DataInlet Data Processing Addendum
Legal document bodies are currently available in English only.
On this page
Effective date: September 1, 2026
Last updated: September 2, 2026
This Data Processing Addendum (DPA) forms part of the DataInlet Terms of Service or other agreement governing Customer's use of the DataInlet Service (the Agreement) between Customer and Chang Wu, an individual operating DataInlet (DataInlet).
This DPA applies where DataInlet processes Personal Data contained in Customer Content on behalf of Customer.
1. Definitions
Customer Personal Data means Personal Data contained in Customer Content that DataInlet processes on behalf of Customer in providing the Service.
Data Protection Laws means privacy and data-protection laws applicable to the processing under the Agreement, including, where applicable, the EU General Data Protection Regulation (EU GDPR), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended (CCPA).
Personal Data, Controller, Processor, Data Subject, Processing, and Personal Data Breach have the meanings given by applicable Data Protection Laws. Business, Service Provider, Contractor, Consumer, Sell, and Share have the meanings given by the CCPA where applicable.
Subprocessor means a third party engaged by DataInlet to process Customer Personal Data on DataInlet's behalf.
Capitalized terms not defined in this DPA have the meaning given in the Agreement.
2. Roles and instructions
For Customer Personal Data, Customer is the Controller or Business and DataInlet is the Processor or Service Provider, except where applicable law requires a different characterization for a specific processing activity.
DataInlet will process Customer Personal Data only:
- on Customer's documented instructions, including the Agreement, Customer's configuration and authorized use of the Service, and other written instructions agreed by the parties;
- as reasonably necessary to provide, secure, support, and maintain the Service; or
- as required by applicable law, in which case DataInlet will inform Customer before processing unless the law prohibits that notice.
If DataInlet believes an instruction violates applicable Data Protection Laws, DataInlet may suspend the affected processing and notify Customer.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing all required notices and obtaining all required rights, consents, or other lawful bases.
3. Scope of processing
The subject matter, duration, nature, purpose, data categories, and data-subject categories are described in Schedule 1.
The Service may process Customer Personal Data through automated parsing, deterministic transformations, AI-assisted reasoning, target-system inspection, preview and validation, and Customer-authorized import or export operations.
4. Confidentiality and personnel
DataInlet will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as reasonably necessary for their responsibilities.
DataInlet will limit privileged access and will not use ordinary manual review of Customer Content as a general product-improvement dataset.
5. No model training and zero-retention AI inference
DataInlet will not use Customer Personal Data or Customer Content to train or fine-tune general-purpose AI models.
DataInlet will not intentionally authorize a Subprocessor to use Customer Personal Data to train or improve general-purpose AI models. Production AI processing involving Customer Personal Data will use only approved AI routing and inference services or endpoints configured for zero data retention (ZDR) and configured not to use Customer prompts or responses for general-purpose model training or product improvement.
DataInlet will not intentionally enable provider-side prompt logging, feedback, dataset contribution, or similar optional features that would retain Customer Personal Data or contribute it for model or product improvement. The ZDR requirement applies to third-party AI routing and inference processing and does not alter DataInlet's own retention of Customer Content under the Agreement, configured retention settings, deletion requests, and applicable law.
6. Security
DataInlet will implement and maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the processing, available technology, implementation costs, and risk.
The baseline measures are described in Schedule 2. DataInlet does not represent that it holds any security certification unless expressly stated in a separate written agreement.
Customer remains responsible for its own account security, user permissions, target-system controls, backups, and configuration decisions.
7. Subprocessors
Customer grants DataInlet general authorization to engage Subprocessors to process Customer Personal Data for the Service.
The current Subprocessors are listed in the DataInlet Subprocessor List. DataInlet will require each Subprocessor to protect Customer Personal Data under written obligations that are materially consistent with DataInlet's applicable data-protection obligations for the processing delegated to that Subprocessor.
DataInlet may add or replace Subprocessors. Where applicable law requires prior notice, DataInlet will provide notice by updating the Subprocessor List, account notice, email, or another reasonable method before the new Subprocessor begins processing Customer Personal Data.
If Customer reasonably objects to a new Subprocessor on documented data-protection grounds, the parties will work in good faith on a commercially reasonable solution. If no reasonable solution is available, DataInlet may allow Customer to discontinue the affected Service without penalty for the affected future period, where required by applicable law or agreed in writing.
8. Data-subject requests
Taking into account the nature of the processing, DataInlet will provide reasonable assistance to Customer through appropriate technical and organizational measures to help Customer respond to requests by Data Subjects to exercise rights under applicable Data Protection Laws.
If DataInlet receives a request directly relating to Customer Personal Data for which Customer is responsible, DataInlet will ordinarily direct the requester to Customer unless DataInlet is legally required to respond directly.
Customer is responsible for determining whether and how to respond to a request.
9. Personal Data Breaches
DataInlet will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notice will include information reasonably available to DataInlet that Customer needs to meet applicable breach-notification obligations, which may include the nature of the incident, affected data or systems, likely consequences, and mitigation steps.
