INNORIX Logo
Transfer BuilderTransfer Finder
Developers
  • Developer Center
  • Examples
  • API Quickstart
  • Developer Guide
  • API Reference
  • GitHub
Industries
  • Government
  • Public Sector
  • Manufacturing
  • Engineering
  • Finance
  • Distribution
  • IT/Telecom
  • Media
  • Healthcare
  • Education

DATA PROCESSING ADDENDUM

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement governing the Customer’s use of INNORIX Services.

It applies where INNORIX processes Personal Data on behalf of a Customer in connection with the Services.

For purposes of this DPA, “Customer” means the organization using the applicable INNORIX Service, and “INNORIX” means the INNORIX contracting entity identified in the applicable subscription, Order Form, invoice, or other agreement.


1. Scope

This DPA applies to Customer Personal Data processed by INNORIX on behalf of Customer in connection with:

  • INNORIX Cloud

  • INNORIX Platform

  • Hybrid deployments

  • On-Premises components that communicate with INNORIX-managed services

  • APIs

  • Device management

  • transfer orchestration

  • operational logging

  • usage metering

  • support

  • related INNORIX Services

This DPA does not replace the INNORIX Privacy Policy.

The Privacy Policy governs Personal Data that INNORIX processes for its own purposes, such as:

  • Account administration

  • Billing administration

  • Website operation

  • Security
  • Customer communications

  • Legal compliance

Privacy Policy

2. Definitions

Customer Personal Data

“Customer Personal Data” means Personal Data processed by INNORIX on behalf of Customer through the Services.

Personal Data

“Personal Data” means information relating to an identified or identifiable individual, or equivalent information protected under applicable privacy or data protection law.

Processing

“Processing” includes collecting, accessing, using, transmitting, storing, organizing, disclosing, deleting, or otherwise handling Personal Data.

Data Protection Law

“Data Protection Law” means applicable privacy and data protection laws governing the Processing of Customer Personal Data.

Subprocessor

“Subprocessor” means a third party engaged by INNORIX to process Customer Personal Data on behalf of Customer.

Security Incident

“Security Incident” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by INNORIX.


3. Roles of the Parties

Where Customer determines the purposes and means of processing Customer Personal Data:

  • Customer acts as Controller

  • INNORIX acts as Processor

Where Customer acts as a Processor on behalf of another organization:

  • Customer acts as Processor

  • INNORIX acts as Subprocessor

The parties’ roles may vary depending on the relevant Processing activity and applicable law.


4. Customer Instructions

INNORIX processes Customer Personal Data only:

  • to provide the Services

  • according to Customer’s documented instructions

  • as described in the applicable agreement

  • as configured by Customer through the Services

  • as required by applicable law

Customer’s use and configuration of the Services, Order Forms, support requests, and written instructions form part of Customer’s documented instructions.

INNORIX will not use Customer Personal Data for unrelated purposes.


5. Customer Responsibilities

Customer is responsible for:

  • having a lawful basis for the Processing

  • providing required privacy notices

  • obtaining consent where required

  • ensuring that Customer instructions comply with applicable law

  • determining which Personal Data is processed through the Services

  • managing access permissions

  • maintaining the security of Customer-controlled systems

  • responding to Data Subject requests where Customer acts as Controller

Customer will not instruct INNORIX to process Personal Data in violation of applicable law.


6. Nature and Purpose of Processing

INNORIX may process Customer Personal Data as necessary to:

  • connect and manage Devices

  • authenticate authorized users and systems

  • execute file transfers

  • run automated workflows

  • maintain transfer status

  • provide audit and operational records

  • monitor service activity

  • troubleshoot errors

  • provide support

  • measure usage

  • apply security and subscription policies

  • protect the Services

  • maintain service reliability


7. Categories of Data Subjects

Depending on Customer’s use of the Services, Data Subjects may include:

  • Customer employees

  • contractors

  • administrators

  • application users

  • business partners

  • Customer’s customers

  • recipients or senders of transferred files

  • other individuals represented in Customer systems or metadata


8. Categories of Personal Data

Customer Personal Data may include:

Account and identity information

  • name

  • business email address

  • user identifier

  • role

  • organization information

Device and connection information

  • Device identifiers

  • host information

  • IP address

  • operating system information

  • connection status

Operational metadata

  • source and destination identifiers

  • transfer metadata

  • Run and Flow identifiers

  • timestamps

  • transfer status

  • file names or paths where required for service functionality

  • error and retry information

  • audit records

Usage information

  • Device usage

  • transfer volume

  • API usage

  • operational usage metrics

Support information

  • communications

  • diagnostic information

  • logs provided by Customer

Customer file content

Customer file content may be processed where technically necessary for the selected Service or transfer architecture.


