Skip to content

Data Processing Agreement

1. Introduction

This Data Processing Agreement (DPA) forms part of, and is supplementary to, the SaaS Terms of Service and/or Master Services Agreement (together, the Agreement) between inGenious AI Pty Ltd ABN 63 617 284 492 (inGenious AI, we, us, our) and the Customer (you, your).

This DPA sets out the terms on which inGenious AI processes Personal Information on behalf of the Customer in connection with the Platform and Services, and reflects the parties’ obligations under the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).

To the extent of any inconsistency between this DPA and the Agreement, this DPA prevails in relation to the processing of Personal Information.

2. Definitions

In this DPA, unless the context requires otherwise:

AI Features means the artificial intelligence and machine learning features available through the Platform, including features that utilise Third-Party AI Model Providers to process Customer Data.

Customer Data means any data, content, or information (including Personal Information) that the Customer or its End Users input into, upload to, transmit via API, or generate within the Platform, including conversation transcripts, taskflow inputs and outputs, workflow execution data, workflow configurations, prompts, and AI-generated outputs.

Customer-Configured Data Destination means any system, service, or endpoint to which Customer Data is transmitted as a result of the Customer’s configuration of integrations within the Platform, including (without limitation) logging destinations, API endpoints, SSO providers, CRM systems, and data warehouses.

Data Breach means any unauthorised access to, or unauthorised disclosure of, Personal Information, or any loss of Personal Information, in circumstances where the loss, access, or disclosure is likely to result in serious harm to any individual to whom the information relates.

Data Processing Region means the geographic region selected by the Customer for the processing and storage of Customer Data, as configured within the Platform.

End User means any individual who interacts with a chatbot, AI agent, workflow, or other service built and deployed by the Customer using the Platform.

Personal Information means personal information as defined in the Privacy Act.

Platform means the inGenious AI software-as-a-service platform for creating, managing, and improving AI-powered chatbots, AI agents, and workflow automation, including the web-portal, any mobile application, and any software development kits (SDKs), widgets, APIs, or embeddable components provided by inGenious AI for integration into the Customer’s websites, applications, or systems.

Subprocessor means any third party engaged by inGenious AI to process Customer Data on behalf of the Customer.

Third-Party AI Model Provider means any third-party provider of artificial intelligence models (including large language models) that the Platform integrates with to deliver AI Features.


Terms defined in the Agreement have the same meaning in this DPA unless otherwise defined.

3. Roles and Responsibilities

3.1 Roles

  1. The Customer is the controller of Customer Data. The Customer determines the purposes and means of processing Customer Data through its use and configuration of the Platform.
  2. inGenious AI is the processor of Customer Data. inGenious AI processes Customer Data only on behalf of, and in accordance with the documented instructions of, the Customer as set out in this DPA and the Agreement.
  3. Where inGenious AI collects Personal Information directly from Customers for its own purposes (such as account registration, billing, and platform administration), inGenious AI acts as a controller of that information and handles it in accordance with its Privacy Policy.

3.2 Customer Responsibilities

The Customer is responsible for:

  1. Ensuring it has a lawful basis to collect and process Personal Information through the Platform, including obtaining any necessary consents from End Users.
  2. The content of all prompts, configurations, workflows, and data inputs made by the Customer or its authorised users within the Platform.
  3. Selecting the appropriate AI model, Data Processing Region, and configuration settings for each AI Feature, having regard to the Customer’s own regulatory, privacy, and compliance requirements.
  4. Determining what Customer Data, including Personal Information, is submitted to the Platform and to AI Features, and ensuring such submission is appropriate and lawful.
  5. Implementing its own privacy policy and informing End Users about how their data is collected, used, and processed, including through AI Features.
  6. Configuring and utilising available guardrails, data controls, and Platform features to manage the handling of sensitive or regulated data.

3.3 inGenious AI Responsibilities

inGenious AI will:

  1. Process Customer Data only in accordance with the Customer’s documented instructions, unless required to do so by applicable law.
  2. Not use Customer Data for any purpose other than providing the Platform and Services to the Customer.
  3. Not sell, share, or disclose Customer Data to any third party except as permitted under this DPA.
  4. Ensure that personnel authorised to process Customer Data are subject to appropriate confidentiality obligations.

4. Data Processing Details

4.1 Nature and Purpose of Processing

inGenious AI processes Customer Data for the purpose of providing the Platform and Services to the Customer, including:

  1. Hosting and operating the Platform and its features.
  2. Transmitting Customer Data to Third-Party AI Model Providers as directed by the Customer’s configuration of AI Features.
  3. Storing conversation transcripts, workflow data, and other Customer Data within the Platform.
  4. Providing analytics, reporting, and performance monitoring as part of the Platform.
  5. Providing support and troubleshooting services.

4.2 Types of Personal Information

The types of Personal Information processed depend on the Customer’s use and configuration of the Platform and may include:

  1. End User names, contact details, and account information.
  2. Content of conversations between End Users and the Customer’s chatbots or AI agents, and any data entered into, uploaded to, collected by, processed by, or generated by the Customer’s workflows.
  3. Any other Personal Information that End Users voluntarily provide in the course of interacting with the Customer’s services.

