Data Processing Addendum
Published: September 21, 2026
This Global Data Processing Addendum (“DPA”) constitutes an integral part of all Agreements by and between Inbenta and Customer, as each Party is identified in the relevant agreement document(s) including each fully executed order or statement of work, or under any services agreement or similar agreement. This DPA reflects the Parties’ agreement with regard to the Processing of Personal Data in accordance with the requirements of Data Protection Laws.
This DPA is effective on the Effective Date of the TOS, and amends, supersedes and replaces any prior agreement relating to data processing or data protection the Parties have entered into. Capitalized terms used but not defined herein have the meaning provided in the TOS.
1. Definitions
In this DPA, the following terms will have the meanings set out below and cognate terms will be construed accordingly for this exhibit only:
“Applicable Data Protection Laws” means all worldwide data protection, data security and privacy laws, rules, and regulations, applicable to the Personal Data Processed in the delivery of the Services.
“Controller” means the Party who, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
“Data Subject Rights” means all rights granted to Data Subjects under the Applicable Data Protection Laws.
“Customer Representative Data” means Personal Data concerning Customer’s employees and other personnel Processed by Inbenta pursuant to or in connection with the Agreement.
“Data Subject” means the identifiable natural person whose Personal Data is being Processed.
“EEA” means the European Economic Area.
“Personal Data” means any of Customer’s information which is protected as “personal data”, “personal information” or “personally identifiable information” or similarly defined terms under Applicable Data Protection Laws.
“Processor” means the Party who Processes Personal Data on behalf of the Controller.
“Processing” or “Processes” means any operation or operations performed on Personal Data, whether or not by automated means, during the provision of Services.
“Restricted Transfer” means the transfer of Personal Data where (1) Customer originally held the Personal Data in, or imported the Personal Data from, the EEA, Switzerland, or the UK, or Customer is otherwise subject to the GDPR, FADP or UK GDPR in relation to such Personal Data, (2) the Personal Data will be received by Inbenta outside of the EEA, Switzerland, or the UK, as applicable, and (3) the transfer would be prohibited by Applicable Data Protection Law in the absence of Standard Contractual Clauses or another adequate transfer mechanism as approved by the relevant regulatory authority.
“Security Breach” means any unauthorized or unlawful access to, or acquisition, alteration, use, disclosure or destruction of Personal Data stored on Inbenta’s equipment or in Inbenta’s facilities resulting in loss, disclosure, or alteration of Personal Data.
“Services” means the services provided to Customer by Inbenta involving the processing of Personal Data on behalf of Customer, as identified in the Agreement.
“Special Category Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person’s sex life or sexual orientation.
“Subprocessor” means any third party (including any Inbenta Affiliates, but excluding an employee of Inbenta or any of its sub-contractors) engaged by or on behalf of Inbenta or any Inbenta Affiliate to Process Personal Data on behalf of Customer or Affiliates in connection with the Agreement.
“User” means any individuals who use the Services that Customer has purchased pursuant to the Agreement, including its customers and prospective customers.
“User Data” means all Personal Data of Users.
The terms, “Commission”, “Member State”, and “Supervisory Authority” will have the same meaning as in the Applicable Data Protection Laws, and their cognate terms will be construed accordingly.
The word “include” will be construed to mean include without limitation, and cognate terms will be construed accordingly.
2. Authority
2.1 Roles of the Parties. The Parties acknowledge and agree that:
- in relation to the Processing of Personal Data while providing the Services, Customer is the Controller and Inbenta is the Processor; and
- in relation to the Processing of Customer Representative Data, Inbenta is an independent Controller and will independently determine the means and purposes of that Processing.
2.2 Controlling Agreement. This DPA supplements the Agreement and in the event of any conflict between the terms of this DPA and the terms of the Agreement, the terms of this DPA prevail.
3. Processing of Customer Representative Data
3.1 Compliance with laws. Inbenta will comply with all Applicable Data Protection Laws in the Processing of Customer Representative Data.
3.2 Purpose limitation. Without prejudice to the generality of the foregoing, Inbenta will not Process Customer Representative Data for any purpose other than the purposes for which it was collected, namely the identification of representatives of Customer for the purposes of controlling access to its systems and the data they contain, fulfilling its contractual obligations to Customer, maintain and improving its services and systems, and fulfilling any relevant regulatory obligations.
