Contents — 44 sections
- Scope and definitions
- 1. Why this DPA exists and when you need it
- 2. How this DPA is accepted (acceptance mechanism)
- 3. Definitions
- 4. Roles of the parties
- 5. Processing on documented instructions
- 6. No use of your content for model development or training
- 7. Confidentiality
- 8. Security
- 9. Sub-processors
- 10. Assistance with data subject rights
- 11. Assistance with DPIAs, consultations and Articles 32 to 36
- 12. Personal data breach
- 13. Deletion and return of Customer Personal Data
- 14. Audit and information rights
- 15. Liability
- 16. International transfers
- 17. Term
- 18. Changes to this DPA
- 19. Governing law and jurisdiction
- 20. General
- 1. Subject matter of the processing
- 2. Duration of the processing
- 3. Nature of the processing
- 4. Purpose of the processing
- 5. Types of personal data
- 6. Categories of data subjects
- 7. Frequency of the transfer
- 8. Retention
- 1. Encryption in transit
- 2. Location of stored data
- 3. Access control
- 4. Per-user data scoping
- 5. Style profile isolation
- 6. Product analytics
- 7. Confidentiality of personnel
- 8. Sub-processor controls
- 9. Deletion
- 10. Minimisation by design
- 11. Measures for transfers
- Part A — Sub-processors
- Part B — Separate and independent controllers
- Part C — Transfers
- Contact
Scope and definitions
Legal and data protection notices: [email protected]
In this DPA, "we", "us", "our" and "Processor" mean IX Labs. "you", "your" and "Customer" mean the organisation or person that subscribes to the Service and accepts this DPA. "party" means either of us and "parties" means both.
Our product is Ingy (the "Service"), a Telegram bot that drafts social media posts from an article link, a video link, an uploaded video, or plain instructions. The Service returns a single copyable plain-text message. Publishing is manual. The bot never posts to any channel, account or audience. A Customer account is the user's Telegram account. The Service learns a per-account "style profile" from the user's own finalised posts. Our website is ingy.app and the bot is @IngyAppBot.
This DPA stands on its own. It does not require you to read, accept or rely on any other document we publish, and it remains fully effective if any other document we publish is changed or withdrawn. Where this DPA refers to your "Subscription Agreement", it means, generically, the agreement under which you subscribe to and are permitted to use the Service, whatever form that agreement takes.
1. Why this DPA exists and when you need it
1.1 Where you use the Service to process personal data for which you decide the purposes and means — for example, where you are a marketing agency or a company and your staff put client material, client contact details or third-party personal data into the Service — we process that personal data on your behalf. Article 28 of the UK GDPR requires that relationship to be governed by a written contract. This DPA is that contract.
1.2 If you use the Service purely for yourself, as an individual, for your own personal or household purposes, you probably do not need this DPA. Accepting it anyway does you no harm.
1.3 This DPA supplements and forms part of your Subscription Agreement. Where this DPA conflicts with the Subscription Agreement on the subject of processing personal data, this DPA prevails. On every other subject, including commercial terms, fees and limitation of liability, the Subscription Agreement prevails.
2. How this DPA is accepted (acceptance mechanism)
2.1 This DPA is pre-executed by publication. We have signed it by publishing it. No signature, countersignature or counter-execution by IX Labs is required for this DPA to take effect, and we do not provide one as a matter of routine. Do not wait for a signature from us before relying on this DPA — you already have our agreement to it in this document.
2.2 This DPA takes effect between you and us on the earlier of the two routes below.
2.3 Route A — automatic acceptance. This DPA applies automatically, without any further step, from the moment you begin using the Service to process personal data on behalf of others in the circumstances described in clause 1.1. Your continued use of the Service constitutes your acceptance of this DPA.
2.4 Route B — countersigned copy. If your internal governance, your own client contracts, or your procurement process requires a signed instrument, you may:
- download this DPA;
- complete and sign the signature block in Schedule A (Customer signature block); and
- email the signed copy to [email protected].
On receipt we will record it against your account and, if you ask in the same email, acknowledge receipt in writing. That acknowledgement is administrative confirmation, not a condition of validity.
2.5 Route B does not change the terms. A copy signed by you and returned to us takes effect on the terms set out in this published version, unaltered. Any amendment, deletion, insertion, rider, addendum, covering letter or purchase-order term that you attach to a returned copy has no effect and is expressly rejected, unless we agree to it separately in a document signed by an authorised signatory of IX Labs. Silence, non-response, or continued provision of the Service by us is not acceptance of any such variation.
2.6 The version of this DPA in force is the version published at ingy.app. Section 18 governs changes.
3. Definitions
3.1 In this DPA:
- "Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and, to the extent it applies to a party's processing under this DPA, Regulation (EU) 2016/679 ("EU GDPR"), in each case as amended or replaced from time to time.
- "UK GDPR" has the meaning given in section 3(10) of the Data Protection Act 2018.
