Last updated: June 2026 · Version 1.1 · InfrAgent AI Ltd
Summary for convenience; the full agreement below governs.
This Data Processing Agreement ("DPA") forms part of the Terms between InfrAgent AI Ltd (the "Processor") and the tenant business (the "Controller"). It applies whenever we process your customers' personal data on your behalf, and incorporates UK GDPR, EU GDPR (Article 28) and India's Digital Personal Data Protection Act 2023.
Processing means receiving, storing, analysing and responding to customer communications across your connected channels (WhatsApp, Instagram, Facebook, Gmail, website chat, inbound calls) and operating bookings, CRM, campaigns and automations — solely to provide the platform, for the duration of your subscription. Data subjects are your customers, prospects and callers; data includes names, contact details and handles, message and call content, booking/enquiry details, and technical metadata. You must not direct us to process special-category data unless your lawful basis supports it.
We process personal data only on your documented instructions (expressed through your platform configuration); ensure our personnel are bound by confidentiality; apply the security measures in section 5; assist you with data-subject requests and your own compliance; and make available the information reasonably needed to demonstrate compliance.
You authorise the sub-processors listed in our Privacy Policy — Supabase (database/auth), OpenAI (AI via API), Twilio (telephony), Meta (channel APIs), Google (Gmail API), Stripe (payments) and Hetzner (EU hosting) — each bound by a written agreement with equivalent data-protection obligations. We give at least 14 days' notice of material changes so you can object.
AES-256-GCM at rest; TLS 1.3 in transit; per-tenant isolation via Postgres row-level security; signature-verified inbound webhooks; role-restricted, MFA-protected, logged production access; encrypted rolling backups; and a responsible-disclosure programme (ISO 27001 / SOC 2 in progress). Primary hosting is in Germany (EU); transfers outside the UK/EEA rely on the UK International Data Transfer Addendum and EU Standard Contractual Clauses, and comply with DPDP cross-border provisions for Indian Controllers.
The platform lets you search, export, correct and delete customer data directly, satisfying most requests without us. Where our assistance is needed, we act on your instruction within 7 days, and we redirect data subjects who contact us directly back to you. If we become aware of a breach affecting your tenant, we notify you without undue delay with the details you need to meet your own 72-hour obligations.
You can export your data any time during the subscription. On termination, we delete all tenant personal data within 30 days except where law requires retention; backups expire on a rolling schedule and are never used to restore deleted tenant data. We provide compliance documentation on request and, where that's insufficient for a legal requirement, will cooperate with an audit on reasonable notice, during business hours, up to once a year, under confidentiality.
Liability under this DPA is subject to the limits in the Terms. Where this DPA conflicts with the Terms, this DPA prevails for data-protection matters. Enterprise customers may request a countersigned DPA with custom annexes via support@infragentai.com.
© 2026 InfrAgent AI Ltd. All rights reserved.