VYXELON.
Pricing Affiliate Program Log in Get Started

Legal

Data Processing Agreement

Effective date: 14 July 2026

On this page

  1. Purpose & scope
  2. Definitions
  3. Subject matter & details of processing
  4. Processor obligations
  5. Sub-processors
  6. International transfers
  7. Personal data breaches
  8. Data subject requests
  9. Audits
  10. Liability
  11. Term
  12. Contact
This DPA forms part of the agreement between InnInk Limited and any business with an active Vyxelon account, and applies automatically wherever InnInk processes personal data on that business's behalf — no separate signature is required, consistent with how most SaaS DPAs operate. If your organisation requires a countersigned version for its own compliance records, contact hello@vyxelon.com.

1. Purpose & scope

This Data Processing Agreement ("DPA") applies whenever InnInk Limited ("Processor", "we") processes personal data on behalf of a Vyxelon customer ("Controller", "you") as part of providing the Vyxelon Service, and reflects the requirements of UK GDPR Article 28 (and, to the extent applicable, EU GDPR Article 28). It supplements our Terms of Service.

2. Definitions

"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Personal Data Breach" have the meanings given in UK GDPR and the Data Protection Act 2018. "Sub-processor" means any third party InnInk engages to process Personal Data in connection with the Service.

3. Subject matter & details of processing

  • Subject matter: provision of the Vyxelon AI customer support Service.
  • Duration: for as long as the Controller's account is active, plus any period required under Section 11 (return or deletion of data).
  • Nature and purpose: automated response generation, escalation routing, and support analytics for the Controller's customer conversations.
  • Types of Personal Data: End Customer name and contact details (email address and/or phone number, where provided), and the content of support conversations.
  • Categories of Data Subjects: the Controller's own customers and website visitors who interact with the Service on the Controller's behalf.

4. Processor obligations

InnInk will:

  • Process Personal Data only on the Controller's documented instructions — including instructions reflected in the Controller's own configuration of the Service — unless required to do otherwise by law, in which case InnInk will inform the Controller first unless the law prohibits this;
  • Ensure personnel authorised to process Personal Data are subject to a duty of confidentiality;
  • Implement appropriate technical and organisational security measures, as described in our Privacy Policy;
  • Assist the Controller, taking into account the nature of processing, in responding to data subject requests and in meeting its own obligations around security, breach notification, and data protection impact assessments;
  • At the Controller's choice, delete or return Personal Data at the end of the relationship, subject to any legal retention requirement; and
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

5. Sub-processors

The Controller authorises InnInk to engage the sub-processors listed below to process Personal Data in connection with the Service. InnInk remains responsible for each sub-processor's compliance with data protection obligations equivalent to those in this DPA.

Sub-processorPurpose
OpenAI / AnthropicGenerating AI responses from conversation content and knowledge base context
CloudflareApplication hosting, database, and vector search infrastructure
StripePayment processing and billing
TwilioWhatsApp Business messaging delivery
Email delivery providersSending account, verification, and chat-summary emails

If InnInk intends to engage a new sub-processor not listed above, we'll give the Controller at least 14 days' notice by email or via the dashboard. If the Controller reasonably objects on data protection grounds within that period, the parties will work in good faith to resolve the objection; if it can't be resolved, the Controller may terminate the affected part of the Service without penalty.

6. International transfers

Where a sub-processor is located outside the UK, InnInk relies on an appropriate transfer mechanism, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent adequacy or certification arrangement.

7. Personal data breaches

InnInk will notify the Controller without undue delay, and in any case within 72 hours of becoming aware, of any Personal Data Breach affecting the Controller's data, providing the information reasonably available to enable the Controller to meet its own notification obligations to regulators or data subjects.

8. Data subject requests

Where InnInk directly receives a request from a data subject relating to the Controller's End Customer data, InnInk will promptly forward it to the Controller without responding substantively, unless legally required to do otherwise. Controllers can also action access, export, and erasure requests for their own End Customer data directly from the Vyxelon dashboard at any time.

9. Audits

On reasonable prior written notice, and no more than once per year (except following a security incident), InnInk will make available information reasonably necessary to demonstrate compliance with this DPA, and permit a reasonable audit by the Controller or its appointed auditor, subject to confidentiality and not unreasonably disrupting InnInk's operations.

10. Liability

Liability under this DPA is subject to the limitations set out in our Terms of Service or, where applicable, a signed Master Service Agreement between the parties.

11. Term

This DPA takes effect when the Controller starts using the Service and continues for as long as InnInk processes Personal Data on the Controller's behalf under the Terms of Service.

12. Contact

Questions about this DPA? Contact us at hello@vyxelon.com.

© Vyxelon, a product of InnInk Limited.

Pricing Affiliate Program Log in Contact
Terms of Service Privacy Policy Data Processing Agreement Refund Policy Master Service Agreement AI Disclaimer