InkDeskInkDesk LogoInkDesk Logo
Start free trial

For You

Solo Tattoo Artists
For independent artists who manage their own bookings and clients.
Tattoo Studios
For studio owners who manage bookings for multiple artists.

Our Features

Client Projects
All client notes, references, and communication history in one place.
Online Scheduling
Choose times yourself or send clients a booking link.
Custom Booking Forms
Collect client details, references, and placement upfront.
Deposit Payments
Collect tattoo deposits online and reduce no-shows.
Digital Waivers
Send secure, paperless tattoo consent forms.
Client Messaging
Manage all client emails and conversations in one inbox.
Automatic Reminders
Reduce no-shows with automated appointment reminders.
Reporting
Track revenue, clients, and performance at a glance.
Pricing
Blog
Sign inStart free trial

Footer

InkDesk LogoInkDesk Logo

The professional booking platform for the modern tattoo artist.

© 2026 InkDesk, Inc. All rights reserved.

InstagramFacebookYouTube
Download on the App StoreGet it on Google Play

Platform

  • Solo Tattoo Artists
  • Tattoo Studios

Features

  • Client Projects
  • Online Scheduling
  • Custom Booking Forms
  • Deposit Payments
  • Digital Waivers
  • Client Messaging
  • Automatic Reminders
  • Reporting

Resources

  • About
  • Blog
  • Pricing

Legal

  • Privacy Policy
  • Terms of Service
  • Legal
Back to the art.
InkDesk

Data Processing Agreement

Last modified: September 3, 2026

Legal

This InkDesk Data Processing Agreement and its Annexes (“DPA”) reflects the parties' agreement with respect to the Processing of Personal Data by us on behalf of you in connection with the InkDesk Subscription Services under the InkDesk Customer Terms of Service (also referred to in this DPA as the “Agreement”).

This DPA is supplemental to, and forms an integral part of, the Agreement and is effective upon its incorporation into the Agreement. In case of any conflict or inconsistency with the terms of the Agreement, this DPA will take precedence over the terms of the Agreement to the extent of such conflict or inconsistency.

We update these terms from time to time. If you have an active InkDesk subscription, we will let you know when we do by email to the address on your account or by a notice in your InkDesk account.

The term of this DPA will follow the term of the Agreement. Terms not otherwise defined in this DPA will have the meaning as set forth in the Agreement.

1. Definitions

“California Personal Information” means Personal Data that is subject to the protection of the CCPA.

"CCPA" means California Civil Code Sec. 1798.100 et seq. (also known as the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 or "CPRA").

"Consumer", "Business", "Sell", "Service Provider", and "Share" will have the meanings given to them in the CCPA.

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

“Data Protection Laws” means all applicable worldwide legislation relating to data protection and privacy which applies to the respective party in the role of Processing Personal Data in question under the Agreement, including without limitation European Data Protection Laws, the CCPA and other applicable U.S. federal and state privacy laws, and the data protection and privacy laws of Canada, including the Personal Information Protection and Electronic Documents Act and substantially similar provincial legislation in Alberta, British Columbia and Quebec; and, where applicable to the Processing in question, the privacy laws of other jurisdictions in which you or your Data Subjects are located; in each case as amended, repealed, consolidated or replaced from time to time.

“Data Subject” means the individual to whom Personal Data relates.

"Europe" means the European Union, the European Economic Area and/or their member states, Switzerland and the United Kingdom.

“European Data” means Personal Data that is subject to the protection of European Data Protection Laws.

"European Data Protection Laws" means data protection laws applicable in Europe, including: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); or (iii) GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"); and (iv) Swiss Federal Data Protection Act on 19 June 1992 and its Ordinance ("Swiss DPA"); in each case, as may be amended, superseded or replaced.

“Instructions” means the written, documented instructions issued by a Controller to a Processor, and directing the same to perform a specific or general action with regard to Personal Data (including, but not limited to, depersonalizing, blocking, deletion, making available).

