Data Processing Addendum
CCPA / TDPSA / VCDPA-compliant processor terms, sub-processor list, breach notice, residency, deletion windows.
Inscendo: Data Processing Addendum (DPA)
Effective Date: June 26, 2026 Version: 1.4 (August 29, 2026 — Backblaze, Inc. added to the § 6.2 Sub-Processor table as off-site immutable backup storage, United States, posted before any Customer Data is stored with it (§ 6.3); new § 8.1(j) discloses that restoration from a backup after a failure may not recover data written after the most recent recovery point and commits Inscendo to notify affected Customers of the recovery point used; § 12.1 now states that any off-site immutable backup copy is retained for a fixed period not exceeding ninety (90) days and cannot be deleted earlier by anyone, including Inscendo, so the Privacy Policy § 5 backup-retention ceiling is confirmed rather than changed. No recovery-time or recovery-point objective is promised. No change to roles, data residency (§ 11, United States only), or any Customer obligation. Version 1.3, August 6, 2026 — Cloudflare and GoDaddy sub-processor entries describe the domains generically rather than naming one; no change to the sub-processor list, its roles, or data residency) Provider ("Processor"): Inscendo Automation Inc., a Texas corporation Customer ("Controller"): the entity entering into the Inscendo Master Subscription Agreement
This Data Processing Addendum ("DPA") supplements and forms part of the Inscendo Master Subscription Agreement ("MSA") and applies whenever Inscendo processes Personal Information on Customer's behalf in connection with the Service. In the event of conflict between this DPA and the MSA on data-protection matters, this DPA controls. Capitalized terms not defined here have the meanings given in the MSA.
The Service is offered exclusively to U.S.-based businesses (MSA § 2.2). This DPA is drafted to satisfy applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Texas Data Privacy and Security Act ("TDPSA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), the Utah Consumer Privacy Act ("UCPA"), and analogous state statutes in force or in scope at the Effective Date, and is not drafted to satisfy the GDPR, UK GDPR, China PIPL, Brazil LGPD, Quebec Law 25, or other non-U.S. data-protection regimes. Customer represents that Customer does not require Inscendo to comply with any non-U.S. data-protection regime in connection with the Service.
1. Definitions
1.1 "Personal Information" or "PI" means information that identifies, relates to, describes, or is reasonably capable of being associated with a particular natural person or household, as defined under applicable U.S. state privacy law.
1.2 "Sensitive Personal Information" or "SPI" has the meaning given under applicable U.S. state privacy law (e.g., CCPA Cal. Civ. Code § 1798.140(ae)).
1.3 "Customer Personal Information" means PI that Customer submits to the Service, that the Service collects from Customer's End-Users on Customer's behalf, or that the Service generates by processing on Customer's behalf.
1.4 "Service Provider," "Processor," "Sub-Processor," "Controller," "Business," "Consumer," "Sale," "Sharing," "Cross-Context Behavioral Advertising," and "Processing" have the meanings given under applicable U.S. state privacy law.
1.5 "Security Incident" means a confirmed unauthorized acquisition of, access to, disclosure of, or use of Customer Personal Information that compromises the security, confidentiality, or integrity of such Customer Personal Information. Unsuccessful attempts (pings, port scans, defeated login attempts, denial-of-service attacks that did not result in unauthorized access) are not Security Incidents.
2. Roles
2.1 Roles. With respect to Customer Personal Information, Customer is the Business / Controller and Inscendo is the Service Provider / Processor.
2.2 Sub-processor escalation (B2B2C). To the extent Customer acts as a Service Provider / Processor for any third party (for example, Customer's own End-Users), Inscendo acts as a Sub-Processor to Customer with respect to Customer Personal Information attributable to that third party. Customer represents and warrants that Customer has all required authorizations to engage Inscendo as a Sub-Processor in this configuration.