- "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" each have the meaning given in the UK GDPR. "process", "processes" and "processed" are construed accordingly.
- "Customer Personal Data" means personal data contained in Customer Content and processed by us on your behalf under this DPA. It does not include Operational Data (clause 4.4).
- "Customer Content" means the material you or your users submit to the Service — including source links, uploaded files, instructions and prompts — and the outputs generated from it, including drafted posts and the derived style profile.
- "Operational Data" means the data described in clause 4.4, which we process as an independent controller.
- "Sub-processor" means any third party engaged by us to process Customer Personal Data on our behalf in connection with providing the Service.
- "Restricted Transfer" means a transfer of personal data to a country or international organisation outside the United Kingdom (or, where the EU GDPR applies, outside the European Economic Area) that is not covered by an adequacy decision or adequacy regulations.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022, as revised or replaced.
- "IDTA" means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, as revised or replaced.
- "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as revised or replaced.
- "Annex" means an annex to this DPA. The Annexes form part of this DPA.
3.2 References to a statute or statutory provision include that statute or provision as amended, extended or re-enacted.
4. Roles of the parties
4.1 You are the controller. You are the controller of Customer Personal Data. You determine the purposes and means of its processing. You decide what goes into the Service.
4.2 We are the processor. We are a processor of Customer Personal Data and we process it only as described in clause 5.
4.3 Your responsibilities as controller. You warrant and undertake that:
- (a) you have a valid lawful basis under Article 6 of the UK GDPR (and, where special category or criminal offence data is involved, a valid condition under Article 9 or Article 10) for each purpose for which you submit Customer Personal Data to the Service;
- (b) you have given all notices and obtained all consents, authorisations and permissions required for us and our Sub-processors to process Customer Personal Data as contemplated by this DPA;
- (c) you have the right to submit each source you submit, and to submit the content of it to the Service;
- (d) your instructions to us do not require us or our Sub-processors to breach Applicable Data Protection Law; and
- (e) you have carried out any assessment required of you as controller, including any data protection impact assessment.
4.4 CARVE-OUT — we are an independent controller for our own operational data. Separately from and in addition to our role as processor, we act as an independent controller in respect of the following ("Operational Data"), and this DPA does not apply to it:
- (a) account data — the Telegram identifiers and account records we need to create, identify, authenticate and administer an account, and the record of which plan an account is on;
- (b) billing and financial data — subscription, plan, transaction, invoicing, refund, chargeback, tax and accounting records, and records we must keep to comply with law;
- (c) security and abuse-prevention data — logs, access records, rate-limit and quota records, and records generated in detecting, investigating and preventing fraud, abuse, security incidents and breaches of our acceptable use rules;
- (d) service-operation and telemetry data — technical logs, error and diagnostic records, uptime and performance metrics, and aggregated product analytics about how the Service is used, which do not include the content of Customer Content;
- (e) business contact data — the contact details of your personnel used to administer the relationship, respond to support requests, give service notices and manage the account; and
- (f) aggregated and de-identified statistics derived from the operation of the Service which are not, and cannot reasonably be used to identify, any data subject.
We process Operational Data for our own legitimate business purposes: operating, securing, supporting, billing for and improving the Service, and complying with our legal obligations. As controller of Operational Data we are directly responsible for it under Applicable Data Protection Law. For the avoidance of doubt, clause 6 (no use for model development) applies to Customer Content and Customer Personal Data, and (d) and (f) above do not entitle us to use Customer Content for model development.
4.5 Separate controllers. Where a third party engaged in providing the Service acts as a separate and independent controller in its own right — in particular Creem (Armitage Labs OÜ) as Merchant of Record for payments, and Telegram as the messaging platform through which the Service is delivered — it is not our Sub-processor in respect of that processing and we are not responsible for its processing as controller. See Annex 3.
4.6 No joint controllership. Nothing in this DPA makes the parties joint controllers within the meaning of Article 26 of the UK GDPR.
5. Processing on documented instructions
5.1 We will process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law to which we are subject. Where we are required by law to process otherwise, we will inform you of that legal requirement before processing, unless that law prohibits us from doing so on important grounds of public interest.
5.2 What the documented instructions are. Your documented instructions are, and are limited to:
- (a) your Subscription Agreement;
- (b) this DPA, including its Annexes;
- (c) your and your users' use of the Service through its ordinary functionality — every source link, upload, prompt and instruction submitted through the Service is an instruction to process the personal data it contains for the purpose of producing the requested output; and
- (d) any further written instruction you give us that we accept in writing.
Together these are the complete documented instructions. We are not obliged to act on any instruction communicated by any other means.
5.3 Additional instructions. We are not obliged to act on any instruction that is outside the scope of the Service as it is then provided, that requires changes to the Service, or that would cause us to incur material cost or effort. Where we agree to act on such an instruction, we may charge you our reasonable costs of doing so, and we will tell you the expected charge before we start.
