Data Processing Agreement
Last updated: 23 August 2026
1. Introduction and parties
This Data Processing Agreement ("DPA") forms part of, and is subject to, the agreement between JoPaJoEm Pty Ltd (ACN 125 834 184) as trustee for the JoPaJoEm Family Trust (ABN 98 473 397 086), trading as "Inqelo" of 167 Flinders Street, Adelaide SA 5000, Australia ("Inqelo"), and the customer identified in the order or online registration ("Customer"), each a "Party".
It governs Inqelo's Processing of Personal Data on behalf of Customer in connection with the Inqelo services — call, form, inbound-email and uploaded-document capture, understanding, lead valuation, retrieval and analysis of publicly accessible web content where Customer expressly enables and instructs it, and the return of results and configured signals to Customer's advertising and analytics systems (the "Services").
Effective Date: the earlier of (i) Customer's first use of the Services, or (ii) the date Customer accepts the Terms that incorporate this DPA. Acceptance of those Terms is also each Party's agreement to the Standard Contractual Clauses and UK Addendum incorporated by clause 9.
2. Definitions
Capitalised terms not defined here have the meaning in the main agreement. "Data Protection Legislation" means all laws applicable to the Processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR and Data Protection Act 2018, and any legislation replacing or supplementing them. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have their EU GDPR meanings.
"Lead Data" means Personal Data relating to Customer's prospects, callers and enquirers, Customer staff appearing in interactions, individuals identified in documents Customer uploads, and individuals appearing in publicly accessible web content retrieved on Customer's instruction, captured and processed through the Services on Customer's behalf. "Sub-processor" means a third party engaged by Inqelo to Process Lead Data. "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914 as completed in Schedule 4; "UK Addendum" means the ICO International Data Transfer Addendum (B1.0) as completed in Schedule 4.
3. Roles
3.1. Customer is the Controller and Inqelo is the Processor of Lead Data. Where Customer itself acts as a processor for a further controller, Customer warrants it has that controller's authorisations, and Inqelo acts as Customer's sub-processor.
3.2. Each Party complies with the obligations that apply to it under Data Protection Legislation. Customer warrants its instructions are lawful and that it is entitled to give them.
4. Description of processing
The subject-matter, nature, purpose and duration of Processing, and the categories of Personal Data and Data Subjects, are in Schedule 1, extracted from Inqelo's Article 30 record.
5. Instructions
5.1. Inqelo Processes Lead Data only on Customer's documented instructions, unless required by Union or Member State, or UK, law to which Inqelo is subject. This DPA, the main agreement, and Customer's configuration of the Services — including the retention election, integration settings, consent signals and support requests — are Customer's complete documented instructions.
5.2. Compelled processing. Where Processing is governed by the EU GDPR, Inqelo may Process Lead Data beyond Customer's instructions only where required by Union or Member State law. Where Processing is governed by the UK GDPR, Inqelo may do so where required by UK law. Requests arising under Australian or other third-country law are handled under clause 7.9 and the applicable transfer instrument. Where such a legal requirement applies, Inqelo informs Customer of it before Processing, unless that law prohibits such information on important grounds of public interest.
5.3. Service testing and monitoring. Customer instructs Inqelo to Process Lead Data as necessary to provide, secure, maintain, and periodically test and monitor the Services Inqelo provides to Customer, so that extraction, transcription, valuation and delivery keep working correctly for Customer. Under this instruction Inqelo retains Lead Data only as set out in Schedule 1, does not use Lead Data to train models, and does not combine Customer's Lead Data with any other customer's data. Inqelo has no independent right to use Lead Data for its own purposes.
5.4. Inqelo informs Customer without undue delay if, in its opinion, an instruction infringes Data Protection Legislation, and may suspend the affected Processing until the instruction is confirmed or amended.
6. Customer obligations
Customer shall: (a) ensure it has the lawful basis, and has given the notices and obtained any consents required, to capture Lead Data and disclose it to Inqelo — including call-recording notices and the consent signals the tracking script and ad delivery rely on; (b) configure the Services so Lead Data is adequate, relevant and limited to what is necessary; (c) not configure the Services to solicit special-category data, and notify Inqelo without undue delay if such data is captured in error, with clause 7.8 governing deletion; and (d) keep its retention election appropriate to its own purposes — Customer, not Inqelo, decides how long Lead Data is kept.
