Skip to content
Legal

Data Processing Agreement

Template version 1.1 — September 21, 2026

This page describes the standard terms of our Data Processing Agreement (DPA) for business customers. It covers personal data INCLUXA processes on your behalf when you use the widget, scanner, API and portal. To request a countersigned copy, email privacy@incluxa.com. See also our Privacy Policy and Security pages.

1. Definitions·2. Scope & Duration·3. Roles & Responsibilities·4. Permitted Purposes·5. Data Processed·6. Security Measures·7. Sub-Processors·8. Retention & Deletion·9. Data Subject Rights·10. Breach Notification·11. International Transfers·12. Audits & Certifications·13. Schools & Student Data·14. Liability·15. Execution

This is a summary of our standard DPA terms for business customers. The legally binding agreement is the executed document signed by both parties. The DPA is provided at no additional cost. To request a countersigned copy, email privacy@incluxa.com.

Schools and districts: student data is covered by the district agreement (SDPC National Data Privacy Agreement v2.0 + state exhibit) signed in the portal under Settings → Schools, with a district-selected retention period of 1–120 months. This DPA does not apply to student data.

1. Definitions

TermMeaning
ControllerThe Customer — the business or organization that uses INCLUXA and determines the purposes and means of processing Customer Personal Data.
ProcessorAngstroma, Inc., operating INCLUXA ("INCLUXA") — processes Customer Personal Data on behalf of and under instruction from the Controller.
Customer Personal DataAny personal data provided to or accessed by INCLUXA on the Customer's behalf under the Agreement, such as widget end-user preference data, portal user details, usage logs and scan data.
AgreementThe INCLUXA Terms of Service and the Customer's subscription, together with this DPA.
ProcessingAny operation performed on Customer Personal Data, including collection, storage, retrieval, transmission, alteration, or deletion.
Sub-ProcessorA third party engaged by INCLUXA to process Customer Personal Data on its behalf.
EEAThe European Economic Area.
GDPRRegulation (EU) 2016/679 and, where applicable, the UK GDPR and the UK Data Protection Act 2018.
CCPAThe California Consumer Privacy Act, as amended by the California Privacy Rights Act.

2. Scope & Duration

This DPA applies to all processing of Customer Personal Data by INCLUXA on behalf of the Customer in connection with the INCLUXA services (widget, scanner, API, portal and reports).

The DPA takes effect on the date it is countersigned and remains in force for the duration of the Customer's subscription, plus any applicable retention period thereafter (Section 8).

Scope limitation: This DPA does not cover student data processed on the Schools tier, which is governed by the district agreement (Section 13). Personal data for which INCLUXA is itself the controller — for example billing and account-security records — is covered by our Privacy Policy.

3. Roles & Responsibilities

3.1 Customer (Controller)

The Customer is the data controller for all Customer Personal Data. The Customer:

  • Determines what Customer Personal Data is provided to INCLUXA and for what purpose
  • Ensures it has a lawful basis for the processing under applicable data protection law
  • Is responsible for giving any required notice to its own end users (for example, in its own privacy policy)
  • Remains responsible for its own compliance with applicable data protection law
  • Provides documented instructions to INCLUXA regarding processing; INCLUXA will not process outside those instructions unless required by law

3.2 INCLUXA (Processor)

INCLUXA is the data processor. INCLUXA:

  • Processes Customer Personal Data only on documented instructions from the Customer
  • Maintains appropriate technical and organizational security measures (Section 6)
  • Does not determine the purposes or means of processing Customer Personal Data
  • Does not sell, rent, share, or use Customer Personal Data for any purpose other than delivering the contracted services
  • Ensures that personnel with access to Customer Personal Data are bound by confidentiality obligations

4. Permitted Purposes

INCLUXA is authorized to process Customer Personal Data solely for the following purposes:

  1. Delivering the Services. Operating the widget, scanner, API, portal and compliance reports the Customer has subscribed to.
  2. Accessibility Preferences. Storing and retrieving widget end users' accessibility settings so they persist across visits.
  3. Support and Security. Troubleshooting, abuse prevention, rate limiting and security monitoring.
  4. Service Improvement (Aggregated Only). Using de-identified, aggregated data to improve reliability and performance. No individual is identifiable in this processing.
  5. Legal Compliance. Processing necessary to comply with applicable law, including responding to court orders, provided INCLUXA notifies the Customer unless legally prohibited.

Prohibited purposes: INCLUXA will not use Customer Personal Data for advertising, behavioral profiling, sale to third parties, training AI models, or any purpose not listed above.

