Legal

Data Processing Addendum

Last updated 8 September 2026

1. Scope and incorporation

This Data Processing Addendum (“DPA”) applies whenever Inlay processes End-Visitor Personal Data (defined in Section 3) on your behalf as part of the Service, and forms part of the Terms of Service for every Inlay account. It applies automatically from the effective date of your Inlay account — no separate signature is required, in the same way this DPA is pre-accepted the moment you register a site, matching how our own infrastructure sub-processors (Section 6) make their DPAs effective for us.

Nothing in this DPA expands Inlay's liability beyond the limits in Terms §8.

2. Definitions

“Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, and “Processing” have the meanings given in the GDPR (EU 2016/679) and, where applicable, the UK GDPR and Swiss FADP (together, “Data Protection Laws”). “End Visitor” means a visitor to your website whose browser loads the Inlay embed script. “Service” means Inlay's ad-serving platform as described in the Terms of Service.

3. Roles of the parties

Inlay processes two distinct categories of personal data under two different roles. Conflating them is a common source of confusion, so this section is explicit about which is which.

You (the Publisher) are the Controller for End-Visitor Personal Data: the page URL, a redacted structural snapshot of the page (never its visible text, links, or images — see Privacy Policy §2), the TCF/GPP consent string your CMP reports (if any), and the visitor's IP address as briefly used for rate-limiting. You determine the purposes and means of collecting this data by installing the embed script on your site. Inlay is the Processorfor this data, acting only on your instructions as expressed through the Service's configuration (placements, consent handling, and this DPA) — Inlay does not sell it, use it to build cross-site profiles, or repurpose it for its own advertising.

Inlay is the Controller for your own Account Data — name, email, billing details, payout history, and the sites/placements you configure. That processing is governed by the Privacy Policy, not this DPA.

Demand-side platforms (SSPs) that receive bid-request data during the auction (contextual signals, consent string, and the page URL — see Serve API reference) are independent Controllers for their own processing, not Inlay sub-processors: each selects and prices ads using its own systems, for its own purposes, under its own privacy policy and (where applicable) its own IAB TCF Vendor registration. Inlay is not responsible for an SSP's processing once a bid request has been sent, beyond gating that request on valid consent as described in Section 5.

4. Subject matter and details of processing

  • Subject matter: operating the server-side ad auction and generating AI native-ad templates for your site.
  • Duration: for as long as the embed script is active on your site and your Inlay account remains open, plus the deletion window described in Section 8.
  • Nature and purpose: matching an ad to a page, running the programmatic auction, rendering the winning creative, and measuring viewability — see How it works.
  • Categories of data: page URL, redacted page-structure snapshot, contextual metadata (title, keywords, language), TCF/GPP consent signals, and IP address (rate-limiting only — not stored against a persistent visitor identifier).
  • Categories of data subjects: End Visitors to your site.

5. Inlay's obligations

As Processor for End-Visitor Personal Data, Inlay will:

  • Process it only on your documented instructions — as configured through the Service — unless required otherwise by law, and tell you if such a legal requirement prevents Inlay from following an instruction.
  • Gate the auction and all third-party trackers on valid consent for EU/UK/Swiss End Visitors, and honor Global Privacy Control and GPP opt-out signals, as described in Privacy & Consent.
  • Ensure personnel with access are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures, including encryption in transit, access controls, and scrubbing of visitor-identifying fields from error-monitoring telemetry.
  • Assist you, at your request, in responding to End-Visitor data subject requests, and in meeting your own security, breach-notification, and (where applicable) DPIA obligations for this processing.
  • Notify you without undue delay after becoming aware of a personal data breach affecting End-Visitor Personal Data.
  • Delete or anonymise End-Visitor Personal Data in Inlay's systems within the retention windows described in Privacy Policy §5, and on request where feasible.
  • Make available the information reasonably necessary to demonstrate compliance with this section, including this DPA and the sub-processor list below.

6. Sub-processors

You give Inlay general authorisation to engage the following sub-processors for End-Visitor Personal Data, each bound by its own data processing agreement incorporating Standard Contractual Clauses (SCCs) for transfers out of the EEA/UK/Switzerland:

  • Vercel (USA/EU) — hosts the Service and runs the auction; SCCs + UK Addendum.
  • Anthropic (USA) — processes the redacted page-structure snapshot (Section 4) via the Claude API to help select an ad format; DPA with SCCs.
  • Sentry (USA/EU) — error monitoring on the ad-serving path, scrubbed of visitor page content, consent strings, and IP addresses wherever technically feasible; DPA with SCCs (Module 2/3).
  • Upstash (USA/EU, if configured) — distributed rate limiting, keyed on a short-lived IP-derived value; DPA with SCCs.

Stripe and Resend also appear in our Privacy Policy subprocessor list, but only in Inlay's Controller role (billing and transactional email to you) — they do not process End-Visitor Personal Data and are not sub-processors under this DPA.

Inlay will give notice of a new sub-processor or a change to one above (e.g. via this page or the dashboard) before it begins processing End-Visitor Personal Data, and you may object on reasonable data-protection grounds within 14 days by contacting privacy@useinlay.com; if unresolved, either party may treat that as grounds to terminate the affected part of the Service.

7. International transfers

End-Visitor Personal Data from the EEA, UK, or Switzerland may be transferred to and processed in the United States by Inlay and the sub-processors listed in Section 6. Each such transfer relies on Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum) incorporated into Inlay's or the relevant sub-processor's own data processing terms, as the applicable transfer mechanism under Data Protection Laws.

8. Deletion and audits

On termination of your Inlay account, Inlay deletes or anonymises End-Visitor Personal Data within the retention windows in Privacy Policy §5, except aggregated records already stripped of identifying fields. On reasonable written request, no more than once per 12 months (or promptly after a confirmed personal data breach affecting your data), Inlay will provide information reasonably necessary to demonstrate compliance with this DPA; on-site audits are available for enterprise plans by mutual written agreement on scope, timing, and confidentiality.

9. Contact

For DPA questions, sub-processor objections, or to request an executed copy for your own records, contact privacy@useinlay.com.