A notification is not an admission of fault or liability.
Customer is responsible for notifications to regulators, Data Subjects, or other third parties unless applicable law places that duty directly on DataInlet.
10. Assistance with compliance
Taking into account the nature of processing and information available to DataInlet, DataInlet will provide reasonable assistance with Customer's obligations relating to processing security, breach response, data-protection impact assessments, and prior consultation with regulators where required by applicable Data Protection Laws.
Customer will reimburse reasonable out-of-pocket or material professional-service costs for assistance that is unusually burdensome or outside normal Service functionality, unless the assistance is required because of DataInlet's breach of this DPA.
11. Return and deletion
During the Agreement, Customer may use available Service functionality to export or delete Customer Content.
Upon valid deletion of an Inlet, DataInlet will delete DataInlet-controlled Customer Content within the applicable disposition scope. Deletion does not automatically delete records already written to a Customer-controlled target system.
Following termination or Customer's documented deletion instruction, DataInlet will delete or return Customer Personal Data as required by applicable law and the Agreement, except to the extent retention is legally required.
Customer Personal Data may remain in protected disaster-recovery backups until overwritten or deleted through DataInlet's ordinary backup-rotation process. DataInlet will not intentionally restore deleted Customer Personal Data to active use except where necessary for disaster recovery, and any restored environment remains subject to applicable deletion obligations.
Minimal content-free audit, security, billing, or legal records may be retained where reasonably necessary and permitted by law.
12. Audits and information rights
DataInlet will make available information reasonably necessary to demonstrate compliance with this DPA.
Where Data Protection Laws require audit rights, Customer may conduct an audit no more than once in any twelve-month period unless a regulator requires otherwise or a material Personal Data Breach reasonably justifies an additional audit.
Audits must:
- begin with available documentation, questionnaires, or remote review where reasonably sufficient;
- be conducted during normal business hours on reasonable advance notice;
- avoid unreasonable disruption or access to other customers' data, DataInlet source code, or security-sensitive information unrelated to compliance;
- be conducted by Customer or an independent auditor subject to confidentiality obligations.
Customer bears its audit costs unless the audit identifies a material breach of this DPA by DataInlet.
13. CCPA terms
To the extent the CCPA applies and DataInlet processes Personal Information as a Service Provider or Contractor, DataInlet will not Sell or Share that Personal Information and will not retain, use, or disclose it outside the direct business relationship with Customer except for purposes permitted by the CCPA and the Agreement.
DataInlet will process the Personal Information for the specific business purposes described in the Agreement and Schedule 1, will provide the same level of privacy protection required by applicable CCPA provisions for the role it performs, and will notify Customer if DataInlet determines it can no longer meet those obligations.
Customer may take reasonable and appropriate steps, consistent with applicable law and this DPA, to help ensure that DataInlet uses the Personal Information consistently with Customer's obligations.
14. International transfers
DataInlet uses production cloud infrastructure in the United States and may process Customer Personal Data from the operator's location and through Subprocessors in other countries.
14.1 EEA restricted transfers
If Customer transfers Customer Personal Data to DataInlet and the transfer requires an approved safeguard under the EU GDPR, the parties incorporate the European Commission's 2021 Standard Contractual Clauses for international transfers (EU SCCs) as follows, to the extent legally applicable:
- Module Two (Controller to Processor) applies where Customer is a Controller and DataInlet is a Processor;
- Module Three (Processor to Processor) applies where Customer is itself a Processor and DataInlet acts as a subprocessor;
- the optional docking clause applies;
- for Clause 9, Option 2 (general written authorization) applies and DataInlet will provide at least 30 days' notice of a new Subprocessor where the EU SCCs require an agreed notice period;
- the optional language in Clause 11 does not apply;
- for Clause 17, the governing law of the EU SCCs is the law of Ireland;
- for Clause 18, disputes under the EU SCCs will be resolved by the courts of Ireland;
- the information in the Agreement, this DPA, Schedule 1, Schedule 2, and the current Subprocessor List completes the relevant annex information to the extent applicable;
- the competent supervisory authority is determined in accordance with Clause 13 of the EU SCCs.
If the EU SCCs conflict with another provision of the Agreement regarding an EEA restricted transfer, the EU SCCs control to the extent of the conflict.
14.2 UK restricted transfers
For a restricted transfer subject to the UK GDPR, the parties agree that the then-current International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (UK Addendum) applies to the transfer to the extent legally required.
For purposes of completing the UK Addendum, the parties' details are those in the Agreement and Schedule 1; the selected EU SCC modules and options are those stated in Section 14.1; the processing and security information is in Schedules 1 and 2; and the current Subprocessor List supplies the applicable subprocessor information. The mandatory clauses of the approved UK Addendum apply as issued by the ICO and may be changed only as the approved Addendum permits. If a signature or additional table completion is legally required for a particular Customer, the parties will reasonably cooperate to complete it.
14.3 Other jurisdictions
For another jurisdiction that requires a specific data-transfer mechanism, the parties will reasonably cooperate to implement a legally valid mechanism to the extent required for Customer's lawful use of the Service.