5. Categories of Customer Personal Data Processed

CategoryExamplesRetention
Portal user detailsName, email, role, hashed password, two-factor settingsDuration of account + 90 days after deletion
Widget end-user preferencesAccessibility settings stored under an encrypted token — no names or email addresses12 months of inactivity
Usage and API logsAPI calls, feature usage, IP addresses (masked in audit logs)13 months rolling
Scan dataScanned page URLs and content, issues found, reportsDuration of account + 90 days after deletion
AI inputs (AI add-on only)Content submitted to AI features, scrubbed of personal identifiers before it is sent to AnthropicCached results up to 7 days; not used for model training
Audit logsWho did what, when, and from where2 years (internal audit-log retention policy)

Minimum necessary principle: INCLUXA processes only the Customer Personal Data needed to deliver the contracted services. The widget does not ask site visitors for names or email addresses.

6. Technical & Organizational Security Measures

INCLUXA maintains the following security measures, consistent with the sensitivity of Customer Personal Data:

6.1 Encryption

  • Data encrypted at rest (AES-256) in Azure SQL Database and Azure Blob Storage
  • TLS 1.2 or higher enforced for all data in transit (TLS 1.3 preferred)
  • Selected sensitive fields additionally encrypted at the application level

6.2 Access Control

  • Role-based access control (Owner, Admin, Developer, Viewer) within each customer account
  • Multi-factor authentication required for INCLUXA personnel with access to production systems
  • Least-privilege principle enforced; access reviewed periodically

6.3 Infrastructure

  • Hosted on Microsoft Azure, United States regions (Central US / East US)
  • Cloudflare WAF and DDoS protection on all endpoints
  • Network segmentation; database not publicly reachable
  • Automatic patching and vulnerability scanning

6.4 Procedures

  • Documented incident response plan with 24-hour customer notification (Section 10)
  • Confidentiality obligations and security awareness practices for anyone with access to Customer Personal Data
  • Immutable audit logs retained for 2 years

7. Approved Sub-Processors

By executing this DPA, the Customer provides general authorization for INCLUXA to engage the following sub-processors for the listed purposes. INCLUXA will notify the Customer at least 30 days in advance of adding or replacing a sub-processor that handles Customer Personal Data, giving the Customer the opportunity to object.

Sub-ProcessorPurposeData CategoriesLocation
Microsoft AzureCloud infrastructure, encrypted database, blob storage, managed identity, secrets management (Key Vault), application performance monitoring (Application Insights)All Customer Personal Data categories (encrypted at rest)United States (Central US / East US)
Anthropic, PBC (Claude AI)AI features for customers with the AI add-on; IEP accommodation extraction for Schools customersContent submitted to AI features, scrubbed of personal identifiers before sendingUnited States
Cloudflare, Inc.DNS, WAF, DDoS protection, TLS termination, bot mitigation (Turnstile CAPTCHA)IP addresses and request metadata onlyGlobal (edge; configuration data stored in US)
Vercel Inc.Hosting for marketing site and customer portal; TLS termination; edge request routingIP addresses, request metadata, and authenticated session cookies — no customer data persisted on VercelGlobal (edge; primary region US)
Bunny CDN (BunnyWay d.o.o.)Widget SDK and static asset deliveryIP addresses and user-agent onlyGlobal (edge)
Stripe, Inc.Payment processing, subscription management, tax calculation, customer billing portalBilling contact details, tokenized payment method, invoice metadataUnited States
Resend (Resend.com, Inc.)Transactional email delivery (account verification, password reset, team invites, 2FA codes, billing notifications). Links are time-limited and single-use.Recipient email address and message contentUnited States
Have I Been Pwned (Superlative Enterprises Pty Ltd)Password breach screening at registration and password changeOur server sends only the first 5 characters of the SHA-1 hash of the password (k-anonymity); the password itself is never sent to Have I Been PwnedAustralia
Sentry (Functional Software, Inc.)Application error monitoring and debuggingError context — personal identifiers suppressed from error payloads where possibleUnited States
Google LLCSign in with Google (portal and Chrome Extension); Google Fonts loaded by the widget; Google Workspace (Gmail) inbox for privacy, security and support mailSign-in: name, email and Google account ID of users who choose Google sign-in. Fonts: site visitor IP address and browser details. Workspace: content of emails sent to usUnited States
jsDelivrOpen-source files loaded by the widget from the jsDelivr CDNSite visitor IP address and browser detailsGlobal (CDN)

INCLUXA maintains its own Data Processing Agreements (or the provider's standard data processing terms) with each sub-processor listed above. Contact privacy@incluxa.com for copies of applicable sub-processor DPAs.

8. Retention & Deletion

8.1 Standard Retention

Customer Personal Data is retained for the periods listed in Section 5.