7. Inqelo obligations
7.1. Instructions only. Process Lead Data only per clause 5.
7.2. Confidentiality. Ensure persons authorised to Process Lead Data are committed to confidentiality or under an appropriate statutory obligation.
7.3. Security (Art. 32). Implement and maintain the technical and organisational measures in Schedule 2, appropriate to the risk, and review them regularly.
7.4. Sub-processors. Engage them only per clause 8.
7.5. Data-subject rights (Arts. 12–23). Taking into account the nature of the Processing, Inqelo provides appropriate technical and organisational measures and reasonable assistance to enable Customer to respond to requests under Data Protection Legislation, including access, export and erasure functionality where available.
Inqelo forwards to Customer, without undue delay and without responding itself, any request it receives directly from a Data Subject.
7.6. Breach (Arts. 33–34). Notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Lead Data. Where all required information is not immediately available, Inqelo may provide it in phases without undue further delay. The notice will include the available information about the nature of the breach, affected Data Subjects and records, likely consequences, measures taken or proposed, and a contact point.
7.7. DPIA and prior-consultation assistance (Arts. 35–36). Provide Customer, on request, with information reasonably necessary to assist with applicable data protection impact assessments and supervisory-authority consultations.
7.8. Special-category deletion. On Customer's notice under clause 6(c), delete the affected content without undue delay; where the content sits in an ancillary store that deletes only by expiry, Inqelo confirms the applicable expiry instead.
7.9. Government and third-party access. Do not disclose Lead Data to a public authority unless legally compelled; where lawful, notify Customer before disclosure or as soon as permitted, challenge overbroad or unlawful requests, and disclose the minimum required. The SCCs' Clause 15 commitments apply to transfers they govern.
7.10. Deletion or return at end of Services (Art. 28(3)(g)). At Customer's choice, Inqelo will delete or return Lead Data following termination in accordance with Schedule 1. If Customer makes no election within 30 days after termination, Inqelo deletes the Lead Data. Residual copies in backups and ancillary systems remain isolated from ordinary use and expire under their applicable retention periods. If a backup is restored, applicable erasure and expiry records are reapplied before the restored data is returned to production use. Inqelo may retain data where Union, Member State or UK law requires it.
7.11. Records, information and audits (Art. 28(3)(h)). Maintain records of Processing and make available to Customer all information necessary to demonstrate compliance with this DPA. Inqelo shall allow for and contribute to audits, including inspections, conducted by Customer or its mandated auditor: first through written information and documentation; where that reasonably fails to resolve the question, by remote or on-premises inspection on at least 30 days' notice, at most once per 12-month period, except after a Personal Data Breach or evident non-compliance where no frequency limit applies, during business hours, under confidentiality, at Customer's cost, and without access to other customers' data.
8. Sub-processing
8.1. Customer grants general written authorisation for the Sub-processors in Schedule 3, which mirrors SCC Annex III, and for the integration destinations Customer itself configures. Customer's own Google, Meta and analytics accounts and its own telephony provider are Customer's suppliers, not Inqelo's Sub-processors.
8.2. Inqelo imposes on each Sub-processor, by written contract, data-protection obligations materially equivalent to this DPA, and remains fully liable for their performance. Any exception is identified in Schedule 2.
8.3. Inqelo gives Customer at least 30 days' written notice by email to every active Platform account before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected Services pro rata.
9. International transfers
9.1. Lead Data is stored at rest in EU regions. The processing location of each Sub-processor is stated in Schedule 3. Inqelo is established in Australia, and limited authorised personnel may access the Services from Australia under the safeguards in this clause 9, including the SCCs. Certain infrastructure providers, including the edge and TLS provider identified in Schedule 3, may Process network traffic or associated metadata outside the EEA. This is not a claim that Lead Data is immune from non-EU jurisdiction.
