INNORIX
Transfer BuilderTransfer FinderDevelopersResourcesCustomers
Start Free
INNORIX

LET FILES
MOVE THEMSELVES

INNORIX provides enterprise file infrastructure for moving and automating files across every system and environment.
Trusted by more than 5,000 enterprise and government agencies.

START HERE

  • Build the Transfer You Need
  • Find the Transfer You Need

POPULAR TRANSFERS

  • Sync Team Folders
  • Send Large Files to Clients
  • Explore Files Across Systems
  • Migrate FTP, SFTP, SCP & rsync
  • Add Transfer to Any App
  • Add Web Upload & Download
  • Build AI & Data Workflows
  • Browse All Transfers→

DEVELOPERS

  • Developer Center
  • Examples
  • API Quickstart
  • Developer Guide
  • API Reference
  • GitHub

RESOURCES

  • Resource Center
  • Product Guide
  • Integrations
  • Deploy & Manage
  • Help Center

CUSTOMERS

  • Government
  • Public Sector
  • Manufacturing
  • Engineering
  • Finance
  • Distribution
  • IT/Telecom
  • Media
  • Healthcare
  • Education

PLANS

  • Pricing

COMPANY

About Us

OTHER INNORIX PRODUCT

Al.bert — Smart Traffic AI

GLOBAL OFFICES

  • New York, USA
  • Seoul, South Korea
  • Ho Chi Minh City, Vietnam
  • View Office Locations→

(C)2026 INNORIX. All rights reserved.

  • Security
  • Status
  • Terms
  • Privacy
  • Cookies

DATA PROCESSING ADDENDUM

Data Processing Addendum

Review the INNORIX Data Processing Addendum governing the processing of Customer Personal Data in connection with eligible INNORIX services.

On this page

  1. 1. Scope
  2. 2. Definitions
  3. 3. Roles of the Parties
  4. 4. Customer Instructions
  5. 5. Customer Responsibilities
  6. 6. Nature and Purpose of Processing
  7. 7. Categories of Data Subjects
  8. 8. Categories of Personal Data
  9. 9. Direct Transfer Architecture
  10. 10. Data Minimization
  11. 11. Confidentiality
  12. 12. Security Measures
  13. 13. Customer-Managed Infrastructure
  14. 14. Subprocessors
  15. 15. Subprocessor Obligations
  16. 16. Changes to Subprocessors
  17. 17. International Data Transfers
  18. 18. Data Location
  19. 19. Data Subject Requests
  20. 20. Requests Received Directly by INNORIX
  21. 21. Security Incident Notification
  22. 22. Security Incident Cooperation
  23. 23. Customer Security Incidents
  24. 24. Audit and Compliance Information
  25. 25. Additional Audit Requests
  26. 26. Government and Legal Requests
  27. 27. Data Retention
  28. 28. Operational Logs
  29. 29. Billing and Legal Records
  30. 30. Termination and Data Export
  31. 31. Data Deletion
  32. 32. Backups
  33. 33. On-Premises Deployments
  34. 34. Hybrid Deployments
  35. 35. Air-Gapped Deployments
  36. 36. Usage Metering
  37. 37. Customer File Content
  38. 38. Secondary Use
  39. 39. Support Data
  40. 40. Business Continuity
  41. 41. Compliance with Applicable Law
  42. 42. Conflict
  43. 43. Liability
  44. 44. Duration
  45. Related Resources

Legal documents

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Security
  • Service Level Agreement
  • Data Processing Addendum
  • Subprocessors

This Data Processing Addendum (“DPA”) forms part of the agreement governing the Customer’s use of INNORIX Services.

It applies where INNORIX processes Personal Data on behalf of a Customer in connection with the Services.

For purposes of this DPA, “Customer” means the organization using the applicable INNORIX Service, and “INNORIX” means the INNORIX contracting entity identified in the applicable subscription, Order Form, invoice, or other agreement.


1. Scope#

This DPA applies to Customer Personal Data processed by INNORIX on behalf of Customer in connection with:

  • INNORIX Cloud

  • INNORIX Platform

  • Hybrid deployments

  • On-Premises components that communicate with INNORIX-managed services

  • APIs

  • Device management

  • transfer orchestration

  • operational logging

  • usage metering

  • support

  • related INNORIX Services

This DPA does not replace the INNORIX Privacy Policy.

The Privacy Policy governs Personal Data that INNORIX processes for its own purposes, such as:

  • Account administration

  • Billing administration

  • Website operation

  • Security

  • Customer communications

  • Legal compliance

Privacy Policy →


2. Definitions#

Customer Personal Data#

“Customer Personal Data” means Personal Data processed by INNORIX on behalf of Customer through the Services.

