DATA PROCESSING ADDENDUM
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement governing the Customer’s use of INNORIX Services.
It applies where INNORIX processes Personal Data on behalf of a Customer in connection with the Services.
For purposes of this DPA, “Customer” means the organization using the applicable INNORIX Service, and “INNORIX” means the INNORIX contracting entity identified in the applicable subscription, Order Form, invoice, or other agreement.
1. Scope
This DPA applies to Customer Personal Data processed by INNORIX on behalf of Customer in connection with:
-
INNORIX Cloud
-
INNORIX Platform
-
Hybrid deployments
-
On-Premises components that communicate with INNORIX-managed services
-
APIs
-
Device management
-
transfer orchestration
-
operational logging
-
usage metering
-
support
-
related INNORIX Services
This DPA does not replace the INNORIX Privacy Policy.
The Privacy Policy governs Personal Data that INNORIX processes for its own purposes, such as:
-
Account administration
-
Billing administration
-
Website operation
- Security
-
Customer communications
-
Legal compliance
2. Definitions
Customer Personal Data
“Customer Personal Data” means Personal Data processed by INNORIX on behalf of Customer through the Services.
Personal Data
“Personal Data” means information relating to an identified or identifiable individual, or equivalent information protected under applicable privacy or data protection law.
Processing
“Processing” includes collecting, accessing, using, transmitting, storing, organizing, disclosing, deleting, or otherwise handling Personal Data.
Data Protection Law
“Data Protection Law” means applicable privacy and data protection laws governing the Processing of Customer Personal Data.
Subprocessor
“Subprocessor” means a third party engaged by INNORIX to process Customer Personal Data on behalf of Customer.
Security Incident
“Security Incident” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by INNORIX.
3. Roles of the Parties
Where Customer determines the purposes and means of processing Customer Personal Data:
-
Customer acts as Controller
-
INNORIX acts as Processor
Where Customer acts as a Processor on behalf of another organization:
-
Customer acts as Processor
-
INNORIX acts as Subprocessor
The parties’ roles may vary depending on the relevant Processing activity and applicable law.
4. Customer Instructions
INNORIX processes Customer Personal Data only:
-
to provide the Services
-
according to Customer’s documented instructions
-
as described in the applicable agreement
-
as configured by Customer through the Services
-
as required by applicable law
Customer’s use and configuration of the Services, Order Forms, support requests, and written instructions form part of Customer’s documented instructions.
INNORIX will not use Customer Personal Data for unrelated purposes.
5. Customer Responsibilities
Customer is responsible for:
-
having a lawful basis for the Processing
-
providing required privacy notices
-
obtaining consent where required
-
ensuring that Customer instructions comply with applicable law
-
determining which Personal Data is processed through the Services
-
managing access permissions
-
maintaining the security of Customer-controlled systems
-
responding to Data Subject requests where Customer acts as Controller
Customer will not instruct INNORIX to process Personal Data in violation of applicable law.
6. Nature and Purpose of Processing
INNORIX may process Customer Personal Data as necessary to:
-
connect and manage Devices
-
authenticate authorized users and systems
-
execute file transfers
-
run automated workflows
-
maintain transfer status
-
provide audit and operational records
-
monitor service activity
-
troubleshoot errors
-
provide support
-
measure usage
-
apply security and subscription policies
-
protect the Services
-
maintain service reliability
7. Categories of Data Subjects
Depending on Customer’s use of the Services, Data Subjects may include:
-
Customer employees
-
contractors
-
administrators
-
application users
-
business partners
-
Customer’s customers
-
recipients or senders of transferred files
-
other individuals represented in Customer systems or metadata
8. Categories of Personal Data
Customer Personal Data may include:
Account and identity information
-
name
-
business email address
-
user identifier
-
role
-
organization information
Device and connection information
-
Device identifiers
-
host information
-
IP address
-
operating system information
-
connection status
Operational metadata
-
source and destination identifiers
-
transfer metadata
-
Run and Flow identifiers
-
timestamps
-
transfer status
-
file names or paths where required for service functionality
-
error and retry information
-
audit records
Usage information
-
Device usage
-
transfer volume
-
API usage
-
operational usage metrics
Support information
-
communications
-
diagnostic information
-
logs provided by Customer
Customer file content
Customer file content may be processed where technically necessary for the selected Service or transfer architecture.
9. Direct Transfer Architecture
INNORIX supports direct endpoint-to-endpoint file transfer in applicable configurations.
Where Direct Transfer is used:
-
file content moves between authorized Source and Destination systems
-
INNORIX Cloud does not serve as a mandatory intermediate file repository
-
the INNORIX Control Plane manages connection, policy, orchestration, status, and operational metadata
The actual data path depends on the selected Deployment, routing, network configuration, and any additional services used by Customer.
10. Data Minimization
INNORIX limits Processing to information reasonably necessary to provide and operate the Services.
