This policy explains how World XP™ — the world experience powered by the DEASHA™ Framework — treats Customer Data, separates Customer environments, governs AI features, and protects platform intellectual property.
It is incorporated into the Terms of Service and read together with the Privacy Policy.
These policies are provided for transparency and are intended to be reviewed and finalized by qualified legal counsel. They are not legal advice and do not guarantee compliance with every jurisdiction, industry, or regulatory requirement that may apply to a Customer.
8.1 Data Ownership
Customers retain ownership of their Customer Data. World XP™ does not acquire ownership of Customer Data merely because it is stored or processed through the platform.
Customer Data may include:
- Contacts, members, customers, clients, leads, and participants.
- Communications and message history created by the Customer.
- Programs, events, and opportunities.
- Uploaded files, documents, and brand assets.
- Forms, intake submissions, and kickoff responses.
- Organization information and Customer-created content.
- Other information submitted into the Customer's World XP™ environment.
Customer ownership is subject to third-party rights, applicable law, and the Customer's own agreements with the individuals whose information it submits.
8.2 Data Processing Limitation
World XP™ processes Customer Data to:
- Provide the contracted Services.
- Maintain accounts, organizations, and user access.
- Deliver requested functionality and communications.
- Provide support and onboarding.
- Secure the platform and prevent fraud and abuse.
- Troubleshoot problems and monitor reliability.
- Perform backups and disaster recovery.
- Comply with legal requirements.
Where analytics or platform improvement involves Customer Data, we use aggregated or de-identified information where reasonably appropriate. We do not use identifiable Customer Data to train general-purpose AI models.
8.3 No Sale of Customer Data
World XP™ does not sell Customer Data.
- We do not use Customer Data to create unrelated customer lists for resale.
- We do not use identifiable Customer Data to create competing datasets.
- We do not disclose one Customer's Customer Data to another Customer.
8.4 Multi-Tenant Data Isolation
World XP™ is designed to maintain logical separation between Customer environments. Controls include:
- Tenant and organization identifiers applied to Customer records.
- Role-based access controls and permission levels.
- Row-level security policies where implemented.
- Authorization checks on data access paths.
- Administrative permission boundaries.
- Segregated data access for files and uploads.
- Operational and audit logging where implemented.
One Customer is not authorized to access another Customer's data. We do not promise absolute security or isolation beyond what the implemented controls provide.
8.5 Administrative Access
Authorized World XP™ personnel may access Customer Data when reasonably necessary for support, security, troubleshooting, maintenance, legal compliance, incident investigation, and service operations.
Such access is limited according to role and operational necessity, is granted to personnel bound by confidentiality obligations, and is logged where logging is implemented for the relevant system.
8.6 AI and Customer Data
Where AI-assisted features are enabled, they must respect:
- Customer access permissions.
- Tenant and organization boundaries.
- User roles and authorization levels.
- Data authorization rules configured for the environment.
- Applicable privacy requirements.
Where technically implemented, AI context is scoped to the appropriate Customer environment. World XP™ does not intentionally use one Customer's identifiable information to answer another Customer's questions.
Where AI services are provided through third-party providers, their applicable data-processing and AI-use terms may also apply. We do not claim zero retention or zero training by AI providers except where that is technically and contractually confirmed for the relevant feature.
AI-generated results may be inaccurate or incomplete. Customers remain responsible for reviewing AI output before relying on it for business, legal, financial, medical, employment, compliance, or other consequential decisions. AI features operate according to the requesting user's authorization and are not autonomous decision-makers.
8.7 AI Reproduction and Platform IP
AI features, Authorized Users, and any other person may not use World XP™ to:
- Extract proprietary source code.
- Reconstruct internal platform architecture.
- Clone the DEASHA™ Framework.
- Reproduce proprietary workflows or automation logic.
- Extract internal database schemas.
- Replicate platform configuration.
- Create a substantially similar competing implementation using protected platform materials.
- Circumvent platform security controls.
- Extract proprietary prompts, system instructions, or internal configuration.