"Permitted Affiliates" means any of your Affiliates that (i) are permitted to use the Subscription Services pursuant to the Agreement, but have not signed their own separate agreement with us and are not a “Customer” as defined under the Agreement, (ii) qualify as a Controller of Personal Data Processed by us, and (iii) are subject to European Data Protection Laws.

“Personal Data” means any information relating to an identified or identifiable individual where (i) such information is contained within Customer Data; and (ii) is protected similarly as personal data, personal information, or personally identifiable information under applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by us and/or our Sub-Processors in connection with the provision of the Subscription Services. "Personal Data Breach" will not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

“Processing” means any operation or set of operations which is performed on Personal Data, encompassing the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction or erasure of Personal Data. The terms “Process”, “Processes” and “Processed” will be construed accordingly.

“Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

“Standard Contractual Clauses” means the standard contractual clauses annexed to the European Commission's Decision (EU) 2021/914 of 4 June 2021 currently found at https://eur-lex.europa.eu/eli/dec_impl/2021/914, as may be amended, superseded or replaced.

“Sub-Processor” means any Processor engaged by us or our Affiliates to assist in fulfilling our obligations with respect to the provision of the Subscription Services under the Agreement. Sub-Processors may include third parties or our Affiliates but will exclude any InkDesk employee or consultant.

“UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 currently found at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf, as may be amended, superseded, or replaced.

2. Customer Responsibilities

a. Compliance with Laws. Within the scope of the Agreement and in its use of the services, you will be responsible for complying with all requirements that apply to it under applicable Data Protection Laws with respect to its Processing of Personal Data and the Instructions it issues to us.

In particular but without prejudice to the generality of the foregoing, you acknowledge and agree that you will be solely responsible for: (i) the accuracy, quality, and legality of Customer Data and the means by which you acquired Personal Data; (ii) complying with all necessary transparency and lawfulness requirements under applicable Data Protection Laws for the collection and use of the Personal Data, including obtaining any necessary consents and authorizations (particularly for use by Customer for marketing purposes); (iii) ensuring you have the right to transfer, or provide access to, the Personal Data to us for Processing in accordance with the terms of the Agreement (including this DPA); (iv) ensuring that your Instructions to us regarding the Processing of Personal Data comply with applicable laws, including Data Protection Laws; and (v) complying with all laws (including Data Protection Laws) applicable to any emails or other content created, sent or managed through the Subscription Services, including those relating to obtaining consents (where required) to send emails, the content of the emails and its email deployment practices. You will inform us without undue delay if you are not able to comply with your responsibilities under this 'Compliance with Laws' section or applicable Data Protection Laws.

b. Controller Instructions. The parties agree that the Agreement (including this DPA), together with your use of the Subscription Service in accordance with the Agreement, constitute your complete Instructions to us in relation to the Processing of Personal Data, so long as you may provide additional instructions during the subscription term that are consistent with the Agreement, the nature and lawful use of the Subscription Service.

c. Security. You are responsible for independently determining whether the data security provided for in the Subscription Service adequately meets your obligations under applicable Data Protection Laws. You are also responsible for your secure use of the Subscription Service, including protecting the security of Personal Data in transit to and from the Subscription Service (including to securely backup or encrypt any such Personal Data).

3. InkDesk Obligations

a. Compliance with Instructions. We will only Process Personal Data for the purposes described in this DPA or as otherwise agreed within the scope of your lawful Instructions, except where and to the extent otherwise required by applicable law. We are not responsible for compliance with any Data Protection Laws applicable to you or your industry that are not generally applicable to us.

b. Conflict of Laws. If we become aware that we cannot Process Personal Data in accordance with your Instructions due to a legal requirement under any applicable law, we will (i) promptly notify you of that legal requirement to the extent permitted by the applicable law; and (ii) where necessary, cease all Processing (other than merely storing and maintaining the security of the affected Personal Data) until such time as you issue new Instructions with which we are able to comply. If this provision is invoked, we will not be liable to you under the Agreement for any failure to perform the applicable Subscription Services until such time as you issue new lawful Instructions with regard to the Processing.