3.3 Details of Processing Activities. The subject matter, duration of the Processing, the nature and purpose of the Processing, the types of Customer Representative Data and categories of Data Subjects Processed under this DPA are further specified in Appendix 1 – Part A of this DPA.
4. Processing of User Data
4.1 Compliance with laws. Both parties will comply with all Applicable Data Protection Laws in the Processing of User Data.
4.2 Purpose limitation. Without prejudice to the generality of the foregoing, Inbenta will not Process User Data other than on Customer’s documented instructions unless Processing is required by Applicable Data Protection Laws to which Inbenta is subject, in which case Inbenta will, to the extent permitted by Applicable Data Protection Laws, inform Customer of such legal requirement.
4.3 Customer’s instructions and obligations. Without prejudice to the generality of clause 4.1, Customer will provide any required notice to Users of the Processing. Customer warrants that its instructions to Inbenta for the Processing of User Data pursuant to this DPA comply with the Applicable Data Protection Laws. Customer instructs Inbenta to Process User Data as reasonably necessary for the provision of the Services and consistent with the Agreement; and represents that it is and will at all relevant times remain duly and effectively authorized to give the instruction set out herein. Inbenta will inform Customer without undue delay if, in its opinion, any instruction for Processing infringes the Applicable Data Protection Laws. Where User Data is used for automated decision-making, including profiling based on scoring systems established by Customer, Customer will comply with Applicable Data Protection Laws with respect to Users’ privacy or personal integrity and comply with applicable legal requirements. Customer will also uphold Data Subject Rights to obtain human intervention, express their point of view, and challenge decisions based solely on automated processing where required.
4.4 Details of Processing Activities. The subject matter, duration of the Processing, the nature and purpose of the Processing, the types of User Data and categories of Data Subjects Processed under this DPA are further specified in Appendix 1 – Part B of this DPA.
4.5 Excluded Personal Data. It is not in the Parties’ intention that the Services will be used to collect and otherwise process financial or payment information, or any Special Category Data, concerning Users. Customer acknowledges that Inbenta provides an obfuscation tool that can be enabled by Customer which will serve to mask Personal Data identified by Customer once the information has been provided by the User through the Services. Customer will ensure that it takes all reasonable steps to prevent Users from providing financial or payment information, or any Special Category Data, concerning Users through use of the Services; and, to the extent such information is provided by a User, Customer will ensure it deletes such information immediately. Additionally, Customer will not include Personal Data of any kind in its knowledge content provided by Customer for the use of the Services, unless otherwise explicitly agreed to in writing by Inbenta with appropriate amendments made to this DPA to the extent necessary.
5. Inbenta’s Obligations
5.1 Confidentiality. Inbenta will ensure that its personnel engaged in the Processing of Personal Data are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities and have executed written confidentiality agreements. Inbenta will ensure that such confidentiality obligations survive the termination of the personnel engagement. Inbenta will ensure that access to Personal Data is limited to those personnel performing Services in accordance with the Agreement on a need-to-know basis.
5.2 Data Subject Requests. Inbenta will, to the extent legally permitted, promptly notify Customer if Inbenta receives a request from a Data Subject to exercise a Data Subject Right relating to User Data. Inbenta will assist Customer by implementing reasonable technical and organizational measures, insofar as this is possible, to fulfil Customer’s obligation to respond to requests for exercising Data Subject Rights. To the extent Customer, in its use of the Services, does not have the ability to address a Data Subject request or claim, Inbenta will upon Customer’s written request provide commercially reasonable assistance to Customer without undue delay in responding to such Data Subject request or claim, to the extent Inbenta is legally permitted to do so and the response to such Data Subject request is required under Applicable Data Protection Laws. To the extent legally permitted, Customer will be responsible for any costs arising from Inbenta’s provision of such assistance.
5.3 Supervisory Authority Requests. Inbenta will assist Customer in addressing any communications and abiding by any advice or orders from the Supervisory Authority relating to User Data within the timeframe specified by the Supervisory Authority, to the extent required under Applicable Data Protection Laws.
5.4 Disclosure to Third Parties. Inbenta will not disclose User Data to third parties except as permitted by this DPA or the Agreement, unless Inbenta is legally required to disclose User Data, in which case Inbenta will, to the extent legally permitted, notify Customer in writing and liaise with Customer before complying with such disclosure request.
