Data Processing Addendum

Effective Date: February 23, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Use or other written or electronic agreement between IBOHero ("Processor," "we," "us," or "our") and the customer ("Controller," "Customer," "you," or "your") for the provision of IBOHero services (the "Agreement").

This DPA reflects the parties' agreement with respect to the Processing of Personal Data by IBOHero on behalf of Customer in connection with the Services, in compliance with Applicable Data Protection Law.

1. Definitions

For purposes of this DPA, the following terms shall have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given to them in the Agreement.

"Applicable Data Protection Law"
means all data protection and privacy laws and regulations applicable to the Processing of Personal Data under this DPA, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and any other applicable national or state data protection laws.
"Controller"
means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For purposes of this DPA, the Customer is the Controller with respect to Personal Data submitted to the Services.
"Data Subject"
means an identified or identifiable natural person to whom Personal Data relates.
"Personal Data"
means any information relating to an identified or identifiable natural person that is Processed by IBOHero on behalf of Customer in connection with the Services. This includes "personal information" as defined under CCPA/CPRA.
"Processing" (and "Process")
means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
"Processor"
means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller. For purposes of this DPA, IBOHero acts as Processor with respect to Personal Data submitted by Customer to the Services.
"Subprocessor"
means any third party engaged by IBOHero to Process Personal Data on behalf of Customer in connection with the Services.
"Standard Contractual Clauses" or "SCCs"
means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission, as may be amended or replaced from time to time.

2. Scope and Applicability

This DPA applies to the Processing of Personal Data by IBOHero on behalf of Customer in connection with the Services provided under the Agreement.

This DPA applies where:

  • Customer acts as a Controller of Personal Data and IBOHero Processes such Personal Data on Customer's behalf as a Processor; and
  • Applicable Data Protection Law applies to such Processing of Personal Data.

This DPA does not apply to Personal Data for which IBOHero acts as a Controller, such as Customer account information, billing data, and usage analytics collected for IBOHero's own operational purposes. The Processing of such data is governed by the IBOHero Privacy Policy.

In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail with respect to data protection matters.

3. Roles of the Parties

3.1 Customer as Controller

Customer is the Controller of the Personal Data submitted to the Services. Customer determines the purposes and means of Processing Personal Data and is responsible for:

  • Lawful Basis: Ensuring a valid legal basis for the collection and Processing of Personal Data, including obtaining any necessary consents from Data Subjects
  • Data Subject Rights: Responding to Data Subject requests regarding their Personal Data, with assistance from IBOHero as described in this DPA
  • Compliance: Complying with all Applicable Data Protection Law, including providing appropriate privacy notices to Data Subjects
  • Anti-Spam Compliance: Ensuring compliance with applicable email marketing laws (CAN-SPAM, GDPR, CASL, etc.) when using email features
  • Marketing Lists: Ensuring that all marketing contact lists submitted to the Services contain only individuals who have provided appropriate consent or for whom Customer has another lawful basis

3.2 IBOHero as Processor

IBOHero acts as a Processor of Personal Data submitted by Customer to the Services. IBOHero shall Process Personal Data only in accordance with Customer's documented instructions as described in this DPA and the Agreement.

CCPA/CPRA Service Provider Status: To the extent IBOHero Processes Personal Data subject to CCPA/CPRA, IBOHero acts as a "Service Provider" as defined in CCPA/CPRA. IBOHero shall not sell or share Personal Data, retain, use, or disclose Personal Data for any purpose other than performing the Services, or combine Personal Data with other data except as permitted by CCPA/CPRA.

4. Subject Matter and Duration of Processing

4.1 Subject Matter

The subject matter of Processing under this DPA is the provision of the IBOHero Services to Customer, including AI-powered content creation, email marketing tools, landing page hosting, and related features as described in the Agreement.

4.2 Duration

IBOHero shall Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing or required by Applicable Data Protection Law. Upon termination of the Agreement, IBOHero shall cease Processing and handle Personal Data as described in Section 14 (Data Retention and Deletion).

5. Nature and Purpose of Processing

IBOHero Processes Personal Data for the following purposes in connection with providing the Services:

5.1 Hosting User-Generated Content

Processing Personal Data contained in content created, uploaded, or published by Customer through the Services, including blog posts, profile information, product descriptions, and other marketing materials.

5.2 Sending Outbound Email

Processing contact information and email addresses to send transactional emails, newsletters, and marketing campaigns on Customer's behalf. Email delivery is facilitated through cloud email infrastructure providers.

5.3 Processing Inbound Email Replies

Receiving and Processing inbound email replies to facilitate communication between Customer and their audience, including storing and displaying such communications within the Services.

