Data Processing Agreement
Version 1.0, effective 30 September 2026 · History
In short
- When you put other people's data into InksForm (customer lists, contacts, photos of people), you're the controller and we're your processor.
- We process it only on your instructions, keep it confidential and secure, and use only the listed sub-processors.
- We tell you 30 days before adding a sub-processor, and you can object.
- This agreement applies automatically when you use InksForm. No signature is needed.
Parties and scope
This agreement is between you (the customer, "controller") and SIA Inksform (InksForm, "processor"). It forms part of the Terms of Service and applies whenever we process personal data on your behalf, for example contact lists, customer details or photos of people you upload, and personal data in the documents, sheets, sites, chats and messages you create.
Details of the processing
- Subject matter and duration: providing the service, for as long as your account is open, plus the deletion period below.
- Nature and purpose: storing, organising, displaying, sharing at your request, and processing with our AI providers the data you put into your work, so the features you use work.
- Types of data: contact details, photos and voices of people, messages, and any other data you choose to put in.
- Data subjects: people whose data you put into your work, for example your customers, contacts, team members and people in your photos.
Our obligations
- Process the data only on your documented instructions, including for transfers outside the EU/EEA (these terms and your use of the features), unless the law requires otherwise, in which case we tell you first where allowed.
- Tell you immediately if we think an instruction breaks data protection law.
- Make sure everyone who can access it is bound by confidentiality.
- Keep appropriate technical and organisational security measures: encryption in transit and at rest, access control through database row-level security, least-privilege staff access, logging, and daily database backups.
- Help you answer data subjects' requests (download and delete tools, and help from us on request), and help with security, breach notification and impact assessments where needed.
- Tell you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data.
- Delete or return the data when you delete it or close your account (within 30 days, and 35 days for backups), unless the law requires us to keep it.
- Make available the information needed to show compliance, and allow audits, including inspections by you or an auditor you mandate, on reasonable notice; we normally start with written answers and reports.
Sub-processors
You authorise us to use the sub-processors listed below. We bind each one to data protection terms at least as protective as these, and we stay responsible for them.
- Supabase
Database, sign-in and file storage
- Data
- Account details, everything you create or upload, usage and credits
- Where
- EU (Ireland)
- Safeguards
- Data stays in the EU; Standard Contractual Clauses for support access
- Vercel
Hosting the app and running its server functions
- Data
- Requests, IP addresses, technical logs
- Where
- EU functions (Ireland), global edge network
- Safeguards
- EU–US Data Privacy Framework and Standard Contractual Clauses
- Anthropic (Claude API)
Writing, code, assistant and research with Claude
- Data
- Prompts, the pictures and documents you choose to use, conversations with the assistant, generated text and code
- Where
- United States
- Safeguards
- Standard Contractual Clauses (Anthropic's Data Processing Addendum). API data is not used to train Anthropic's models and is deleted within 30 days (up to 2 years if flagged as misuse)
- Google (Gemini API, Veo)
Generating and editing images and video, and reading audio and video you add
- Data
- Prompts, the files you choose to use, generated results
- Where
- United States and other Google locations
- Safeguards
- EU–US Data Privacy Framework and Standard Contractual Clauses. Paid API data is not used to train Google's models
- ElevenLabs
Voice, music, sound effects and transcription, live captions and call transcripts
- Data
- Text to speak, audio you record or upload; in calls, the voice of whoever is speaking while captions or notes are on
- Where
- United States and EU
- Safeguards
- Standard Contractual Clauses
- Stripe
Payments for plans and credit packs: checkout, subscriptions, receipts, refunds and fraud checks
- Data
- Name, email, billing address, payment method (card details go straight to Stripe, never to us), what you bought and when
- Where
- EU (Ireland) and United States
- Safeguards
- EU–US Data Privacy Framework and Standard Contractual Clauses (Stripe's Data Processing Agreement)
- LiveKitPlanned, not yet in use
Carrying the audio, video and shared screens of calls through its media servers, once our call server is switched on (until then calls go straight between devices)
- Data
- Call audio and video while in transit (not recorded or stored), participant names and technical connection data
- Where
- EU and global edge network (LiveKit Cloud)
- Safeguards
- Standard Contractual Clauses
- CloudflarePlanned, not yet in use
Hosting published websites, spam protection on forms
- Data
- Published site files, visitor requests, form submissions
- Where
- EU and global edge network
- Safeguards
- EU–US Data Privacy Framework and Standard Contractual Clauses
- ResendPlanned, not yet in use
Sending sign-in, notification and receipt emails
- Data
- Email address, email content
- Where
- United States
- Safeguards
- Standard Contractual Clauses
- SentryPlanned, not yet in use
Error reports so we can fix problems
- Data
- Technical error details with personal data removed where possible
- Where
- EU (Germany)
- Safeguards
- Data stays in the EU
We list a new or replaced sub-processor at least 30 days before it starts on the Sub-processors page, where you can subscribe to updates. If you object on reasonable data protection grounds and we can't resolve it, you may end the affected service and get a refund of prepaid, unused fees.
International transfers
Where a sub-processor processes data outside the EU/EEA, the transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
Your responsibilities
You make sure you have a lawful basis to put the data into InksForm, give the people concerned the information they need (for example the privacy notice on your website), and only instruct processing that is lawful.
Order of precedence
If this agreement conflicts with the Terms of Service on personal data, this agreement wins.