Data Processing Addendum
Last updated: July 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”, the “Controller”) and InBio, Inc., a Delaware corporation doing business as “ComBase” (“InBio”, “Processor”, “we”). It applies where we process personal data on Customer’s behalf in providing the ComBase service (the “Service”). If there’s a conflict between this DPA and the Terms on the subject of data protection, this DPA controls.
1. Roles and scope
For community content and member data, the Customer is the controller and InBio is the processor, processing that data only to provide the Service and on the Customer’s documented instructions (including as set out in the Terms and this DPA). InBio acts as an independent controller only for its own account, billing and marketing-site data, which is covered by our Privacy Policy.
2. Our obligations as processor
- Process personal data only on the Customer’s documented instructions, unless required by law.
- Ensure people authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Annex B).
- Assist the Customer, taking into account the nature of processing, with security, breach notification, data-protection impact assessments, and responding to data-subject requests.
- Not sell personal data and not use community content to train AI models.
3. Subprocessors
The Customer authorises InBio to engage the subprocessors listed in Annex A. We impose data-protection obligations on each subprocessor no less protective than those in this DPA, and we remain responsible for their performance. We will give the Customer at least 30 days’ notice (by email and/or by updating this page) before adding or replacing a subprocessor, during which the Customer may object on reasonable data-protection grounds; if we can’t resolve the objection, the Customer may terminate the affected part of the Service.
4. International transfers
Where processing involves transferring personal data out of the EEA, UK or Switzerland to a country without an adequacy decision, the parties rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum / Swiss amendments where applicable), which are incorporated by reference and completed with the details in the Annexes.
5. Data-subject requests
Taking into account the nature of the processing, we will assist the Customer with appropriate technical and organisational measures — including the export, correction and deletion tools in the Service — to respond to requests from data subjects to exercise their rights. If we receive such a request directly, we’ll forward it to the Customer rather than respond ourselves, unless legally required.
6. Personal-data breach notification
We will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal-data breach affecting the Customer’s data, with the information the Customer reasonably needs to meet its own notification obligations, and we’ll keep the Customer updated as we investigate and remediate.
7. Return and deletion of data
On termination, the Customer can export its data during the export window described in the Terms. After that window, we delete or return the personal data and delete existing copies, except where retention is required by law; deleted data is removed from active systems and aged out of backups within 30 days.
8. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits — which may be satisfied by up-to-date third-party reports or security documentation where available.
9. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
Annex A — Subprocessors
- Cloudflare, Inc. — hosting, CDN, object storage, security · United States / global edge.
- Stripe, Inc. — payment processing · United States.
- Functional Software, Inc. (Sentry) — error & performance monitoring · United States.
- Resend — transactional email · United States.
Annex B — Security measures
- Encryption of data in transit (TLS) and at rest.
- Logical tenant separation between communities.
- Role-based access controls and least-privilege access to production.
- Regular backups, with a documented retention and restoration process.
- Logging and monitoring; error and security alerting.
- A documented incident-response process and vulnerability-disclosure contact ([email protected]).
- Production data is not used for development or testing.
Signing this DPA
This page is our standard DPA and applies to all customers. Business customers who need a countersigned copy for their records can request one at [email protected]. Contact: InBio, Inc. (d/b/a ComBase), 1111B S Governors Ave STE 39177, Dover, DE 19904, USA.