Legal
Last updated 8 September 2026
This Data Processing Addendum (“DPA”) applies whenever Inlay processes End-Visitor Personal Data (defined in Section 3) on your behalf as part of the Service, and forms part of the Terms of Service for every Inlay account. It applies automatically from the effective date of your Inlay account — no separate signature is required, in the same way this DPA is pre-accepted the moment you register a site, matching how our own infrastructure sub-processors (Section 6) make their DPAs effective for us.
Nothing in this DPA expands Inlay's liability beyond the limits in Terms §8.
“Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, and “Processing” have the meanings given in the GDPR (EU 2016/679) and, where applicable, the UK GDPR and Swiss FADP (together, “Data Protection Laws”). “End Visitor” means a visitor to your website whose browser loads the Inlay embed script. “Service” means Inlay's ad-serving platform as described in the Terms of Service.
Inlay processes two distinct categories of personal data under two different roles. Conflating them is a common source of confusion, so this section is explicit about which is which.
You (the Publisher) are the Controller for End-Visitor Personal Data: the page URL, a redacted structural snapshot of the page (never its visible text, links, or images — see Privacy Policy §2), the TCF/GPP consent string your CMP reports (if any), and the visitor's IP address as briefly used for rate-limiting. You determine the purposes and means of collecting this data by installing the embed script on your site. Inlay is the Processorfor this data, acting only on your instructions as expressed through the Service's configuration (placements, consent handling, and this DPA) — Inlay does not sell it, use it to build cross-site profiles, or repurpose it for its own advertising.
Inlay is the Controller for your own Account Data — name, email, billing details, payout history, and the sites/placements you configure. That processing is governed by the Privacy Policy, not this DPA.
Demand-side platforms (SSPs) that receive bid-request data during the auction (contextual signals, consent string, and the page URL — see Serve API reference) are independent Controllers for their own processing, not Inlay sub-processors: each selects and prices ads using its own systems, for its own purposes, under its own privacy policy and (where applicable) its own IAB TCF Vendor registration. Inlay is not responsible for an SSP's processing once a bid request has been sent, beyond gating that request on valid consent as described in Section 5.
As Processor for End-Visitor Personal Data, Inlay will:
You give Inlay general authorisation to engage the following sub-processors for End-Visitor Personal Data, each bound by its own data processing agreement incorporating Standard Contractual Clauses (SCCs) for transfers out of the EEA/UK/Switzerland:
Stripe and Resend also appear in our Privacy Policy subprocessor list, but only in Inlay's Controller role (billing and transactional email to you) — they do not process End-Visitor Personal Data and are not sub-processors under this DPA.
Inlay will give notice of a new sub-processor or a change to one above (e.g. via this page or the dashboard) before it begins processing End-Visitor Personal Data, and you may object on reasonable data-protection grounds within 14 days by contacting privacy@useinlay.com; if unresolved, either party may treat that as grounds to terminate the affected part of the Service.
End-Visitor Personal Data from the EEA, UK, or Switzerland may be transferred to and processed in the United States by Inlay and the sub-processors listed in Section 6. Each such transfer relies on Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum) incorporated into Inlay's or the relevant sub-processor's own data processing terms, as the applicable transfer mechanism under Data Protection Laws.
On termination of your Inlay account, Inlay deletes or anonymises End-Visitor Personal Data within the retention windows in Privacy Policy §5, except aggregated records already stripped of identifying fields. On reasonable written request, no more than once per 12 months (or promptly after a confirmed personal data breach affecting your data), Inlay will provide information reasonably necessary to demonstrate compliance with this DPA; on-site audits are available for enterprise plans by mutual written agreement on scope, timing, and confidentiality.
For DPA questions, sub-processor objections, or to request an executed copy for your own records, contact privacy@useinlay.com.