9. Direct Transfer Architecture

INNORIX supports direct endpoint-to-endpoint file transfer in applicable configurations.

Where Direct Transfer is used:

  • file content moves between authorized Source and Destination systems

  • INNORIX Cloud does not serve as a mandatory intermediate file repository

  • the INNORIX Control Plane manages connection, policy, orchestration, status, and operational metadata

The actual data path depends on the selected Deployment, routing, network configuration, and any additional services used by Customer.


10. Data Minimization

INNORIX limits Processing to information reasonably necessary to provide and operate the Services.

Metering, Billing, and Policy systems are designed to use identifiers and usage data rather than unnecessary Personal Data.

INNORIX does not intentionally store the following in standard Metering or Billing records:

  • file contents

  • passwords

  • raw access tokens

  • raw object-storage credentials

  • secret keys


11. Confidentiality

INNORIX limits access to Customer Personal Data to authorized personnel and systems that require access for legitimate business or technical purposes.

Personnel with access to Customer Personal Data are subject to appropriate confidentiality obligations.


12. Security Measures

INNORIX maintains technical and organizational safeguards designed to protect Customer Personal Data from unauthorized access, disclosure, alteration, loss, or destruction.

These safeguards include measures related to:

  • authentication

  • access control

  • role-based permissions

  • encrypted communications

  • secure credential handling

  • audit logging

  • operational monitoring

  • vulnerability management

  • change management

  • incident response

  • backup and recovery

  • secure development practices

Additional information is available on the INNORIX Security page.

Security

13. Customer-Managed Infrastructure

Customer remains responsible for the security and administration of Customer-controlled:

  • servers

  • operating systems

  • virtual machines

  • Kubernetes environments

  • storage

  • cloud accounts

  • networks

  • firewalls

  • VPNs

  • credentials

  • access permissions

This DPA does not transfer responsibility for Customer-managed infrastructure to INNORIX.


14. Subprocessors

Customer authorizes INNORIX to use Subprocessors where reasonably necessary to provide the Services.

INNORIX maintains a current list of relevant Subprocessors and service providers.

Subprocessors

The Subprocessor list may include information such as:

  • provider

  • purpose

  • service category

  • relevant data

  • processing location information


15. Subprocessor Obligations

Where a Subprocessor processes Customer Personal Data on behalf of INNORIX, INNORIX requires appropriate contractual data protection obligations.

INNORIX remains responsible for its Subprocessors to the extent required by applicable Data Protection Law and the applicable Customer agreement.


16. Changes to Subprocessors

INNORIX may add, replace, or discontinue Subprocessors as its Services and infrastructure evolve.

Where required by applicable law or contract, INNORIX will provide appropriate notice of material changes involving Subprocessors that process Customer Personal Data.

Customer may raise reasonable data protection concerns regarding a new Subprocessor through the applicable INNORIX contact channel.


17. International Data Transfers

Customer Personal Data may be processed in jurisdictions other than the jurisdiction where Customer is located.

Where applicable Data Protection Law requires safeguards for an international transfer, INNORIX uses an appropriate lawful transfer mechanism.

Such mechanisms may include:

  • legally recognized standard contractual protections

  • adequacy mechanisms

  • approved transfer frameworks

  • other lawful safeguards

The applicable mechanism depends on the relevant jurisdictions and Processing activity.


18. Data Location

The location in which Customer Personal Data is processed may vary depending on:

  • selected Service

  • Deployment

  • Cloud region

  • Customer configuration

  • Subprocessor

  • support requirements

A specific data residency commitment applies only where expressly included in the applicable Service or Customer agreement.