This does not prevent Customers from exporting or using their own Customer Data where the Services permit it.
8.8 World XP™ Intellectual Property
World XP™ and its underlying technology may include proprietary:
- Software, source code, and object code.
- Architecture, data models, and database structures.
- APIs and platform integrations.
- UI and UX patterns and designs.
- Workflows, automation logic, and business logic.
- System configurations and AI orchestration.
- Documentation, methodologies, and frameworks.
- Trademarks, service marks, and branding.
The DEASHA™ Framework is the proprietary intellectual property of its owner. Customers receive a limited right to use World XP™ during an active subscription and do not receive ownership of the underlying framework or platform.
8.9 Customer Content vs. Platform IP
Customer owns / controls
Customer-created content and Customer Data, subject to applicable agreements and third-party rights.
World XP™ / DEASHA™ owns / controls
The underlying platform, technology, framework, architecture, software, workflows, systems, proprietary methods, branding, and reusable platform components.
Configuring, customizing, or requesting changes to a World XP™ environment does not transfer ownership of the underlying platform architecture or reusable components.
8.10 Aggregated and De-Identified Information
World XP™ may create aggregated or de-identified information for legitimate platform purposes where permitted by law, such as:
- Overall usage trends.
- System performance and reliability metrics.
- Feature utilization.
- Aggregate engagement patterns.
Such information is not presented in a way that identifies a specific Customer unless that Customer authorizes it, and it does not expose Customer-specific configurations or proprietary Customer workflows.
8.11 Audit and Security Logging
Where implemented, security and operational logs may record the acting user, timestamp, organization or tenant, action taken, authentication events, administrative actions, exports, deletions, security events, and system events.
Logs are used for security, auditing, troubleshooting, compliance, and operational purposes, and are retained for a period appropriate to those purposes. We do not represent that logs are immutable unless immutable logging is implemented for the relevant system.
8.12 Data Export and Termination
Where the Services support export, Customers may retrieve their Customer Data during an active subscription and for a limited period following cancellation or termination, as set out in the Terms of Service and the applicable Customer agreement.
After that period, Customer Data may be deleted in the ordinary course. Copies may persist in routine backups until those backups cycle out, and information may be retained longer where legal, tax, security, or dispute-resolution obligations require it. We do not promise immediate or instantaneous deletion.
8.13 Security Incidents
We maintain processes to investigate and respond to suspected security incidents affecting Customer Data, including containment, assessment, and remediation. Where required by applicable law or a contractual obligation, we will notify affected Customers without undue delay and provide information reasonably available to us. Specific notification timelines apply only where imposed by law or a signed agreement.
Customers must promptly report suspected compromise of their accounts, credentials, or environment.
8.14 Regulated and Industry-Specific Data
Customers should not upload or process regulated or highly sensitive information unless World XP™ expressly supports that use through applicable agreements, security controls, and contractual commitments. We do not claim HIPAA, FERPA, CJIS, PCI DSS, GDPR, SOC 2, or other compliance or certification status simply because security features exist. Where industry-specific processing is supported, appropriate contractual terms — such as a data processing agreement or business associate agreement — are required.
8.15 Contractual Intellectual Property Clause
The World XP™ platform and the DEASHA™ Framework, including their underlying software, architecture, workflows, automation, data structures, interfaces, system designs, proprietary methods, and related intellectual property, are proprietary. Subject to the Customer's rights in its Customer Data and Customer Content, the Customer receives only the limited rights expressly granted under the applicable agreement. No license is granted to copy, reproduce, reverse engineer, extract, reconstruct, distribute, or create a competing implementation from the proprietary technology or framework except as expressly permitted by law or written agreement.
This clause is intended to be reviewed by legal counsel before publication or contractual use.
8.16 Contact
Questions about this policy, data protection, or intellectual property can be directed to privacy@deasha.com.
World XP™ Data Protection & Intellectual Property Policy · Version 1.0 · Effective September 16, 2026 · Last updated September 16, 2026