5.4 Unlawful instructions. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law. We may suspend performance of the instruction until it is amended, confirmed or withdrawn. Notifying you does not make us responsible for verifying the lawfulness of your instructions generally, which remains your responsibility as controller.
5.5 Special category and high-risk data. The Service is not designed for, and you must not submit to it, special category personal data (Article 9 UK GDPR), criminal offence data (Article 10 UK GDPR), children's personal data, government identifiers, financial account or payment card numbers, health data, or personal data whose disclosure would create a significant risk of harm to a data subject. If you submit such data, you do so at your own risk and on the basis that you are responsible for it; the technical and organisational measures in Annex 2 are calibrated to content intended for publication, not to high-risk categories.
6. No use of your content for model development or training
6.1 The commitment. Where this DPA applies, we will not use your Customer Content or Customer Personal Data to develop, train, fine-tune, evaluate against, or otherwise improve any machine learning or artificial intelligence model, whether ours or anyone else's. We will not use it for any purpose of our own.
6.2 Why. Under this DPA we act as your processor. A processor may process personal data only on the controller's documented instructions and for the purposes the controller determines. Repurposing your content for our own model development would make us a controller of that data for that purpose, and we do not do it.
6.3 Scope of the permitted purpose. We use Customer Content solely to (a) provide the Service to you — that is, to generate the requested output and to maintain the per-account style profile that produces output in your users' voice; (b) secure and support the Service; and (c) comply with law.
6.4 The style profile. The per-account style profile is derived from the account's own finalised posts and is used only for that account. It is not pooled, shared across accounts, or used as training material for any general model.
6.5 Operational commitment. Operationally, accounts covered by this DPA are excluded from model development. We will maintain the internal controls needed to give effect to this clause, including flagging accounts covered by this DPA so that their content is excluded from any dataset used for model development or evaluation.
6.6 Sub-processors. We will not authorise any Sub-processor to use Customer Personal Data to train or improve its models on its own account, and we will use the configuration options available to us with each Sub-processor to give effect to this. Where a Sub-processor's terms are the mechanism by which this is achieved, our obligation is to procure and maintain that configuration.
6.7 Nothing in this clause restricts our use of aggregated, de-identified statistics falling within clause 4.4(f), which contain no Customer Content and cannot be used to identify any data subject or to reconstruct any Customer Content.
7. Confidentiality
7.1 We will treat Customer Personal Data as confidential and will not disclose it except as permitted by this DPA or required by law.
7.2 We will ensure that each person authorised by us to process Customer Personal Data:
- (a) is subject to a binding duty of confidentiality, whether contractual or statutory, that survives the end of their engagement;
- (b) processes Customer Personal Data only on our instructions and only as necessary for their role; and
- (c) has received appropriate guidance on their data protection responsibilities.
7.3 Where we are compelled by law, court order or a competent authority to disclose Customer Personal Data, we will, unless legally prohibited, notify you before disclosing so that you may seek protective relief, and we will disclose only what we are legally required to disclose.
8. Security
8.1 We will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 of the UK GDPR.
8.2 The measures we have in place are set out in Annex 2. Annex 2 is an accurate description of the measures in place as at the effective date of this version, and is the complete statement of our security commitments. No security representation outside Annex 2 forms part of this DPA.
8.3 We may update the measures in Annex 2 from time to time provided the updated measures do not materially reduce the overall level of security.
8.4 Your responsibility. You are responsible for the security of your own environment, including the security of your users' Telegram accounts and devices, your decisions about who in your organisation may use the Service, and your decisions about what personal data to submit. Access to the Service is through Telegram accounts that we do not control and cannot secure.
9. Sub-processors
9.1 General authorisation. You give us a general authorisation to engage Sub-processors to process Customer Personal Data, subject to this clause 9.
9.2 Current Sub-processors. The Sub-processors engaged as at the effective date of this version are listed in Annex 3.
9.3 Our obligations. Before engaging a Sub-processor we will carry out reasonable due diligence on its ability to provide the level of protection required by this DPA. We will impose on each Sub-processor, by written contract, data protection obligations that are in substance no less protective than those in this DPA, to the extent applicable to the services it provides.
9.4 Our liability for Sub-processors. We remain fully liable to you for the performance of each Sub-processor's data protection obligations in relation to Customer Personal Data, subject always to clause 15 (Liability).
9.5 Changes and notice. We will give you at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, or before we replace one. Notice is given by updating Annex 3 as published at ingy.app and, where you have given us an email address for this purpose, by email to that address. You are responsible for keeping that address current and for subscribing to any notification mechanism we offer.
