Legal

Data Processing Addendum

This Data Processing Addendum sets out how we process personal data on behalf of our customers in compliance with global data protection law.

Last updated: July 2, 2026

This Data Processing Addendum (“DPA”) forms part of and supplements the Terms of Service (the “Agreement”) between the customer (“Customer,” “you”) and Byteonic Labs, the entity that operates Inletbase and is based in Noida, Uttar Pradesh, India (“Inletbase,” “we,” “us”). It applies where we process Personal Data on your behalf in connection with the Services. By accepting the Agreement, you enter into this DPA on behalf of yourself and, to the extent required by Data Protection Laws, your Affiliates. Capitalized terms not defined here have the meaning given in the Agreement.

1. Definitions

  • “Affiliate” means an entity that controls, is controlled by, or is under common control with a party.
  • “Customer Personal Data” means Personal Data contained within Customer Data that we process on your behalf as a processor to provide the Services.
  • “Account & Usage Data” means data relating to your account and your use of the Services (such as contact and billing details of authorized users, and activity/telemetry logs) that we process as an independent controller.
  • “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including the EU GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the California Consumer Privacy Act as amended (“CCPA”), in each case as amended or replaced.
  • “Standard Contractual Clauses” (“SCCs”) means (a) the clauses approved by the European Commission in Decision 2021/914 (the “EU SCCs”) and (b) the UK International Data Transfer Addendum issued by the UK Information Commissioner (the “UK Addendum”).
  • The terms “controller,” “processor,” “data subject,” “personal data,” “personal data breach,” and “processing” have the meanings given in the GDPR.

2. Roles & Processing of Personal Data

With respect to Customer Personal Data, you act as the controller (or as a processor on behalf of a third-party controller) and we act as your processor (or sub-processor). You are responsible for the accuracy, quality, and legality of Customer Personal Data, the means by which you obtained it, and the instructions you give us. You must ensure you have a valid legal basis and have provided all required notices to, and obtained all required consents from, your End Users.

We will process Customer Personal Data only: (a) to provide, secure, and support the Services; (b) in accordance with your documented instructions, including as set out in the Agreement, this DPA, and Annex I; and (c) as required by law, in which case we will inform you (unless legally prohibited). We will promptly notify you if, in our opinion, an instruction infringes Data Protection Laws.

3. CCPA Service Provider Terms

To the extent the CCPA applies, we act as a “service provider” and receive personal information from you solely to perform the Services (a business purpose). We do not sell or share personal information (as those terms are defined in the CCPA), and we will not retain, use, or disclose it for any purpose other than performing the Services or as otherwise permitted by the CCPA. We certify that we understand and will comply with these restrictions.

4. Confidentiality

We ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and are trained on their data protection responsibilities. Access is limited to personnel who need it to provide the Services.

5. Subprocessors

You provide general authorization for us to engage Affiliates and third-party subprocessors to process Customer Personal Data in connection with the Services. We maintain a current list of subprocessors on our Subprocessors page. We will:

  • impose data protection obligations on each subprocessor that are substantially similar to those in this DPA;
  • remain liable to you for a subprocessor’s performance of its data protection obligations; and
  • give you reasonable prior notice of any new subprocessor and a reasonable opportunity to object on legitimate data protection grounds. If we cannot address a reasonable objection, you may discontinue the affected Service.

6. Security of Personal Data

Taking into account the state of the art, costs of implementation, and the nature, scope, and purposes of processing, we implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, as described in Annex II. These measures include encryption in transit and at rest, access controls and multi-factor authentication, network hardening, logging and monitoring, backups, and secure software development practices.

7. International Data Transfers

We may transfer and process Personal Data in countries other than your own, including India, the United States, and other jurisdictions where we or our subprocessors operate. Where such a transfer is from the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards under Data Protection Laws:

  • EEA transfers: the EU SCCs are incorporated into this DPA by reference, with the applicable module completed based on the parties’ roles (Controller-to-Processor or Processor-to-Sub-processor). Governing law and forum default to Ireland where the EU SCCs require a selection.
  • UK transfers: the UK Addendum is incorporated and amends the EU SCCs as required for transfers subject to the UK GDPR.
  • Swiss transfers: the EU SCCs apply with modifications so that the Swiss FADP governs, the Swiss Federal Data Protection and Information Commissioner is the competent authority, and data subjects in Switzerland may enforce their rights.

Where required, we will, on request, execute the applicable SCCs as a separate document. If a transfer mechanism ceases to be valid, we will implement an alternative lawful mechanism.

