Data Processing Addendum

Effective Date: July 25, 2026
Last Updated: July 25, 2026

This Data Processing Addendum ("DPA") governs personal data that Inferon Techlabs Private Limited ("Inferon", "we", "Processor") processes on behalf of a business customer ("Customer", "you", "Controller") in the course of providing the Services.

It forms part of, and is incorporated into, the agreement between you and us. Where this DPA conflicts with that agreement, this DPA controls for matters of personal data processing.

A countersigned copy is available on request from privacy@inferon.ai.


Index

  1. Definitions
  2. Roles
  3. Scope of Processing
  4. Customer Instructions
  5. Customer Obligations
  6. Confidentiality
  7. Security Measures
  8. Subprocessors
  9. International Transfers
  10. Data Subject Requests
  11. Personal Data Breach
  12. Audits
  13. Deletion and Return
  14. Biometric Data
  15. Liability
  16. Term
  17. Annexes

1. Definitions

"Applicable Data Protection Law" means all laws relating to the processing of personal data that apply to a party, including India's Digital Personal Data Protection Act, 2023, the EU General Data Protection Regulation 2016/679, the UK GDPR, and applicable US state privacy laws.

"Personal Data" means personal data, personal information, or personal data as defined in Applicable Data Protection Law, processed by us on your behalf under the agreement.

"Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. Under India's DPDP Act, "Controller" corresponds to Data Fiduciary, "Processor" to Data Processor, and "Data Subject" to Data Principal.

"Standard Contractual Clauses" means the clauses approved by the European Commission in Decision 2021/914, and, for the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner.


2. Roles

You are the Controller of Personal Data you submit to the Services. We are the Processor, acting on your instructions.

Where you are yourself a processor for another controller, you warrant that you have the authority to appoint us as a subprocessor and to give the instructions in this DPA.

We act as an independent Controller for a limited set of data that we determine the purposes of, namely account and billing records, security and audit logs, and aggregated usage statistics used to operate and improve the Services. That processing is governed by our Privacy Policy rather than this DPA.


3. Scope of Processing

Subject matter: Provision of the AI content generation Services under the agreement.

Duration: The term of the agreement, plus the deletion period in Section 13.

Nature and purpose: Hosting, storing, transmitting, and processing Customer content in order to authenticate users, generate Outputs through our own and third-party models, store the results, apply safety and moderation controls, meter usage, and provide support.

Types of Personal Data: As set out in Annex A.

Categories of Data Subjects: As set out in Annex A.


4. Customer Instructions

We process Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law. Where a legal requirement compels other processing, we will inform you before processing unless the law prohibits it on important grounds of public interest.

Your use of the Services, together with the agreement and this DPA, constitutes your complete documented instructions. Additional instructions require written agreement and may attract additional charges where they require work outside the scope of the Services.

We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.


5. Customer Obligations

You are responsible for:

  • Ensuring you have a lawful basis for the processing you instruct
  • Providing the notices and obtaining the consents your Data Subjects' law requires
  • The accuracy, quality, and legality of the Personal Data you submit
  • Configuring workspace membership, roles, and retention appropriately
  • Responding to Data Subject requests, with our assistance under Section 10
  • Not submitting Personal Data outside the categories described in Annex A without agreement, and in particular not submitting special category or sensitive data beyond what the Services are designed to handle

6. Confidentiality

We ensure that personnel authorized to process Personal Data are bound by confidentiality obligations, receive appropriate data protection training, and are granted access only to the extent necessary for their role.


7. Security Measures

We implement and maintain the technical and organizational measures described in Annex B, taking into account the state of the art, implementation cost, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.

We may update these measures over time provided the level of protection is not materially reduced. Our current practices are described in our Security Policy.


8. Subprocessors

You grant general authorization for us to engage subprocessors.

Our current subprocessors are published at Subprocessors, which forms part of this DPA.

We will:

  • Give you 30 days' advance notice before engaging a new subprocessor, where you have subscribed to notifications
  • Impose data protection obligations on each subprocessor that are no less protective than those in this DPA
  • Remain fully liable to you for the performance of each subprocessor's obligations

You may object to a new subprocessor on reasonable data protection grounds within the notice period. We will work with you in good faith to find a resolution. If we cannot, you may terminate the affected Services without penalty, with a pro-rata refund of prepaid fees for the unused period.


9. International Transfers

We are established in India and our subprocessors operate in several jurisdictions, so Personal Data is transferred internationally.

Where you transfer Personal Data subject to the GDPR to us, or where we onward-transfer it, the Standard Contractual Clauses apply and are incorporated into this DPA by reference:

  • Module Two (controller to processor) applies where you are a controller.
  • Module Three (processor to processor) applies where you are a processor.
  • The governing law and forum are those of Ireland, unless the agreement specifies another EU member state.
  • Annex A of this DPA populates Annex I of the Clauses; Annex B populates Annex II.
  • For UK transfers, the UK International Data Transfer Addendum applies, with the information tables completed by reference to those annexes.

