Effective Date: February 23, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Use or other written or electronic agreement between IBOHero ("Processor," "we," "us," or "our") and the customer ("Controller," "Customer," "you," or "your") for the provision of IBOHero services (the "Agreement").
This DPA reflects the parties' agreement with respect to the Processing of Personal Data by IBOHero on behalf of Customer in connection with the Services, in compliance with Applicable Data Protection Law.
For purposes of this DPA, the following terms shall have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given to them in the Agreement.
This DPA applies to the Processing of Personal Data by IBOHero on behalf of Customer in connection with the Services provided under the Agreement.
This DPA applies where:
This DPA does not apply to Personal Data for which IBOHero acts as a Controller, such as Customer account information, billing data, and usage analytics collected for IBOHero's own operational purposes. The Processing of such data is governed by the IBOHero Privacy Policy.
In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail with respect to data protection matters.
Customer is the Controller of the Personal Data submitted to the Services. Customer determines the purposes and means of Processing Personal Data and is responsible for:
IBOHero acts as a Processor of Personal Data submitted by Customer to the Services. IBOHero shall Process Personal Data only in accordance with Customer's documented instructions as described in this DPA and the Agreement.
CCPA/CPRA Service Provider Status: To the extent IBOHero Processes Personal Data subject to CCPA/CPRA, IBOHero acts as a "Service Provider" as defined in CCPA/CPRA. IBOHero shall not sell or share Personal Data, retain, use, or disclose Personal Data for any purpose other than performing the Services, or combine Personal Data with other data except as permitted by CCPA/CPRA.
The subject matter of Processing under this DPA is the provision of the IBOHero Services to Customer, including AI-powered content creation, email marketing tools, landing page hosting, and related features as described in the Agreement.
IBOHero shall Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing or required by Applicable Data Protection Law. Upon termination of the Agreement, IBOHero shall cease Processing and handle Personal Data as described in Section 14 (Data Retention and Deletion).
IBOHero Processes Personal Data for the following purposes in connection with providing the Services:
Processing Personal Data contained in content created, uploaded, or published by Customer through the Services, including blog posts, profile information, product descriptions, and other marketing materials.
Processing contact information and email addresses to send transactional emails, newsletters, and marketing campaigns on Customer's behalf. Email delivery is facilitated through cloud email infrastructure providers.
Receiving and Processing inbound email replies to facilitate communication between Customer and their audience, including storing and displaying such communications within the Services.
Collecting and Processing usage data, engagement metrics, and analytics to provide insights to Customer regarding the performance of their content and campaigns.
Processing data provided by Customer, which may include Personal Data, to generate AI-powered content. This Processing may involve transmitting data to AI service providers acting as Subprocessors. AI Processing is temporary and content generation does not involve permanent storage of Personal Data by AI providers beyond what is necessary to generate the requested output.
Processing Personal Data as necessary to maintain the security, integrity, and availability of the Services, detect and prevent fraud, abuse, spam, and other harmful activities.
Personal Data Processed under this DPA may relate to the following categories of Data Subjects:
IBOHero may Process the following categories of Personal Data on behalf of Customer:
Customer shall not submit Sensitive Personal Data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data) to the Services unless expressly agreed in writing.
IBOHero shall Process Personal Data only on documented instructions from Customer, including the instructions specified in this DPA and the Agreement, unless Processing is required by Applicable Data Protection Law. In such case, IBOHero shall inform Customer of the legal requirement before Processing, unless prohibited by law.
IBOHero shall immediately inform Customer if, in IBOHero's opinion, an instruction from Customer infringes Applicable Data Protection Law.
IBOHero shall ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. IBOHero shall ensure that access to Personal Data is limited to personnel who require access to perform the Services.
IBOHero shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage. These measures are described in Annex II of this DPA.
IBOHero shall maintain security controls appropriate to the nature, scope, context, and purposes of Processing, including:
Taking into account the nature of the Processing, IBOHero shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
IBOHero shall assist Customer in ensuring compliance with Customer's obligations under Applicable Data Protection Law regarding security, data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of Processing and the information available to IBOHero.
Customer provides general authorization for IBOHero to engage Subprocessors to Process Personal Data in connection with the Services, subject to the requirements of this Section 9.
IBOHero uses the following categories of Subprocessors to provide the Services:
A current list of Subprocessors is available upon request. IBOHero maintains appropriate data processing agreements with all Subprocessors.
IBOHero shall impose data protection obligations on Subprocessors that are substantially similar to those imposed on IBOHero under this DPA. IBOHero shall remain liable to Customer for the performance of its Subprocessors.