c. Security. We will implement and maintain appropriate technical and organizational measures to protect Personal Data from Personal Data Breaches, as described under Annex 2 to this DPA ("Security Measures"). Notwithstanding any provision to the contrary, we may modify or update the Security Measures at our discretion provided that such modification or update does not result in a material degradation in the protection offered by the Security Measures.

d. Confidentiality. We will ensure that any personnel whom we authorize to Process Personal Data on our behalf is subject to appropriate confidentiality obligations (whether a contractual or statutory duty) with respect to that Personal Data.

e. Data Protection Impact Assessments. Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance to you with any data protection impact assessment you are required to carry out under applicable Data Protection Laws in relation to the Subscription Service, and with any prior consultation with a supervisory authority arising from it. This assistance will ordinarily take the form of the information in this DPA, our Privacy Policy and our security documentation; where you reasonably require more, we will provide it on written request, and you will reimburse our commercially reasonable costs.

f. Personal Data Breaches. We will notify you without undue delay after we become aware of any Personal Data Breach and will provide timely information relating to the Personal Data Breach as it becomes known or reasonably requested by you. At your request, we will promptly provide you with such reasonable assistance as necessary to enable you to notify relevant Personal Data Breaches to competent authorities and/or affected Data Subjects, if you are required to do so under Data Protection Laws.

g. Deletion or Return of Personal Data. You may export Customer Data from your account at any time while your subscription is active. When you delete your account, Customer Data is erased from our live systems immediately. This term will apply except where we are required by applicable law to retain some or all of the Customer Data, and except that copies persist in database backups for the point-in-time recovery window described in Annex 2 and in any retained snapshots until those age out, which data we securely isolate and protect from any further Processing. We also retain a limited record of a deleted account — the email address and an abuse indicator — in order to detect and prevent abuse of the deletion process; that record is not used for any other purpose. You may request the deletion of your InkDesk account after expiration or termination of your subscription by sending a request to [email protected].

If you need help retrieving your Customer Data during the Subscription Term, we will provide reasonable assistance to you, at your cost, and in accordance with the 'Confidentiality' section of the General Terms.

4. Data Subject Requests

The Subscription Service provides you with controls that you can use to access, retrieve and correct Personal Data in your account, which you can use to assist you in connection with your obligations under Data Protection Laws, including your obligations relating to responding to requests from Data Subjects to exercise their rights under applicable Data Protection Laws ("Data Subject Requests"). Where the Subscription Service does not provide a self-service control for a particular action — including deletion of an individual record — we will action your documented instruction on your behalf within a reasonable period, at no charge for requests arising from a Data Subject Request.

To the extent that you are unable to independently address a Data Subject Request through the Subscription Service, then upon your written request we will provide reasonable assistance to you to respond to any Data Subject Requests or requests from data protection authorities relating to the Processing of Personal Data under the Agreement. You will reimburse us for the commercially reasonable costs arising from this assistance.

If a Data Subject Request or other communication regarding the Processing of Personal Data under the Agreement is made directly to us, we will promptly inform you and will advise the Data Subject to submit their request to you. You will be solely responsible for responding substantively to any such Data Subject Requests or communications involving Personal Data.

5. Sub-Processors

You agree we may engage Sub-Processors to Process Personal Data on your behalf, and we do so in three ways. First, we may engage Sub-Processors to assist us with hosting and infrastructure. Second, we may engage with Sub-Processors to support product features and integrations. Third, we may engage with InkDesk Affiliates as Sub-Processors for service and support. Some Sub-Processors will apply to you as default, and some Sub-Processors will apply only if you opt-in.

We have currently appointed, as Sub-Processors, the third parties and InkDesk Affiliates listed in Annex 3 to this DPA.