5.4 Analytics and Engagement Tracking

Collecting and Processing usage data, engagement metrics, and analytics to provide insights to Customer regarding the performance of their content and campaigns.

5.5 AI Content Generation

Processing data provided by Customer, which may include Personal Data, to generate AI-powered content. This Processing may involve transmitting data to AI service providers acting as Subprocessors. AI Processing is temporary and content generation does not involve permanent storage of Personal Data by AI providers beyond what is necessary to generate the requested output.

5.6 Security and Abuse Prevention

Processing Personal Data as necessary to maintain the security, integrity, and availability of the Services, detect and prevent fraud, abuse, spam, and other harmful activities.

6. Categories of Data Subjects

Personal Data Processed under this DPA may relate to the following categories of Data Subjects:

  • IBO Account Holders: Customer's authorized users who access and use the Services, including their account and profile information
  • Marketing Recipients: Individuals on Customer's marketing contact lists who receive email communications sent through the Services
  • End Users: Individuals who interact with Customer's content published through the Services, such as blog readers and landing page visitors
  • Contacts and Leads: Individuals whose contact information Customer stores or manages within the Services

7. Categories of Personal Data

IBOHero may Process the following categories of Personal Data on behalf of Customer:

  • Contact Information: Names, email addresses, phone numbers, mailing addresses, and other contact details
  • Email Addresses: Subscriber email addresses for marketing communications and transactional notifications
  • IP Addresses: IP addresses collected from visitors to Customer's content and email recipients
  • Device Information: Browser type, operating system, device identifiers, and other technical information
  • User-Generated Content: Any Personal Data contained in content created, uploaded, or submitted by Customer, including text, images, and multimedia
  • Social Authentication Identifiers: Unique identifiers and profile information obtained through social login integrations (Facebook, X, Apple, Google, and similar providers)
  • Engagement Data: Email opens, clicks, website visits, and other interaction metrics
  • Communication Content: Content of emails and messages sent or received through the Services

Customer shall not submit Sensitive Personal Data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data) to the Services unless expressly agreed in writing.

8. Processor Obligations

8.1 Processing on Documented Instructions

IBOHero shall Process Personal Data only on documented instructions from Customer, including the instructions specified in this DPA and the Agreement, unless Processing is required by Applicable Data Protection Law. In such case, IBOHero shall inform Customer of the legal requirement before Processing, unless prohibited by law.

IBOHero shall immediately inform Customer if, in IBOHero's opinion, an instruction from Customer infringes Applicable Data Protection Law.

8.2 Confidentiality

IBOHero shall ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. IBOHero shall ensure that access to Personal Data is limited to personnel who require access to perform the Services.

8.3 Technical and Organizational Measures

IBOHero shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage. These measures are described in Annex II of this DPA.

8.4 Security Controls

IBOHero shall maintain security controls appropriate to the nature, scope, context, and purposes of Processing, including:

  • Encryption of Personal Data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and vulnerability testing
  • Incident response and business continuity procedures
  • Employee training on data protection and security

8.5 Assistance with Data Subject Requests

Taking into account the nature of the Processing, IBOHero shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

8.6 Assistance with Compliance Obligations

IBOHero shall assist Customer in ensuring compliance with Customer's obligations under Applicable Data Protection Law regarding security, data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of Processing and the information available to IBOHero.

9. Subprocessors

9.1 Authorization to Use Subprocessors

Customer provides general authorization for IBOHero to engage Subprocessors to Process Personal Data in connection with the Services, subject to the requirements of this Section 9.

9.2 Current Subprocessors

IBOHero uses the following categories of Subprocessors to provide the Services:

  • Cloud Infrastructure Providers: Including Amazon Web Services (AWS) for hosting, storage (S3), computing (Lambda), database (DynamoDB), and related infrastructure services
  • Email Infrastructure: Including Amazon Simple Email Service (SES) for email delivery and processing
  • AI Service Providers: Third-party providers of large language models and AI services used for content generation features
  • Analytics Providers: Services used to collect and analyze usage data and engagement metrics
  • Authentication Providers: OAuth and social login providers (Facebook, X, Apple, Google, and similar services) for user authentication
  • Payment Processors: Third-party payment services for subscription billing

A current list of Subprocessors is available upon request. IBOHero maintains appropriate data processing agreements with all Subprocessors.

9.3 Subprocessor Obligations

IBOHero shall impose data protection obligations on Subprocessors that are substantially similar to those imposed on IBOHero under this DPA. IBOHero shall remain liable to Customer for the performance of its Subprocessors.

9.4 Changes to Subprocessors

IBOHero shall notify Customer of any intended changes to Subprocessors, including additions or replacements, by updating the Subprocessor list and providing notice through the Services or by email. Customer may object to the use of a new Subprocessor by providing written notice within fourteen (14) days of receiving notice.

