Inqevra AI Legal Center
Business Data Processing Addendum
Baseline data-processing terms for Business and Enterprise customers that use Inqevra AI for organisational work.
- Effective
- 23 September 2026
- Last updated
- 23 September 2026
- Status
- Pre-launch policy
1. Scope and roles
This Addendum applies only when a Business or Enterprise order form or written agreement incorporates it. For personal accounts, Inquev generally determines the purposes of processing and the Privacy Policy applies. For organisational data processed on the customer's documented instructions, the customer acts as controller or equivalent and Inquev acts as processor or service provider to the extent required by applicable law.
2. Customer instructions and responsibilities
- Provide lawful, documented instructions and notices for organisational data submitted to the Service.
- Ensure users have the required permissions and that restricted, highly sensitive, or regulated data is used only with an appropriate written arrangement and enabled feature.
- Respond to data-subject requests, configure retention, and manage workspace membership and access according to your obligations.
- Do not instruct Inquev to process data for unlawful purposes or to bypass safety, security, or provider requirements.
3. Inquev obligations
- Process covered data only to provide, secure, support, and improve the contracted Service as instructed and as required by law.
- Apply reasonable technical and organisational safeguards, access controls, confidentiality obligations, logging, recovery, and incident response.
- Use subprocessors listed in the Subprocessor Notice and impose appropriate contractual obligations on them.
- Assist, where reasonably practicable, with access, correction, deletion, security, and incident-response requests that the customer cannot complete directly.
4. Security incidents
Inquev will notify the customer without undue delay after confirming a security incident affecting covered organisational data, provide reasonably available information about impact and mitigation, and cooperate on lawful notices. Notification does not mean that every unsuccessful probe or blocked request is a personal-data breach.
5. International transfers and provider processing
Providers may process data outside India or the customer's country. The parties will use the contractual, technical, and organisational safeguards required by applicable law. Provider-specific terms, regional availability, and data-residency options may vary by plan and feature.
6. Return, deletion, and audit information
At the end of the applicable subscription or on documented request, Inquev will provide the deletion or export options supported by the Service, subject to backup cycles, security records, payment records, legal holds, and other lawful retention requirements. We will make available reasonable information needed to demonstrate the safeguards described in this Addendum, subject to confidentiality and security limits.
7. Order of precedence
If this Addendum conflicts with the Privacy Policy or Terms of Service for covered organisational processing, this Addendum controls to the extent of the conflict. The order form controls commercial terms. A signed negotiated DPA controls this baseline Addendum.