We maintain the current list of Sub-Processors in Annex 3 to this DPA at https://inkdesk.app/legal/data-processing-agreement. Before we engage a new Sub-Processor that will Process Personal Data, we will update that Annex and give you notice by email to the address on your account, at least thirty (30) days in advance, unless the appointment is urgent and necessary to maintain the security or availability of the Subscription Service, in which case we will give notice as soon as reasonably practicable. You may ask us to add an email address for these notices by contacting [email protected].

We will give you the opportunity to object to the engagement of new Sub-Processors on reasonable grounds relating to the protection of Personal Data within 30 days of notifying you. If you do notify us of such an objection, the parties will discuss your concerns in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, we will, at our sole discretion, either not appoint the new Sub-Processor, or permit you to suspend or terminate the affected Subscription Service in accordance with the termination provisions of the Agreement without liability to either party (but without prejudice to any fees incurred by you prior to suspension or termination). The parties agree that by complying with this sub-section, InkDesk fulfills its obligations under Clause 9 of the Standard Contractual Clauses.

Where we engage Sub-Processors, we will impose data protection terms on the Sub-Processors that provide at least the same level of protection for Personal Data as those in this DPA (including, where appropriate, the Standard Contractual Clauses), to the extent applicable to the nature of the services provided by such Sub-Processors. We will remain responsible for each Sub-Processor's compliance with the obligations of this DPA and for any acts or omissions of such Sub-Processor that cause us to breach any of its obligations under this DPA.

6. Data Transfers

a. General. You acknowledge and agree that we may access and Process Personal Data on a global basis as necessary to provide the Subscription Service, and that Personal Data may be transferred to and Processed by us and our Sub-Processors in the United States and other jurisdictions. Wherever Personal Data is transferred outside its country of origin, each party will ensure the transfer is made in compliance with applicable Data Protection Laws.

b. Transfers of European Data. Where we Process European Data and transfer it out of Europe to a country that has not been the subject of an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA by reference and apply to that transfer, as follows:

  • Module Two (Controller to Processor) applies where you are a Controller of the European Data, and Module Three (Processor to Processor) applies where you are a Processor acting on behalf of a third-party Controller.
  • Clause 7 (docking clause) applies.
  • Under Clause 9 (use of Sub-processors), Option 2 (general written authorisation) applies, with the notice period set out in the 'Sub-Processors' section of this DPA.
  • Under Clause 11 (redress), the optional independent dispute resolution language does not apply.
  • Under Clause 17 (governing law), the Standard Contractual Clauses are governed by the law of Ireland.
  • Under Clause 18 (choice of forum and jurisdiction), disputes will be resolved before the courts of Ireland.
  • Annex I is populated by Annex 1 to this DPA, Annex II by Annex 2 to this DPA, and Annex III by Annex 3 to this DPA.

c. Transfers from the United Kingdom. Where the transfer is subject to UK GDPR, the UK Addendum is incorporated by reference and applies to the Standard Contractual Clauses, with Table 1 populated by Annex 1 to this DPA, Table 2 selecting the Modules and options identified in subsection (b), Table 3 populated by Annexes 1 to 3 to this DPA, and Table 4 providing that neither party may end the Addendum as set out in Section 19 of the Addendum.

d. Transfers from Switzerland. Where the transfer is subject to the Swiss DPA, the Standard Contractual Clauses apply with the following adaptations: references to the GDPR are to the Swiss DPA; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term "member state" does not prevent a data subject in Switzerland from bringing proceedings in Switzerland; and the Standard Contractual Clauses also protect the data of legal entities until the Swiss DPA ceases to extend to them.

e. Alternative mechanisms. If we adopt an alternative lawful transfer mechanism recognised under applicable Data Protection Laws, that mechanism will apply instead of, or in addition to, the Standard Contractual Clauses, and we will update this section.

f. Conflict. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

g. Canadian adequacy. Nothing in this section limits any transfer mechanism otherwise available to the parties, including the European Commission's adequacy decision in respect of Canadian organisations subject to the Personal Information Protection and Electronic Documents Act.