9.6 Right to object. You may object to a proposed new or replacement Sub-processor on reasonable data protection grounds by giving written notice to [email protected] within the 30-day notice period, setting out your grounds. We will work with you in good faith to address the objection, which may include offering a reasonable alternative or a change of configuration. If we cannot resolve it within a reasonable period, your sole and exclusive remedy is to terminate your subscription to the affected part of the Service on written notice, with no refund of amounts already paid other than any refund available to you under our published refund and cancellation terms as they then apply or under applicable law.
9.7 Emergency changes. Where a Sub-processor must be engaged or replaced urgently to maintain security or continuity of the Service, we may do so with such notice as is reasonably practicable, and clause 9.6 then applies from the date notice is given.
10. Assistance with data subject rights
10.1 Taking into account the nature of the processing, we will provide reasonable assistance by appropriate technical and organisational measures, insofar as this is possible, to enable you to fulfil your obligation to respond to requests from data subjects exercising their rights under Chapter III of the UK GDPR.
10.2 Requests received by us. If we receive a request from a data subject relating to Customer Personal Data, we will not respond to it substantively ourselves. We will promptly forward it to you, unless we are legally required to respond. You are responsible for responding.
10.3 What we will do. On your written request we will, so far as it is possible and proportionate given the nature of the Service, help you to locate, provide a copy of, correct, restrict, delete or export Customer Personal Data held in an account you identify.
10.4 What you must give us. You must identify the relevant account or accounts. We are not able to search Customer Content across accounts for a named individual, and we are not obliged to build a capability to do so.
10.5 Charges. Assistance under this clause is provided at no charge for requests that are reasonable in number and scope. Where requests are manifestly unfounded, excessive, repetitive, or require material engineering effort or effort beyond the ordinary functionality of the Service, we may charge our reasonable costs at our then-current professional rates. We will tell you the expected charge before incurring it and will not proceed until you approve it in writing.
11. Assistance with DPIAs, consultations and Articles 32 to 36
11.1 Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to help you comply with your obligations under Articles 32 to 36 of the UK GDPR — security of processing, personal data breach notification and communication, data protection impact assessments, and prior consultation with a supervisory authority — in each case only to the extent the matter relates to our processing of Customer Personal Data.
11.2 That assistance will ordinarily take the form of the information in this DPA and its Annexes, together with written answers to reasonable, specific questions. The information in this DPA and its Annexes is intended to satisfy the greater part of any assessment you undertake.
11.3 Clause 10.5 (Charges) applies equally to assistance under this clause.
12. Personal data breach
12.1 We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
12.2 Our notification will include, to the extent known to us at the time and insofar as we are able to provide it:
- (a) a description of the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
- (b) the likely consequences of the breach;
- (c) the measures taken or proposed to be taken to address the breach, including where appropriate measures to mitigate its possible adverse effects; and
- (d) a point of contact from whom more information can be obtained.
12.3 Where we cannot provide all of that information at once, we will provide it in phases as it becomes available, without further undue delay.
12.4 We will notify you by email to the address associated with your account and, where you have given us a dedicated security contact address in writing, to that address. You are responsible for keeping those addresses accurate and monitored.
12.5 Your responsibility. You are responsible for deciding whether the breach must be notified to a supervisory authority or communicated to data subjects, and for making any such notification or communication. We will provide reasonable assistance under clause 11.
12.6 Not an admission. Our notification of, or response to, a personal data breach is not and must not be treated as an acknowledgement of fault or liability by us.
12.7 You must not make any public statement identifying us in connection with a personal data breach without our prior written consent, except where you are required to do so by law or by a supervisory authority.
13. Deletion and return of Customer Personal Data
13.1 On termination or expiry of your Subscription Agreement, or at any earlier time on your written request, we will, at your choice, delete or return Customer Personal Data to you, and delete existing copies.
13.2 Making the choice. You must tell us which you want, in writing to [email protected], within 30 days of termination or expiry. If you do not, we will delete the Customer Personal Data. Deletion is permanent and we cannot recover deleted data afterwards. If you want to keep drafts or outputs, export or copy them before termination.
13.3 Form of return. Where you ask for return, we will provide the data in a commonly used electronic format that we are reasonably able to produce. We may charge our reasonable costs where the request requires effort beyond the ordinary export functionality of the Service.
13.4 Timing of deletion. We will complete deletion within 90 days of the later of termination and your instruction, subject to clause 13.5.
13.5 Retention carve-out. We may retain Customer Personal Data to the extent, and for as long as, required by law to which we are subject, or where it is necessary for the establishment, exercise or defence of legal claims. In particular:
- (a) we retain financial and transaction records for 6 years as required by UK law;
- (b) we may retain records reasonably necessary to evidence compliance with our own legal obligations; and
- (c) data held in routine backups is deleted in accordance with our ordinary backup rotation rather than on demand.
Any data retained under this clause remains subject to clauses 6 (no model development), 7 (confidentiality) and 8 (security), and will not be processed for any purpose other than the purpose for which it is retained.
14. Audit and information rights
This clause is deliberately specific. It sets out the complete extent of your audit rights under this DPA.
