Legal

Data Processing Agreement

This page describes the standard terms of our Data Processing Agreement (DPA) for business customers. It covers personal data INCLUXA processes on your behalf when you use the widget, scanner, API and portal. To request a countersigned copy, email privacy@incluxa.com. See also our Privacy Policy and Security pages.

This is a summary of our standard DPA terms for business customers. The legally binding agreement is the executed document signed by both parties. The DPA is provided at no additional cost. To request a countersigned copy, email privacy@incluxa.com.

Schools and districts: student data is covered by the district agreement (SDPC National Data Privacy Agreement v2.0 + state exhibit) signed in the portal under Settings → Schools, with a district-selected retention period of 1–120 months. This DPA does not apply to student data.

1. Definitions

2. Scope & Duration

This DPA applies to all processing of Customer Personal Data by INCLUXA on behalf of the Customer in connection with the INCLUXA services (widget, scanner, API, portal and reports).

The DPA takes effect on the date it is countersigned and remains in force for the duration of the Customer's subscription, plus any applicable retention period thereafter (Section 8).

Scope limitation: This DPA does not cover student data processed on the Schools tier, which is governed by the district agreement (Section 13). Personal data for which INCLUXA is itself the controller — for example billing and account-security records — is covered by our Privacy Policy.

3. Roles & Responsibilities

3.1 Customer (Controller)

The Customer is the data controller for all Customer Personal Data. The Customer:

  • Determines what Customer Personal Data is provided to INCLUXA and for what purpose
  • Ensures it has a lawful basis for the processing under applicable data protection law
  • Is responsible for giving any required notice to its own end users (for example, in its own privacy policy)
  • Remains responsible for its own compliance with applicable data protection law
  • Provides documented instructions to INCLUXA regarding processing; INCLUXA will not process outside those instructions unless required by law

3.2 INCLUXA (Processor)

INCLUXA is the data processor. INCLUXA:

  • Processes Customer Personal Data only on documented instructions from the Customer
  • Maintains appropriate technical and organizational security measures (Section 6)
  • Does not determine the purposes or means of processing Customer Personal Data
  • Does not sell, rent, share, or use Customer Personal Data for any purpose other than delivering the contracted services
  • Ensures that personnel with access to Customer Personal Data are bound by confidentiality obligations

4. Permitted Purposes

INCLUXA is authorized to process Customer Personal Data solely for the following purposes:

  1. Delivering the Services. Operating the widget, scanner, API, portal and compliance reports the Customer has subscribed to.
  2. Accessibility Preferences. Storing and retrieving widget end users' accessibility settings so they persist across visits.
  3. Support and Security. Troubleshooting, abuse prevention, rate limiting and security monitoring.
  4. Service Improvement (Aggregated Only). Using de-identified, aggregated data to improve reliability and performance. No individual is identifiable in this processing.
  5. Legal Compliance. Processing necessary to comply with applicable law, including responding to court orders, provided INCLUXA notifies the Customer unless legally prohibited.

Prohibited purposes: INCLUXA will not use Customer Personal Data for advertising, behavioral profiling, sale to third parties, training AI models, or any purpose not listed above.

5. Categories of Customer Personal Data Processed

Minimum necessary principle: INCLUXA processes only the Customer Personal Data needed to deliver the contracted services. The widget does not ask site visitors for names or email addresses.

6. Technical & Organizational Security Measures

INCLUXA maintains the following security measures, consistent with the sensitivity of Customer Personal Data:

6.1 Encryption

  • Data encrypted at rest (AES-256) in Azure SQL Database and Azure Blob Storage
  • TLS 1.2 or higher enforced for all data in transit (TLS 1.3 preferred)
  • Selected sensitive fields additionally encrypted at the application level

6.2 Access Control

  • Role-based access control (Owner, Admin, Developer, Viewer) within each customer account
  • Multi-factor authentication required for INCLUXA personnel with access to production systems
  • Least-privilege principle enforced; access reviewed periodically

6.3 Infrastructure

  • Hosted on Microsoft Azure, United States regions (Central US / East US)
  • Cloudflare WAF and DDoS protection on all endpoints
  • Network segmentation; database not publicly reachable
  • Automatic patching and vulnerability scanning

6.4 Procedures

  • Documented incident response plan with 24-hour customer notification (Section 10)
  • Confidentiality obligations and security awareness practices for anyone with access to Customer Personal Data
  • Immutable audit logs retained for 2 years

7. Approved Sub-Processors

By executing this DPA, the Customer provides general authorization for INCLUXA to engage the following sub-processors for the listed purposes. INCLUXA will notify the Customer at least 30 days in advance of adding or replacing a sub-processor that handles Customer Personal Data, giving the Customer the opportunity to object.

INCLUXA maintains its own Data Processing Agreements (or the provider's standard data processing terms) with each sub-processor listed above. Contact privacy@incluxa.com for copies of applicable sub-processor DPAs.