If Customer objects to a new Subprocessor based on reasonable data protection concerns, the parties shall work in good faith to resolve the objection. If no resolution is reached, Customer may terminate the affected Services without penalty.

10. International Data Transfers

10.1 Transfer Mechanisms

IBOHero may transfer Personal Data to countries outside the European Economic Area ("EEA"), United Kingdom, or Switzerland in connection with providing the Services. Such transfers shall be made in compliance with Applicable Data Protection Law using appropriate safeguards.

10.2 Standard Contractual Clauses

For transfers of Personal Data from the EEA to countries not recognized as providing an adequate level of data protection, the parties agree that the Standard Contractual Clauses (Module Two: Controller to Processor) adopted by the European Commission shall apply. By entering into this DPA, the parties are deemed to have executed the SCCs.

For the purposes of the SCCs:

  • Customer is the "data exporter" and IBOHero is the "data importer"
  • The details of Processing are as set forth in Annex I of this DPA
  • The technical and organizational measures are as set forth in Annex II
  • The competent supervisory authority shall be determined in accordance with Clause 13 of the SCCs

10.3 UK International Data Transfer Addendum

For transfers of Personal Data from the United Kingdom to countries not recognized as providing an adequate level of data protection, the UK International Data Transfer Addendum to the EU SCCs ("UK Addendum") issued by the UK Information Commissioner's Office shall apply to the extent required by UK GDPR.

10.4 Additional Transfer Safeguards

IBOHero shall implement supplementary measures as necessary to ensure that the level of protection required by Applicable Data Protection Law is maintained for international transfers, taking into account the legal framework of the destination country.

11. Data Security Measures

IBOHero implements and maintains comprehensive technical and organizational security measures to protect Personal Data. Key security measures include:

11.1 Encryption

  • Encryption in Transit: All data transmitted between Customer systems and IBOHero infrastructure is encrypted using TLS 1.2 or higher
  • Encryption at Rest: Personal Data stored in databases and storage systems is encrypted using industry-standard encryption algorithms

11.2 Access Controls

  • Role-based access control (RBAC) limiting access to Personal Data
  • Multi-factor authentication for administrative access
  • Regular access reviews and prompt deprovisioning

11.3 Logging and Monitoring

  • Comprehensive logging of access to Personal Data
  • Real-time monitoring for security events and anomalies
  • Intrusion detection and prevention systems

11.4 Least Privilege Access

IBOHero implements the principle of least privilege, ensuring that personnel have access only to the Personal Data and systems necessary to perform their job functions.

11.5 Multi-Tenant Isolation

IBOHero maintains logical separation of Customer data in our multi-tenant architecture. Data belonging to different Customers is isolated through access controls, database-level segregation, and application-level security measures.

Detailed technical and organizational measures are set forth in Annex II of this DPA.

12. Data Breach Notification

12.1 Notification to Customer

IBOHero shall notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data Processed on behalf of Customer. Notification shall be made to Customer's designated contact within seventy-two (72) hours where feasible.

12.2 Content of Notification

The notification shall include, to the extent known:

  • A description of the nature of the breach, including categories and approximate number of Data Subjects and records affected
  • The name and contact details of IBOHero's point of contact
  • A description of the likely consequences of the breach
  • A description of measures taken or proposed to address the breach and mitigate its effects

12.3 Cooperation

IBOHero shall cooperate with Customer and provide reasonable assistance in investigating and mitigating the breach, including assistance with any notifications to supervisory authorities or Data Subjects that Customer is required to make.

12.4 Documentation

IBOHero shall document all Personal Data breaches, including the facts surrounding the breach, its effects, and remedial actions taken.

13. Data Subject Rights Assistance

IBOHero shall assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law, including:

  • Right of access to Personal Data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of Processing
  • Right to data portability
  • Right to object to Processing
  • Rights related to automated decision-making

13.1 Forwarding Requests

If IBOHero receives a request directly from a Data Subject regarding Personal Data Processed on behalf of Customer, IBOHero shall promptly forward the request to Customer and shall not respond directly unless authorized by Customer or required by law.

13.2 Technical Assistance

IBOHero provides functionality within the Services to enable Customer to access, export, correct, and delete Personal Data. IBOHero shall provide additional reasonable assistance upon Customer's request.

14. Data Retention and Deletion

14.1 Retention During Agreement

IBOHero shall retain Personal Data only for as long as necessary to provide the Services and in accordance with Customer's instructions.

14.2 Deletion Upon Termination

Upon termination of the Agreement, IBOHero shall, at Customer's choice:

  • Return all Personal Data to Customer in a commonly used, machine-readable format; or
  • Delete all Personal Data and certify such deletion in writing

Customer must make this election within thirty (30) days of termination. If no election is made, IBOHero shall delete the Personal Data.

