Indent Data Processing Addendum
Last updated: September 2026
This Data Processing Addendum ("DPA") forms part of the agreement that incorporates it between Minimal Surface, Inc. ("Company") and Customer (the "Agreement"). This DPA applies only to the extent Data Protection Laws apply to Company's Processing of Personal Data in Customer Content as a Processor on Customer's behalf in connection with the Services.
1. Definitions
1.1. "Data Protection Laws" means all data protection and privacy laws applicable to a party's Processing under this DPA, including, where applicable, the California Consumer Privacy Act of 2018, as amended ("CCPA"), the EU General Data Protection Regulation 2016/679 ("EU GDPR"), and the EU GDPR as incorporated into United Kingdom law ("UK GDPR").
1.2. "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Company or a Subprocessor.
1.3. "EU SCCs" means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.4. "Personal Data" means information relating to an identified or identifiable natural person that is included in Customer Content and Processed by Company on Customer's behalf under the Agreement.
1.5. "Services" means the cloud services described in the Agreement, including Indent's AI agent platform and its software-engineering, data-analysis, integration, and collaboration features.
1.6. "Subprocessor" means a third party appointed by or on behalf of Company to Process Personal Data in connection with the Services.
1.7. "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner's Office and laid before Parliament in accordance with the UK Data Protection Act 2018.
1.8. "Controller," "Data Subject," "Process," "Processed," "Processing," and "Processor" have the meanings given under applicable Data Protection Laws. Other capitalized terms not defined in this DPA have the meanings given in the Agreement.
2. Scope and Order of Precedence
2.1. This DPA applies only to Company's Processing of Personal Data as a Processor on Customer's behalf that is subject to Data Protection Laws. If Customer is a Processor of that Personal Data, Company is Customer's Subprocessor.
2.2. If this DPA conflicts with the Agreement, this DPA controls with respect to the Processing of Personal Data. If the EU SCCs or UK Addendum conflict with this DPA or the Agreement, the EU SCCs or UK Addendum, as applicable, control.
2.3. Claims under this DPA remain subject to the exclusions and limitations of liability in the Agreement unless applicable Data Protection Laws prohibit that limitation.
3. Processing Instructions and Restrictions
3.1. Company will Process Personal Data only to provide, secure, support, maintain, develop, and improve the Services; comply with Customer's documented lawful instructions; and comply with applicable law. The Agreement and Customer's use and configuration of the Services constitute Customer's documented instructions.
3.2. If Company is required by law to Process Personal Data for another purpose, Company will inform Customer before that Processing unless the law prohibits notice. Company will promptly inform Customer if, in Company's reasonable opinion, an instruction infringes Data Protection Laws.
3.3. To the extent the CCPA applies to Customer's disclosure of Personal Data to Company, Company acts as Customer's service provider or contractor, and the following terms apply:
- The limited and specified purposes for Company's Processing are the purposes described in Section 3.1 and Appendix 1, in each case with respect to the Services provided to Customer under the Agreement.
- Company will comply with applicable obligations under the CCPA and provide the same level of privacy protection for Personal Data as required by the CCPA.
- Company will not sell or share Personal Data as those terms are defined by the CCPA.
- Company will not retain, use, or disclose Personal Data outside the direct business relationship between Company and Customer or for a commercial purpose other than the limited and specified purposes described above, except as permitted by the CCPA.
- Company will not combine Personal Data with personal information received from another person or collected from Company's own interaction with a Data Subject except as permitted by the CCPA.
- Company will notify Customer if Company determines that it can no longer meet its obligations under the CCPA.
- Customer may take reasonable and appropriate steps, including through Section 10, to help ensure that Company uses Personal Data consistently with Customer's obligations under the CCPA. Upon notice, including notice under the preceding paragraph, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
Company certifies that it understands and will comply with these restrictions.
3.4. Customer is responsible for the lawfulness of its instructions and for providing all notices and obtaining all rights and lawful bases necessary for Company to Process Personal Data under the Agreement. Customer will not provide Personal Data prohibited by the Agreement unless the parties expressly authorize it in writing.
4. Details of Processing
4.1. The subject matter, nature, purpose, and duration of Processing, categories of Data Subjects, and types of Personal Data are described in Appendix 1.
4.2. Company will ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
5. Security
5.1. Company will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures in effect as of the effective date of this DPA are described in Appendix 2.