8. Retention & Deletion

8.1 Standard Retention

Customer Personal Data is retained for the periods listed in Section 5.

8.2 Individual Deletion Requests

The Customer may request deletion of specific Customer Personal Data at any time via privacy@incluxa.com. INCLUXA will complete deletion within 30 days and provide written confirmation. Audit log entries recording that a deletion occurred are retained for the audit-log retention period.

8.3 Termination Deletion

Within 90 days of account closure, INCLUXA will permanently delete (or, on written request, return) all Customer Personal Data, except audit logs retained under Section 5. Written confirmation of deletion will be provided on request.

9. Data Subject Rights

INCLUXA will assist the Customer, taking into account the nature of the processing, in responding to requests from individuals exercising their rights under GDPR (Articles 15–22), the CCPA and similar laws, including access, correction, deletion and portability.

If INCLUXA receives a request directly from an individual about Customer Personal Data, it will forward the request to the Customer. The Customer can send requests for assistance to privacy@incluxa.com; INCLUXA responds within 30 days.

10. Breach Notification

In the event of any actual or reasonably suspected unauthorized access to, disclosure, loss, or alteration of Customer Personal Data, INCLUXA will:

  1. Notify the Customer within 24 hours of becoming aware of the incident. Notification may be preliminary if investigation is ongoing — INCLUXA will not delay notification to complete the full investigation.
  2. Include in the notification: the nature of the incident; the categories and approximate volume of Customer Personal Data involved; the likely consequences; the measures taken or proposed to address the incident and mitigate its effects.
  3. Cooperate fully with the Customer's incident response and any regulatory investigation.
  4. Provide updates at least every 48 hours until the incident is fully resolved and remediated.
  5. Assist with regulatory notifications to the extent required — including providing information the Customer needs to notify supervisory authorities or affected individuals.

To report a security incident: security@incluxa.com (monitored daily).

11. International Data Transfers

INCLUXA processes and stores Customer Personal Data in the United States (Microsoft Azure, United States regions). There is no EU, UK or Canada hosting region. If the Customer is located in a jurisdiction with cross-border data transfer restrictions (e.g., EU/EEA member states, UK), the following mechanisms apply:

  • EU/EEA: The European Commission Standard Contractual Clauses for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), Module Two — Controller to Processor, are incorporated into this DPA by reference. Annex I (parties & processing description), Annex II (technical and organisational measures), and Annex III (sub-processors) are populated by Sections 2 and 5, Section 6, and Section 7 of this DPA respectively. Docking clause (Clause 7) is accepted; optional Clause 11(a) (independent dispute resolution) is not selected. Governing law: Ireland; forum: Irish courts. Full SCC text is available on written request to privacy@incluxa.com.
  • United Kingdom: The ICO's International Data Transfer Addendum issued under s.119A of the Data Protection Act 2018 is appended to the EU SCCs above and incorporated by reference.
  • Other jurisdictions: INCLUXA will enter into any transfer mechanism required by applicable law on written request.

For U.S. customers, Customer Personal Data is stored in the United States; sub-processors that operate global edge networks (Section 7) may handle request data outside the United States in transit.

12. Audits & Certifications

INCLUXA operates security controls aligned to the SOC 2 Trust Services Criteria (SOC 2 audit-ready, not yet certified). We engage a CPA audit firm only when a customer requires a report; certification is available within 60 days of committed engagement. Once a SOC 2 report is issued, it will be shared with customers under NDA on written request.

In the meantime, INCLUXA will:

  • Respond to reasonable written security questionnaires within 20 business days
  • Provide evidence of security controls (penetration-test summary, access control policies) under NDA on written request
  • Allow customers to conduct audits (at the customer's expense, with 30 days' notice, no more than once per year) provided such audits do not compromise other customers' data security

13. Schools & Student Data

Schools and districts: student data is covered by the district agreement (SDPC National Data Privacy Agreement v2.0 + state exhibit) signed in the portal under Settings → Schools, with a district-selected retention period of 1–120 months. This DPA does not apply to student data.

See our Privacy Policy §12 and Terms §18 for the Schools terms that apply alongside the district agreement.

14. Liability

Each party's liability under this DPA is subject to the liability limitations in the INCLUXA Terms of Service, unless a signed agreement between the parties says otherwise.

15. How to Execute a DPA

To receive and countersign a binding DPA:

  1. Email privacy@incluxa.com with the subject line "DPA Request — [Company Name]".
  2. INCLUXA sends the DPA with your company's details and the sub-processors relevant to your subscription.
  3. Sign and return the DPA to privacy@incluxa.com; INCLUXA countersigns and returns a fully executed copy.

No charge: The DPA is provided at no additional cost to all paid customers. Schools and districts sign the district agreement in the portal instead (Section 13).

Contact