2 certified data centers with strong physical and network security controls.
- Data segregation – multi-tenant architecture with logical separation of client data, ensuring PHI is isolated and protected from other tenants.
- Incident response protocols – documented procedures to identify, contain, and report any potential data breaches in compliance with HIPAA requirements.
- Business Associate Agreement (BAA) – available for clients in the healthcare sector who require contractual assurance of HIPAA compliance.
System Requirement
Does Xoxoday reward payout solution meet all regulatory recordkeeping and reporting requirements applicable to the vendor?
Does Xoxoday reward payout solution meet all regulatory recordkeeping and reporting requirements applicable to the vendor?
How does the system ensure confidentiality of sensitive research data and human subject information?
How does the system ensure confidentiality of sensitive research data and human subject information?
Are you PCI-DSS compliant?
Are you PCI-DSS compliant?
Can the system scale efficiently during promotions or seasonal spikes in traffic?
Can the system scale efficiently during promotions or seasonal spikes in traffic?
- Stateless services scale out behind the ALB; critical data is cached to avoid database hot spots.
- Kafka-backed queues smooth “flash-sale” style traffic; consumers scale horizontally to drain backlogs.
- Search & audit workloads are offloaded to managed Elasticsearch; analytics run on Redshift so reporting never competes with transactions.
- WAF/Bot protection (Cloudflare) shields the perimeter, important during promos when bot traffic rises.
Legal
Can high-denomination physical Visa gift cards (e.g., $1,000–$1,500) be sourced if needed?
Can high-denomination physical Visa gift cards (e.g., $1,000–$1,500) be sourced if needed?
Security and Compliance
How does your firm stay current with state regulations that impact multi-state or multi-location users?
How does your firm stay current with state regulations that impact multi-state or multi-location users?
- Dedicated Compliance & Legal Teams: We have specialized compliance, data privacy, and legal teams who continuously monitor state, federal, and international regulations affecting employment, data privacy, rewards, taxation, and payments. Regulations such as GDPR, CCPA/CPRA, HIPAA (where applicable), SOC 2, and ISO 27001 are embedded into our global frameworks.
- Regulatory Intelligence & Partnerships: Xoxoday leverages partnerships with audit firms, legal advisors, and compliance consultants in different geographies to stay ahead of state-specific regulatory updates. We subscribe to regulatory intelligence feeds and compliance monitoring services that track multi-state taxation, digital rewards governance, data residency, and employment-related laws.
- Product Flexibility for Multi-State Needs: Our Platforms allow localization of program rules, including tax handling, redemption catalogs, accrual structures, payout modes, and communication templates, ensuring adaptability to state or region-specific mandates. For payments and financial products, we integrate with licensed payment partners who are compliant with state money movement and tax reporting laws.
- Global Best Practices in Data Privacy and Security Compliance: We adopt Privacy by Design and Security by Default principles across all products. Frequent third-party audits, penetration testing, and certification renewals validate compliance against changing standards. Our multi-region hosting options (e.g., USA, Singapore, EU) ensure adherence to data residency and sovereignty requirements.
- Customer Communication & Assurance: Any regulatory changes impacting product usage are communicated through release notes, compliance updates, and customer success reviews. Clients benefit from configurable compliance controls such as audit trails, retention policies, and access management to meet their own internal governance needs.
Security Requirement
Will the platform have access to confidential business data?
Will the platform have access to confidential business data?
- Employee and customer PII (names, emails, contact details)
- Transaction and redemption history
- Financial identifiers for payouts and prepaid cards
- Enterprise-grade encryption for data at rest and in transit
- Role-based access control (RBAC)
- Secure API integrations with audit logs
- Compliance with GDPR and relevant local data privacy laws
- Regular third-party audits to prevent unauthorized access and mitigate risks
Technical Requirement
Does your solution require institutions to host a virtual appliance or make firewall exceptions for remote access?
Does your solution require institutions to host a virtual appliance or make firewall exceptions for remote access?
- Global rewards marketplace & payout platform: Fully cloud-hosted, with optional on-premise deployment available for highly regulated environments.
- Employee engagement & recognition platform: Delivered as SaaS, accessible via browsers and mobile apps with no additional network configuration.
- Sales commission & incentive management system: Cloud-native, integrating securely with CRM and HRMS platforms via APIs.