8.2 Individual Deletion Requests

The Customer may request deletion of specific Customer Personal Data at any time via privacy@incluxa.com. INCLUXA will complete deletion within 30 days and provide written confirmation. Audit log entries recording that a deletion occurred are retained for the audit-log retention period.

8.3 Termination Deletion

Within 90 days of account closure, INCLUXA will permanently delete (or, on written request, return) all Customer Personal Data, except audit logs retained under Section 5. Written confirmation of deletion will be provided on request.

9. Data Subject Rights

INCLUXA will assist the Customer, taking into account the nature of the processing, in responding to requests from individuals exercising their rights under GDPR (Articles 15–22), the CCPA and similar laws, including access, correction, deletion and portability.

If INCLUXA receives a request directly from an individual about Customer Personal Data, it will forward the request to the Customer. The Customer can send requests for assistance to privacy@incluxa.com; INCLUXA responds within 30 days.

10. Breach Notification

In the event of any actual or reasonably suspected unauthorized access to, disclosure, loss, or alteration of Customer Personal Data, INCLUXA will:

  1. Notify the Customer within 24 hours of becoming aware of the incident. Notification may be preliminary if investigation is ongoing — INCLUXA will not delay notification to complete the full investigation.
  2. Include in the notification: the nature of the incident; the categories and approximate volume of Customer Personal Data involved; the likely consequences; the measures taken or proposed to address the incident and mitigate its effects.
  3. Cooperate fully with the Customer's incident response and any regulatory investigation.
  4. Provide updates at least every 48 hours until the incident is fully resolved and remediated.
  5. Assist with regulatory notifications to the extent required — including providing information the Customer needs to notify supervisory authorities or affected individuals.

To report a security incident: security@incluxa.com (monitored daily).

11. International Data Transfers

INCLUXA processes and stores Customer Personal Data in the United States (Microsoft Azure, United States regions). There is no EU, UK or Canada hosting region. If the Customer is located in a jurisdiction with cross-border data transfer restrictions (e.g., EU/EEA member states, UK), the following mechanisms apply:

  • EU/EEA: The European Commission Standard Contractual Clauses for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), Module Two — Controller to Processor, are incorporated into this DPA by reference. Annex I (parties & processing description), Annex II (technical and organisational measures), and Annex III (sub-processors) are populated by Sections 2 and 5, Section 6, and Section 7 of this DPA respectively. Docking clause (Clause 7) is accepted; optional Clause 11(a) (independent dispute resolution) is not selected. Governing law: Ireland; forum: Irish courts. Full SCC text is available on written request to privacy@incluxa.com.
  • United Kingdom: The ICO's International Data Transfer Addendum issued under s.119A of the Data Protection Act 2018 is appended to the EU SCCs above and incorporated by reference.
  • Other jurisdictions: INCLUXA will enter into any transfer mechanism required by applicable law on written request.

For U.S. customers, Customer Personal Data is stored in the United States; sub-processors that operate global edge networks (Section 7) may handle request data outside the United States in transit.

12. Audits & Certifications

INCLUXA operates security controls aligned to the SOC 2 Trust Services Criteria (SOC 2 audit-ready, not yet certified). We engage a CPA audit firm only when a customer requires a report; certification is available within 60 days of committed engagement. Once a SOC 2 report is issued, it will be shared with customers under NDA on written request.

In the meantime, INCLUXA will:

  • Respond to reasonable written security questionnaires within 20 business days
  • Provide evidence of security controls (penetration-test summary, access control policies) under NDA on written request
  • Allow customers to conduct audits (at the customer's expense, with 30 days' notice, no more than once per year) provided such audits do not compromise other customers' data security

13. Schools & Student Data

Schools and districts: student data is covered by the district agreement (SDPC National Data Privacy Agreement v2.0 + state exhibit) signed in the portal under Settings → Schools, with a district-selected retention period of 1–120 months. This DPA does not apply to student data.

See our Privacy Policy §12 and Terms §18 for the Schools terms that apply alongside the district agreement.

14. Liability

Each party's liability under this DPA is subject to the liability limitations in the INCLUXA Terms of Service, unless a signed agreement between the parties says otherwise.

15. How to Execute a DPA

To receive and countersign a binding DPA:

  1. Email privacy@incluxa.com with the subject line "DPA Request — [Company Name]".
  2. INCLUXA sends the DPA with your company's details and the sub-processors relevant to your subscription.
  3. Sign and return the DPA to privacy@incluxa.com; INCLUXA countersigns and returns a fully executed copy.

No charge: The DPA is provided at no additional cost to all paid customers. Schools and districts sign the district agreement in the portal instead (Section 13).

Contact

DPA requests & executionprivacy@incluxa.com
Student privacy (Schools)privacy@incluxa.com
Security incidentssecurity@incluxa.com
Legal inquirieslegal@incluxa.com