IBOHero shall notify Customer of any intended changes to Subprocessors, including additions or replacements, by updating the Subprocessor list and providing notice through the Services or by email. Customer may object to the use of a new Subprocessor by providing written notice within fourteen (14) days of receiving notice.
If Customer objects to a new Subprocessor based on reasonable data protection concerns, the parties shall work in good faith to resolve the objection. If no resolution is reached, Customer may terminate the affected Services without penalty.
IBOHero may transfer Personal Data to countries outside the European Economic Area ("EEA"), United Kingdom, or Switzerland in connection with providing the Services. Such transfers shall be made in compliance with Applicable Data Protection Law using appropriate safeguards.
For transfers of Personal Data from the EEA to countries not recognized as providing an adequate level of data protection, the parties agree that the Standard Contractual Clauses (Module Two: Controller to Processor) adopted by the European Commission shall apply. By entering into this DPA, the parties are deemed to have executed the SCCs.
For the purposes of the SCCs:
For transfers of Personal Data from the United Kingdom to countries not recognized as providing an adequate level of data protection, the UK International Data Transfer Addendum to the EU SCCs ("UK Addendum") issued by the UK Information Commissioner's Office shall apply to the extent required by UK GDPR.
IBOHero shall implement supplementary measures as necessary to ensure that the level of protection required by Applicable Data Protection Law is maintained for international transfers, taking into account the legal framework of the destination country.
IBOHero implements and maintains comprehensive technical and organizational security measures to protect Personal Data. Key security measures include:
IBOHero implements the principle of least privilege, ensuring that personnel have access only to the Personal Data and systems necessary to perform their job functions.
IBOHero maintains logical separation of Customer data in our multi-tenant architecture. Data belonging to different Customers is isolated through access controls, database-level segregation, and application-level security measures.
Detailed technical and organizational measures are set forth in Annex II of this DPA.
IBOHero shall notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data Processed on behalf of Customer. Notification shall be made to Customer's designated contact within seventy-two (72) hours where feasible.
The notification shall include, to the extent known:
IBOHero shall cooperate with Customer and provide reasonable assistance in investigating and mitigating the breach, including assistance with any notifications to supervisory authorities or Data Subjects that Customer is required to make.
IBOHero shall document all Personal Data breaches, including the facts surrounding the breach, its effects, and remedial actions taken.
IBOHero shall assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law, including:
If IBOHero receives a request directly from a Data Subject regarding Personal Data Processed on behalf of Customer, IBOHero shall promptly forward the request to Customer and shall not respond directly unless authorized by Customer or required by law.
IBOHero provides functionality within the Services to enable Customer to access, export, correct, and delete Personal Data. IBOHero shall provide additional reasonable assistance upon Customer's request.
IBOHero shall retain Personal Data only for as long as necessary to provide the Services and in accordance with Customer's instructions.
Upon termination of the Agreement, IBOHero shall, at Customer's choice:
Customer must make this election within thirty (30) days of termination. If no election is made, IBOHero shall delete the Personal Data.
IBOHero may retain Personal Data to the extent required by Applicable Data Protection Law, in which case IBOHero shall protect the confidentiality of such data and Process it only as required by law. IBOHero may also retain Personal Data in encrypted backups for a reasonable period as part of its disaster recovery procedures.
IBOHero shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
Audits shall be conducted subject to the following conditions:
IBOHero may satisfy audit requirements by providing Customer with relevant third-party certifications, audit reports, or attestations (such as SOC 2 reports) upon request, subject to confidentiality obligations.
Each party's liability under this DPA shall be subject to the limitations of liability set forth in the Agreement. Nothing in this DPA shall limit either party's liability for:
This DPA shall be governed by and construed in accordance with the governing law provisions of the Agreement, except where Applicable Data Protection Law requires otherwise. For the purposes of the Standard Contractual Clauses:
| Data Exporter (Controller) | Customer, as identified in the Agreement |
|---|---|
| Data Importer (Processor) | IBOHero |
| Subject Matter | Provision of IBOHero SaaS platform services, including AI-powered content creation, email marketing, and web hosting |
|---|---|
| Duration | For the term of the Agreement between Customer and IBOHero |
| Nature of Processing | Collection, storage, organization, retrieval, use, disclosure by transmission, and deletion of Personal Data |
| Purpose of Processing | To provide the Services as described in the Agreement, including hosting content, sending email communications, generating AI content, and providing analytics |
No sensitive data or special categories of data are intended to be Processed unless expressly agreed in writing.
Continuous, for the duration of the Agreement.
Personal Data is retained for the duration of the Agreement and deleted or returned upon termination as described in Section 14.
IBOHero implements the following technical and organizational security measures to protect Personal Data:
For questions or concerns regarding this Data Processing Addendum, please contact us: