Legal
Data Processing Addendum
Effective 22 August 2026
Parties and scope
This Data Processing Addendum (DPA) forms part of the Terms of Service or other agreement between Incld (Incld) and the customer. It applies when Incld processes personal data in Customer Data on the customer's behalf.
The customer is the controller or processor, as applicable, and Incld is its processor or subprocessor. Each party will comply with data-protection laws applicable to its role. Capitalised privacy terms have the meanings given by applicable law.
Instructions and purpose
Incld will process personal data only to provide, secure, support, and improve the contracted service; comply with documented lawful instructions; and meet legal obligations. The agreement, product configuration, API calls, and support requests comprise the customer's documented instructions.
Processing may include collection, recording, organisation, storage, retrieval, consultation, transmission to configured destinations, restriction, deletion, and other operations needed for schedules, approvals, audit, bulk processing, authentication, billing entitlements, and support.
Data subjects and data types
Data subjects may include customer personnel, developers, administrators, reviewers, requesters, the customer's end users, and individuals represented in Customer Data.
Data may include identity and contact data; external user and resource identifiers; account, role, and project membership; schedule, approval, audit, bulk-operation, webhook, usage, and support data; IP, device, log, and security data; and other personal data the customer chooses to submit. Sensitive data is excluded unless expressly agreed in writing.
Confidentiality and security
Incld will ensure persons authorised to process personal data are bound by confidentiality and will maintain appropriate technical and organisational measures considering the nature, scope, context, purpose, and risk of processing.
Measures include encrypted transmission, access control and least privilege, scoped production credentials, signed webhook delivery, environment separation, logging and monitoring, vulnerability management, backups, incident procedures, and provider diligence. Security measures may evolve without materially reducing overall protection.
Subprocessors
The customer gives general authorisation for subprocessors listed on our Subprocessors page. Incld will impose materially equivalent data-protection obligations on subprocessors and remains responsible for their performance to the extent required by law.
We will publish material changes and provide an objection process as described on that page. If the parties cannot resolve a legitimate objection, the customer may stop the affected feature or terminate the affected service.
Requests, assessments, and audits
Taking into account the nature of processing, Incld will provide reasonable assistance with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and regulator consultations where required. The customer remains responsible for responding to individuals and regulators as controller.
On reasonable written request, no more than once annually unless an incident or regulator requires otherwise, Incld will provide available security and compliance information. On-site or invasive audits require a demonstrated legal need, reasonable notice, confidentiality, minimal disruption, and reimbursement of reasonable costs.
Security incidents
Incld will notify the customer without undue delay after confirming a personal-data breach affecting Customer Data and provide information reasonably available about its nature, likely consequences, affected data, mitigation, and contact point. Notification is not an admission of fault.
International transfers
Where a restricted transfer requires safeguards, the parties incorporate the then-current EU Standard Contractual Clauses using the controller-to-processor or processor-to-processor module as applicable, with the customer as exporter and Incld as importer. The UK International Data Transfer Addendum and Swiss adaptations apply where required.
The governing-law and forum options will use a legally permitted jurisdiction connected to the customer or Incld. The DPA, service description, Subprocessors page, and Security page supply the annex information.
Return, deletion, and priority
At termination and on written request, Incld will delete or return Customer Data within a reasonable period unless retention is required by law. Backup copies will be protected and deleted on their normal rotation. Billing, security, and legal records may be retained where independently required.
If this DPA conflicts with the agreement on personal-data processing, this DPA controls. Liability under this DPA is subject to the agreement's liability provisions unless applicable law requires otherwise. To request an executed copy, contact [email protected].