19. Data Subject Requests

Taking into account the nature of the Processing, INNORIX will provide reasonable assistance to Customer with legally valid Data Subject requests relating to Customer Personal Data.

Requests may concern:

  • access

  • correction

  • deletion

  • restriction

  • portability

  • objection

Where Customer can fulfill a request using available product functionality, Customer should use that functionality.


20. Requests Received Directly by INNORIX

If INNORIX receives a request from an individual relating to Customer Personal Data for which Customer is the Controller, INNORIX may direct the individual to Customer unless prohibited by law.

INNORIX will not independently act as Customer’s Controller for that data solely because it receives such a request.


21. Security Incident Notification

INNORIX will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data where notification is required by applicable law or contract.

Information may include, as reasonably available:

  • nature of the Security Incident

  • affected systems or data

  • known or likely impact

  • mitigation measures

  • remediation status

  • contact information for follow-up

Information may be provided in stages as an investigation develops.


22. Security Incident Cooperation

INNORIX will take reasonable steps to:

  • investigate the incident

  • contain affected systems

  • mitigate known risks

  • restore affected services

  • support Customer’s applicable compliance obligations

A Security Incident notification does not constitute an admission of liability.


23. Customer Security Incidents

Customer is responsible for incidents arising solely from Customer-controlled:

  • credentials

  • endpoints

  • networks

  • cloud accounts

  • storage

  • configuration

  • third-party services

unless the incident results from INNORIX’s failure to meet its obligations under the applicable agreement.


24. Audit and Compliance Information

INNORIX will make available information reasonably necessary to demonstrate compliance with this DPA.

This may include:

  • Security documentation

  • Subprocessor information

  • compliance information

  • questionnaire responses

  • available audit or assurance information

Customer audit requests must be reasonable in scope and conducted in a manner that protects:

  • INNORIX Confidential Information

  • security information

  • information relating to other customers

  • service availability


25. Additional Audit Requests

Where available documentation is insufficient and applicable law requires additional audit rights, the parties will cooperate in good faith regarding an appropriate review.

Any review must:

  • be proportionate

  • avoid unnecessary service disruption

  • protect confidential information

  • follow reasonable security procedures


26. Government and Legal Requests

If INNORIX receives a legally binding request for Customer Personal Data, INNORIX will disclose only information required by the applicable legal process.

Where legally permitted, INNORIX may notify Customer of the request.


27. Data Retention

INNORIX retains Customer Personal Data only for as long as reasonably necessary to:

  • provide the Services

  • support Customer

  • maintain security

  • meet contractual obligations

  • comply with applicable law

Different categories of information may have different retention periods.


28. Operational Logs

Searchable operational log retention depends on the applicable:

  • Plan

  • Deployment

  • configuration

  • Customer agreement

Longer retention may be available through supported archive or external monitoring options.


29. Billing and Legal Records

Certain information may be retained after termination where required for:

  • billing

  • tax

  • accounting

  • fraud prevention

  • dispute resolution

  • legal compliance

These records are maintained separately from active Customer service data.


30. Termination and Data Export

When a Subscription ends, Customer may have a limited period under the applicable Terms to review or export available service information.

This may include:

  • logs

  • receipts

  • configuration

  • operational records

Customer should export information it needs to retain before access ends.


31. Data Deletion

After the applicable access or Grace Period, INNORIX may begin deletion of Customer Personal Data from active systems where the information is no longer required.

Deletion may be delayed where retention is required by:

  • applicable law

  • tax or accounting obligations

  • court order

  • regulatory requirement

  • legal hold

  • unresolved dispute


32. Backups

Customer Personal Data deleted from active systems may remain temporarily in Backup copies until removed through normal Backup Rotation.

Backup data remains protected and is not returned to active use except where required for legitimate service recovery or legal purposes.


33. On-Premises Deployments

In Customer-managed On-Premises environments:

  • Customer controls the underlying infrastructure

  • Customer controls local storage

  • Customer controls operating systems

  • Customer controls network access

INNORIX’s responsibilities are limited to the components and Services managed by INNORIX.


34. Hybrid Deployments

In Hybrid environments, Processing responsibilities are divided according to the systems operated by each party.