8. Rights of Data Subjects

To the extent permitted by law, we will promptly notify you if we receive a request from a data subject to exercise their rights (access, rectification, erasure, restriction, portability, objection, or withdrawal of consent) in relation to Customer Personal Data, and we will direct the data subject to you. Taking into account the nature of the processing, we will provide reasonable assistance (including via the Services’ self-service functionality) to help you respond to such requests. You are responsible for responding to data subject requests relating to Customer Personal Data.

9. Assistance, Records & Audits

  • DPIAs & consultation. Taking into account the nature of processing and information available to us, we will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.
  • Records. We maintain records sufficient to demonstrate compliance with this DPA.
  • Audits. On reasonable prior written notice, and no more than once per year (unless required by a supervisory authority or following a breach), we will make available information necessary to demonstrate compliance, which may take the form of up-to-date certifications or third-party audit reports (for example, SOC 2). Where those are insufficient under Data Protection Laws, we will allow an audit by you or an independent auditor, subject to reasonable confidentiality and security controls.

10. Personal Data Breach Notification

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations to supervisory authorities and affected data subjects. Our notification is not an acknowledgment of fault or liability.

11. Return & Deletion of Personal Data

On termination or expiry of the Agreement, or on your written request, we will delete or return Customer Personal Data (at your choice), unless further storage is required by law. Where deletion is not immediately practicable (for example, data held in routine backups), we will isolate and protect such data from further processing until deletion is possible.

12. Inletbase as an Independent Controller

With respect to Account & Usage Data, we act as an independent controller (not a joint controller) to: manage our relationship with you; run core business operations such as billing, accounting, and compliance; detect and prevent fraud, security incidents, and misuse; verify identity; and meet our legal obligations. Such processing is carried out in accordance with our Privacy Policy.

13. Liability & Order of Precedence

Each party’s liability under this DPA is subject to the exclusions and limitations in the Agreement. In the event of a conflict, the order of precedence is: (1) the applicable SCCs; (2) this DPA; (3) the Agreement; and (4) our Privacy Policy.

Annex I — Details of Processing

Subject matter & nature of processing: providing the Inletbase form-backend and AI chatbot Services, including receiving, storing, organizing, analyzing, transmitting, and (on instruction) deleting Personal Data, and disclosing it to authorized subprocessors.

Purpose: to perform our obligations under the Agreement and this DPA and to act on your documented instructions.

Duration: for the term of the Agreement and any period thereafter permitted or required by law, after which data is deleted or returned as described in Section 11.

Categories of data subjects: your End Users and other individuals whose Personal Data you submit through the Services (for example, people who complete your forms or interact with your chatbots), and your authorized users.

Categories of Personal Data: contact details (such as name, email, phone), message and form-field content you choose to collect, chatbot conversation content, and technical metadata (such as IP address, page URL, timestamp, and browser user-agent). You control which fields are collected.

Special category data: the Services are not intended for special categories of Personal Data (for example, health, biometric, or criminal-history data), and you agree not to submit such data unless expressly agreed in writing and lawful.

Annex II — Technical & Organizational Security Measures

We maintain the following categories of measures, which may be updated as the Services evolve provided the overall level of security is not reduced:

MeasureDescription
EncryptionData is encrypted in transit using current TLS protocols and at rest using strong, industry-standard ciphers.
Access control & authenticationRole-based access on a least-privilege basis, with multi-factor authentication required for administrative and production access.
Network & application securityHardened infrastructure, rate limiting, honeypot and spam filtering, domain allow-listing for embedded widgets, and secure configuration of services.
Resilience & recoveryRegular backups of production datastores and processes to restore availability and access following an incident.
Logging & monitoringMonitoring of access to systems that process Customer Personal Data, with investigation and escalation of security events.
Data minimization & retentionCustomers control what data enters the Services, and can delete or suppress data through self-service tools or on request.
Vendor managementSubprocessors are bound by data protection agreements with obligations substantially similar to those in this DPA.
Governance & accountabilityDocumented security and privacy policies, assigned responsibilities, breach recording and reporting, and periodic review.

Annex III — Subprocessors

We use a limited set of subprocessors to deliver the Services, such as cloud hosting and infrastructure providers (Amazon Web Services and Google Cloud / Firebase), payment processing, product analytics, and AI model providers. The current list, including each subprocessor’s purpose and processing location, is published on our Subprocessors page.

Contact

For questions about this DPA or to request our subprocessor list or SCCs, contact hello@inletbase.com.