2.3 Inscendo as a Business for limited purposes. Inscendo acts as a Business / Controller in its own right with respect to (a) PI Inscendo collects directly from Customer's authorized users in connection with account administration, billing, identity verification, and Service security; (b) telemetry and metadata used to operate the Service; and (c) aggregated, anonymized, or de-identified data derived from the Service. The Privacy Policy applies to such processing.
3. Scope, Duration, Nature, and Purpose
| Item | Description |
|---|---|
| Subject matter | Provision of the Inscendo service (AI agent orchestration, workflow automation, browser-control extension) |
| Duration | The Subscription Term plus any post-termination retention period under MSA § 4.8 |
| Nature | Hosting, transmission, organization, structuring, storage, retrieval, consultation, processing by AI models, transmission to and from third-party services, deletion |
| Purpose | Performing the MSA, enabling AI agent functionality, supporting Customer Configurations, processing Customer's instructions, and the Permitted Purposes in § 4 |
| Categories of data subjects | Customer's authorized users; Customer's End-Users where Customer chooses to process their PI through the Service; persons whose PI Customer submits |
| Categories of PI | Determined by Customer; may include identifiers (name, email, phone), commercial information, internet activity, geolocation, professional information, content of communications, AI-generated content describing data subjects |
| SPI | Customer is prohibited from processing SPI through the Service (see MSA § 3.2(h) and AUP § 1.7) absent a separate written addendum |
4. Inscendo's Processing Obligations
4.1 Permitted purposes. Inscendo shall process Customer Personal Information only for the following purposes (each a "Permitted Purpose"):
(a) providing, operating, maintaining, supporting, securing, and improving the Service in accordance with Customer's documented instructions (including the MSA, this DPA, and Customer's in-product configuration); (b) detecting, preventing, and investigating Security Incidents and AUP violations; (c) complying with applicable law and lawful requests from government authorities; (d) the Permitted Business Purposes enumerated in CCPA Reg. § 7050(a) (helping ensure security and integrity, debugging, short-term transient use, performing services on behalf of the Business, providing services on behalf of the Business, undertaking internal research for technological development and demonstration, undertaking activities to verify or maintain quality or safety of a service); (e) creating aggregated or de-identified data, which Inscendo may use as set forth in MSA § 4.5; and (f) other purposes Customer expressly authorizes in writing.
4.2 CCPA Service Provider commitments. As required by CCPA Reg. § 7051(a), Inscendo:
(i) shall not Sell or Share Customer Personal Information; (ii) shall not retain, use, or disclose Customer Personal Information outside the direct business relationship with Customer or for any purpose other than the Permitted Purposes specified in § 4.1, including not retaining, using, or disclosing PI for a commercial purpose other than providing the Services; (iii) shall not combine Customer Personal Information with PI received from another source, except as permitted by CCPA Reg. § 7050(b) (security, fraud, debugging, services performed on behalf of the Business); (iv) shall comply with applicable CCPA/CPRA obligations and provide the same level of privacy protection required of a Business under CCPA; (v) shall notify Customer if Inscendo determines it can no longer meet its obligations under CCPA; (vi) shall permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.
4.3 No foundation-model training. Inscendo shall not use Customer Personal Information to train, fine-tune, or evaluate generalized or "foundation" generative AI models. Inscendo's API agreement with its foundation-model provider (and any successor provider) prohibits use of Customer's data sent through Inscendo's commercial tier for foundation-model training; Inscendo will, on Customer's reasonable request, provide a summary of the relevant terms.
4.4 Confidentiality. Inscendo personnel with access to Customer Personal Information are bound by confidentiality obligations.
5. Customer's Obligations
5.1 Lawful basis and notice. Customer represents and warrants that (a) Customer has provided all required notices and obtained all required consents from data subjects to enable the Service to process Customer Personal Information for the Permitted Purposes; (b) Customer has the legal authority and lawful basis to instruct Inscendo to process Customer Personal Information; (c) Customer's instructions comply with applicable law; and (d) Customer's processing through the Service complies with all applicable U.S. federal, state, and local laws.