4.3 Data Controls

Personal Information provided by End Users or entered into the Platform (such as names, addresses, or health-related information) may be stored as part of Customer Data, including conversation transcripts and workflow data. The Customer may configure guardrails and data controls through the Platform and through Third-Party AI Model Provider services to manage the handling of sensitive or regulated data.

4.4 Categories of Data Subjects

Data subjects may include the Customer’s employees, contractors, end users, customers, and any other individuals whose Personal Information is submitted to or processed through the Platform.

4.5 Customer-Configured Data Destinations

The Platform enables the Customer to configure integrations and data flows that transmit Customer Data to the Customer’s own systems or third-party services. These may include, without limitation, logging destinations, API calls to external systems, single sign-on (SSO) providers, CRM systems, data warehouses, and other services configured by the Customer within the Platform.

The transmission of Customer Data to Customer-Configured Data Destinations is initiated and controlled entirely by the Customer through the Customer’s configuration of the Platform. inGenious AI does not determine the destination, content, or purpose of these transmissions.

inGenious AI is not responsible for the processing, storage, security, or handling of Customer Data once it has been transmitted to a Customer-Configured Data Destination. The Customer is solely responsible for:

  1. Ensuring that any Customer-Configured Data Destination is appropriate and compliant with the Customer’s own regulatory, privacy, and security requirements.
  2. The terms and conditions governing the Customer’s relationship with any third-party service that receives Customer Data via a Customer-Configured Data Destination.
  3. Ensuring that the transmission of Customer Data (including any Personal Information) to a Customer-Configured Data Destination is lawful and appropriate.

5. AI-Specific Processing

5.1 Third-Party AI Model Providers

  1. The Platform integrates with Third-Party AI Model Providers to deliver AI Features. The Customer selects which AI model and provider is used for each AI Feature.
  2. Customer Data submitted to AI Features is transmitted to the selected Third-Party AI Model Provider for processing. This transmission occurs within the Data Processing Region selected by the Customer.
  3. inGenious AI maintains contractual arrangements with Third-Party AI Model Providers that prohibit the use of Customer Data for model training or improvement of the provider’s general models.

5.2 No Model Training

  1. inGenious AI does not use Customer Data to train, fine-tune, or improve any artificial intelligence or machine learning models for purposes other than providing the Services to the Customer.
  2. The Platform provides optional fine-tuning capabilities that the Customer may elect to use at its sole discretion. inGenious AI will not initiate fine-tuning on behalf of the Customer. Where the Customer elects to use fine-tuning features, such processing is performed using only that Customer’s own data and the resulting model or configuration is owned by and available only to that Customer.

5.3 AI-Generated Outputs

Outputs generated by AI Features in response to Customer Data and prompts are part of the Customer Data and are owned by the Customer, subject to any Intellectual Property provisions in the Agreement.

6. Data Location and Sovereignty

  1. Customer Data is processed and stored within the Data Processing Region selected by the Customer within the Platform. Currently available regions include Australia, with additional regions being made available from time to time.
  2. inGenious AI will not transfer or process Customer Data outside the Customer’s selected Data Processing Region without the Customer’s prior written consent.
  3. The Customer acknowledges that selecting a Data Processing Region is the Customer’s responsibility and should be made having regard to the Customer’s own regulatory and compliance requirements.
  4. If inGenious AI receives a request or demand from any government, law enforcement, or regulatory authority to disclose Customer Data, inGenious AI will (to the extent legally permitted):
    (i) promptly notify the Customer of the request;
    (ii) take reasonable steps to challenge or limit the scope of the request; and
    (iii) only disclose the minimum Customer Data required to comply. inGenious
    AI will not voluntarily disclose Customer Data to any government or law enforcement authority.
  5. The Customer acknowledges that the Platform is hosted on infrastructure provided by a third party (currently Amazon Web Services) that may be subject to foreign law disclosure obligations, including the United States CLOUD Act. inGenious AI mitigates this risk by ensuring all Customer Data is processed and stored within the Customer’s selected Data Processing Region and is encrypted at rest and in transit. Where inGenious AI becomes aware of any compelled disclosure affecting Customer Data under foreign law, it will comply with clause 6(d).

7. Subprocessors

7.1 Approved Subprocessors

The Customer authorises inGenious AI to engage the following Subprocessors:

SubprocessorPurposeData Processed
Amazon Web Services (AWS)Platform hosting, infrastructure, AI model provider servicesCustomer Data (within selected Data Processing Region)
DatadogPlatform monitoring, telemetry and SIEMPlatform operational and security log data only. No Customer Data (no conversation transcripts, taskflow data, workflow data, or Personal Information)

7.2 Changes to Subprocessors

  1. inGenious AI will notify the Customer in writing at least 30 days before engaging any new Subprocessor that will process Customer Data.
  2. If the Customer objects to the engagement of a new Subprocessor on reasonable grounds, the parties will work together in good faith to find an alternative solution. If no alternative is available, either party may terminate the affected Services on 30 days’ written notice.
  3. inGenious AI will ensure that each Subprocessor that processes Customer Data is bound by data protection obligations no less protective than those set out in this DPA.