7. Demonstration of Compliance

We will make all information reasonably necessary to demonstrate compliance with this DPA available to you and allow for and contribute to audits, including inspections conducted by you or your auditor in order to assess compliance with this DPA, where required by applicable law. You acknowledge and agree that you will exercise your audit rights under this DPA and Clause 8.9 of the Standard Contractual Clauses by instructing us to comply with the audit measures described in this 'Demonstration of Compliance' section. You acknowledge that the Subscription Service is hosted by our hosting Sub-Processors who maintain independently validated security programs (including SOC 2 and ISO 27001). Further, at your written request, we will provide written responses (on a confidential basis) to all reasonable requests for information made by you necessary to confirm our compliance with this DPA, provided that you will not exercise this right more than once per calendar year unless you have reasonable grounds to suspect non-compliance with the DPA.

8. Additional Provisions for California Personal Information

a. Scope. The 'Additional Provisions for California Personal Information' section of the DPA will apply only with respect to California Personal Information.

b. Roles of the Parties. When processing California Personal Information in accordance with your Instructions, the parties acknowledge and agree that you are a Business and we are a Service Provider for the purposes of the CCPA.

c. Responsibilities. We certify that we will Process California Personal Information as a Service Provider strictly for the purpose of performing the Subscription Services under the Agreement (the "Business Purpose") or as otherwise permitted by the CCPA, including as described in the 'Usage Data' section of our Privacy Policy. Further, we certify we i) will not Sell or Share California Personal Information; (ii) will not Process California Personal Information outside the direct business relationship between the parties, unless required by applicable law; and (iii) will not combine the California Personal Information included in Customer Data with personal information that we collect or receive from another source (other than information we receive from another source in connection with our obligations as a Service Provider under the Agreement).

d. Compliance. We will (i) comply with obligations applicable to us as a Service Provider under the CCPA and (ii) provide California Personal Information with the same level of privacy protection as is required by the CCPA. We will notify you if we make a determination that we can no longer meet our obligations as a Service Provider under the CCPA.

e. CCPA Audits. You will have the right to take reasonable and appropriate steps to help ensure that we use California Personal Information in a manner consistent with Customer's obligations under the CCPA. Upon notice, you will have the right to take reasonable and appropriate steps in accordance with the Agreement to stop and remediate unauthorized use of California Personal Information.

f. Not a Sale. The parties acknowledge and agree that the disclosure of California Personal Information by the Customer to InkDesk does not form part of any monetary or other valuable consideration exchanged between the parties.

9. General Provisions

a. Amendments. Notwithstanding anything else to the contrary in the Agreement and without prejudice to the 'Compliance with Instructions' or 'Security' sections of this DPA, we reserve the right to make any updates and changes to this DPA and the terms that apply in the 'Amendment; No Waiver' section of the General Terms will apply.

b. Severability. If any individual provisions of this DPA are determined to be invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.

c. Limitation of Liability. Each party and each of their Affiliates' liability, taken in aggregate, arising out of or related to this DPA (and any other DPAs between the parties) and the Standard Contractual Clauses (where applicable), whether in contract, tort or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in the 'Limitation of Liability' section of the General Terms and any reference in such section to the liability of a party means aggregate liability of that party and all of its Affiliates under the Agreement (including this DPA). For the avoidance of doubt, if InkDesk is not a party to the Agreement, the 'Limitation of Liability' section of the General Terms will apply as between you and InkDesk, and in such respect any references to 'InkDesk', 'we', 'us' or 'our' will include both InkDesk and the InkDesk that is a party to the Agreement. In no event will either party's liability be limited with respect to any individual's data protection rights under this DPA (including the Standard Contractual Clauses) or otherwise.

d. Governing Law. This DPA will be governed by and construed in accordance with the law specified in the 'Contracting Entity; Governing Law; Notice' section of the General Terms, except that (i) the Standard Contractual Clauses are governed by the law specified in the 'Data Transfers' section of this DPA, and (ii) where Data Protection Laws require otherwise, those laws prevail.