5.2. Customer is responsible for using the Services securely, including protecting account credentials, configuring integrations and permissions, and making appropriate backups of Customer Content where the Services permit.
6. Data Breach Response
6.1. Company will notify Customer without undue delay after becoming aware of a Data Breach affecting Customer's Personal Data.
6.2. Taking into account the nature of Processing and the information available to Company, Company will provide timely information reasonably requested by Customer to meet Customer's applicable breach-notification obligations. Company will take reasonable steps to identify and remediate the cause of the Data Breach.
6.3. Company's notice or response to a Data Breach is not an acknowledgment of fault or liability.
7. Subprocessing
7.1. Customer generally authorizes Company to engage Subprocessors. Company's current Subprocessor list is available upon written request to privacy@indent.com.
7.2. Company will enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective in all material respects than those in this DPA to the extent applicable to the Subprocessor's services. Company remains responsible for each Subprocessor's performance of those obligations to the extent required by Data Protection Laws.
7.3. Where applicable Data Protection Laws require notice of Subprocessor changes or an opportunity to object, Company will provide that notice or opportunity as required.
8. Assistance
8.1. Taking into account the nature of Processing, Company will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to requests from Data Subjects exercising rights under Data Protection Laws. If Company receives a request relating to Customer's Personal Data, Company will promptly notify Customer and will not respond except on Customer's documented instructions or as required by law.
8.2. To the extent Customer has obligations under applicable Data Protection Laws concerning security, Data Breaches, data-protection impact assessments, or prior consultations with supervisory authorities, and taking into account the nature of Processing and the information available to Company, Company will provide reasonable assistance with those obligations.
8.3. To the extent required by applicable Data Protection Laws, if a regulator or other authority contacts Company about Customer's Personal Data, Company will notify Customer and provide a copy of the request unless prohibited by law. Company will not respond on Customer's behalf without Customer's authorization unless required by law.
9. Return and Deletion
9.1. If and to the extent required by applicable Data Protection Laws, Company will, upon expiration or termination of the Agreement and at Customer's election, delete or return Personal Data in its possession or control, unless applicable law requires retention or return is not reasonably feasible. When this Section 9.1 applies, Customer must make its election before termination or expiration; otherwise, Company may delete the Personal Data.
9.2. Section 9.1 does not require Company to alter archival backups maintained in accordance with its standard backup and continuity procedures. Until deleted in the ordinary course, Personal Data retained in backups will remain protected under this DPA and will not be actively Processed except for restoration, security, legal compliance, or continuity purposes.
10. Audits and Information
10.1. To the extent required by applicable Data Protection Laws or the EU SCCs, upon Customer's reasonable written request, Company will provide information necessary to demonstrate compliance with this DPA. Company may satisfy this obligation by providing then-current third-party audit reports, certifications, security summaries, penetration-test summaries, or other relevant documentation on a confidential basis.
10.2. Company is not required to disclose information that would compromise another customer's security or privacy, Company's security, privileged information, or Company trade secrets. Nothing in this Section limits an audit right that cannot be restricted under applicable Data Protection Laws or the EU SCCs.
11. International Transfers
11.1. Company and its Subprocessors may Process Personal Data in any country where they operate, subject to the safeguards required by Data Protection Laws.
11.2. If Customer transfers Personal Data protected by the EU GDPR to Company in a country that is not subject to an applicable adequacy decision and the transfer is not otherwise lawfully supported, the EU SCCs are incorporated into this DPA as follows:
- Module 2 applies where Customer is a Controller and Company is a Processor. Module 3 applies where Customer is a Processor and Company is a Subprocessor.
- Clause 7 (Docking Clause) applies.
- In Clause 9, Option 2 applies and Company will provide notice of additions or replacements of Subprocessors a reasonable period in advance.
- The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland.
- In Clause 18(b), disputes will be resolved by the courts of Ireland.
- Annexes I, II, and III are completed with the information in Appendices 1, 2, and 3 of this DPA, respectively. The competent supervisory authority is determined under Clause 13.
11.3. For transfers subject to the UK GDPR, the EU SCCs as completed by Section 11.2 apply as modified by the UK Addendum, which is incorporated into this DPA. Tables 1 through 3 of the UK Addendum are completed using the parties' information and the selections and appendices in this DPA. For Table 4, either party may end the UK Addendum as permitted by Section 19 of the UK Addendum.