Metering, Billing, and Policy systems are designed to use identifiers and usage data rather than unnecessary Personal Data.
INNORIX does not intentionally store the following in standard Metering or Billing records:
-
file contents
-
passwords
-
raw access tokens
-
raw object-storage credentials
-
secret keys
11. Confidentiality
INNORIX limits access to Customer Personal Data to authorized personnel and systems that require access for legitimate business or technical purposes.
Personnel with access to Customer Personal Data are subject to appropriate confidentiality obligations.
12. Security Measures
INNORIX maintains technical and organizational safeguards designed to protect Customer Personal Data from unauthorized access, disclosure, alteration, loss, or destruction.
These safeguards include measures related to:
-
authentication
-
access control
-
role-based permissions
-
encrypted communications
-
secure credential handling
-
audit logging
-
operational monitoring
-
vulnerability management
-
change management
-
incident response
-
backup and recovery
-
secure development practices
Additional information is available on the INNORIX Security page.
Security13. Customer-Managed Infrastructure
Customer remains responsible for the security and administration of Customer-controlled:
-
servers
-
operating systems
-
virtual machines
-
Kubernetes environments
-
storage
-
cloud accounts
-
networks
-
firewalls
-
VPNs
-
credentials
-
access permissions
This DPA does not transfer responsibility for Customer-managed infrastructure to INNORIX.
14. Subprocessors
Customer authorizes INNORIX to use Subprocessors where reasonably necessary to provide the Services.
INNORIX maintains a current list of relevant Subprocessors and service providers.
SubprocessorsThe Subprocessor list may include information such as:
-
provider
-
purpose
-
service category
-
relevant data
-
processing location information
15. Subprocessor Obligations
Where a Subprocessor processes Customer Personal Data on behalf of INNORIX, INNORIX requires appropriate contractual data protection obligations.
INNORIX remains responsible for its Subprocessors to the extent required by applicable Data Protection Law and the applicable Customer agreement.
16. Changes to Subprocessors
INNORIX may add, replace, or discontinue Subprocessors as its Services and infrastructure evolve.
Where required by applicable law or contract, INNORIX will provide appropriate notice of material changes involving Subprocessors that process Customer Personal Data.
Customer may raise reasonable data protection concerns regarding a new Subprocessor through the applicable INNORIX contact channel.
17. International Data Transfers
Customer Personal Data may be processed in jurisdictions other than the jurisdiction where Customer is located.
Where applicable Data Protection Law requires safeguards for an international transfer, INNORIX uses an appropriate lawful transfer mechanism.
Such mechanisms may include:
-
legally recognized standard contractual protections
-
adequacy mechanisms
-
approved transfer frameworks
-
other lawful safeguards
The applicable mechanism depends on the relevant jurisdictions and Processing activity.
18. Data Location
The location in which Customer Personal Data is processed may vary depending on:
-
selected Service
-
Deployment
-
Cloud region
-
Customer configuration
-
Subprocessor
-
support requirements
A specific data residency commitment applies only where expressly included in the applicable Service or Customer agreement.
19. Data Subject Requests
Taking into account the nature of the Processing, INNORIX will provide reasonable assistance to Customer with legally valid Data Subject requests relating to Customer Personal Data.
Requests may concern:
-
access
-
correction
-
deletion
-
restriction
-
portability
-
objection
Where Customer can fulfill a request using available product functionality, Customer should use that functionality.
20. Requests Received Directly by INNORIX
If INNORIX receives a request from an individual relating to Customer Personal Data for which Customer is the Controller, INNORIX may direct the individual to Customer unless prohibited by law.
INNORIX will not independently act as Customer’s Controller for that data solely because it receives such a request.
21. Security Incident Notification
INNORIX will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data where notification is required by applicable law or contract.
Information may include, as reasonably available:
-
nature of the Security Incident
-
affected systems or data
-
known or likely impact
-
mitigation measures
-
remediation status
-
contact information for follow-up
Information may be provided in stages as an investigation develops.
22. Security Incident Cooperation
INNORIX will take reasonable steps to:
-
investigate the incident
-
contain affected systems
-
mitigate known risks
-
restore affected services
-
support Customer’s applicable compliance obligations
A Security Incident notification does not constitute an admission of liability.
23. Customer Security Incidents
Customer is responsible for incidents arising solely from Customer-controlled:
-
credentials
-
endpoints
-
networks
-
cloud accounts
-
storage
-
configuration
-
third-party services
unless the incident results from INNORIX’s failure to meet its obligations under the applicable agreement.
24. Audit and Compliance Information
INNORIX will make available information reasonably necessary to demonstrate compliance with this DPA.
This may include:
-
Security documentation
-
Subprocessor information
-
compliance information
-
questionnaire responses
-
available audit or assurance information
Customer audit requests must be reasonable in scope and conducted in a manner that protects:
-
INNORIX Confidential Information
-
security information
-
information relating to other customers
-
service availability
25. Additional Audit Requests
Where available documentation is insufficient and applicable law requires additional audit rights, the parties will cooperate in good faith regarding an appropriate review.