14.1 Information first. We will make available to you the information necessary to demonstrate compliance with the obligations in Article 28 of the UK GDPR. In the first instance, that obligation is satisfied by this DPA and its Annexes.
14.2 Questionnaire route — the primary mechanism. Your audit and inspection rights are satisfied in the first instance by our providing written responses to a reasonable security and data protection questionnaire, submitted to [email protected], no more than once in any 12-month period. We will respond within 30 days of receiving a questionnaire that is reasonable in length and scope and relevant to our processing of Customer Personal Data. We are not obliged to complete bespoke questionnaires of unreasonable length, or to answer questions that are not relevant to our processing of Customer Personal Data.
14.3 On-site or on-premises audit. An on-site audit, or an inspection beyond clause 14.2, may be conducted only where it is required by Applicable Data Protection Law or by a supervisory authority with jurisdiction over you, and only on all of the following conditions:
- (a) you give us at least 30 days' prior written notice to [email protected], identifying the legal requirement relied on;
- (b) the audit takes place during our normal business hours, on a date we agree, and lasts no more than one business day;
- (c) the audit is conducted at your cost, and you also reimburse our reasonable costs and the time of our personnel at our then-current professional rates;
- (d) the auditor is you or an independent professional auditor appointed by you who is not a competitor of ours, and the auditor signs a confidentiality undertaking with us before the audit begins, on terms reasonably acceptable to us;
- (e) the audit does not include any form of penetration testing, vulnerability scanning, code review, or access to our source code, our systems, or our production environment, and does not require us to disclose information belonging to, or personal data of, any other customer, or information subject to confidentiality obligations owed to a third party or subject to legal professional privilege;
- (f) you take all reasonable steps to avoid causing damage, injury or disruption to our premises, equipment, personnel and business; and
- (g) findings are confidential to the parties and used only to assess our compliance with this DPA.
14.4 No audit during an incident. We may postpone an audit where an audit at that time would, in our reasonable opinion, prejudice our response to an ongoing security incident, personal data breach, investigation or regulatory matter, or where it would create a material risk to the security or availability of the Service. We will offer an alternative date once the incident is resolved.
14.5 Frequency. Absent a personal data breach affecting your Customer Personal Data, or a specific requirement imposed on you by a supervisory authority, you may exercise the right in clause 14.3 no more than once in any 24-month period.
14.6 Third-party reports. Where we hold third-party attestations, certifications or audit reports relevant to the Service, we may provide them in satisfaction of clauses 14.2 and 14.3. We do not currently hold any such attestation or certification and we do not represent that we do. See Annex 2.
15. Liability
15.1 THIS IS IMPORTANT. All liability of each party arising out of or in connection with this DPA — whether in contract, tort (including negligence), breach of statutory duty, restitution or otherwise — is subject to, and counts towards, the exclusions and the aggregate limitation of liability set out in the Subscription Agreement. The aggregate cap in the Subscription Agreement is a single, combined cap covering liability under the Subscription Agreement and this DPA together. This DPA does not create a separate, additional or uncapped head of liability, and no claim under this DPA may exceed, or be recovered on top of, that aggregate cap.
15.2 If for any reason the Subscription Agreement does not contain an enforceable aggregate limitation of liability, our total aggregate liability arising out of or in connection with this DPA is limited to the total amounts paid or payable by you for the Service in the 12 months immediately preceding the first event giving rise to liability.
15.3 Neither party is liable to the other under this DPA for loss of profit, loss of revenue, loss of anticipated savings, loss of business or business opportunity, loss of goodwill, or any indirect or consequential loss, in each case however arising.
15.4 Nothing in this DPA limits or excludes either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited or excluded. Nothing in this clause 15 limits or affects the rights of data subjects, or the powers of a supervisory authority, under Applicable Data Protection Law.
15.5 Allocation between the parties. Where a party pays compensation to a data subject or a fine to a supervisory authority in respect of damage caused by processing, it may claim back from the other party the part of that compensation or fine corresponding to the other party's part of the responsibility for the damage, subject always to clauses 15.1 to 15.3.
15.6 Your indemnity. You will indemnify us against all claims, losses, fines and reasonable costs (including reasonable legal costs) we suffer arising from (a) your breach of clause 4.3 or clause 5.5, (b) your instructions where we have notified you under clause 5.4 and you have confirmed the instruction, or (c) any claim by a data subject or third party that you had no right to submit their personal data to the Service.
16. International transfers
16.1 You authorise us and our Sub-processors to transfer Customer Personal Data outside the United Kingdom where necessary to provide the Service, subject to this clause 16 and to Annex 3.
16.2 Where data is stored. Customer Personal Data at rest is stored in Germany, with Hetzner Online GmbH. Certain Sub-processors listed in Annex 3 process Customer Personal Data in the United States.