15. Conflict and liability
If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls for that subject matter. The EU SCCs or UK Addendum control over conflicting terms to the extent required for the applicable restricted transfer.
Liability arising under this DPA is subject to the limitations of liability in the Agreement to the maximum extent permitted by applicable law, except where an applicable mandatory transfer mechanism or law provides otherwise.
16. Governing law
Except for provisions governed by mandatory transfer clauses or applicable Data Protection Laws, this DPA is governed by the governing-law and jurisdiction provisions of the Agreement.
Schedule 1 — Details of Processing
A. Parties
Customer / data exporter: The customer identified in the applicable account, order, or Agreement, including its contact details.
Role: Controller or Processor, as applicable.
DataInlet / data importer: Chang Wu, an individual operating DataInlet.
Address: Floor 4, Building F9, Wangjing Street, Chaoyang District, Beijing 100020, China
Privacy contact: contact@datainlet.com
Role: Processor or Subprocessor, as applicable.
B. Subject matter and purpose
Processing Customer Personal Data to provide the DataInlet AI-assisted import service, including source analysis, target-system evidence gathering, import planning, validation, preview, Customer-authorized execution or export, support, security, and deletion.
C. Duration
For the term of Customer's use of the Service and thereafter only for the period reasonably necessary to complete deletion, backup rotation, legal retention, security investigation, or other obligations described in the Agreement and this DPA.
D. Nature of processing
Processing may include collection, receipt, hosting, storage, retrieval, parsing, extraction, organization, structuring, comparison, analysis, AI inference, transformation, generation, validation, transmission to Customer-authorized systems, export, access for support or security, and deletion.
E. Categories of Data Subjects
Depending on Customer Content, Data Subjects may include:
- Customer users, employees, contractors, and administrators;
- Customer's customers, prospects, suppliers, vendors, partners, and business contacts;
- employees, contractors, applicants, or organizational contacts represented in business data;
- other individuals whose personal data Customer lawfully includes in source files or connected systems.
F. Categories of Personal Data
Depending on Customer Content, Personal Data may include:
- names, business email addresses, telephone numbers, addresses, identifiers, and contact information;
- organizational, employment, role, department, and business-relationship information;
- customer, supplier, product, order, catalog, operational, and other business records;
- free-text fields, notes, attachments, and source-file content;
- target-system identifiers, relationships, metadata, and import instructions;
- technical and audit metadata associated with Customer-authorized processing.
G. Sensitive or specially regulated data
Self-service DataInlet plans are not designed for full payment-card data, biometric identifiers used for identification, specialized medical or health records, government-issued identity-document datasets, children's personal data, or other categories requiring sector-specific compliance commitments, unless DataInlet expressly agrees otherwise in writing.
Customer remains responsible for ensuring that the categories of Customer Personal Data it submits are permitted by the Agreement and lawful for the intended processing.
H. Frequency
On an on-demand and recurring basis as Customer and its authorized users use the Service.
I. Subprocessors
The current Subprocessors are identified in the DataInlet Subprocessor List.
Schedule 2 — Technical and Organizational Measures
DataInlet maintains measures appropriate to the current Service and risk profile, including, as applicable:
- Access control — authenticated access, authorization boundaries, least-privilege administrative access, and separation between ordinary user access and privileged operational access.
- Transport security — encrypted network transport for public and provider connections using current industry-standard TLS where supported.
- Secret handling — designated secret-management mechanisms for production credentials and avoidance of intentionally logging secret values.
- Cloud infrastructure controls — production workloads and Customer Content hosted on Google Cloud Platform with cloud access controls and private storage configuration appropriate to the Service.
- Tenant and ownership checks — application-level authorization intended to prevent one customer from retrieving or operating on another customer's Customer Content.
- AI-provider controls — production Customer Content is routed only through approved third-party AI routing and inference services or endpoints configured for zero data retention and not to use prompts or responses for general product improvement or model training; provider-side prompt logging, feedback, dataset contribution, or similar optional retention features are not intentionally enabled for production Customer Content.
- Logging and auditability — operational, security, and data-lifecycle records designed to support troubleshooting, abuse detection, and deletion workflows while minimizing unnecessary Customer Content in durable audit records.
- Retention and deletion controls — Inlet-level deletion/disposition mechanisms and configurable inactivity retention where supported, with ordinary backup rotation for disaster-recovery copies.
- Vulnerability and dependency management — reasonable maintenance, patching, dependency updates, and remediation practices appropriate to the Service's development stage and risk.
- Incident response — procedures to investigate, contain, remediate, and communicate confirmed security incidents affecting Customer Personal Data.
- Business continuity — backups or recovery mechanisms appropriate to the Service, with access controls intended to prevent backup data from becoming an ordinary active processing source.
- Confidentiality — access to Customer Personal Data limited to persons and providers with a legitimate need to provide, secure, or support the Service and subject to confidentiality obligations.
These measures may evolve as long as the overall level of protection is not materially reduced during an active Agreement without lawful basis or Customer agreement where required.