10. Parties to this DPA

a. Permitted Affiliates. By signing the Agreement, you enter into this DPA (including, where applicable, the Standard Contractual Clauses) on behalf of yourself and in the name and on behalf of your Permitted Affiliates. For the purposes of this DPA only, and except where indicated otherwise, the terms “Customer”, “you” and “your” will include you and such Permitted Affiliates.

b. Authorization. The legal entity agreeing to this DPA as Customer represents that it is authorized to agree to and enter into this DPA for and on behalf of itself and, as applicable, each of its Permitted Affiliates.

c. Remedies. The parties agree that (i) solely the Customer entity that is the contracting party to the Agreement will exercise any right or seek any remedy any Permitted Affiliate may have under this DPA on behalf of its Affiliates, and (ii) the Customer entity that is the contracting party to the Agreement will exercise any such rights under this DPA not separately for each Permitted Affiliate individually but in a combined manner for itself and all of its Permitted Affiliates together. The Customer entity that is the contracting entity is responsible for coordinating all Instructions, authorizations and communications with us under the DPA and will be entitled to make and receive any communications related to this DPA on behalf of its Permitted Affiliates.

d. Other rights. The parties agree that you will, when reviewing our compliance with this DPA pursuant to the 'Demonstration of Compliance' section, take all reasonable measures to limit any impact on us and our Affiliates by combining several audit requests carried out on behalf of the Customer entity that is the contracting party to the Agreement and all of its Permitted Affiliates in one single audit.

Annex 1 — Details of Processing

A. Parties

Data exporter / Controller: the Customer identified in the InkDesk account, being the artist, studio or other business that subscribes to the Subscription Service. Contact details are those held in the Customer's InkDesk account.

Data importer / Processor: InkDesk Inc. ("InkDesk"), a corporation incorporated under the Canada Business Corporations Act (corporation number 1535227-4), 2144 Glenhampton Road, Oakville, Ontario L6M 3X1, Canada. Contact: [email protected].

B. Subject matter and duration

The subject matter is InkDesk's provision of the Subscription Service to the Customer. Processing continues for the duration of the Subscription Term and for the retention period described in the 'Deletion or Return of Personal Data' section.

C. Nature and purpose of the processing

Hosting, storage, organisation, retrieval, transmission, display and deletion of Customer Data in order to provide the Subscription Service, which includes: client and project record management; appointment scheduling and calendar synchronisation; publication of booking pages and booking forms; sending, receiving and storing communications between the Customer and its clients, including automated and scheduled messages; creation, sending, completion and storage of digital waivers, including electronic signatures and files uploaded with them; storage and display of images and files uploaded by the Customer or its clients; facilitation of deposit and payment requests through a third-party payment processor; automated screening of inbound messages and submissions for spam and abuse; and provision of support to the Customer.

D. Categories of Data Subjects

  • The Customer's personnel — account owners, administrators, artists and other Users.
  • The Customer's clients and prospective clients, including individuals who submit a booking request, visit the Customer's public booking or profile page, receive or complete a waiver, exchange messages with the Customer, or make a payment through the Subscription Service. Most of these individuals have no account with, and no direct relationship to, InkDesk; they interact with the Subscription Service only through the Customer.
  • Any other individual whose information the Customer chooses to enter into the Subscription Service, including a person named in a free-text note, message or booking-form answer written by the Customer or by one of its clients.

E. Categories of Personal Data

  • Identity and contact data — name, email address, phone number, postal address, date of birth.
  • Account data — user identifiers, role within the account, authentication data, preferences and settings.
  • Booking and project data — appointment dates and times, session details, project notes, status, pricing information, booking form responses.
  • Communications data — the content of messages, emails and automated communications between the Customer and its clients, and associated metadata including timestamps and delivery status.
  • Content uploaded by the Customer or its clients — photographs, reference images, artwork, and documents.
  • Waiver data — waiver and consent form responses, electronic signatures, files uploaded as part of signing (which Customers commonly use to collect an image of a government-issued identity document), a snapshot of the signer's name, email address and telephone number taken at submission, and submission metadata comprising the submission timestamp, the IP address the submission was made from, and the browser user-agent string.
  • Payment-related data — deposit and payment amounts, dates, status, refund and dispute records, and payment processor identifiers. InkDesk does not receive or store payment card numbers.
  • Technical and usage data — IP address, device and browser information, log data, and product usage events.