16.3 Adequacy first. Where the destination country benefits from UK adequacy regulations (or, where the EU GDPR applies, an EU adequacy decision), the transfer is made in reliance on that adequacy. As at the effective date of this version, transfers to the EEA — including to Germany — are covered by UK adequacy regulations.
16.4 Restricted Transfers — UK. Where a transfer of Customer Personal Data subject to the UK GDPR is a Restricted Transfer, the parties agree that:
- (a) the EU SCCs are incorporated into this DPA by reference and apply as varied by the UK Addendum, which is also incorporated by reference; or, at our election where more appropriate, the IDTA is incorporated by reference and applies in place of them; and
- (b) the following modules and options apply, unless we notify you otherwise in writing:
- Module Two (controller to processor) applies where you are a controller and we are your processor, which is the ordinary case under this DPA;
- Module Three (processor to processor) applies where you are yourself a processor acting for your own customer and we are your sub-processor;
- in Clause 7 (docking clause): included;
- in Clause 9(a) (sub-processors): Option 2, general written authorisation applies, with a notice period of 30 days, consistent with clause 9.5 of this DPA;
- in Clause 11(a) (redress): the optional independent dispute resolution language is not included;
- in Clause 17 (governing law) and Clause 18(b) (choice of forum): as varied by the UK Addendum, the governing law and forum are those of England and Wales;
- the period for Clause 8.6 audits and the frequency of audits under the EU SCCs are as set out in clause 14 of this DPA, to the extent that clause is not inconsistent with the EU SCCs;
- Annex I.A (parties) is completed by the identity details in this DPA and, where you have countersigned, in Schedule A; you are the data exporter and we are the data importer;
- Annex I.B (description of transfer) is completed by Annex 1 of this DPA;
- Annex I.C (competent supervisory authority) is the Information Commissioner's Office;
- Annex II (technical and organisational measures) is completed by Annex 2 of this DPA; and
- Annex III (sub-processors) is completed by Annex 3 of this DPA.
16.5 Restricted Transfers — EU. Where a transfer of Customer Personal Data subject to the EU GDPR is a Restricted Transfer, the EU SCCs are incorporated by reference and apply on the same modules and options as in clause 16.4(b), save that the competent supervisory authority is determined in accordance with Clause 13 of the EU SCCs and the governing law and forum are those of the Republic of Ireland.
16.6 Priority. Where the EU SCCs, the UK Addendum or the IDTA apply and there is a conflict between them and this DPA, the EU SCCs, the UK Addendum or the IDTA prevail to the extent of the conflict. Signature of this DPA under clause 2, or acceptance under clause 2.3, constitutes signature and acceptance of the incorporated transfer mechanisms.
16.7 Onward transfers by Sub-processors. We will ensure that an appropriate transfer mechanism is in place for each Restricted Transfer to a Sub-processor listed in Annex 3.
16.8 Change of law. If the transfer mechanism relied on is invalidated, replaced or ceases to provide an adequate safeguard, we will implement an alternative lawful transfer mechanism without undue delay, and this clause 16 will be read as referring to that mechanism.
17. Term
17.1 This DPA takes effect on the date determined under clause 2 and continues for as long as we process Customer Personal Data on your behalf.
17.2 Clauses 7 (Confidentiality), 13 (Deletion and return), 14 (Audit), 15 (Liability), 16 (International transfers), 19 (Governing law) and 20 (General), and the definitions needed to interpret them, survive termination.
18. Changes to this DPA
18.1 We may update this DPA where required to reflect a change in Applicable Data Protection Law, guidance from a supervisory authority, a change in our Sub-processors, or a change in how the Service works.
18.2 Where a change materially reduces your rights or our obligations under this DPA, we will give you at least 30 days' notice before it takes effect, by publishing the updated version at ingy.app with a new version number and effective date and, where you have given us an email address for notices, by email. Continued use of the Service after the effective date constitutes acceptance. If you do not accept a material change, your remedy is to stop using the Service and terminate your subscription before the change takes effect.
18.3 Updates to Annex 3 (Sub-processors) are governed by clause 9.5 and 9.6.
18.4 The version of this DPA in force at the time of the relevant processing applies to that processing.
19. Governing law and jurisdiction
19.1 This DPA and any dispute or claim arising out of or in connection with it, including a non-contractual dispute or claim, is governed by and construed in accordance with the law of England and Wales.
19.2 The parties irrevocably submit to the exclusive jurisdiction of the courts of England and Wales, subject only to clause 16 where an incorporated transfer mechanism provides otherwise.
20. General
20.1 Entire agreement on processing. This DPA, together with the Subscription Agreement, is the entire agreement between the parties on the processing of Customer Personal Data and supersedes any prior data processing agreement, data protection schedule, or representation on that subject.
20.2 Order of precedence. In the event of conflict, the order of precedence is: (1) an incorporated transfer mechanism under clause 16, (2) the body of this DPA, (3) the Annexes, (4) the Subscription Agreement — except that clause 1.3 and clause 15 apply as written.