9.2. Because Inqelo is established in Australia, the Parties enter into the EU SCCs as completed in Schedule 4, including Annexes I–III, and incorporated by reference. The module that applies is the one matching the Parties' actual roles under clause 3.1, without further action by either Party:
- Module 2 (controller to processor) where Customer is the Controller of Lead Data; or
- Module 3 (processor to processor) where Customer itself acts as a processor for a further controller, in which case Inqelo is Customer's sub-processor and Customer's warranty in clause 3.1, that it holds that controller's authorisations including for onward transfer, is the basis on which Module 3 operates.
Both modules take the same option selections, so no separate negotiation is required. For transfers subject to the UK GDPR, the UK Addendum completed in Schedule 4 applies in addition. Acceptance of the Terms that incorporate this DPA executes whichever module applies, together with the Addendum. In case of conflict between this DPA and the SCCs or UK Addendum, the SCCs or Addendum prevail for the transfers they govern.
9.3. Onward transfers by Inqelo to Sub-processors are made under each Sub-processor's DPA with incorporated SCCs or an applicable adequacy mechanism, per Schedule 3 and Inqelo's supplier evidence library. Inqelo maintains a documented Australia transfer impact assessment.
10. Liability
The liability regime and caps of the main agreement apply to this DPA, save where the SCCs prohibit limitation; Data Subjects' third-party beneficiary claims under the SCCs are not capped by this clause.
11. Term
This DPA runs until the later of expiry of the main agreement and completion of deletion or return under clause 7.10. Clauses that by nature survive, including confidentiality, receipts and liability, survive.
12. General
If any provision is unenforceable, the remainder stands. On data-protection matters this DPA prevails over the main agreement; the SCCs and UK Addendum prevail over both for the transfers they govern.
Governing law: the law of the main agreement — South Australia, Australia — without prejudice to clause 9's instruments. The SCCs are governed by the law of Ireland under Clause 17 Option 1, with the courts of Ireland as forum under Clause 18(b). The UK Addendum is governed by the law of England and Wales. Three laws therefore apply to three different instruments, which is the normal result of an Australian processor serving EU and UK exporters.
Signatures
Executed by acceptance of the Terms during company onboarding, a plan change or through an accepted order.
For JoPaJoEm Pty Ltd (ACN 125 834 184) as trustee for the JoPaJoEm Family Trust (ABN 98 473 397 086), trading as Inqelo: Inqelo authorised representative. Privacy contact: admin@inqelo.com. EU representative under Article 27: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. UK representative under UK GDPR Article 27: Prighter Ltd, 20 Mortlake High Street, London SW14 8JN, United Kingdom. Both are reachable through the Prighter portal, quoting ID-19935887204.
Schedule 1 — Processing particulars
| Item | Description |
|---|---|
| Subject-matter and nature | Capture and processing of Customer-configured enquiries and supporting material through supported channels, including calls, web forms, email and uploaded documents, where enabled by Customer; ingestion, transcription, parsing, extraction, summarisation, classification, valuation, deduplication, storage, retrieval, erasure and delivery of results to Customer-configured destinations. Where expressly enabled and instructed by Customer, retrieval and analysis of publicly accessible web content relevant to the Customer's configured assessment purposes. |
| Purpose | Provision of the Services on Customer's documented instructions, including the clause 5.3 testing-and-monitoring instruction for Customer's own service only. |
| Duration | The term of the main agreement, plus the clause 7.10 deletion and return window. |
| Data Subjects | Customer's prospects, callers, form-submitters and email enquirers; Customer staff appearing in interactions, such as the named call-taker; individuals identified in documents Customer uploads; individuals appearing in publicly accessible web content retrieved on Customer's instruction. |
| Categories of Personal Data | Contact and identity data; enquiry and communication content; attribution, campaign and interaction data; device, network and telephony metadata; Customer-provided documents; publicly available information retrieved on Customer instruction; and derived assessment and classification data. |
| Special categories | Inqelo does not require or intentionally solicit special-category personal data or personal data relating to criminal convictions and offences. Because the Services process unstructured communications and documents, such information may be included incidentally. Customer must not intentionally configure the Services to collect such information unless separately agreed and lawfully authorised. The safeguards listed under Special-category safeguards below apply, under clauses 6(c) and 7.8. |
| Retention | Customer elects a retention period per company from the options offered in the Platform, including an explicit unlimited-retention election. Where no election has been made, 365 days applies from the enquiry event time. Ancillary operational records expire under bounded periods: records in stores that support individual erasure (including LLM traces) are deleted on request as described in clause 7.5 and in any event expire within 90 days; records in stores that delete only by expiry — short-lived pre-lead captures, provider-held transcription artifacts, operational logs and managed database backups — expire within 30 days. Erasure receipts are retained for 6 years for Inqelo's legitimate interests in demonstrating compliance and in establishing or defending legal claims. |
Special-category safeguards. Where such material is present incidentally:
- no use of Lead Data to train models;
- no cross-customer use;
- no intentional inference or targeting based on sensitive characteristics;
- least-privilege access;
- access logging;
- restricted onward transfer;
- customer-operated deletion and redaction;
- expedited handling when sensitive material is identified.
