GDPR statement
How Onbixo complies with the EU and UK General Data Protection Regulation.
17 August 2026 · InkWired Technologies Pvt. Ltd.
1. Our roles
If you are in the EEA, UK, or Switzerland, the GDPR (or UK GDPR) applies to how Onbixo handles personal data. Our role depends on the data:
- Controller for your account and billing data - we decide how it is used. See the Privacy Policy.
- Processor for your end users' data - we process it on your instructions. See the Data Processing Agreement.
InkWired Technologies Pvt. Ltd., registered in India, is the responsible legal entity.
2. Lawful bases for processing
For your account data, we rely on:
- Contract performance - to provide the service you signed up for.
- Legitimate interest - security, fraud prevention, and product improvement, balanced against your rights.
- Consent - for optional analytics cookies on the marketing site.
- Legal obligation - tax and invoicing records.
For end-user data, the lawful basis is determined by you as the controller; we process it only on your instructions.
3. Your rights (as our customer)
You have the right to access, rectification, erasure, restriction, portability, and to object to processing. To exercise a right, email [email protected]; we respond within 30 days. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
4. Rights of your end users
Your end users' rights are exercised through you, the controller. If an end user contacts us directly, we will refer them to the relevant customer. As your processor, we assist you in responding to those requests - for example, you can delete a specific end user's data from the dashboard, and we honor deletion requests within the retention window.
5. International transfers
Personal data may be transferred to and processed in India and other countries where our providers operate, including the United States. For transfers of EEA, UK, or Swiss personal data to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) as appropriate safeguards. You can request a copy at [email protected].
6. Sub-processors
We engage sub-processors under written terms no less protective than our own obligations, and remain responsible for their performance. The current list of sub-processors handling end-user data is available in the DPA, and we give notice of changes so you can object on reasonable grounds.
7. AI features and automated decision-making
Our optional AI features (the OnbiAI assistant and in-editor AI shortcuts) use a third-party AI provider as a sub-processor to generate drafts from the content and instructions you submit. They do not make any decision that produces legal or similarly significant effects on an individual: every AI output is a suggestion a human reviews and approves, so there is no solely automated decision-making within the meaning of Article 22 GDPR.
We send only your own content to the AI provider (flow text, your natural-language instructions, trait/event key names, and aggregate funnel figures) - never your end users' personal data. On the provider's paid tier your data is not used to train its models. What is and is not sent is detailed in the Privacy Policy, and the provider is listed in the DPA.
8. Breach notification
In the event of a personal data breach that poses a risk to individuals' rights, we will notify the relevant supervisory authority within 72 hours where we are the controller, and inform affected users where the risk is high. Where we are your processor, we notify you without undue delay so you can meet your own obligations.
9. Contact and complaints
For GDPR requests or questions, contact us:
- Company: InkWired Technologies Pvt. Ltd.
- Address: C-101, Mahesh Nagar, Jaipur, Rajasthan, Pin Code - 302015, India
- Email: [email protected]
You also have the right to lodge a complaint with your national data protection authority, though we ask that you contact us first so we can try to resolve the issue directly.