Data Processing Agreement
How Onbixo processes your end users' personal data on your behalf, as your processor.
17 August 2026 · InkWired Technologies Pvt. Ltd.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", the controller) and InkWired Technologies Pvt. Ltd. ("Onbixo", the processor). It governs our processing of personal data relating to your end users. Where it conflicts with the Terms on the subject of end-user data processing, this DPA prevails.
1. Roles of the parties
For personal data relating to your end users that we process through the Onbixo runtime and APIs, you are the controller and Onbixo is the processor. For data about you as our customer (your account and billing), we are the controller, governed by the Privacy Policy.
2. Scope and your instructions
We process end-user personal data only to provide the service, and only on your documented instructions, which include these terms and your configuration of the product (your flows, targeting rules, and the identify calls you make). We will not use end-user data for our own purposes, and we will not sell it. If we believe an instruction breaches data-protection law, we will inform you.
3. Nature of the processing
| Item | Detail |
|---|---|
| Subject matter | Delivering onboarding flows to your end users and measuring them |
| Duration | For the term of your account, plus the retention windows below |
| Purpose | Targeting, rendering, frequency control, and analytics of your flows |
| Categories of data subject | Your end users (the people who use your application) |
| Categories of personal data | End-user reference/identifier; user and company traits you send; flow events (views, completions, dismissals); server-derived browser, OS, device type, and country |
| Special-category data | None requested by the service. You must not send us special-category data through the identify API. |
4. Confidentiality
We ensure that personnel authorized to process end-user data are bound by confidentiality obligations and access it only as needed to provide the service.
5. Security measures
We implement appropriate technical and organizational measures, including:
- Encryption of data in transit, and encryption at rest at the infrastructure level
- Workspace isolation enforced on our servers, so one customer's end-user data is never accessible to another
- The runtime authenticates with a scoped install token bound to your account and approved domains, and security-relevant details are determined on our side rather than trusted from the browser
- Least-data collection - the runtime collects only what onboarding needs, and the information you send is size-limited
- Access controls, rate limiting, and logging for abuse prevention
6. Sub-processors
You authorize us to engage sub-processors to help provide the service. We impose data-protection obligations on each sub-processor no less protective than this DPA, and we remain responsible for their performance. Our current sub-processors include:
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Application hosting, database, and data storage | United States |
| Cloudflare, Inc. | DNS, TLS, CDN, and DDoS protection (traffic proxy) | Global (US-headquartered) |
| Bunny.net (BunnyWay d.o.o.) | Content delivery network for the runtime bundle and static assets | Global (EU-headquartered) |
| Mailgun (Sinch) | Transactional and lifecycle email delivery | United States |
| Google (Gemini API) | AI-assisted content generation for the optional AI features - processes only the customer content and instructions you submit with an AI action (never end users' personal data); on a paid tier that is not used to train Google's models | Global (US-headquartered) |
| PayPal (default) / Stripe / Paddle | Payment processing (account billing only - never end-user data) | Global |
We will give you reasonable notice of any new or replacement sub-processor that handles end-user data, and you may object on reasonable data-protection grounds. To request the current list, contact [email protected].
7. International transfers
End-user data may be processed in India and in other countries where our sub-processors operate (which may include the United States). Where we transfer personal data of EEA, UK, or Swiss data subjects to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), which are incorporated into this DPA by reference.
8. Assisting you
Taking into account the nature of the processing, we will assist you, by appropriate technical and organizational measures and insofar as possible, to:
- Respond to end users exercising their rights (access, correction, erasure). You can delete a specific end user's data from the dashboard, and we honor deletion requests within the retention window.
- Meet your obligations for security, breach notification, and data-protection impact assessments.
9. Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting your end users' data, and provide the information you reasonably need to meet your own notification obligations.
10. Return and deletion of data
End-user profiles and events are retained for a rolling window for analytics and targeting, then purged. On request, we delete a specific end user's data. When you delete your account, we delete your end users' data within 30 days, except where retention is required by law or for a short period in routine backups, after which it is overwritten.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for audits limited to our processing of your end-user data. Where available, we may satisfy audit requests by providing relevant certifications or reports.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.
13. Contact
For any matter relating to this DPA, contact us:
- Company: InkWired Technologies Pvt. Ltd.
- Address: C-101, Mahesh Nagar, Jaipur, Rajasthan, Pin Code - 302015, India
- Email: [email protected]