F. Special categories of Personal Data (if any)

The Subscription Service is not designed for or marketed as a tool for processing special-category data. However, where a Customer designs a waiver, consent form or booking form that asks for it, Customer Data may include health-related information (for example allergies, medical conditions, medications, or pregnancy status), images of identity documents, and images of a data subject's body, and an electronic signature. The Customer determines whether to collect such data and is solely responsible for establishing a lawful basis and any additional condition required under Article 9 of the GDPR or equivalent law, and for any applicable restriction under health-privacy or biometric-privacy legislation. InkDesk applies the security measures in Annex 2 to all Customer Data without distinction.

G. Frequency of transfer

Continuous, for the duration of the Subscription Term.

H. Retention

As described in the 'Deletion or Return of Personal Data' section of this DPA.

I. Sub-processors

As listed in Annex 3, for the purposes and durations described there.

J. Competent supervisory authority (for SCC purposes)

Determined in accordance with Clause 13 of the Standard Contractual Clauses, being the supervisory authority of the EEA member state in which the data exporter is established or, where the exporter is not established in the EEA, the supervisory authority of the member state in which its Article 27 representative is established or in which the data subjects are located.

Annex 2 — Security Measures

InkDesk maintains the following technical and organisational measures. We may update them, provided that an update does not materially reduce the protection they provide.

1. Encryption. Personal Data is encrypted in transit over public networks using TLS. Files and attachments stored in our object storage — including images, documents and files uploaded with waiver submissions — are encrypted at rest using AES-256, and the buckets holding them are versioned with public access blocked.

2. Access control. Access to production systems is restricted to per-service roles scoped to the minimum permissions each service requires, using short-lived credentials issued to workloads rather than shared static credentials. Administrative tooling is accessed through federated single sign-on.

2a. Privileged support access. A limited number of authorised personnel can access a Customer's account in order to provide support, investigate an incident, or comply with a legal obligation, including by viewing the account as the Customer sees it. Use of this access is stamped on our application logs for the duration of the session and retained in accordance with our log retention period. Personnel using this access are restricted from making certain changes to Customer configuration while doing so, and product analytics are disabled for the duration.

3. Application-level access control. Within the Subscription Service, access to Customer Data is scoped to the Customer's account and enforced by role-based permissions the Customer configures. Access to particularly sensitive material — including files uploaded with waiver submissions — additionally requires recent re-authentication, and each such access is recorded in an activity log available to the Customer.

4. Authentication. User authentication is handled by a dedicated identity service. Passwords are stored using a modern password-hashing algorithm. Available to Users are: time-based one-time passwords from an authenticator app; single-use backup codes; and sign-in with Google or Apple. Changing security settings requires the highest authentication level the User has enrolled, and privileged actions require re-authentication within a five-minute window.

5. Network and infrastructure security. Production infrastructure runs in a cloud environment with network segmentation, restricted administrative access, and a web application firewall and denial-of-service protection at the network edge.

6. Malware scanning. Files uploaded to the Subscription Service are scanned for malware, and a file is removed when an infection is detected.

7. Logging and monitoring. Application, access and security events are logged and monitored, and error and performance monitoring is in place. Logs are retained for thirty (30) days.

8. Backups and resilience. The production database runs with a standby in a second availability zone and is backed up daily, with point-in-time recovery across a rolling fourteen (14) day window. Object storage is versioned, with non-current versions retained for thirty (30) days.

9. Change management. Changes to production systems are made through version control, are built and checked automatically before merge, and are deployed through an automated pipeline with a rollback path. Database migrations are additionally guarded against schema drift.

10. Personnel. Personnel with access to Personal Data are subject to confidentiality obligations.

11. Vendor management. Sub-processors are assessed before engagement and are bound by written terms imposing data protection obligations no less protective than those in this DPA.