Schedule 2 — Technical and organisational measures
The complete technical and organisational measures in SCC Annex II are incorporated here as Schedule 2. The schedule includes the operated controls, Sub-processor contract exception and disclosed residual limitations.
Because it contains detailed security-control information, Schedule 2 is available to signed-in account holders on the Technical and Organisational Measures page, including before company creation and Terms acceptance.
Schedule 3 — Authorised Sub-processors
This list is also available as a standalone Sub-processors page. Change notice is governed by clause 8.3.
| Sub-processor | Processing | Location |
|---|---|---|
| Requesty Ltd (company no. 15165717) | EU LLM routing and gateway services for extraction, enhancement, formatting, summarisation, setup and valuation. Prompts and outputs are not retained or used for training. | Frankfurt, Germany |
| Model hosting providers authorised under Requesty's DPA: Google LLC (Vertex AI), Microsoft Azure AI, TensorX Ltd., sference, Amazon Web Services (Bedrock), Nebius AI and Inceptron AB | Model inference reached only through Requesty. Inqelo restricts approved routes to EU processing, zero retention and no training. Requesty contracts with and remains responsible for these providers. | European Union regions |
| AssemblyAI Inc. | Call transcription. Final transcription artifacts begin automatic deletion after 30 days, and content submitted through the European servers is not used for model training. | Dublin, Ireland through the EU endpoint |
| LlamaIndex Inc. | Parsing Customer-uploaded documents. | European Union through the EU endpoint |
| ClickHouse, Inc. (Langfuse Cloud) | LLM trace storage. Traces expire after 90 days and can be deleted for an individual. | European Union region |
| Amazon Web Services, Inc. and the AWS Contracting Party for the account country | File storage, retrieval and control-plane storage. | Frankfurt, Germany |
| DigitalOcean, LLC | Primary datastore and application hosting. | Amsterdam, Netherlands |
| VostokInc SAS (ScrapingBee) | Retrieval of publicly accessible webpages on Customer instruction. The request may use a Customer-selected proxy country outside the EEA. | Request-specific |
| Cloudflare, Inc. | Edge delivery, network security and TLS termination for the Platform. | Global edge network |
| Twilio Inc. (SendGrid) | Service and alert email, including alert content containing Lead Data. | European Union residency endpoint |
| CallTrackingMetrics | Tracking number supply, call handling and call recording, where Inqelo supplies the call tracking. Used for customers in the European Union and the Americas. | United States |
| FoneDynamics | Tracking number supply, call handling and call recording, where Inqelo supplies the call tracking. Used only for customers in Australia and New Zealand. | Australia |
Schedule 4 — Transfer instruments
The official, unmodified European Commission Standard Contractual Clauses are incorporated with the completed Module 2 and Module 3 selections and Appendix information on the EU Standard Contractual Clauses page.
For Restricted Transfers governed by UK Data Protection Laws, the completed UK International Data Transfer Addendum applies in addition. Its completed Part 1 Tables are published on that page, and the official Mandatory Clauses are incorporated without modification by reference.