Any review must:
-
be proportionate
-
avoid unnecessary service disruption
-
protect confidential information
-
follow reasonable security procedures
26. Government and Legal Requests
If INNORIX receives a legally binding request for Customer Personal Data, INNORIX will disclose only information required by the applicable legal process.
Where legally permitted, INNORIX may notify Customer of the request.
27. Data Retention
INNORIX retains Customer Personal Data only for as long as reasonably necessary to:
-
provide the Services
-
support Customer
-
maintain security
-
meet contractual obligations
-
comply with applicable law
Different categories of information may have different retention periods.
28. Operational Logs
Searchable operational log retention depends on the applicable:
-
Plan
-
Deployment
-
configuration
-
Customer agreement
Longer retention may be available through supported archive or external monitoring options.
29. Billing and Legal Records
Certain information may be retained after termination where required for:
-
billing
-
tax
-
accounting
-
fraud prevention
-
dispute resolution
-
legal compliance
These records are maintained separately from active Customer service data.
30. Termination and Data Export
When a Subscription ends, Customer may have a limited period under the applicable Terms to review or export available service information.
This may include:
-
logs
-
receipts
-
configuration
-
operational records
Customer should export information it needs to retain before access ends.
31. Data Deletion
After the applicable access or Grace Period, INNORIX may begin deletion of Customer Personal Data from active systems where the information is no longer required.
Deletion may be delayed where retention is required by:
-
applicable law
-
tax or accounting obligations
-
court order
-
regulatory requirement
-
legal hold
-
unresolved dispute
32. Backups
Customer Personal Data deleted from active systems may remain temporarily in Backup copies until removed through normal Backup Rotation.
Backup data remains protected and is not returned to active use except where required for legitimate service recovery or legal purposes.
33. On-Premises Deployments
In Customer-managed On-Premises environments:
-
Customer controls the underlying infrastructure
-
Customer controls local storage
-
Customer controls operating systems
-
Customer controls network access
INNORIX’s responsibilities are limited to the components and Services managed by INNORIX.
34. Hybrid Deployments
In Hybrid environments, Processing responsibilities are divided according to the systems operated by each party.
Customer remains responsible for Customer-managed infrastructure, while INNORIX remains responsible for the INNORIX-managed components within the scope of the applicable agreement.
35. Air-Gapped Deployments
Air-Gapped environments may operate without routine online communication with INNORIX Cloud.
Where Customer provides information to INNORIX for:
-
support
-
licensing
-
usage reporting
-
diagnostics
such information is handled according to this DPA and the applicable agreement where it contains Customer Personal Data.
36. Usage Metering
INNORIX may process usage information necessary to:
-
enforce Subscription limits
-
calculate charges
-
provide usage visibility
-
protect against abuse
-
operate the Services
Metering is designed to use the minimum information reasonably necessary for these purposes.
37. Customer File Content
INNORIX does not acquire ownership of Customer file content.
INNORIX processes Customer file content only as necessary to provide the selected Service and according to Customer instructions.
INNORIX does not sell Customer file content.
38. Secondary Use
INNORIX does not use Customer Personal Data processed on behalf of Customer for unrelated advertising.
Any materially different secondary use would require an appropriate legal and contractual basis.
39. Support Data
Where Customer voluntarily provides logs, screenshots, diagnostic files, or other information to INNORIX for support, Customer authorizes INNORIX to process that information for:
-
troubleshooting
-
support
-
service restoration
- security
-
issue analysis
Customer should avoid providing unnecessary Personal Data.
40. Business Continuity
INNORIX may maintain Backup and recovery measures appropriate to the INNORIX-managed Services.
Customer remains responsible for backup and business continuity for Customer-managed infrastructure unless otherwise agreed.
41. Compliance with Applicable Law
Each party will comply with Data Protection Law applicable to its own Processing activities.
Nothing in this DPA requires either party to violate applicable law.
42. Conflict
If this DPA conflicts with the Terms or Customer Agreement regarding the Processing of Customer Personal Data, this DPA controls for that subject matter.
Customer-specific Order Forms or privacy addenda may contain additional terms.
43. Liability
Liability relating to this DPA is governed by the liability provisions of the applicable Terms, Customer Agreement, or Order Form, except where applicable law requires otherwise.
44. Duration
This DPA remains in effect for as long as INNORIX processes Customer Personal Data on behalf of Customer.
Obligations relating to confidentiality, security, deletion, and lawful Processing continue for as long as INNORIX retains Customer Personal Data subject to this DPA.
Related Resources
Privacy Policy
How INNORIX processes Personal Data in connection with its website, Accounts and Services.
Security
Security architecture and safeguards for INNORIX Services.
Subprocessors
Third-party providers involved in operating applicable INNORIX Services.
Terms
General terms governing the use of INNORIX Services.