5.2 No regulated data without addendum. Customer shall not process through the Service any (i) Protected Health Information; (ii) Cardholder Data subject to PCI-DSS; (iii) information regulated under GLBA, FERPA, COPPA, or the FCRA; (iv) biometric identifiers regulated under BIPA, CUBI, or Washington's biometric law; (v) personal information of any individual under 18; (vi) Sensitive Personal Information as defined under applicable U.S. state privacy law; or (vii) classified or export-controlled data, without first executing a separate written addendum with Inscendo.
5.3 No EEA / UK / non-U.S. PI. Customer shall not process through the Service any personal data of any individual located in the European Economic Area, the United Kingdom, Switzerland, the People's Republic of China, the Russian Federation, Brazil, or any other jurisdiction whose data-protection law would impose extraterritorial obligations on Inscendo. If Customer breaches this § 5.3, Customer shall indemnify Inscendo for any resulting fine, penalty, or claim.
5.4 Pass-through (B2B2C). Where Customer makes the Service available to End-Users, Customer shall (a) maintain Customer's own privacy notice and terms of service, no less protective than this DPA, (b) act as the controller (Business) for End-User PI in Customer's relationship with the End-User, and (c) be solely responsible for handling End-User data-subject rights requests from Customer's End-Users; Inscendo will provide reasonable cooperation as set out in § 7.
6. Sub-Processors
6.1 Authorization. Customer authorizes Inscendo to engage Sub-Processors. Inscendo shall (a) impose data-protection obligations on each Sub-Processor that are no less protective than this DPA, (b) remain liable for each Sub-Processor's compliance, and (c) maintain a current list of Sub-Processors at https://inscendoiq.com/trust/subprocessors (the "Sub-Processor List").
6.2 Current Sub-Processors. The following Sub-Processors are engaged as of the Effective Date. The current list is maintained at the Sub-Processor List URL referenced in § 6.1 and supersedes this table if they diverge.
| Sub-Processor | Role | Region |
|---|---|---|
| AI foundation-model provider | Primary AI model provider; processes prompts and generates outputs | United States |
| AI embedding provider | Embedding provider; turns text submitted to memory, document-search, and conversation-search features into search vectors | United States |
| Microsoft Corporation (Azure) | Cloud hosting and infrastructure | United States |
| Postmark (Wildbit, LLC) | Primary transactional and identity email delivery for platform notifications (e.g., account, security, and verification emails) | United States |
| Microsoft Azure Communication Services | Fallback transactional and identity email delivery for platform notifications | United States |
| Stripe, Inc. | Payment processing for Wallet Funds; tokenized card storage | United States |
| Cloudflare, Inc. | Edge networking and reverse proxy; authoritative DNS for the domains Inscendo operates; DDoS protection and rate limiting; edge-based country-level access controls used and/or reserved to support the U.S.-only eligibility rule in MSA § 2.2 and this DPA § 5.3; content-delivery network and edge caching; TLS termination; edge-level request analytics | United States |
| GoDaddy.com, LLC | Domain registrar (authoritative DNS is provided by Cloudflare; registrar only, does not process Customer application data) | United States |
| GitHub, Inc. | Source-code hosting and CI/CD for Inscendo's own platform code; does not, in the ordinary course, store Customer Configurations (which reside in per-tenant platform storage) or Customer Personal Information | United States |
| Backblaze, Inc. | Off-site, immutable (write-once) encrypted backup storage of Customer Data and Customer Configurations for disaster recovery (§ 8.1(j)); each copy is retained for a fixed period not exceeding ninety (90) days and cannot be deleted earlier by anyone, including Inscendo (§ 12.1) | United States |
Customer-configured outbound providers (for example, any SMS, email, voice, chat, or other API provider Customer connects through the Service) act as Sub-Processors only where, and to the extent, Customer chooses to connect and use them; Customer is responsible for the terms governing any such provider it selects.