20.3 Severance. If any provision of this DPA is held to be invalid or unenforceable, it is severed and the rest of this DPA continues in force.
20.4 No waiver. A failure or delay in exercising a right under this DPA is not a waiver of it.
20.5 Assignment. You may not assign or transfer this DPA without our prior written consent. We may assign this DPA to a successor in connection with a merger, acquisition or sale of all or substantially all of our assets, on notice to you.
20.6 Third party rights. A person who is not a party to this DPA has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms. This does not affect the rights of data subjects under Applicable Data Protection Law or under any incorporated transfer mechanism.
20.7 Notices. Notices to us under this DPA must be sent to [email protected] or to IX Labs, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Notices to you are sent to the email address associated with your account or, where you have countersigned, the address in Schedule A.
20.8 Counterparts and electronic signature. This DPA may be accepted electronically and, where countersigned, may be signed in counterparts and by electronic signature, each of which is an original and all of which together constitute one agreement.
20.9 Data protection contact. Our contact point for all matters under this DPA is [email protected]. We have not appointed a Data Protection Officer, and, based on the nature and scale of our processing, we are not required to appoint one under Article 37 of the UK GDPR.
Annex 1 — Description of processing
This Annex forms part of this DPA and completes Annex I.B of the EU SCCs where they apply.
1. Subject matter of the processing
Provision of the Ingy service: the generation of draft social media posts from sources and instructions submitted by the Customer's users, and the maintenance of a per-account style profile derived from that account's own finalised posts.
2. Duration of the processing
For the duration of the Customer's subscription to the Service, plus the deletion and retention periods set out in clause 13.
3. Nature of the processing
Collection, receipt, retrieval of submitted source URLs, transcription of audio and video, text extraction, storage, structuring, transmission to and from AI model providers, generation of output text, derivation and storage of a style profile, display of output to the user within Telegram, deletion, and backup.
4. Purpose of the processing
To provide the Service to the Customer in accordance with the Customer's documented instructions — namely producing a draft post from a submitted source or instruction, in the style associated with the account — together with securing and supporting the Service and complying with law. The processing does not include use of Customer Content for model development or training (clause 6).
5. Types of personal data
Personal data is not required by the Service, but personal data may be present in the following, depending entirely on what the Customer's users choose to submit:
| Category | Description |
|---|---|
| Source content | Personal data contained within the article at a submitted link, the transcript of a submitted or uploaded video, or other submitted source material — for example the names, job titles, quotations, opinions, affiliations and public statements of individuals mentioned in that source. |
| Instructions and prompts | Personal data contained in free-text instructions typed by the user — for example the name of a client, a colleague, a customer, or the subject of a post. |
| Uploaded files | Personal data contained in uploaded video files, including images and voices of individuals appearing or speaking in them, and any personal data visible or audible in the footage. |
| Generated posts | Personal data reproduced in, or generated into, the draft output, and in saved versions and edits of it. |
| Derived style profile | Stylistic characteristics derived from the account's own finalised posts. This may constitute personal data about the author where the account is used by an identifiable individual, and may incidentally retain fragments of subject matter from the posts it was derived from. |
| Telegram identifiers | The Telegram user ID, and where the user has set them, Telegram username, display name and language setting, used to identify the account, deliver output to the correct conversation and enforce quota. |
| Usage and interaction records | Records of generation requests, timestamps, plan and quota usage associated with the account. Processed by us principally as controller under clause 4.4, and included here to the extent linked to Customer Personal Data. |
The Service is not designed for special category data, criminal offence data, children's data, financial account data or government identifiers, and the Customer must not submit them (clause 5.5).
6. Categories of data subjects
| Category | Description |
|---|---|
| The Customer's users | The individuals at the Customer — staff, contractors, freelancers — who operate the Service through their Telegram accounts. |
| The Customer's clients and their personnel | Where the Customer is an agency, the individuals at its client organisations whose names, roles, statements or material appear in submitted sources, instructions or output. |
| Individuals appearing in submitted sources | Authors, interviewees, speakers, presenters, named individuals, quoted individuals and individuals appearing or audible in submitted or uploaded videos and articles. |
| Individuals named in instructions or output | Any individual the Customer's users choose to reference in a prompt, an instruction or a finalised post. |
7. Frequency of the transfer
Continuous, for the duration of the subscription, on each occasion a user submits a source or instruction to the Service.
8. Retention
For the duration of the subscription and thereafter in accordance with clause 13, subject to the legal retention carve-out in clause 13.5.
Annex 2 — Technical and organisational measures
This Annex forms part of this DPA and completes Annex II of the EU SCCs where they apply. It describes the measures in place as at the effective date of this version.
1. Encryption in transit
Data transmitted between the user, the Service and our Sub-processors is protected in transit using TLS.
