Legal
Effective date: 14 July 2026
This Data Processing Agreement ("DPA") applies whenever InnInk Limited ("Processor", "we") processes personal data on behalf of a Vyxelon customer ("Controller", "you") as part of providing the Vyxelon Service, and reflects the requirements of UK GDPR Article 28 (and, to the extent applicable, EU GDPR Article 28). It supplements our Terms of Service.
"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Personal Data Breach" have the meanings given in UK GDPR and the Data Protection Act 2018. "Sub-processor" means any third party InnInk engages to process Personal Data in connection with the Service.
InnInk will:
The Controller authorises InnInk to engage the sub-processors listed below to process Personal Data in connection with the Service. InnInk remains responsible for each sub-processor's compliance with data protection obligations equivalent to those in this DPA.
| Sub-processor | Purpose |
|---|---|
| OpenAI / Anthropic | Generating AI responses from conversation content and knowledge base context |
| Cloudflare | Application hosting, database, and vector search infrastructure |
| Stripe | Payment processing and billing |
| Twilio | WhatsApp Business messaging delivery |
| Email delivery providers | Sending account, verification, and chat-summary emails |
If InnInk intends to engage a new sub-processor not listed above, we'll give the Controller at least 14 days' notice by email or via the dashboard. If the Controller reasonably objects on data protection grounds within that period, the parties will work in good faith to resolve the objection; if it can't be resolved, the Controller may terminate the affected part of the Service without penalty.
Where a sub-processor is located outside the UK, InnInk relies on an appropriate transfer mechanism, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent adequacy or certification arrangement.
InnInk will notify the Controller without undue delay, and in any case within 72 hours of becoming aware, of any Personal Data Breach affecting the Controller's data, providing the information reasonably available to enable the Controller to meet its own notification obligations to regulators or data subjects.
Where InnInk directly receives a request from a data subject relating to the Controller's End Customer data, InnInk will promptly forward it to the Controller without responding substantively, unless legally required to do otherwise. Controllers can also action access, export, and erasure requests for their own End Customer data directly from the Vyxelon dashboard at any time.
On reasonable prior written notice, and no more than once per year (except following a security incident), InnInk will make available information reasonably necessary to demonstrate compliance with this DPA, and permit a reasonable audit by the Controller or its appointed auditor, subject to confidentiality and not unreasonably disrupting InnInk's operations.
Liability under this DPA is subject to the limitations set out in our Terms of Service or, where applicable, a signed Master Service Agreement between the parties.
This DPA takes effect when the Controller starts using the Service and continues for as long as InnInk processes Personal Data on the Controller's behalf under the Terms of Service.
Questions about this DPA? Contact us at hello@vyxelon.com.