Personal Data#

“Personal Data” means information relating to an identified or identifiable individual, or equivalent information protected under applicable privacy or data protection law.

Processing#

“Processing” includes collecting, accessing, using, transmitting, storing, organizing, disclosing, deleting, or otherwise handling Personal Data.

Data Protection Law#

“Data Protection Law” means applicable privacy and data protection laws governing the Processing of Customer Personal Data.

Subprocessor#

“Subprocessor” means a third party engaged by INNORIX to process Customer Personal Data on behalf of Customer.

Security Incident#

“Security Incident” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by INNORIX.


3. Roles of the Parties#

Where Customer determines the purposes and means of processing Customer Personal Data:

  • Customer acts as Controller

  • INNORIX acts as Processor

Where Customer acts as a Processor on behalf of another organization:

  • Customer acts as Processor

  • INNORIX acts as Subprocessor

The parties’ roles may vary depending on the relevant Processing activity and applicable law.


4. Customer Instructions#

INNORIX processes Customer Personal Data only:

  • to provide the Services

  • according to Customer’s documented instructions

  • as described in the applicable agreement

  • as configured by Customer through the Services

  • as required by applicable law

Customer’s use and configuration of the Services, Order Forms, support requests, and written instructions form part of Customer’s documented instructions.

INNORIX will not use Customer Personal Data for unrelated purposes.


5. Customer Responsibilities#

Customer is responsible for:

  • having a lawful basis for the Processing

  • providing required privacy notices

  • obtaining consent where required

  • ensuring that Customer instructions comply with applicable law

  • determining which Personal Data is processed through the Services

  • managing access permissions

  • maintaining the security of Customer-controlled systems

  • responding to Data Subject requests where Customer acts as Controller

Customer will not instruct INNORIX to process Personal Data in violation of applicable law.


6. Nature and Purpose of Processing#

INNORIX may process Customer Personal Data as necessary to:

  • connect and manage Devices

  • authenticate authorized users and systems

  • execute file transfers

  • run automated workflows

  • maintain transfer status

  • provide audit and operational records

  • monitor service activity

  • troubleshoot errors

  • provide support

  • measure usage

  • apply security and subscription policies

  • protect the Services

  • maintain service reliability


7. Categories of Data Subjects#

Depending on Customer’s use of the Services, Data Subjects may include:

  • Customer employees

  • contractors

  • administrators

  • application users

  • business partners

  • Customer’s customers

  • recipients or senders of transferred files

  • other individuals represented in Customer systems or metadata


8. Categories of Personal Data#

Customer Personal Data may include:

Account and identity information#

  • name

  • business email address

  • user identifier

  • role

  • organization information

Device and connection information#

  • Device identifiers

  • host information

  • IP address

  • operating system information

  • connection status

Operational metadata#

  • source and destination identifiers

  • transfer metadata

  • Run and Flow identifiers

  • timestamps

  • transfer status

  • file names or paths where required for service functionality

  • error and retry information

  • audit records

Usage information#

  • Device usage

  • transfer volume

  • API usage

  • operational usage metrics

Support information#

  • communications

  • diagnostic information

  • logs provided by Customer

Customer file content#

Customer file content may be processed where technically necessary for the selected Service or transfer architecture.


9. Direct Transfer Architecture#

INNORIX supports direct endpoint-to-endpoint file transfer in applicable configurations.

Where Direct Transfer is used:

  • file content moves between authorized Source and Destination systems

  • INNORIX Cloud does not serve as a mandatory intermediate file repository

  • the INNORIX Control Plane manages connection, policy, orchestration, status, and operational metadata

The actual data path depends on the selected Deployment, routing, network configuration, and any additional services used by Customer.


10. Data Minimization#

INNORIX limits Processing to information reasonably necessary to provide and operate the Services.

Metering, Billing, and Policy systems are designed to use identifiers and usage data rather than unnecessary Personal Data.

INNORIX does not intentionally store the following in standard Metering or Billing records:

  • file contents

  • passwords

  • raw access tokens

  • raw object-storage credentials

  • secret keys


11. Confidentiality#

INNORIX limits access to Customer Personal Data to authorized personnel and systems that require access for legitimate business or technical purposes.

Personnel with access to Customer Personal Data are subject to appropriate confidentiality obligations.


12. Security Measures#

INNORIX maintains technical and organizational safeguards designed to protect Customer Personal Data from unauthorized access, disclosure, alteration, loss, or destruction.