We conduct transfer impact assessments where required and will provide the relevant documentation on request.


10. Data Subject Requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to Data Subject requests.

The Services provide self-service functionality for access, correction, export, and deletion. Where a request cannot be fulfilled through the Services, we will provide reasonable assistance.

If we receive a request directly from your Data Subject, we will not respond to it substantively, and will promptly refer the individual to you, unless legally required to respond.


11. Personal Data Breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.

The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available immediately, we will provide information in phases as the investigation progresses.

We will assist you in meeting your own notification obligations to supervisory authorities and Data Subjects.

Our notification is not an acknowledgement of fault or liability.


12. Audits

We will make available all information reasonably necessary to demonstrate compliance with this DPA.

We will satisfy audit requests in the first instance by providing our security documentation, subprocessor list, and responses to reasonable questionnaires, as described in Compliance.

Where that is insufficient to meet a requirement of Applicable Data Protection Law, you may conduct an audit, subject to the following: no more than once in any twelve-month period unless required by a supervisory authority or following a Personal Data Breach; on at least 30 days' written notice; during business hours; without unreasonable disruption; subject to confidentiality; and at your cost. Audits may not include access to other customers' data or to systems in a way that would compromise their security.


13. Deletion and Return

On termination or expiry of the agreement, we will make Customer content available for export for 30 days.

After that period we will delete Personal Data processed on your behalf, and will procure that our subprocessors do the same, except where retention is required by law. Content deleted from active systems is purged from backups within 90 days.

We will confirm deletion in writing on request.


14. Biometric Data

Where the Services process biometric data supplied by you or your end users, the following apply in addition.

  • You are the Controller of that data and are responsible for obtaining every consent required by the Data Subject's law, including any written release required by the Illinois Biometric Information Privacy Act or an equivalent statute.
  • You warrant that you have obtained those consents and will produce evidence of them on request.
  • We process biometric data solely to deliver the requested feature, and never to identify individuals, build identification databases, or train general-purpose models.
  • We do not sell, lease, or otherwise profit from biometric data.
  • We apply the retention and destruction schedule in our Biometric Data Policy, including the three-year outer limit, unless your agreement specifies a shorter period.
  • You must not submit biometric data concerning a minor.

15. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the agreement.

Nothing in this DPA limits either party's liability to a Data Subject under Applicable Data Protection Law, or the rights of Data Subjects under the Standard Contractual Clauses.


16. Term

This DPA takes effect when the agreement takes effect and continues until we have deleted all Personal Data processed on your behalf in accordance with Section 13.


17. Annexes

Annex A — Details of Processing

Categories of Data Subjects

  • Customer's personnel and authorized users
  • Customer's own customers and end users, where their data is submitted to the Services
  • Individuals depicted in images, video, or audio submitted to the Services

Types of Personal Data

  • Identity and contact data: name, email address, username, organization
  • Account data: role, workspace membership, authentication events
  • Content data: prompts, uploaded images, video, audio, documents, and generated Outputs
  • Media metadata: capture time, device information, and other metadata embedded in uploaded files
  • Usage data: generation history, credits consumed, API usage, IP address, device and browser information
  • Support data: correspondence and its contents

Special Category or Sensitive Data

Biometric data in the form of facial geometry templates and voice models, derived from material submitted for avatar, lip-sync, and voice features. Processing is subject to Section 14 and our Biometric Data Policy.

Customer must not submit other special category data.

Frequency: Continuous, for the duration of the agreement.

Retention: As set out in Section 13 and in our Privacy Policy.

Annex B — Technical and Organizational Measures

  • Encryption. TLS for all data in transit, including to model providers. Encryption at rest for object storage and databases. Encrypted secret management.
  • Access control. Least privilege, tied to named individuals, reviewed periodically and on role change or departure. Multi-factor authentication. Single sign-on for enterprise customers.
  • Logical separation. Customer data separated by organization and workspace, with access enforced at the application layer.
  • Logging and monitoring. Audit logging of administrative actions, security monitoring and alerting, error and anomaly detection.
  • Resilience. Encrypted backups with defined retention, and documented recovery procedures.
  • Vulnerability management. Dependency monitoring, prioritized remediation of critical issues, and a published responsible disclosure process with researcher safe harbour.
  • Incident response. Defined process covering investigation, containment, restoration, notification, and post-incident review.
  • Personnel. Confidentiality obligations, data protection training, and access provisioning tied to role.
  • Subprocessor management. Written agreements imposing equivalent obligations, and a published subprocessor list with advance notice of changes.
  • Deletion. Defined retention schedules, deletion on request, and purging of backups within 90 days.

These measures are described more fully in our Security Policy.