Data processing addendum

SMS Bridge, a product of Ino Tek Plus Holding

Template for review. This document was prepared for review by qualified counsel in each market where it is used. It is not legal advice.

This is a template prepared for review by qualified counsel. It is not legal advice. A DPA is a binding legal instrument and must be finalized by a lawyer before execution with any customer.

Last reviewed: August 31, 2026

Part A: Data Processing Addendum (DPA)

This Data Processing Addendum ("DPA") is entered into between Ino Tek Plus Holding ("Processor," "we") and the Customer identified in the applicable Terms of Service ("Controller," "you"), and forms part of the Terms of Service between the parties.

A1. Scope and roles

This DPA applies where we process personal data on Customer's behalf in connection with SMS Bridge, specifically:

For self hosted deployments running entirely on Customer's own infrastructure with no optional cloud features enabled, we generally do not process Customer's end customer or employee personal data and this DPA's operative processing obligations are correspondingly narrow. Verified on 31 August 2026: the current default build does send message content to a hosted classification provider in the United States, in self hosted deployments as well. A customer that needs classification to stay on its own hardware must take the local classification build, and that should be written into the order.

A2. Nature and purpose of processing

Processing personal data as necessary to provide the SMS Bridge service, including message routing, the Company Gate logic (holding and escalating messages per Customer's configuration), AI classification of message content for routing purposes, storage and backup, and customer support.

A3. Categories of data subjects

Customer's end customers (people who text Customer's business), and Customer's employees or contractors who use SMS Bridge.

A4. Categories of personal data

As described in privacy_policy.md, Section 2: account/billing data, message content, contact records, employee/user data, AI classification outputs, technical/diagnostic data.

A5. Processor obligations

We will:

  1. Process personal data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case we will inform Customer, unless prohibited from doing so).
  2. Ensure persons authorized to process the data are subject to confidentiality obligations.
  3. Implement appropriate technical and organizational security measures.
  4. Assist Customer, at Customer's reasonable request and expense, in responding to data subject requests and in meeting Customer's obligations regarding security, breach notification, and data protection impact assessments, to the extent applicable.
  5. Notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data. A specific notification timeframe, for example "within 72 hours of confirming a breach," should be inserted here once agreed; GDPR requires the controller to notify its supervisory authority within 72 hours of the controller becoming aware, which means our own notice to Customer needs to be fast enough for Customer to meet that clock. I have not fixed a specific number of hours in this draft; needs a business and legal decision.
  6. At Customer's choice, delete or return all personal data at the end of the provision of services, per the Data Export on Exit provisions in terms_of_service.md, except where retention is required by law.
  7. Make available information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality protections.
  8. Not engage a new sub-processor without providing Customer notice and an opportunity to object, per Part B below.

A6. International transfers

Where we transfer personal data outside the country or region in which it was collected, we will rely on an adequate legal mechanism, which may include Standard Contractual Clauses (EU), the UK International Data Transfer Addendum, or another mechanism recognized under applicable law. The specific transfer mechanism to attach as an appendix (SCC module, IDTA text) should be selected and attached by counsel once the current hosting locations are confirmed; not attached in this draft.

A7. Liability

Liability under this DPA is subject to the limitation of liability provisions in the Terms of Service, except to the extent applicable law (for example GDPR Art. 82) requires otherwise.

Part B: Sub-processor list, structure

We maintain a current sub-processor list and will provide advance notice of any new sub-processor with a reasonable objection period (commonly 15 to 30 days). The exact notice period needs a business decision; I have not fixed a number of days.

Recommended structure for the published sub-processor list:

Sub-processor Purpose Location of processing Data categories involved Transfer mechanism
OVH Server hosting and database for hosted deployments Beauharnois and Montreal, Quebec, Canada All categories in hosted deployments None, processing stays in Canada
Hosted model provider, United States Classification of a single inbound message United States Message content Cross border, on the customer's instruction, under the contractual safeguards in this DPA. A local classification build is available on request and removes this transfer entirely.
Bell Canada Mobile carriage of the company line used by the relay handset Canada Message content, phone numbers None, carriage stays in Canada
Registered carrier gateway, optional A2P and 10DLC delivery for customers who take the registered line upgrade Confirmed at the point the upgrade is taken, not in use by default Message content, phone numbers Disclosed to the customer before the upgrade is enabled
Payment processor Billing Not applicable None No payment processor is in use. Checkout runs in sandbox and no card data is collected.

Accurate as of 31 August 2026, verified against the running system. This list is kept current, and a customer is told before a new sub-processor is added.

Sub-processors in use as of 31 August 2026, verified against the running system: hosting and database, OVH, Beauharnois and Montreal, Quebec, Canada, all data categories, no cross border transfer; message classification, a hosted model provider in the United States, message content only, transferred cross border under the customer's own consent and contractual safeguards; mobile carrier, Bell Canada, for the company line used by the relay, message content and phone numbers, no cross border transfer. No payment processor is in use yet, because checkout runs in sandbox. A registered carrier gateway is an optional upgrade and is not in use by default.


Reminder: this is a template DPA and sub-processor list structure. Execution copies must be finalized by qualified counsel, and the sub-processor table must be completed and kept current.