These safeguards include measures related to:

  • authentication

  • access control

  • role-based permissions

  • encrypted communications

  • secure credential handling

  • audit logging

  • operational monitoring

  • vulnerability management

  • change management

  • incident response

  • backup and recovery

  • secure development practices

Additional information is available on the INNORIX Security page.

Security →


13. Customer-Managed Infrastructure#

Customer remains responsible for the security and administration of Customer-controlled:

  • servers

  • operating systems

  • virtual machines

  • Kubernetes environments

  • storage

  • cloud accounts

  • networks

  • firewalls

  • VPNs

  • credentials

  • access permissions

This DPA does not transfer responsibility for Customer-managed infrastructure to INNORIX.


14. Subprocessors#

Customer authorizes INNORIX to use Subprocessors where reasonably necessary to provide the Services.

INNORIX maintains a current list of relevant Subprocessors and service providers.

Subprocessors →

The Subprocessor list may include information such as:

  • provider

  • purpose

  • service category

  • relevant data

  • processing location information


15. Subprocessor Obligations#

Where a Subprocessor processes Customer Personal Data on behalf of INNORIX, INNORIX requires appropriate contractual data protection obligations.

INNORIX remains responsible for its Subprocessors to the extent required by applicable Data Protection Law and the applicable Customer agreement.


16. Changes to Subprocessors#

INNORIX may add, replace, or discontinue Subprocessors as its Services and infrastructure evolve.

Where required by applicable law or contract, INNORIX will provide appropriate notice of material changes involving Subprocessors that process Customer Personal Data.

Customer may raise reasonable data protection concerns regarding a new Subprocessor through the applicable INNORIX contact channel.


17. International Data Transfers#

Customer Personal Data may be processed in jurisdictions other than the jurisdiction where Customer is located.

Where applicable Data Protection Law requires safeguards for an international transfer, INNORIX uses an appropriate lawful transfer mechanism.

Such mechanisms may include:

  • legally recognized standard contractual protections

  • adequacy mechanisms

  • approved transfer frameworks

  • other lawful safeguards

The applicable mechanism depends on the relevant jurisdictions and Processing activity.


18. Data Location#

The location in which Customer Personal Data is processed may vary depending on:

  • selected Service

  • Deployment

  • Cloud region

  • Customer configuration

  • Subprocessor

  • support requirements

A specific data residency commitment applies only where expressly included in the applicable Service or Customer agreement.


19. Data Subject Requests#

Taking into account the nature of the Processing, INNORIX will provide reasonable assistance to Customer with legally valid Data Subject requests relating to Customer Personal Data.

Requests may concern:

  • access

  • correction

  • deletion

  • restriction

  • portability

  • objection

Where Customer can fulfill a request using available product functionality, Customer should use that functionality.


20. Requests Received Directly by INNORIX#

If INNORIX receives a request from an individual relating to Customer Personal Data for which Customer is the Controller, INNORIX may direct the individual to Customer unless prohibited by law.

INNORIX will not independently act as Customer’s Controller for that data solely because it receives such a request.


21. Security Incident Notification#

INNORIX will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data where notification is required by applicable law or contract.

Information may include, as reasonably available:

  • nature of the Security Incident

  • affected systems or data

  • known or likely impact

  • mitigation measures

  • remediation status

  • contact information for follow-up

Information may be provided in stages as an investigation develops.


22. Security Incident Cooperation#

INNORIX will take reasonable steps to:

  • investigate the incident

  • contain affected systems

  • mitigate known risks

  • restore affected services

  • support Customer’s applicable compliance obligations

A Security Incident notification does not constitute an admission of liability.


23. Customer Security Incidents#

Customer is responsible for incidents arising solely from Customer-controlled:

  • credentials

  • endpoints

  • networks

  • cloud accounts

  • storage

  • configuration

  • third-party services

unless the incident results from INNORIX’s failure to meet its obligations under the applicable agreement.


24. Audit and Compliance Information#

INNORIX will make available information reasonably necessary to demonstrate compliance with this DPA.

This may include:

  • Security documentation

  • Subprocessor information

  • compliance information

  • questionnaire responses

  • available audit or assurance information

Customer audit requests must be reasonable in scope and conducted in a manner that protects:

  • INNORIX Confidential Information

  • security information

  • information relating to other customers

  • service availability


25. Additional Audit Requests#

Where available documentation is insufficient and applicable law requires additional audit rights, the parties will cooperate in good faith regarding an appropriate review.

Any review must:

  • be proportionate

  • avoid unnecessary service disruption

  • protect confidential information

  • follow reasonable security procedures


26. Government and Legal Requests#

If INNORIX receives a legally binding request for Customer Personal Data, INNORIX will disclose only information required by the applicable legal process.