Customer remains responsible for Customer-managed infrastructure, while INNORIX remains responsible for the INNORIX-managed components within the scope of the applicable agreement.


35. Air-Gapped Deployments

Air-Gapped environments may operate without routine online communication with INNORIX Cloud.

Where Customer provides information to INNORIX for:

  • support

  • licensing

  • usage reporting

  • diagnostics

such information is handled according to this DPA and the applicable agreement where it contains Customer Personal Data.


36. Usage Metering

INNORIX may process usage information necessary to:

  • enforce Subscription limits

  • calculate charges

  • provide usage visibility

  • protect against abuse

  • operate the Services

Metering is designed to use the minimum information reasonably necessary for these purposes.


37. Customer File Content

INNORIX does not acquire ownership of Customer file content.

INNORIX processes Customer file content only as necessary to provide the selected Service and according to Customer instructions.

INNORIX does not sell Customer file content.


38. Secondary Use

INNORIX does not use Customer Personal Data processed on behalf of Customer for unrelated advertising.

Any materially different secondary use would require an appropriate legal and contractual basis.


39. Support Data

Where Customer voluntarily provides logs, screenshots, diagnostic files, or other information to INNORIX for support, Customer authorizes INNORIX to process that information for:

  • troubleshooting

  • support

  • service restoration

  • security
  • issue analysis

Customer should avoid providing unnecessary Personal Data.


40. Business Continuity

INNORIX may maintain Backup and recovery measures appropriate to the INNORIX-managed Services.

Customer remains responsible for backup and business continuity for Customer-managed infrastructure unless otherwise agreed.


41. Compliance with Applicable Law

Each party will comply with Data Protection Law applicable to its own Processing activities.

Nothing in this DPA requires either party to violate applicable law.


42. Conflict

If this DPA conflicts with the Terms or Customer Agreement regarding the Processing of Customer Personal Data, this DPA controls for that subject matter.

Customer-specific Order Forms or privacy addenda may contain additional terms.


43. Liability

Liability relating to this DPA is governed by the liability provisions of the applicable Terms, Customer Agreement, or Order Form, except where applicable law requires otherwise.


44. Duration

This DPA remains in effect for as long as INNORIX processes Customer Personal Data on behalf of Customer.

Obligations relating to confidentiality, security, deletion, and lawful Processing continue for as long as INNORIX retains Customer Personal Data subject to this DPA.


Related Resources

Privacy Policy
How INNORIX processes Personal Data in connection with its website, Accounts and Services.

Security
Security architecture and safeguards for INNORIX Services.

Subprocessors
Third-party providers involved in operating applicable INNORIX Services.

Terms
General terms governing the use of INNORIX Services.

START HERE

Build the Transfer You NeedFind the Transfer You Need

POPULAR TRANSFERS

Sync Team FoldersSend Large Files to ClientsExplore Files Across SystemsMigrate FTP, SFTP, SCP & rsyncAdd Transfer to Any AppAdd Web Upload & DownloadBuild AI & Data WorkflowsBrowse All Transfers

DEVELOPERS

Developer CenterExamplesAPI QuickstartDeveloper GuideAPI ReferenceGitHub

RESOURCES

Resource CenterProduct GuideIntegrationsDeploy & ManageHelp Center

INDUSTRIES

GovernmentPublic SectorManufacturingEngineeringFinanceDistributionIT/TelecomMediaHealthcareEducation

PLANS

Pricing
INNORIX Eliminate Complexity
INNORIX provides enterprise file infrastructure for moving and automating files across every system and environment. Trusted by more than 5,000 enterprise and public-sector organizations.
EN
  • English
  • Korean (한국어)

COMPANY

About Us

OTHER INNORIX PRODUCT

Al.bert — Smart Traffic AI

GLOBAL OFFICES

New York, USASeoul, South KoreaHo Chi Minh City, VietnamView Office Locations
SecurityStatusTermsPrivacyCookiesCookie Preferences
(C)2026 INNORIX. All rights reserved.

Cookie Preferences

The INNORIX website uses cookies to provide our services. Essential cookies are always on. You can allow or reject optional cookies below.