Data Processing Agreement

Last Updated: July 26, 2025

Our DPA explains how IONI acts as a data processor, the security measures we apply, and the rights and responsibilities of our customers as data controllers under GDPR.

1. Subject Matter and Duration

This Data Processing Agreement (“DPA”) is incorporated into the Terms & Conditions between IONI (legal name - Springs LLC) (“Processor”) and any customer using the IONI services (“Controller”).

By using the IONI services, the Controller accepts this DPA, which forms part of the Agreement. This DPA governs the processing of personal data by Processor on behalf of Controller in connection with the IONI SaaS platform. Processing continues for as long as the Agreement is in force.

2. Roles of the Parties

Controller decides the purposes and means of personal data processing.
Processor processes data only on instructions from Controller, unless required by law.

3. Data and Data Subjects

The personal data processed may include:
- Contact details (names, emails, phone numbers);
- Account details (usernames, login credentials);
- Business content and communications uploaded by Controller.

Data subjects may include Controller’s employees, contractors, customers, or other individuals whose data is provided by Controller.

4. Processor Obligations

Processor will:
- process personal data only under Controller’s instructions;
- ensure authorised personnel are bound by confidentiality;
- implement appropriate technical and organisational measures (“TOMs”) for security;
- assist Controller with data subject rights, breach notifications, and DPIAs;
- delete or return personal data upon termination, unless law requires retention;
- provide information to demonstrate compliance and allow for audits.

5. Sub-processors

Controller authorises Processor to use sub-processors listed at Privacy Policy.
Processor will impose equivalent data protection obligations on all sub-processors.
Controller will be notified of changes and may object.

6. International Transfers

If data is transferred outside the EEA/UK, Processor ensures appropriate safeguards like EU Standard Contractual Clauses.

7. Data Subject Rights

Processor shall assist Controller in responding to requests from data subjects under GDPR Articles 15–22.

8. Security and Breach Notification

Processor maintains appropriate TOMs (e.g., encryption, access control, monitoring).In the event of a personal data breach, Processor notifies Controller without undue delay.

9. Audits

Controller may conduct audits or inspections once per year (unless otherwise required).
Compliance may also be demonstrated via independent certifications or audit reports.

10. Liability

Liability follows the limitations set out in the Agreement, except where GDPR requires otherwise.

11. Termination

When the Agreement ends, Processor will delete or return all personal data unless retention is required by law.

12. Governing Law

This DPA is governed by the law and jurisdiction specified in the Agreement.

Annex 1 – Processing Details

- Purpose: Provision of IONI SaaS platform
- Data Types: Contact details, account data, business content
- Data Subjects: Users, employees, contractors, customers
- Duration: For the term of the Agreement

Annex 2 – Technical and Organisational Measures (TOMs)

- Encryption in transit (TLS) and at rest;
- Access controls, strong authentication, role-based permissions;
- Regular backups and secure storage;
- Monitoring, logging, intrusion detection;
- Security awareness training for staffIncident response and breach management procedures

Acceptance

This DPA is pre-signed by IONI (legal name - Springs LLC)
It automatically applies to all Controllers using the Services.
Customers may request a signed PDF copy via sergey@ioni.ai.