Where legally permitted, INNORIX may notify Customer of the request.


27. Data Retention#

INNORIX retains Customer Personal Data only for as long as reasonably necessary to:

  • provide the Services

  • support Customer

  • maintain security

  • meet contractual obligations

  • comply with applicable law

Different categories of information may have different retention periods.


28. Operational Logs#

Searchable operational log retention depends on the applicable:

  • Plan

  • Deployment

  • configuration

  • Customer agreement

Longer retention may be available through supported archive or external monitoring options.


29. Billing and Legal Records#

Certain information may be retained after termination where required for:

  • billing

  • tax

  • accounting

  • fraud prevention

  • dispute resolution

  • legal compliance

These records are maintained separately from active Customer service data.


30. Termination and Data Export#

When a Subscription ends, Customer may have a limited period under the applicable Terms to review or export available service information.

This may include:

  • logs

  • receipts

  • configuration

  • operational records

Customer should export information it needs to retain before access ends.


31. Data Deletion#

After the applicable access or Grace Period, INNORIX may begin deletion of Customer Personal Data from active systems where the information is no longer required.

Deletion may be delayed where retention is required by:

  • applicable law

  • tax or accounting obligations

  • court order

  • regulatory requirement

  • legal hold

  • unresolved dispute


32. Backups#

Customer Personal Data deleted from active systems may remain temporarily in Backup copies until removed through normal Backup Rotation.

Backup data remains protected and is not returned to active use except where required for legitimate service recovery or legal purposes.


33. On-Premises Deployments#

In Customer-managed On-Premises environments:

  • Customer controls the underlying infrastructure

  • Customer controls local storage

  • Customer controls operating systems

  • Customer controls network access

INNORIX’s responsibilities are limited to the components and Services managed by INNORIX.


34. Hybrid Deployments#

In Hybrid environments, Processing responsibilities are divided according to the systems operated by each party.

Customer remains responsible for Customer-managed infrastructure, while INNORIX remains responsible for the INNORIX-managed components within the scope of the applicable agreement.


35. Air-Gapped Deployments#

Air-Gapped environments may operate without routine online communication with INNORIX Cloud.

Where Customer provides information to INNORIX for:

  • support

  • licensing

  • usage reporting

  • diagnostics

such information is handled according to this DPA and the applicable agreement where it contains Customer Personal Data.


36. Usage Metering#

INNORIX may process usage information necessary to:

  • enforce Subscription limits

  • calculate charges

  • provide usage visibility

  • protect against abuse

  • operate the Services

Metering is designed to use the minimum information reasonably necessary for these purposes.


37. Customer File Content#

INNORIX does not acquire ownership of Customer file content.

INNORIX processes Customer file content only as necessary to provide the selected Service and according to Customer instructions.

INNORIX does not sell Customer file content.


38. Secondary Use#

INNORIX does not use Customer Personal Data processed on behalf of Customer for unrelated advertising.

Any materially different secondary use would require an appropriate legal and contractual basis.


39. Support Data#

Where Customer voluntarily provides logs, screenshots, diagnostic files, or other information to INNORIX for support, Customer authorizes INNORIX to process that information for:

  • troubleshooting

  • support

  • service restoration

  • security

  • issue analysis

Customer should avoid providing unnecessary Personal Data.


40. Business Continuity#

INNORIX may maintain Backup and recovery measures appropriate to the INNORIX-managed Services.

Customer remains responsible for backup and business continuity for Customer-managed infrastructure unless otherwise agreed.


41. Compliance with Applicable Law#

Each party will comply with Data Protection Law applicable to its own Processing activities.

Nothing in this DPA requires either party to violate applicable law.


42. Conflict#

If this DPA conflicts with the Terms or Customer Agreement regarding the Processing of Customer Personal Data, this DPA controls for that subject matter.

Customer-specific Order Forms or privacy addenda may contain additional terms.


43. Liability#

Liability relating to this DPA is governed by the liability provisions of the applicable Terms, Customer Agreement, or Order Form, except where applicable law requires otherwise.


44. Duration#

This DPA remains in effect for as long as INNORIX processes Customer Personal Data on behalf of Customer.

Obligations relating to confidentiality, security, deletion, and lawful Processing continue for as long as INNORIX retains Customer Personal Data subject to this DPA.


Related Resources#

Privacy Policy
How INNORIX processes Personal Data in connection with its website, Accounts and Services.

Security
Security architecture and safeguards for INNORIX Services.

Subprocessors
Third-party providers involved in operating applicable INNORIX Services.

Terms
General terms governing the use of INNORIX Services.