8. Security Measures

inGenious AI implements and maintains appropriate technical and organisational measures to protect Customer Data, including:

  1. Encryption of Customer Data at rest using AES-256 via AWS KMS and in transit using TLS 1.2 or higher.
  2. Data isolation through dedicated or multi-tenant infrastructure as agreed with the Customer. In multi-tenant environments, strict logical separation is maintained at the software layer between customers. Dedicated environments are available upon request.
  3. Role-based access controls enforcing the principle of least privilege.
  4. Automated vulnerability scanning and code security checks on every deployment.
  5. Regular independent penetration testing.
  6. Continuous monitoring, logging, and anomaly detection.
  7. SOC 2 Type 2 and ISO/IEC 27001 certification.

8.2 Audit Logging and Monitoring

inGenious AI maintains comprehensive security audit logging of all user and system activity for networks, servers, storage, and applications. Security audit logs are immutable and include the date and time of each event, the user or system responsible, a description of the event, and the outcome. Security audit logs are retained indefinitely via AWS CloudTrail.

8.3 Vulnerability Management

inGenious AI will remediate identified security vulnerabilities in accordance with the following timeframes:

  1. emergency vulnerabilities (actively exploited in the wild): within 48 hours;
  2. critical and high-risk vulnerabilities: within 2 weeks;
  3. medium and low-risk operating system vulnerabilities: within 4 weeks; and
  4. medium and low-risk application and database vulnerabilities: within 24 weeks.

9. Data Retention and Deletion

9.1 Retention

  1. Customer Data (including conversation transcripts, taskflow inputs and outputs, workflow execution data, and associated data) is retained for a default period of 90 days, unless a different retention period is configured by the Customer within the Platform or a data deletion request via API.
  2. Upon expiry of the retention period, Customer Data is securely overwritten.
  3. Temporary data in caches and queues is cleared within 1 hour.

9.2 Deletion

The Customer may delete Customer Data (including platform user data, AI Agent configurations, taskflow and workflow configurations, conversation transcripts, taskflow inputs and outputs, and any data entered into, uploaded to, transmitted via API, collected by, processed by, or generated by the Customer’s workflows and taskflows) at any time through the Platform dashboard, API or by written request to inGenious AI.

9.3 End of Agreement

Within 180 days of termination or expiry of the Agreement, inGenious AI will securely destroy all Customer Data by overwriting with pseudo-random data or zeroing out, making recovery technically unfeasible. inGenious AI will provide written certification of destruction upon the Customer’s request.

Customer Data may persist in automated backup systems for up to 180 days following deletion, after which backups containing that data are overwritten in the ordinary course.

10. Data Breach Notification

  1. inGenious AI will notify the Customer of a confirmed Data Breach involving Customer Data as follows:

Security breaches: within 48 hours of confirmation, or as otherwise specified in the applicable Contract.

Other data incidents: within 72 hours of confirmation, or as otherwise specified in the applicable Contract.

  1. Notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
  2. inGenious AI will cooperate with the Customer in investigating and remediating any Data Breach and will take all reasonable steps to mitigate the effects of the breach.
  3. inGenious AI will maintain a data breach response process comprising containment, risk evaluation, notification, and prevention.

11. Audit and Compliance

  1. inGenious AI will make available to the Customer, upon reasonable request, information necessary to demonstrate compliance with this DPA.
  2. inGenious AI maintains SOC 2 Type 2 and ISO/IEC 27001 certifications. Current certification reports and summaries are available upon request and are intended to satisfy the Customer’s audit requirements in the ordinary course.
  3. Where the Customer requires additional assurance beyond available certification reports, inGenious AI will allow and contribute to audits conducted by the Customer or the Customer’s appointed independent third-party auditor, subject to reasonable advance notice, scope, and confidentiality arrangements.

12. Cooperation

inGenious AI will provide reasonable assistance to the Customer in:

  1. Responding to requests from individuals exercising their rights under the Privacy Act (including access, correction, and deletion requests) in relation to Personal Information processed through the Platform.
  2. Conducting privacy impact assessments or data protection impact assessments where required by applicable law.
  3. Complying with any directions or determinations of the Office of the Australian Information Commissioner.

13. Term and Survival

This DPA commences on the date the Customer first accesses or uses the Platform and continues for the duration of the Agreement.

The obligations in this DPA relating to confidentiality, data deletion, and data breach notification survive the termination or expiry of the Agreement and continue to apply for so long as inGenious AI retains any Customer Data (including in backup systems).

14. General

  1. This DPA is governed by the laws of the state of Victoria, Australia.
  2. Where inGenious AI proposes to make a material change to this DPA, inGenious AI will provide the Customer with no less than 30 days’ written notice. If the Customer does not accept the change, the Customer may terminate the Agreement by giving written notice within the 30-day notice period.
  3. If any provision of this DPA is held to be invalid or unenforceable, it is ineffective to the extent of the invalidity or unenforceability without affecting the remaining provisions.

Version 1.1 (14/04/2026)