Agreement

Data Processing Agreement

The terms on which we process personal data on your behalf. It binds us from the moment you create an account — there is nothing to request and nothing to sign.

Version
2.0
Effective
10 September 2026
Precedence
2 of 5

Read clauses 6 and 17 first

This document is written against the system we actually run, so two of its clauses say things a template DPA would not. Model providers receive your content on every answered message and it cannot be switched off. And there is no choice of data region — none, on any plan.

If either is a problem for you, it is better to find out now, from this page, than during an audit.

1.Parties, and how this becomes binding

This Data Processing Agreement is between you (the Controller) and integrable.cloud (the Processor). It forms part of the Terms of Service and applies whenever you process personal data through the Service.

You do not have to sign anything

This DPA binds us from the moment you create an account. There is no form to request, no plan you have to be on, and no sales conversation in the way. If your procurement process needs a counter-signed copy, or needs to be on your own paper, email legal@integrable.cloud and we will read yours rather than insisting on ours.

Where this DPA conflicts with the Terms of Service, this DPA wins on anything concerning personal data. Where it conflicts with the Standard Contractual Clauses, the Clauses win.

2.Definitions

Data Protection Law
Every law applicable to the processing under this DPA — including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, India's Digital Personal Data Protection Act 2023, and US state privacy laws.
Customer Personal Data
Personal data contained in Your Content, or processed by an assistant on your behalf — principally what the people who talk to your assistants type, and what you configure it to collect.
SCCs
The Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
UK Addendum
The International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
Controller, Processor, Subprocessor, Data Subject, Personal Data Breach, Supervisory Authority
Each has the meaning given in the GDPR. Data Fiduciary, Data Processor and Data Principal have the meanings given in India's DPDP Act.

3.Roles

DataYou areWe are
Everything your assistants process about the people who talk to themController / Data FiduciaryProcessor / Data Processor
Your own account, billing and support dataData subjectController — governed by the Privacy Policy, not this DPA

Where you are yourself a processor acting for someone else — an agency running assistants for clients — we are a subprocessor, and Module Three of the SCCs applies instead of Module Two.

4.Our instructions

We process Customer Personal Data only on your documented instructions, including for transfers to a third country, unless required otherwise by a law we are subject to — in which case we will tell you before processing, unless that law prohibits it on important grounds of public interest.

Your instructions are:

  • The Terms of Service and this DPA
  • How you configure your workspace, assistants, integrations and lead destinations
  • Your use of the API and the dashboard
  • Any further written instruction we accept in writing at legal@integrable.cloud

We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to give you legal advice, and we may decline an instruction that would put us in breach.

5.Purpose and limits

We process Customer Personal Data solely to provide the Service: answering questions your visitors ask, capturing leads, making the bookings you have configured, delivering leads to the destinations you have connected, producing your dashboard analytics, and maintaining security and availability. We do not process it for our own purposes, we do not sell it, we do not share it for advertising, and we do not combine it with data from other sources.

6.Model providers — read this one

A transfer happens on every answered message

Answering a question requires sending the visitor’s message and the retrieved passages from your content to a model provider. This is a disclosure of Customer Personal Data to a subprocessor, it happens on every answered message, and it is inherent to what the product is rather than a feature you can switch off.

The providers are named in the subprocessor list, and what they receive and retain is set out in the AI transparency statement. If your obligations do not permit this, the product is not suitable for you, and we would rather you knew that from this page than from an audit.

7.No training on your data

Customer Personal Data and Your Content are not used to train, fine-tune or evaluate any AI model — not by us, and not by our model providers, whose commercial terms with us prohibit it. This is a contractual commitment, not a setting, and it does not change between plans.

8.Subprocessors

You give general written authorisation for us to engage subprocessors. The current list is maintained at subprocessors, split into those always in the path and those that receive data only if you connect them. That list forms Annex III to the SCCs.

We will give you at least 30 days’ notice by email before adding or replacing a subprocessor. If you reasonably object on data protection grounds within that period, tell us and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of the unused period, without penalty.

We impose data protection terms on every subprocessor that are no less protective than this DPA, and we remain fully liable to you for their performance.

9.Security

We implement and maintain the technical and organisational measures in Annex II, taking account of the state of the art, the cost of implementation, and the risk to data subjects.

We may update those measures, provided the level of protection does not decrease. What we do not have — the certifications we hold none of — is stated at compliance, and is part of this disclosure rather than a marketing omission.

