Data Processing Addendum
The data-processing terms, instructions, safeguards, and transfer mechanisms that apply when Ancil processes Customer Personal Data.
1. Scope and roles
This DPA forms part of the Agreement between the customer identified in an order form or Ancil workspace ("Customer") and INSIDEA, Inc., 8 The Green, Ste R, Dover, DE 19901, United States ("INSIDEA") for Customer Personal Data processed through Ancil.
Customer is Controller and INSIDEA is Processor, except where Customer acts as a Processor for another Controller, in which case INSIDEA acts as Customer’s Sub-processor. Terms such as Personal Data, Process, Controller, Processor, and Supervisory Authority have the meanings given by applicable Data Protection Law.
2. Subject matter and duration
Subject matter and purpose: hosting and administering Ancil, authenticating users, reading or writing customer-authorised HubSpot data, generating audits and governed recommendations, providing support, securing the service, and carrying out documented Customer instructions.
Duration: the Agreement term plus the limited retention and backup periods described in the Privacy Policy, unless law requires longer retention.
Nature and frequency: collection, access, organisation, analysis, retrieval, transmission, storage, modification at Customer direction, restriction, export, and deletion, on a continuous or Customer-initiated basis.
3. Categories of data and data subjects
Categories of Personal Data: names, work contact details, account and role data, professional information, CRM objects and properties, sales and service records, communication metadata, project evidence, usage events, and other fields Customer chooses to process.
Categories of Data Subjects: Customer users and personnel; Customer prospects, leads, contacts, customers, suppliers, and other individuals represented in connected systems.
Sensitive data is not required for normal use. Customer must not submit special-category, regulated financial, health, biometric, government-identifier, or children’s data unless the parties first document appropriate instructions and safeguards.
4. Processor obligations
Process personal data only on documented Controller instructions.
Ensure persons authorised to process personal data are bound by confidentiality.
Implement appropriate technical and organisational measures.
Assist Controller with data subject requests, security incidents, DPIAs, and prior consultations.
Delete or return personal data at the end of the service, subject to any law requiring retention.
Notify Customer if, in our reasonable opinion, an instruction infringes applicable Data Protection Law, and suspend that instruction while the parties resolve it.
Maintain records of processing and make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
5. Customer obligations and instructions
The Agreement, documented product configuration, support requests, approved actions, and written instructions from authorised Customer users constitute Customer’s documented instructions.
Customer is responsible for the lawfulness, accuracy, and minimisation of Customer Personal Data; the notices, rights, consents, and legal bases required for processing; user permissions; and responding to Data Subjects as Controller.
Customer will not instruct INSIDEA to process Personal Data in violation of law or a third party’s rights.
6. Confidentiality and personnel
INSIDEA limits access to authorised personnel and contractors with a need to know, appropriate training, and enforceable confidentiality obligations. Access is reviewed and removed when no longer required.
7. Sub-processors
Customer grants general authorisation for the providers listed at ancil.ai/legal/subprocessors. INSIDEA requires each Sub-processor to protect Personal Data through written obligations materially consistent with this DPA.
INSIDEA will provide at least 30 days’ notice before a new Sub-processor begins processing Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, Customer may terminate the affected service.
INSIDEA remains responsible for each Sub-processor’s performance of its data-protection obligations to the extent required by applicable law.
8. International transfers
For restricted transfers from the EEA, the EU Standard Contractual Clauses adopted by Decision 2021/914 are incorporated by reference. Module Two applies where Customer is Controller and INSIDEA is Processor; Module Three applies where both parties act as Processors. The optional docking clause applies, Clause 9 uses Option 2 with the notice period in Section 7, and the supervisory authority and governing-law selections follow the exporter’s establishment where legally permitted.
For UK restricted transfers, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses is incorporated. Swiss references are interpreted to include the Swiss Federal Act on Data Protection where applicable.
The Agreement and this DPA provide Annex I processing details; the Security page and Section 9 provide Annex II safeguards; the Sub-processor Register provides Annex III. INSIDEA applies supplementary technical and organisational measures where reasonably required.
9. Technical and organisational measures
INSIDEA maintains measures appropriate to risk, including TLS 1.2+ in transit, managed encryption at rest, application-layer AES-256-GCM for HubSpot tokens, secure authentication cookies, CSRF protection, role and workspace-scoped authorisation, private attachment access, administrative audit logging, vulnerability management, backup procedures, and incident response.
INSIDEA reviews these measures as technology and risk evolve. Detailed evidence may be provided under confidentiality, subject to security and third-party restrictions. SOC 2 Type II observations are in progress and are not represented as completed certification.
10. Personal Data Breach
INSIDEA will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Notification will include available information about the nature, likely consequences, affected data, mitigation, and a contact point, with updates as investigation continues.
INSIDEA will take reasonable steps to contain, investigate, remediate, preserve evidence, and assist Customer with legally required notifications. Notice is not an admission of fault or liability.
11. Assistance
Taking into account the nature of processing and information available, INSIDEA will reasonably assist Customer with Data Subject requests, security obligations, breach notices, data-protection impact assessments, and prior consultation. Customer remains responsible for determining whether and how to respond as Controller.
If a Data Subject contacts INSIDEA about Customer Personal Data, INSIDEA will direct the request to Customer unless law requires otherwise and will not respond substantively without Customer instructions.
12. Return and deletion
During the service and for the export period stated in the Terms, Customer may use available export tools or request assistance. After termination, INSIDEA will delete or return Customer Personal Data in accordance with Customer’s choice, except for data retained by law or in backups until normal expiry.
Upon written request, INSIDEA will provide reasonable confirmation of completed production-data deletion after the applicable retention process finishes.
13. Audits
INSIDEA will provide current security documentation, relevant independent-assurance reports when available, and reasonable written responses to security questionnaires under appropriate confidentiality.
If that information is insufficient to demonstrate compliance, Customer may request one audit per 12-month period on at least 30 days’ written notice. Audits must occur during business hours, avoid disruption, protect other customers and confidential systems, use an independent qualified auditor bound by confidentiality, and be at Customer’s cost unless the audit identifies a material breach by INSIDEA.
14. Government requests
Unless legally prohibited, INSIDEA will notify Customer of a binding government request for Customer Personal Data. INSIDEA will review the request for lawful authority, challenge disproportionate requests where reasonable, and disclose only what it is legally required to provide.
15. Liability
Liability under this DPA is governed by the limitation of liability in the Agreement.
16. Conflict
In the event of conflict between this DPA and the Agreement, this DPA prevails for matters of personal data processing.
17. Execution and contact
Electronic acceptance of the Terms by an authorised workspace owner incorporates this DPA. A countersigned copy is available on request at legal@insidea.com or privacy@insidea.com.
Questions or requests: hello@ancil.ai.