2. Location of stored data
Customer Personal Data at rest is stored on infrastructure provided by Hetzner Online GmbH, located in Germany.
3. Access control
Access to systems holding Customer Personal Data is restricted to authorised personnel on a need-to-know basis, limited to what each person requires to perform their role. Access is removed when it is no longer required.
4. Per-user data scoping
The application enforces per-user data scoping: each account's content, saved versions and style profile are scoped to that account and are not exposed to other accounts through the Service.
5. Style profile isolation
The per-account style profile is derived from, and used only for, the account it belongs to. It is not pooled across accounts.
6. Product analytics
Product analytics collected about use of the Service contain no user content — no source material, no prompts, no generated posts.
7. Confidentiality of personnel
Personnel authorised to process Customer Personal Data are bound by a duty of confidentiality that survives the end of their engagement (clause 7.2).
8. Sub-processor controls
Sub-processors are engaged under written terms imposing data protection obligations in substance no less protective than those in this DPA, and are configured so that Customer Content is not used to train or improve their models (clause 6.6).
9. Deletion
On request or on termination, account content, saved versions and the derived style profile are deleted in accordance with clause 13. Deletion is permanent.
10. Minimisation by design
The Service does not require the Customer to submit personal data in order to function, and does not ask for personal data beyond the Telegram identifiers needed to operate the account.
11. Measures for transfers
The measures in this Annex apply equally to processing carried out by Sub-processors located outside the United Kingdom, in addition to the transfer mechanisms in clause 16.
Annex 3 — Sub-processors and separate controllers
This Annex forms part of this DPA and completes Annex III of the EU SCCs where they apply. It lists the Sub-processors engaged as at the effective date of this version.
Part A — Sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Anthropic | AI generation — producing the draft post from the submitted source and instructions. | USA |
| OpenAI | Whisper transcription — converting submitted or uploaded audio and video into text. | USA |
| Supadata | Retrieval of video transcripts from submitted video links. | USA |
| Firecrawl | Fetching and extracting the text of articles at submitted links, used where direct fetching fails. | USA |
| Langfuse | LLM tracing and observability. Note: Langfuse receives prompt and output content, which may contain personal data present in submitted sources, instructions and generated posts. | EU |
| PostHog | Product analytics, and a separate project for anonymous website analytics. Contains no user content — no source material, no prompts, no generated posts. | USA |
| Hetzner Online GmbH | Hosting and storage of the Service. | Germany |
Part B — Separate and independent controllers
These parties are not our Sub-processors in respect of the processing described. Each determines the purposes and means of that processing itself and is directly responsible for it under Applicable Data Protection Law. Their own terms and privacy notices govern it.
| Party | Role |
|---|---|
| Creem (Armitage Labs OÜ, registry code 16977866, Estonia) | Merchant of Record for purchases. Creem is the contracting seller for the payment transaction and processes payments, chargebacks and any applicable tax, and pays out the refunds we approve. Creem acts as a separate controller of the payment and billing data it collects. |
| WayForPay | Card acquirer for Ukrainian customers, closed to new subscriptions and now processing only renewals and cancellations for customers who subscribed through it earlier. WayForPay acts as a separate controller of the payment data it collects, under its own terms, and processes it in Ukraine. |
| Telegram | The messaging platform through which the Service is delivered. The Customer's account is the user's Telegram account, and all interaction with the Service takes place inside a Telegram conversation. Telegram acts as a separate controller of the data it processes as a communications platform, under its own terms and privacy policy. We do not control Telegram, its retention, or its security. |
Part C — Transfers
Transfers to Sub-processors located in the USA are Restricted Transfers and are made under the mechanisms identified in clause 16. Processing in Germany and in the EU is covered by UK adequacy regulations for the EEA as at the effective date of this version.
Schedule A — Customer signature block
Complete this Schedule only if you are using Route B in clause 2.4. It is not required for this DPA to take effect.
This DPA is pre-executed by IX Labs by publication. No countersignature from IX Labs is required, and none will be provided. Complete the block below, sign, and email the completed document to [email protected].
Accepted and agreed by the Customer:
| Field | Detail |
|---|---|
| Customer legal entity name | ______________________________________________ |
| Company or registration number (if applicable) | ______________________________________________ |
| Registered address | ______________________________________________ |
| ______________________________________________ | |
| ______________________________________________ | |
| Telegram account(s) or account identifier(s) covered | ______________________________________________ |
| Email address for data protection notices | ______________________________________________ |
| Email address for security incident notices | ______________________________________________ |
| Signatory name | ______________________________________________ |
| Signatory title | ______________________________________________ |
| Signature | ______________________________________________ |
| Date | ______________________________________________ |
For and on behalf of IX Labs: pre-executed by publication of this DPA, version 1.0, effective 18 August 2026. No further signature required.
IX Labs, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Questions about this DPA: [email protected].
Contact
IX Labs
27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
General enquiries: [email protected]
Legal notices: [email protected]