10.Personnel

Access to production data is limited to people who need it to operate the Service, is protected by multi-factor authentication, and is logged. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement.

11.Helping you answer data subjects

The dashboard lets you search, export and delete workspace data yourself, which is the fastest route for most requests and needs nothing from us.

Where a request needs our help, we will provide it within a reasonable period and at no additional charge, taking account of the nature of the processing. If a data subject contacts us directly about data we process for you, we will not respond substantively — we will tell them to contact you, and forward the request to you within one business day.

12.Helping you meet your own obligations

Taking account of the nature of processing and the information available to us, we will assist you in complying with Articles 32 to 36 of the GDPR — security, breach notification to authorities and to data subjects, data protection impact assessments, and prior consultation. The vendor questionnaire answers most DPIA inputs in advance so you do not have to ask.

13.Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We will not wait until we understand it fully — the first notification will be sent with what we know at the time, and updated as we learn more.

Each notification will describe, so far as we can:

  • the nature of the breach, and the categories and approximate number of data subjects and records affected
  • the likely consequences
  • the measures we have taken or propose to take, including to mitigate harm
  • a contact point for more information

Affected workspaces are emailed directly rather than left to discover it on a status page. We also publish customer-affecting security incidents within 72 hours of confirming them — see incidents.

Notifying your supervisory authority within your 72-hour deadline remains your responsibility as controller. Our job is to get you the facts in time to do it.

14.Deletion and return

You can export or delete Customer Personal Data at any time from the dashboard or the API, during the term and during any suspension.

After termination, your data remains available for export for 30 days, then we delete it and instruct our subprocessors to do the same. The 30-day window exists so that an account closed by mistake can be recovered. After it, deletion is permanent.

We retain data beyond that only where a law requires it — principally billing records, which Indian tax legislation requires us to keep for seven years. Anything retained on that basis stays subject to this DPA and is not processed for any other purpose.

15.Audits and information

We will make available all information reasonably necessary to demonstrate compliance with this DPA, and answer reasonable written questions about our processing. The vendor questionnaire answers most of them in advance.

We do not have a third-party audit report, because none exists. We are not SOC 2 or ISO 27001 certified, and we will not send you a report from a framework we have not been assessed against. Where an audit is required by Data Protection Law, we will agree a reasonable scope, timing and confidentiality arrangement with you, no more than once a year unless a supervisory authority requires otherwise or a breach has occurred.

16.International transfers, and the clauses we rely on

There is no choice of region

Data is stored and processed in a single region, and model inference happens wherever the provider operates. We do not offer regional hosting, EU-only processing, or data residency in any jurisdiction. If your obligations require it, we cannot meet them today — see data residency.

Where you transfer Customer Personal Data from the EEA, the UK or Switzerland to us, the following apply and are incorporated into this DPA by reference:

InstrumentModule and options selected
EU SCCs (Decision 2021/914)Module Two (controller to processor), or Module Three (processor to processor) where you are yourself a processor. Clause 7 (docking) applies. Clause 9(a) Option 2, general written authorisation, with the 30-day notice period in clause 8 above. Clause 11(a) optional independent dispute resolution does not apply. Clause 17 Option 1, governed by the law of Ireland. Clause 18(b), the courts of Ireland. Annexes I, II and III are below.
UK Addendum (IDTA Addendum, version B1.0)Applies to UK transfers. Tables 1 to 3 are populated by the Annexes below; in Table 4, neither party may end the Addendum as set out in Section 19.
SwitzerlandThe SCCs apply with references to the GDPR read as references to the FADP, the Federal Data Protection and Information Commissioner as supervisory authority, and Swiss law and courts where the transfer is governed by the FADP.

We have carried out a transfer impact assessment covering the laws of the destination countries, including Indian government access powers under the Information Technology Act, and the supplementary measures that mitigate them — per-tenant envelope encryption and database row-level security, described at security architecture. It is available on request. If we become unable to comply with the SCCs we will tell you promptly, and you may suspend transfers or terminate.

17.India — DPDP Act terms

Where you are a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023, this DPA is the valid contract required by section 8(2) of that Act for engaging a Data Processor.

  • We process personal data only on your behalf and under this contract.
  • We implement reasonable security safeguards as required by section 8(5).
  • We will assist you in intimating the Data Protection Board of India and affected Data Principals of a personal data breach, and we will notify you in time for you to do so.
  • We will erase personal data on your instruction, or when you tell us the purpose is served, in line with clause 15.
  • We will not engage a further processor except as permitted by clause 8.