- Customer loyalty management solution: Entirely online, eliminating the need for local hosting or infrastructure.
- Merchant-funded offers & promotion engine: Cloud-based with secure API access for seamless partner integrations.
Does your platform have access to institutional or personal data?
Does your platform have access to institutional or personal data?
- Global rewards marketplace & payout platform: Uses recipient names, emails, and transaction data solely to process and deliver rewards.
- Employee engagement & recognition platform: Stores and processes employee identifiers, email addresses, and engagement activity to support recognition and surveys.
- Sales commission & incentive management system: Handles sales team identifiers, performance metrics, and payout details to calculate and distribute incentives.
- Customer loyalty management solution: Manages loyalty member data including profiles, points balances, and redemption history.
- Merchant-funded offers & promotion engine: Maintains merchant details, customer segment data, and redemption records for campaign management.
Do you have a documented business continuity plan (BCP) with ownership and annual testing?
Do you have a documented business continuity plan (BCP) with ownership and annual testing?
- Global rewards marketplace and payout platform: Includes continuity procedures for reward delivery, catalog access, and payment processing.
- Employee engagement and recognition platform: Ensures uninterrupted engagement, recognition, and survey operations during disruptions.
- Sales commission and incentive management system: Maintains continuous access to commission tracking, incentive calculations, and reporting.
- Customer loyalty management solution: Keeps loyalty enrolment, accrual, and redemption systems available in crisis scenarios.
- Merchant-funded offers and promotion engine: Provides continuity for merchant offer creation, validation, and redemption tracking during outages.
Do you maintain a documented disaster recovery plan (DRP) with ownership and regular testing?
Do you maintain a documented disaster recovery plan (DRP) with ownership and regular testing?
- Global rewards marketplace and payout platform: Covers restoration of transaction processing, catalog services, and payment integrations.
- Employee engagement and recognition platform: Ensures rapid recovery of recognition data, engagement analytics, and survey records.
- Sales commission and incentive management system: Restores commission plans, sales performance data, and payout schedules promptly after incidents.
- Customer loyalty management solution: Recovers loyalty member accounts, points balances, and redemption records with minimal downtime.
- Merchant-funded offers and promotion engine: Brings back merchant campaign data, offer rules, and redemption history in line with recovery targets.
Record Creation
Can the system maintain a secure record of credit card issuance while preserving subject confidentiality?
Can the system maintain a secure record of credit card issuance while preserving subject confidentiality?
Can the system flag studies or projects that are exempt from collecting personally identifiable information (PII) like name or SSN, and assign this flag based on user roles?
Can the system flag studies or projects that are exempt from collecting personally identifiable information (PII) like name or SSN, and assign this flag based on user roles?
Does the system allow attaching an IRS Form W-9 when entering subject information (unless the study is exempt from SSN collection)?
Does the system allow attaching an IRS Form W-9 when entering subject information (unless the study is exempt from SSN collection)?
Can the system flag or identify studies conducted entirely outside the United States?
Can the system flag or identify studies conducted entirely outside the United States?
Does the platform support the externalization of back-office operations such as account management, reporting, reconciliation, and customer support through APIs or partner portals?
Does the platform support the externalization of back-office operations such as account management, reporting, reconciliation, and customer support through APIs or partner portals?
Can Xoxoday host the reward portal within a client's private infrastructure?
Can Xoxoday host the reward portal within a client's private infrastructure?
Is the solution provider a dependency for any business-critical activity?
Is the solution provider a dependency for any business-critical activity?
- Powers customer loyalty programs, employee recognition programs, sales and channel incentives, and instant payout delivery, all of which are essential for business continuity.
- Delivers time-sensitive reward redemptions for events like sales milestones, festive gifting, employee anniversaries, and customer retention campaigns.
- Supports multi-region and multi-currency operations, ensuring that global incentive programs remain uninterrupted.
- Operates on high-availability infrastructure with redundancy, minimizing downtime risk.
- Without Xoxoday, businesses would face disruptions in engagement programs, potentially leading to reduced retention, sales performance, and customer satisfaction.
Is your solution designed to handle, store, or transmit credit card data?
Is your solution designed to handle, store, or transmit credit card data?
Xoxolink
Does Xoxoday comply with regulatory recordkeeping and reporting requirements?
Does Xoxoday comply with regulatory recordkeeping and reporting requirements?
