Legal

Data Processing Agreement

Version 1.0, effective 30 September 2026 · History

In short

  • When you put other people's data into InksForm (customer lists, contacts, photos of people), you're the controller and we're your processor.
  • We process it only on your instructions, keep it confidential and secure, and use only the listed sub-processors.
  • We tell you 30 days before adding a sub-processor, and you can object.
  • This agreement applies automatically when you use InksForm. No signature is needed.

Parties and scope

This agreement is between you (the customer, "controller") and SIA Inksform (InksForm, "processor"). It forms part of the Terms of Service and applies whenever we process personal data on your behalf, for example contact lists, customer details or photos of people you upload, and personal data in the documents, sheets, sites, chats and messages you create.

Details of the processing

  • Subject matter and duration: providing the service, for as long as your account is open, plus the deletion period below.
  • Nature and purpose: storing, organising, displaying, sharing at your request, and processing with our AI providers the data you put into your work, so the features you use work.
  • Types of data: contact details, photos and voices of people, messages, and any other data you choose to put in.
  • Data subjects: people whose data you put into your work, for example your customers, contacts, team members and people in your photos.

Our obligations

  • Process the data only on your documented instructions, including for transfers outside the EU/EEA (these terms and your use of the features), unless the law requires otherwise, in which case we tell you first where allowed.
  • Tell you immediately if we think an instruction breaks data protection law.
  • Make sure everyone who can access it is bound by confidentiality.
  • Keep appropriate technical and organisational security measures: encryption in transit and at rest, access control through database row-level security, least-privilege staff access, logging, and daily database backups.
  • Help you answer data subjects' requests (download and delete tools, and help from us on request), and help with security, breach notification and impact assessments where needed.
  • Tell you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data.
  • Delete or return the data when you delete it or close your account (within 30 days, and 35 days for backups), unless the law requires us to keep it.
  • Make available the information needed to show compliance, and allow audits, including inspections by you or an auditor you mandate, on reasonable notice; we normally start with written answers and reports.

Sub-processors

You authorise us to use the sub-processors listed below. We bind each one to data protection terms at least as protective as these, and we stay responsible for them.

  • Supabase

    Database, sign-in and file storage

    Data
    Account details, everything you create or upload, usage and credits
    Where
    EU (Ireland)
    Safeguards
    Data stays in the EU; Standard Contractual Clauses for support access
  • Vercel

    Hosting the app and running its server functions

    Data
    Requests, IP addresses, technical logs
    Where
    EU functions (Ireland), global edge network
    Safeguards
    EU–US Data Privacy Framework and Standard Contractual Clauses
  • Anthropic (Claude API)

    Writing, code, assistant and research with Claude

    Data
    Prompts, the pictures and documents you choose to use, conversations with the assistant, generated text and code
    Where
    United States
    Safeguards
    Standard Contractual Clauses (Anthropic's Data Processing Addendum). API data is not used to train Anthropic's models and is deleted within 30 days (up to 2 years if flagged as misuse)
  • Google (Gemini API, Veo)

    Generating and editing images and video, and reading audio and video you add

    Data
    Prompts, the files you choose to use, generated results
    Where
    United States and other Google locations
    Safeguards
    EU–US Data Privacy Framework and Standard Contractual Clauses. Paid API data is not used to train Google's models
  • ElevenLabs

    Voice, music, sound effects and transcription, live captions and call transcripts

    Data
    Text to speak, audio you record or upload; in calls, the voice of whoever is speaking while captions or notes are on
    Where
    United States and EU
    Safeguards
    Standard Contractual Clauses
  • Stripe

    Payments for plans and credit packs: checkout, subscriptions, receipts, refunds and fraud checks

    Data
    Name, email, billing address, payment method (card details go straight to Stripe, never to us), what you bought and when
    Where
    EU (Ireland) and United States
    Safeguards
    EU–US Data Privacy Framework and Standard Contractual Clauses (Stripe's Data Processing Agreement)
  • LiveKitPlanned, not yet in use

    Carrying the audio, video and shared screens of calls through its media servers, once our call server is switched on (until then calls go straight between devices)

    Data
    Call audio and video while in transit (not recorded or stored), participant names and technical connection data
    Where
    EU and global edge network (LiveKit Cloud)
    Safeguards
    Standard Contractual Clauses
  • CloudflarePlanned, not yet in use

    Hosting published websites, spam protection on forms

    Data
    Published site files, visitor requests, form submissions
    Where
    EU and global edge network
    Safeguards
    EU–US Data Privacy Framework and Standard Contractual Clauses
  • ResendPlanned, not yet in use

    Sending sign-in, notification and receipt emails

    Data
    Email address, email content
    Where
    United States
    Safeguards
    Standard Contractual Clauses
  • SentryPlanned, not yet in use

    Error reports so we can fix problems

    Data
    Technical error details with personal data removed where possible
    Where
    EU (Germany)
    Safeguards
    Data stays in the EU

We list a new or replaced sub-processor at least 30 days before it starts on the Sub-processors page, where you can subscribe to updates. If you object on reasonable data protection grounds and we can't resolve it, you may end the affected service and get a refund of prepaid, unused fees.

International transfers

Where a sub-processor processes data outside the EU/EEA, the transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.

Your responsibilities

You make sure you have a lawful basis to put the data into InksForm, give the people concerned the information they need (for example the privacy notice on your website), and only instruct processing that is lawful.

Order of precedence

If this agreement conflicts with the Terms of Service on personal data, this agreement wins.