5.5 Data Protection Impact Assessment. Upon Customer’s request, Inbenta will provide Customer with reasonable cooperation and assistance needed to fulfil Customer’s obligation under Applicable Data Protection Laws to carry out a data protection impact assessment related to Customer’s use of the Services, to the extent Customer does not otherwise have access to the relevant information, and to the extent such information is available to Inbenta.
5.6 Retention. Inbenta will retain User Data in accordance with its data retention policy as otherwise required by Customer for Processing, or as required under the applicable law. At the termination of this DPA, or upon Customer’s written request, Inbenta will either delete or return User Data to Customer, unless legal obligations require storage of User Data.
5.7 Security. Inbenta will maintain appropriate administrative, physical, and technical safeguards intended for protection of the security, confidentiality, and integrity of User Data, as such measures are set out in Appendix 2 of this DPA. Inbenta monitors compliance with these safeguards. In assessing the appropriate level of security, Inbenta will take account in particular of the risks that are presented by Processing, in particular from a Security Breach.
6. Third Party Certification and Audits
6.1 Certifications. Upon Customer’s written request at reasonable intervals, but in any event no more than annually, and subject to the confidentiality obligations set forth in the Agreement, Inbenta will make available to Customer (or Customer’s independent, third-party auditor that is not a competitor of Inbenta) a copy of Inbenta’s then most recent third-party audits or certifications, as applicable, in fulfilment of Inbenta’s obligation to make available to the controller all information necessary to demonstrate compliance with the obligations laid down by Applicable Data Protection Laws and to allow for and contribute to audits.
6.2 Audits. Customer may contact Inbenta to request an audit of Inbenta’s procedures relevant to the protection of Personal Data, but only to the extent required under Applicable Data Protection Laws, and at Customer’s sole expense. Such audit will be conducted by an independent third party reasonably acceptable to Inbenta. Before the commencement of any such on-site audit, Customer and Inbenta will mutually agree upon the scope, timing, and duration of the audit, in addition to the reimbursement rate for which Customer will be responsible. Inbenta will provide reasonable assistance to support such audit, including providing access to relevant records and information, subject to appropriate security measures to safeguard confidentiality and integrity of such information. Such audits will not occur more than annually, unless requested by a Supervisory Authority. The results of the inspection and all information reviewed during such inspection will be deemed Inbenta’s confidential information and will be protected by the auditor in accordance with the confidentiality obligations set forth in the Agreement. Notwithstanding any other terms, the auditor may only disclose to Customer specific violations of the DPA, if any, and the basis for such findings, and will not disclose any of the records or information reviewed during the inspection to Customer.
7. Subprocessing
7.1 General Consent. Customer acknowledges and agrees that (a) Inbenta’s Affiliates may be retained as Subprocessors; and (b) Inbenta and Inbenta’s Affiliates respectively may engage third-party Subprocessors in connection with the provision of the Services subject to the conditions noted in this Section. As a condition of engaging Subprocessors, Inbenta or the Inbenta Affiliate will enter into a written agreement with each Subprocessor containing data protection obligations, including security measures, not less protective than those in this DPA with respect to the protection of User Data to the extent applicable to the nature of the services provided by such Subprocessor.
7.2 Consent to Subprocessor Engagement. Customer acknowledges and agrees that Inbenta may engage Subprocessors to Process Personal Data. A current list of Inbenta’s Subprocessors is provided at the following URL: https://trust.inbenta.com/item/subprocessors. Without prejudice to Section 7.3, Customer generally authorizes the engagement as Subprocessor of any other third parties.
7.3 Notification of New Subprocessors and Customer Objection. During the term of the Agreement, Inbenta will update its current Subprocessor list at the URL identified in Section 7.2 periodically to reflect any changes. Inbenta will strive to notify Customer if it adds or removes Subprocessors at least fifteen (15) days prior to any changes if Customer provides Inbenta with written instructions and an appropriate email address for such notification. Customer may object to Inbenta’s use of a new Subprocessor by notifying Inbenta promptly in writing within ten (10) business days after receipt of Inbenta’s notice of appointment of Subprocessor, provided such objection is based on reasonable grounds, such as the violation of Applicable Data Protection Laws or the weakening of the security of the User Data. In the event Customer objects to a new Subprocessor, as permitted in the preceding sentence, the Parties agree to discuss commercially reasonable alternative solutions in good faith. If the Parties cannot reach a resolution within sixty (60) days from the date of Inbenta’s receipt of Customer’s written objection, Customer may discontinue the use of the affected Services by providing written notice to Inbenta. In the absence of timely and valid objection by Customer, such Subprocessor may be commissioned to process User Data.
