Legal
Privacy Policy
Your privacy matters. This policy explains what personal data we process and the choices and rights you have.
Last updated: July 29, 2026
1. Introduction
This Privacy Policy describes how Inletbase (“Inletbase,” “we,” “us,” or “our”), a product operated by Byteonic Labs, collects, uses, discloses, and safeguards personal data when you visit inletbase.com, create an account, or use our form-backend and AI chatbot services (collectively, the “Services”).
We are committed to processing personal data in accordance with applicable data protection laws, including India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, and US state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”). Please read this policy carefully. By using the Services, you acknowledge the practices described here.
2. Who We Are
Inletbase is operated by Byteonic Labs, the entity responsible for the Services (the “data controller” for the purposes of our own account, marketing, and website data). Byteonic Labs is based in Noida, Uttar Pradesh, India. For privacy inquiries, you can reach us at hello@inletbase.com.
Our full registered business address and, where applicable, our data protection representative and Data Protection Officer contact details are available on request via the email above.
3. Scope & Our Role (Controller vs. Processor)
Our role under data protection law depends on the data in question:
- We act as a data controller for personal data relating to our account holders and website visitors — for example, the name, email, and billing details you provide when you register, and analytics we collect about how our website is used.
- We act as a data processor for the personal data contained in end-user submissions your customers send through your forms and chatbots (“Customer Data”). You (our customer) are the controller of that data and determine why and how it is processed. Our processing of Customer Data is governed by our customer terms and our Data Processing Addendum (“DPA”), which forms part of our agreement with you.
4. Information We Collect
4.1 Information you provide
- Account & profile data: name, email address, password, organization name, and role.
- Billing data: billing name, address, and transaction records. Payment card details are collected and processed directly by our payment processor; we do not store full card numbers.
- Support & communications: messages you send us through contact forms, email, or support channels.
4.2 Customer Data processed on your behalf
- Form submissions: the field data your end users submit through forms you connect to Inletbase, together with submission metadata such as the page URL, timestamp, browser user-agent, and originating integration (for example, our WordPress plugin).
- Chatbot conversations: messages exchanged between your end users and your AI chatbots, and related session data.
4.3 Information collected automatically
- Usage & device data: IP address, device and browser type, pages viewed, referring pages, and interactions with the Services.
- Cookies & similar technologies: we use these only in accordance with your choices — see our Cookie Policy and the “Cookies & Tracking” section below.
5. How We Use Information
We use personal data to:
- provide, operate, maintain, and secure the Services;
- create and administer accounts, authenticate users, and process subscriptions and payments;
- route, store, and deliver form submissions and chatbot conversations as directed by our customers;
- provide customer support and respond to your requests;
- monitor, analyze, and improve the performance, safety, and features of the Services, including preventing fraud, spam, and abuse;
- send service, security, and administrative communications, and — where permitted — marketing communications you can opt out of at any time; and
- comply with legal obligations and enforce our terms.
We do not sell personal data or use Customer Data to develop, train, or improve generalized or foundational artificial intelligence or machine learning models.
6. Legal Bases for Processing (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
- Contract: to provide the Services you or your organization have signed up for.
- Legitimate interests: to secure and improve the Services, prevent abuse, and conduct limited direct marketing, balanced against your rights.
- Consent: for certain cookies and marketing, which you may withdraw at any time.
- Legal obligation: to comply with laws, tax, and accounting requirements.
7. How We Share Information
We may disclose personal data to:
- Service providers / subprocessors who help us run the Services (see below), under contracts requiring appropriate safeguards;
- Our customers, where the data is Customer Data we process on their behalf;
- Professional advisers, auditors, and authorities where required by law, legal process, or to protect rights, safety, and property; and
- A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
8. Service Providers & Subprocessors
We engage trusted third parties to deliver the Services, such as cloud hosting and infrastructure (for example, Amazon Web Services and Google Cloud / Firebase), payment processing, product analytics, and AI model providers. These subprocessors are bound by data protection obligations and may only process personal data on our documented instructions. Our current subprocessors are listed on our Subprocessors page and described further in our DPA.
9. Google API Services and Gmail (Limited Use)
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We request the gmail.send scope solely to send emails from a user’s connected Gmail account at their request. We do not read, modify, delete, store, or retrieve existing Gmail messages or mailbox data. This is the narrowest Gmail permission required for this feature.
Information received from Google Workspace APIs is never used, transferred, or sold to develop, improve, or train any generalized or foundational artificial intelligence or machine learning models. This restriction includes any third-party AI or machine-learning services we use (such as Amazon Bedrock): Gmail content and other Google user data are never transmitted to those services, and such services never receive Google user data for training or any secondary purpose.
10. International Data Transfers
We may transfer, store, and process personal data in countries other than your own, including outside the European Economic Area (“EEA”), the United Kingdom, and India. Where we do so, we implement appropriate safeguards recognized under applicable law, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or transfers to countries benefiting from an adequacy decision. You may request a copy of the relevant safeguards using the contact details below.
11. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, including to provide the Services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to your account settings and instructions; when your account is closed or on your documented request, we will delete or return Customer Data within a commercially reasonable period, subject to legal retention requirements and backup cycles.
12. Data Security
We maintain administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. These include encryption in transit and at rest, access controls and least-privilege practices, rate limiting, domain allow-listing for embedded widgets, and activity logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
13. Your Privacy Rights (GDPR / UK GDPR / DPDP Act)
Subject to applicable law, you may have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of your data (“right to be forgotten”);
- restrict or object to certain processing;
- request data portability;
- withdraw consent where processing is based on consent;
- nominate another person to exercise your rights (under the DPDP Act); and
- lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office; in India, the Data Protection Board once operational).
To exercise these rights, contact us at hello@inletbase.com. If your request concerns Customer Data for which we act as processor, we will refer you to the relevant customer (controller) or assist them in responding. We will respond within the timeframes required by law and will not discriminate against you for exercising your rights.
14. US State Privacy Rights (CCPA/CPRA and Similar Laws)
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and how it is used, to request access to or deletion of your personal information, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information and of targeted advertising.
We do not sell your personal information and do not share it for cross-context behavioral advertising in exchange for money. To make a request, email hello@inletbase.com. You may use an authorized agent, and we will verify your identity before responding. We will not discriminate against you for exercising your rights.
15. Cookies & Tracking Technologies
We and our providers use cookies and similar technologies to operate the website, remember your preferences, measure performance, and understand usage. Strictly necessary cookies are always active; analytics and marketing cookies are loaded only after you opt in through our cookie banner, and you can change or withdraw your choice at any time via the “Cookie preferences” link in our footer. Full details of the specific cookies we use are set out in our Cookie Policy.
16. Children’s Privacy
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children below the age of consent set by applicable law (for example, under 18 under India’s DPDP Act, or under 16 under the GDPR unless a lower age applies in your jurisdiction). If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
17. Third-Party Links & Services
The Services may link to or integrate with third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy notices.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
19. How to Contact Us
For questions, requests, or complaints regarding this Privacy Policy or our data practices, contact us at hello@inletbase.com. You can also reach us through our contact page.