6.3 Notice of new Sub-Processors. Inscendo may update the Sub-Processor List from time to time and will post material changes to it at the URL in Section 6.1. Customer is responsible for periodically reviewing the Sub-Processor List.
7. Data Subject Rights
7.1 Customer is the responder. Customer is responsible for receiving and responding to data-subject rights requests (right to know, right to delete, right to correct, right to opt out of Sale or Sharing, right to limit use of SPI, right to non-discrimination, and analogous rights under other state laws) from Customer's authorized users and End-Users.
7.2 Inscendo's cooperation. Inscendo shall provide commercially reasonable assistance to enable Customer to respond to data-subject rights requests, including by providing in-product self-service tools where available and, where not available, by responding to Customer's reasonable written requests within a reasonable time. Inscendo may charge reasonable fees for assistance beyond commercially reasonable amounts.
7.3 Direct requests. If a data subject contacts Inscendo directly, Inscendo will (where lawful) refer the data subject to Customer and will not respond on Customer's behalf except as required by law.
8. Security
8.1 Technical and organizational measures. Inscendo maintains administrative, technical, and physical safeguards designed to protect Customer Personal Information, including:
(a) encryption of Customer Personal Information at rest and in transit (TLS 1.2+); (b) logical separation of tenants, including a separate database per tenant, a per-tenant storage container for tenant files, and integration credentials held in a managed secrets vault under per-tenant secret naming with access controls enforced at the application layer. Certain working files (such as capsule source the agent authors) may reside on shared platform storage that is partitioned and access-controlled per tenant rather than on physically separate storage. Inscendo continues to invest in strengthening tenant isolation; however, as with any multi-tenant service, logical separation reduces but does not eliminate the risk of cross-tenant access, and Inscendo does not warrant that isolation is absolute; (c) identity and access management, applying least privilege where implemented; (d) automated secret-redaction in operational/diagnostic telemetry logs (Inscendo does not redact other personal information from such logs); (e) up to thirty (30)-day retention of operational/diagnostic telemetry logs, with rolling deletion (Customer's conversation history and session records are retained as Customer Data per § 12, not on this schedule); (f) network controls and DDoS protection at the edge, and edge-based geographic access controls that Inscendo uses and/or reserves the right to use; (g) regular platform and dependency updates; (h) confidentiality agreements and security-awareness practices for personnel with access to Customer Personal Information; (i) incident-response procedures; (j) backup and restoration: encrypted backup copies of Customer Data and Customer Configurations, which may include an off-site, immutable (write-once) copy held with the Sub-Processor identified for that purpose in § 6.2. Restoration from a backup after a failure returns the Service to the most recent recovery point available to Inscendo, and Customer Data written after that recovery point may not be recovered. Where Inscendo restores Customer's tenant from a backup, Inscendo will notify Customer without undue delay of the recovery point used; where the event that required the restoration is also a Security Incident, § 9 applies in addition. No recovery-time or recovery-point objective is promised by this DPA or the MSA (MSA § 11.2).
8.2 No specific compliance certification. Inscendo does not represent SOC 2, ISO 27001, HIPAA, PCI-DSS, FedRAMP, NIST 800-171, or other certifications absent an executed addendum stating otherwise.
8.3 Customer security obligations. Customer remains responsible for (a) credential security, (b) configuration of access controls and confirmation gates, (c) review of agent activity logs, (d) prompt reporting of suspected Security Incidents, and (e) any Customer-side encryption, redaction, or pseudonymization of inputs.
9. Security Incident Notification
9.1 Notice. In the event of a Security Incident, Inscendo shall notify Customer without undue delay, and in any event no later than seventy-two (72) hours after Inscendo confirms the Security Incident (the "Notice Period"). The Notice Period begins on Inscendo's confirmation, not on initial alert or suspicion.