14.3 Exceptions

IBOHero may retain Personal Data to the extent required by Applicable Data Protection Law, in which case IBOHero shall protect the confidentiality of such data and Process it only as required by law. IBOHero may also retain Personal Data in encrypted backups for a reasonable period as part of its disaster recovery procedures.

15. Audit Rights

15.1 Audit Information

IBOHero shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.

15.2 Audit Process

Audits shall be conducted subject to the following conditions:

  • Customer shall provide reasonable advance notice of at least thirty (30) days
  • Audits shall be conducted during normal business hours and in a manner that minimizes disruption
  • Customer shall bear the costs of the audit unless the audit reveals material non-compliance
  • Auditors must execute appropriate confidentiality agreements
  • Audits shall not compromise the security or confidentiality of other customers' data

15.3 Third-Party Certifications

IBOHero may satisfy audit requirements by providing Customer with relevant third-party certifications, audit reports, or attestations (such as SOC 2 reports) upon request, subject to confidentiality obligations.

16. Limitation of Liability

Each party's liability under this DPA shall be subject to the limitations of liability set forth in the Agreement. Nothing in this DPA shall limit either party's liability for:

  • Death or personal injury caused by negligence
  • Fraud or fraudulent misrepresentation
  • Any liability that cannot be limited or excluded by law

17. Governing Law

This DPA shall be governed by and construed in accordance with the governing law provisions of the Agreement, except where Applicable Data Protection Law requires otherwise. For the purposes of the Standard Contractual Clauses:

  • For EEA data exporters: The SCCs shall be governed by the law of the EU Member State in which the data exporter is established
  • For UK data exporters: The UK Addendum shall be governed by the laws of England and Wales

Annex I – Details of Processing

A. List of Parties

Data Exporter (Controller)Customer, as identified in the Agreement
Data Importer (Processor)IBOHero

B. Description of Processing

Subject MatterProvision of IBOHero SaaS platform services, including AI-powered content creation, email marketing, and web hosting
DurationFor the term of the Agreement between Customer and IBOHero
Nature of ProcessingCollection, storage, organization, retrieval, use, disclosure by transmission, and deletion of Personal Data
Purpose of ProcessingTo provide the Services as described in the Agreement, including hosting content, sending email communications, generating AI content, and providing analytics

C. Categories of Data Subjects

  • Customer's account holders and authorized users
  • Marketing recipients and subscribers
  • End users and visitors to Customer's content
  • Contacts and leads managed by Customer

D. Categories of Personal Data

  • Contact information (names, email addresses, phone numbers)
  • Technical identifiers (IP addresses, device information)
  • User-generated content that may contain Personal Data
  • Social authentication identifiers
  • Engagement and analytics data
  • Communication content

E. Sensitive Data

No sensitive data or special categories of data are intended to be Processed unless expressly agreed in writing.

F. Frequency of Transfer

Continuous, for the duration of the Agreement.

G. Retention Period

Personal Data is retained for the duration of the Agreement and deleted or returned upon termination as described in Section 14.

Annex II – Technical and Organizational Measures

IBOHero implements the following technical and organizational security measures to protect Personal Data:

1. Encryption and Data Protection

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Encryption key management with regular rotation
  • Secure handling of authentication credentials

2. Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication for administrative access
  • Principle of least privilege
  • Regular access reviews and recertification
  • Immediate deprovisioning upon role change or termination

3. Infrastructure Security

  • Cloud infrastructure with enterprise security certifications
  • Network segmentation and firewalls
  • DDoS protection and mitigation
  • Regular vulnerability scanning and penetration testing
  • Secure software development lifecycle

4. Multi-Tenant Isolation

  • Logical data separation between customers
  • Application-level access controls
  • Database-level tenant isolation
  • Isolated storage namespaces

5. Monitoring and Logging

  • Centralized logging of security events
  • Real-time alerting for suspicious activity
  • Log retention for security analysis
  • Regular log reviews

6. Incident Response

  • Documented incident response procedures
  • Designated incident response team
  • Regular incident response testing
  • Post-incident analysis and improvement

7. Business Continuity

  • Regular data backups with encryption
  • Geographically distributed infrastructure
  • Disaster recovery procedures
  • Service availability monitoring

8. Personnel Security

  • Background checks for employees with data access
  • Confidentiality agreements
  • Regular security awareness training
  • Data protection training

9. Vendor Management

  • Security assessment of Subprocessors
  • Contractual security requirements
  • Ongoing monitoring of Subprocessor compliance

Contact Information

For questions or concerns regarding this Data Processing Addendum, please contact us:

IBOHero – Data Protection

Email: info@ibohero.ai

Website: https://ibohero.ai