7.4 Liability. Inbenta will be liable for the acts and omissions of its Subprocessors to the same extent Inbenta would be liable if performing the services of each Subprocessor directly under the terms of this DPA, except as otherwise set forth in the Agreement.
8. Security Breach
8.1 If Inbenta becomes aware of a Security Breach, Inbenta will without undue delay: (a) notify Customer of the Security Breach; (b) investigate the Security Breach and provide Customer with information about the Security Breach; and (c) take reasonable steps to mitigate the effects and to minimize any damage resulting from the Security Breach. Inbenta’s obligation to report or respond to a Security Breach under this Section is not and will not be construed as an acknowledgement by Inbenta of any fault or liability with respect to the Security Breach.
8.2 Notification(s) of Security Breaches, if any, will be delivered to one or more of Customer’s business, technical or administrative contacts by any means Inbenta selects, including via email. It is Customer’s sole responsibility to ensure it maintains accurate contact information on Inbenta’s support systems at all times. If Customer has questions or wants further information or evidence, Customer may contact their Customer Success Manager or privacy@inbenta.com.
8.3 In the event of a Security Breach, Customer may request evidence or documentation related to the breach. Upon such request, Inbenta will provide Customer with available information and reasonable evidence regarding the nature of the incident, its impact, and any actions taken to mitigate the effects, subject to any applicable legal or regulatory restrictions. Inbenta will make reasonable efforts to cooperate with Customer in addressing concerns related to the breach, including any evidence necessary for Customer’s own compliance with Applicable Data Protection Laws. Inbenta will respond to such requests within a reasonable timeframe, considering the complexity of the incident and any legal obligations under Applicable Data Protection Laws.
9. Limitation of Liability
Inbenta and all of its Affiliates’ liability taken together in the aggregate arising out of or related to this DPA (including the SCCs) will be subject to the exclusions and limitations of liability set forth in the Agreement. The liability described in the SCCs will in no event exceed the limitations set forth in the Agreement, and that under no circumstances and under no legal theory, whether in contract, tort, negligence, or otherwise, will Inbenta or its Affiliates, officers, directors, employees, agents, service providers, suppliers, or licensors be liable to Customer or any third party for any lost profits, lost sales of business, lost data, business interruption, loss of goodwill, or for any type of indirect, incidental, special, exemplary, consequential or punitive loss or damages, regardless of whether such Party has been advised of the possibility of or could have foreseen such damages. For the avoidance of doubt, this Section will not be construed as limiting the liability of either Party with respect to claims brought by Data Subjects.
10. Restricted Transfers
10.1 Inbenta currently has operational centers in the United States, Spain, France and Brazil and complies with Applicable Privacy Laws in such countries. To the extent Personal Data is provided to Inbenta in the EEA, UK or Switzerland by Customer or its representatives, Inbenta will only transfer Personal Data for the purpose of fulfilling contractual obligations or other lawful purpose, and except for the circumstances set out below, will not transfer to, or carry out any processing of Personal Data in a country outside the EEA, UK or Switzerland unless the country has been recognized by the European Commission, UK or Switzerland as having an adequate level of data protection. Transfers to or processing of Personal Data relating to EU, UK or Swiss Data Subjects carried out in the United States are subject to Inbenta’s participation and self-certification to the E.U.-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and UK Extension to the EU-U.S. Data Privacy Framework. As such, there are no circumstances in which a Restricted Transfer is carried out between Customer as Exporter and Inbenta as Importer.
10.2 If the adequacy decisions for the E.U.-U.S. and Swiss-U.S. Data Privacy Frameworks and/or UK Extension to the E.U.-U.S. Data Privacy Framework are invalidated, or if Inbenta no longer participates in the E.U.-U.S. and Swiss-U.S. Data Privacy Frameworks and/or UK Extension, then, as of the moment of invalidation or withdrawal from the Frameworks, transfers of Personal Data from Customer to Inbenta are subject to the Standard Contractual Clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 (“SCC”), hereby incorporated reference into this Agreement, and/or the UK Addendum to the SCCs issued by the Office of the Information Commissioner (ICO), hereby incorporated by reference into this Agreement or other legally recognized mechanisms for ensuring compliance with data protection obligations.
