Tiritix Secure API Infrastructure

XOPOZ API

Secured Service Endpoint
Operational

This application programming interface is a restricted-access system. Any unauthorized access, enumeration, penetration testing, reverse engineering, or automated interaction constitutes a violation of applicable law and contractual obligations.

1

Notice of Restricted Access

This API endpoint (api.tiritix.com/xopoz) is a proprietary, non-public service interface operated by Tiritix exclusively for authorized client applications. Access is granted solely under the terms of a duly executed Application Programming Interface License Agreement (the “Agreement”).

No implicit or explicit right of access is conferred by the availability of this endpoint. The mere technical reachability of this service does not constitute an invitation to interact, test, probe, or consume any of its resources.

2

Classification of Protected Data

This system processes, transmits, and stores real-time and historical geolocation data of natural persons, classified as high-sensitivity personal data under applicable data protection law. Pursuant to GDPR Recital 75, location data is expressly recognized as information whose unauthorized disclosure may cause significant economic or social disadvantage to the data subjects concerned.

Geolocation data processed by this service includes, but is not limited to: precise GPS coordinates (latitude/longitude), device movement trajectories, positional timestamps, speed vectors, and team-contextual location history. Such data is capable of revealing:

The ePrivacy Directive (2002/58/EC), Article 9, imposes specific obligations regarding the processing of location data, requiring explicit consent and purpose limitation. A Data Protection Impact Assessment (DPIA) pursuant to GDPR Article 35 has been conducted for this processing activity, confirming the high-risk nature of the data and the necessity of enhanced technical and organizational safeguards.

Elevated Risk Classification: Unauthorized access to geolocation data constitutes a severe personal data breach under GDPR Article 33/34, triggering mandatory notification to supervisory authorities within 72 hours and direct notification to affected data subjects. The sensitivity of location data is an aggravating factor in the assessment of administrative fines and criminal penalties.

3

Prohibited Activities

Without prior written authorization from Tiritix, the following activities are strictly prohibited and may give rise to civil and criminal liability:

4

Applicable Legal Framework

Unauthorized access to this system is prosecutable under the following statutes and regulatory instruments, without limitation:

5

Jurisdiction & Governing Law

This notice and any dispute arising from unauthorized access shall be governed exclusively by the laws specified below. Tiritix reserves the right to pursue legal proceedings in any competent jurisdiction where the unauthorized activity originated, transited, or produced effects.

Primary Jurisdiction
Federal Republic of Germany
Governing Law
BDSG, StGB, GDPR (EU) 2016/679
Supervisory Authority
BfDI / Landesdatenschutzbeauftragte
Arbitration
ICC Rules, Germany Seat
6

Monitoring, Logging & Evidence Preservation

All interactions with this system are logged, monitored, and retained in accordance with our data retention policy and applicable legal requirements. Metadata collected includes, but is not limited to: source IP addresses, request timestamps (UTC), HTTP methods, URI paths, request headers, TLS fingerprints, and response codes.

Log data is preserved in tamper-evident storage and may be disclosed to law enforcement authorities, regulatory bodies, or legal counsel in connection with any investigation or proceeding arising from unauthorized access.

Civil & Criminal Liability: Violations may result in injunctive relief, statutory damages of up to €20,000,000 or 4% of annual global turnover (GDPR Art. 83), criminal prosecution with custodial sentences of up to 5 years (Directive 2013/40/EU Art. 9), and recovery of all costs incurred in forensic investigation and legal proceedings.

7

Authorized Access & Licensing

Authorized use of this API requires execution of an API License Agreement and issuance of valid client credentials by Tiritix. For licensing inquiries, partnership proposals, or to report a security vulnerability through our responsible disclosure program, contact:

Tiritix — Legal & Compliance Department
xopoz@tiritix.com