11.4. For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with references to the EU GDPR understood to include that Act as applicable; references to Member State law understood to include Swiss law; the competent supervisory authority being the Swiss Federal Data Protection and Information Commissioner; and the term "Member State" not excluding Swiss Data Subjects from enforcing their rights in Switzerland.
11.5. To the extent required by applicable Data Protection Laws, if a transfer mechanism in this Section is invalidated or replaced, the parties will cooperate to implement a lawful alternative, and Company will provide information required for Customer to assess transfers covered by this Section.
12. Government Requests
If a law-enforcement or governmental authority requests Personal Data, Company may attempt to redirect the authority to Customer. If Company is legally compelled to disclose Personal Data, Company will give Customer reasonable notice and an opportunity to seek a protective order or other remedy unless prohibited by law.
13. Miscellaneous
13.1. This DPA terminates when Company no longer Processes Personal Data, except that provisions that by their nature should survive will remain in effect while Company retains Personal Data.
13.2. Except as required by the EU SCCs, UK Addendum, or applicable Data Protection Laws, no person other than a party to this DPA and its permitted successors and assigns may enforce this DPA.
13.3. Except as otherwise required by the EU SCCs, UK Addendum, or applicable Data Protection Laws, this DPA is governed by the governing law stated in the Agreement.
Appendix 1: Details of Processing
Parties
Data exporter: Customer and its relevant affiliates. Customer's contact information and activities are described in the Agreement. Customer is a Controller or Processor, as determined by its Processing of the Personal Data.
Data importer: Minimal Surface, Inc., reachable at privacy@indent.com. Company provides the Services described in the Agreement and acts as a Processor or Subprocessor.
Subject Matter and Duration
Company Processes Personal Data to provide, secure, support, maintain, develop, and improve the Services during the term of the Agreement and for the limited period afterward described in the Agreement and this DPA.
Nature and Purpose
Processing may include collecting, receiving, recording, organizing, structuring, storing, retrieving, consulting, analyzing, transmitting, generating, making available, securing, supporting, and deleting Personal Data as needed to provide, secure, support, maintain, develop, and improve the Services and carry out Customer's instructions.
Categories of Data Subjects
Data Subjects may include Customer's and its affiliates' employees, contractors, authorized users, customers, prospective customers, business partners, end users, and other individuals whose Personal Data Customer submits to or makes accessible through the Services.
Types of Personal Data
Customer determines the Personal Data submitted to the Services. It may include:
- account, profile, identity, authentication, and contact information;
- communications and collaboration content, including email, calendar, document, chat, issue, code-review, and attachment content;
- source code, repository content, files, database records and query results, prompts, instructions, generated outputs, and session history;
- information accessed through Customer-authorized integrations, systems, and tools;
- device, browser, network, usage, diagnostic, support, and operational metadata; and
- any other Personal Data included by Customer or its users in Customer Content.
Sensitive Data
The Services are not intended for categories of data prohibited by the Agreement. Customer determines whether to submit other sensitive data and is responsible for ensuring that its instructions and use comply with applicable law. The safeguards in Appendix 2 apply to all Personal Data.
Frequency and Retention
Processing may occur continuously or as initiated by Customer and its users. Personal Data is retained for the term of the Agreement and afterward as described in the Agreement, Section 9 of this DPA, and applicable law.
Appendix 2: Technical and Organizational Measures
Company maintains measures appropriate to the nature of the Services and the risks of Processing, including:
- encryption of Personal Data in transit over public networks and encryption at rest for primary production databases, object storage, and stored integration credentials;
- logical access controls designed around least privilege, authentication controls, and periodic access review;
- logical separation of customer data within multi-tenant systems;
- logging, monitoring, and alerting for production systems and security-relevant events;
- secure software-development, code-review, dependency-management, vulnerability-management, and change-control practices;
- incident-response procedures for identifying, investigating, containing, remediating, and communicating security incidents;
- backup, recovery, and business-continuity measures appropriate to the Services;
- confidentiality obligations and security training for personnel with access to Personal Data;
- risk-based review and contractual controls for vendors that Process Personal Data.
Company may update these measures as technology and risks change, provided that Company continues to maintain measures appropriate to the nature of the Services and the risks of Processing.
Appendix 3: Subprocessors
Company's current Subprocessor list is available upon written request to privacy@indent.com. The parties agree that this statement satisfies Annex III of the EU SCCs together with the notices provided under Section 7.