Transfers of personal data outside India are permitted under section 16 except to countries the Central Government restricts by notification. We monitor that list and will tell you if a restriction affects the Service.

18.United States — service provider addendum

This clause applies where you are subject to the California Consumer Privacy Act as amended, or to a comparable law in Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana or another US state. We act as your service provider or processor as those laws define the term. We certify that we:

  • do not sell personal information, and do not share it for cross-context behavioural advertising
  • do not retain, use or disclose personal information for any purpose other than performing the Service specified in this DPA, or as otherwise permitted by those laws
  • do not retain, use or disclose it outside the direct business relationship between us
  • do not combine it with personal information received from another source, except as those laws permit
  • will notify you if we determine we can no longer meet these obligations, and will let you take reasonable steps to stop and remediate unauthorised use
  • understand these restrictions and will comply with them

You may take reasonable and appropriate steps to confirm we are using personal information consistently with your obligations — clause 14 describes how.

19.Liability, term and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in clause 16 of the Terms of Service, except where Data Protection Law does not permit it. Nothing here limits a data subject’s rights under the SCCs.

This DPA takes effect when you create an account and continues for as long as we process Customer Personal Data for you. Clauses that by their nature should survive — confidentiality, deletion, liability — do.

20.Annex I — description of the processing

A. Parties. Data exporter: you, the Controller, whose identity and contact details are those on your account. Data importer: integrable.cloud, India, contact privacy@integrable.cloud. Activities relevant to the transfer: providing the Service.

B. Description of transfer.

ItemDetail
Categories of data subjectVisitors to your website and other people who talk to your assistants; your own team members who use the dashboard.
Categories of personal dataMessage content; name, email address and phone number where a visitor provides them; booking details; an anonymous visitor identifier; IP address, user agent, page URL and referrer; account and authentication data for your team.
Special category dataNone is intentionally processed. You must not configure an assistant to collect it, and the Acceptable Use Policy prohibits it. A visitor may nonetheless type anything into a chat box; where that happens it is processed under the same measures as all other message content and is not treated differently, which is a reason to design your assistant not to invite it.
FrequencyContinuous, for as long as your assistants are deployed.
Nature of processingCollection, storage, retrieval, embedding and indexing, transmission to model providers to generate an answer, transmission to lead destinations and calendars you connect, analysis for dashboard analytics, and erasure.
PurposeProviding the Service, as set out in clause 5.
RetentionAs set out in clause 15 and the retention schedule in the Privacy Policy.
Subprocessor transfersSubject matter, nature and duration as described in the subprocessor list.

C. Competent supervisory authority. The supervisory authority of the Member State in which your EU representative is established, or in which the data subjects whose data is transferred are located.

21.Annex II — technical and organisational measures

Described here rather than as a list of adjectives, because Annex II is where a template DPA is easiest to spot. The mechanisms and their limits are set out in full at security architecture.

MeasureHow it is implemented
Tenant isolationEnforced by PostgreSQL row-level security inside the database engine, not in application code. A query that omits its tenant filter returns nothing rather than everything.
Encryption at restPer-tenant envelope encryption. Each workspace has its own data encryption key and a separate index key; credentials for connected accounts are sealed with the workspace key.
Encryption in transitTLS throughout, between clients and the API and between the API and every subprocessor.
Access controlProduction access limited to personnel who need it, protected by multi-factor authentication, and logged.
PseudonymisationWebsite visitors are identified by an anonymous identifier rather than by an account.
Abuse and availabilityRate limiting and quotas per workspace; bot protection on the public chat endpoint.
Logging and monitoringApplication and access logs retained for 180 days, in line with the CERT-In Directions 2022.
Data minimisationAn assistant collects only what you configure it to collect. The product defaults to asking for less.
DeletionDeleting a knowledge base source removes its embeddings in the same operation. Deletion is immediate rather than a soft flag.
CertificationsNone. We hold no SOC 2, ISO 27001 or equivalent certification, and we say so rather than implying otherwise.

22.Annex III — subprocessors

The authorised subprocessors are those listed at subprocessors at any given time, which forms Annex III to the SCCs and is incorporated by reference. That page states what each one does and whether it is in the path always or only if you connect it. Changes are notified under clause 8.

See what it drafts from your site. Free to start, no card, live in minutes.

Start free