11. Obligations Post-Termination
Termination or expiration of this DPA will not discharge the Parties from their obligations meant to survive the termination or expiration of this DPA.
12. Severability
Any provision of this DPA that is prohibited or unenforceable in any jurisdiction will, as to such jurisdiction, be ineffective to the extent of such prohibition or unenforceability without invaliding the remaining provisions hereof, and any such prohibition or unenforceability in any jurisdiction will not invalidate or render unenforceable such provision in any other jurisdiction. The Parties will attempt to agree upon a valid and enforceable provision that is a reasonable substitute and will incorporate such substitute provision into this DPA.
Appendix 1 – Details of Processing
Part A – Customer Representative Data
Subject matter of the processing: Identification of Customer’s representatives for the purpose of granting or denying access to Inbenta’s systems and keeping records of their access.
Duration of the processing: While this Agreement is in force, as long as Customer continues to receive Services and access Inbenta’s systems.
Nature of the processing: Collection, storage, organization, structuring, access, restriction, alteration, erasure, destruction.
Purpose of the processing: Identity verification to control access to the Inbenta systems and the data they contain, fulfilling the contractual obligations, maintaining and improving the services and systems.
Type of personal data: Name, business email, IP Address (or equivalent when accessed through a mobile device), time and date of access, length of session, location.
Categories of data subjects: Employees and other personnel of Customer.
Part B – User Data
Subject matter of the processing: Provision of the Services, as defined in the Agreement and selected by Customer.
Duration of the processing: While this Agreement is in force, as long as Users use the Services that Customer has licensed pursuant to the Agreement and made available for access, use, or communication with such individuals.
Nature of the processing: As necessary for the Services selected by Customer, including collection, storage, organization, structuring, access, restriction, alteration, erasure, sentiment scoring, destruction.
Purpose of the processing: Providing electronic customer communication services to Users that Customer has licensed pursuant to the Agreement including allowing for improvement of the Customer’s services.
Type of Personal Data: Identity and contact data (such as name, gender, address, email address, phone numbers), IP address, session ID, purchase history, opinions, User questions, conversation histories, time and date of access, length of session, location, and other additional data fields (which may not include bank account or other Special Categories of Data) that Customer notifies Inbenta will be relevant to the provision of Services.
Categories of data subjects: Users.
Appendix 2 – Technical and Organizational Measures Related to Information Security
Inbenta maintains appropriate technical and organizational measures designed to protect Personal Data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access, and to provide an appropriate security level for the risk represented by the processing and the nature of the data to be protected.
Accordingly, Inbenta has implemented an Information Security and Information Privacy Management System compliant with ISO 27001, ISO 27017, and ISO 27701 standards which includes, among others, the following measures:
- Data access policies and procedures to check that access to Inbenta’s computer systems is done through individual users and passwords, such as limiting data access to those employees who strictly require it to perform their job.
- Backup copies, where appropriate, of the personal data processed by the controllers that require availability and integrity.
- Ongoing surveillance and monitoring of systems and networks to detect and minimize the impact of any malfunction or threat.
- Logging of user and administrator events and activities.
- Security configurations and perimeter protection systems in the network to avoid intrusions, as well as antivirus protection of its computer systems.
- Registry of security incidents and mechanisms and procedures for the notification of security breaches have been established.
- Physical access control and protection of the equipment, people, and facilities where the data controller is being processed.
- In case of managing support or documents with the controller’s personal data, these are duly stored in cabinets or spaces equipped with locking devices.
- A code of conduct, including prevention of criminal behavior and good practices in security and data privacy.
- A training and awareness platform in information security and data privacy for all Inbenta staff, including phishing simulations and phishing prevention training.
- A Continuity Plan that grants the possibility of restoring the availability of and access to personal data quickly, in the event of a physical or technical incident, within the timeframes required to meet the business commitments the parties are bound to by means of the service contract.
- Contractual clauses and agreements with all subprocessors, including providing sufficient commitments to implement appropriate technical and organizational measures for processing to meet the requirements of the applicable regulations and protect the rights of data subjects.
- Application of privacy principles by design and by default.