12. Incident response. We maintain automated alerting across our infrastructure, application errors and deployments, routed to on-call channels with documented remediation steps, and we notify affected Customers of Personal Data Breaches in accordance with the 'Personal Data Breaches' section of this DPA.

13. Data segregation. Customer Data is logically segregated by account, and access is enforced at the application layer on every request.

14. Deletion. On deletion of an account, Customer Data is erased from live systems immediately. Copies persist in database backups for the point-in-time recovery window described above, and in any retained snapshots, until those age out.

15. Third-party assurance. Our infrastructure and service providers — including our cloud hosting, network, email delivery, payment and monitoring providers — maintain independently validated security programmes such as SOC 2 and ISO 27001. InkDesk does not itself hold a SOC 2 report or ISO 27001 certification.

Annex 3 — Sub-Processors

The following Sub-Processors process Customer Data in connection with the Subscription Service. We may update this Annex as described in the 'Sub-Processors' section of this DPA. Full contact details for any Sub-Processor listed below, including registered address and data protection contact, are available to Customers on request at [email protected].

Infrastructure and hosting

  • Amazon Web Services, Inc. (United States) — cloud hosting, database, file storage and backups. Processing location: United States.
  • Cloudflare, Inc. (United States) — content delivery, network security, bot and abuse protection. Processing location: global edge network.

Communications

  • Postmark, operated by ActiveCampaign, LLC (United States) — delivery of email sent through the Subscription Service, including messages sent by Customers to their clients. Processes recipient address, message content and delivery metadata. Processing location: United States.
  • 650 Industries, Inc. (Expo) (United States) — delivery of push notifications to the InkDesk mobile applications. Processing location: United States.
  • Meta Platforms Ireland Limited and Meta Platforms, Inc. — delivery and receipt of messages where a Customer connects a WhatsApp Business account to their InkDesk account. Processes message content, sender identifiers and message metadata. Applies only to Customers who connect such an account. Processing locations: Ireland and the United States.

Payments

  • Stripe, Inc. (United States) — processing of deposits and payments collected by Customers from their clients. Processing location: United States.

Product analytics, monitoring and support

  • Amplitude, Inc. (United States) — product usage analytics and session replay. Session replay recordings may capture Customer Data displayed on screen. Processing location: United States.
  • Functional Software, Inc. (Sentry) (United States) — error, crash and performance monitoring; may incidentally capture Customer Data present in an error context. Processing location: United States.
  • Crisp IM SAS (France) — in-app and website support chat, where a Customer contacts support. Receives the Customer's name, email address and support conversation content. Processing location: European Union.
  • Grafana Labs (United States) — application, access and security log storage, retained for thirty (30) days. Logs include recipient email addresses for messages sent through the Subscription Service, and may incidentally contain other Personal Data present in a request context. Processing location: United States.

Content screening

  • OpenAI, L.L.C. (United States) — automated classification of inbound messages and booking submissions for spam and abuse. Processes message content. Contractually restricted from using the content to train its models. Processing location: United States.
  • OOPSpam LLC (United States) — spam detection for inbound submissions. Processes the content of the message. Processing locations: United States (API) and the European Union (log storage). Message content is scored in transit and is not retained by OOPSpam.
  • Anthropic PBC (United States) — automated classification of inbound messages and booking submissions for spam and abuse, and other automated text processing. Processes message content. Contractually restricted from using the content to train its models. Processing location: United States.
  • Mistral AI SAS (France) — extraction of text from documents and images a Customer uploads. Processes the uploaded file, which may include a completed form. Processing location: European Union.

Other product features

  • Google LLC (United States) — address and place lookup (Places API) and, where a Customer connects it, Google Calendar synchronisation. Processing location: United States.

Services that are not Sub-Processors. Some providers we use process only our own business information and not Customer Data — for example our subscription billing provider and our marketing analytics providers. They are described in our Privacy Policy and are not listed here.