9.2 Content of notice. To the extent then known, the notice shall describe (a) the nature of the Security Incident, (b) the categories and approximate volume of Customer Personal Information affected, (c) likely consequences, and (d) measures taken or proposed.
9.3 Investigation and mitigation. Inscendo shall investigate, mitigate to the extent within its control, and provide reasonable updates and information necessary for Customer to satisfy Customer's own breach-notification obligations.
9.4 No admission. Notice of a Security Incident is not, and shall not be construed as, an admission of fault, liability, or breach of this DPA.
9.5 Customer is the notifier. Customer is responsible for notifying its own users, End-Users, regulators (state AGs, CPPA, FTC, etc.), and any other party as required by applicable law. Inscendo will provide reasonable cooperation but will not directly notify Customer's End-Users absent express written instruction from Customer or as required by law.
9.6 Customer-caused breach costs (first-party). Where a Security Incident arises from Customer's breach of its Section 5.1 representations, its failure to secure its own credentials or its End-Users' access, or its violation of the AUP or Section 3.2 of the MSA, Customer shall bear the resulting breach-notification, forensic, credit-monitoring, and regulatory-response costs attributable to Customer Personal Information, in addition to Customer's indemnity obligations under the MSA, and notwithstanding the notification-cost allocation elsewhere in this Section 9.
10. Audit
10.1 Information. On reasonable written request and not more often than once per twelve (12) months (except in connection with a confirmed Security Incident or a regulator's request), Inscendo shall provide Customer with reasonable information necessary to demonstrate compliance with this DPA, which may include responses to a written security questionnaire, summaries of policies, and current third-party assessments (where available).
10.2 No on-site audit by default. On-site audits are not permitted absent a separately executed audit addendum. Where required by Customer's regulator, the parties shall negotiate audit terms in good faith.
11. Data Residency
Customer Personal Information is processed and stored in the United States. Inscendo does not commit to processing in any other geography. Customer acknowledges that AI prompts and outputs are transmitted to and processed by Inscendo's AI model provider in the United States.
12. Deletion and Return
12.1 On termination. On termination of the MSA, and on self-service account deletion, Inscendo deletes Customer Personal Information in accordance with MSA § 4.8: a self-service deletion request is subject to a grace period (currently at least seven (7) days) during which it may be cancelled, after which Customer Personal Information is irreversibly purged. Copies may persist in routine backups (including recoverable soft-deleted copies) for a limited additional period that does not exceed the backup-retention window stated in the Privacy Policy (§ 5), subject to legal-hold obligations. Any off-site immutable backup copy kept under § 8.1(j) is written once and is retained for a fixed period not exceeding ninety (90) days from the date it is written; by design it cannot be deleted earlier by anyone, including Inscendo, and it is not retained beyond that period. Customer is responsible for requesting any export it needs before deletion (see § 7 and MSA § 4.8).
12.2 Per-Customer request. During the Subscription Term, Customer may instruct Inscendo to delete specific Customer Personal Information, and Inscendo shall do so within a commercially reasonable time, subject to legal-hold obligations.
13. Liability
13.1 The liability provisions of MSA § 13 (including the cap, exclusions, and carve-outs) apply equally to claims under this DPA, except as required to be more permissive by applicable mandatory law.
13.2 In allocating responsibility for any joint claim under U.S. state privacy law, the parties shall act in good faith proportionate to each party's degree of fault and the harm caused.
14. Conflict; Order of Precedence
In the event of conflict between (a) this DPA, (b) the MSA, (c) any data-protection-specific addendum (such as a HIPAA BAA, where executed), or (d) Customer's general procurement terms: (i) any executed data-protection-specific addendum controls; (ii) this DPA controls over the MSA; (iii) the MSA controls over Customer's procurement terms.
15. Updates
Inscendo may update this DPA from time to time to reflect changes in law, technology, or operations. Material adverse changes will be communicated per MSA § 15.
[End of Data Processing Addendum]