Data Processing Addendum

Last updated: July 28, 2026

Read this first. This document is published for transparency during evaluation — it tells you what we do with personal data before you spend time asking. It has not yet been reviewed by counsel and does not name a contracting legal entity.

If you need an executed DPA, email support@indemo.ai and we'll send a signable version. Don't rely on this page as the executed agreement.

This Addendum supplements the Terms of Service and applies where inDemo processes personal data on your behalf in providing the service.

1. Roles

You are the controller. inDemo is the processor, acting only on your documented instructions — which, in the ordinary case, means providing the service as described in the Terms.

Note the split that matters for this product: the demo recordings, transcripts, and lead contact details generated when inDemo demos your product to your prospects are your data about your prospects. We process them for you. Separately, we are a controller for our own account and billing records about you as a customer, which the Privacy Policy covers.

2. What we process

Categories of data subject

Categories of personal data

inDemo is not designed for special-category data under Article 9 GDPR, and you shouldn't route it through the service.

3. Purpose and duration

We process personal data solely to provide the service: running demos, producing recordings and transcripts, generating recaps and follow-ups on your behalf, and securing and improving the service. Processing lasts for the term of your subscription, plus the deletion window in section 8.

4. Security measures

The technical and organizational measures in place, described in operational detail on our Security page:

We do not currently hold SOC 2 or ISO 27001 certification, and no third-party penetration test has been performed. We state this plainly rather than leaving it to be discovered.

5. Confidentiality

Personnel authorized to process personal data are bound by confidentiality obligations and have access only as needed to operate and support the service.

6. Subprocessors

You give general authorization for the subprocessors below. Each is engaged under terms requiring protection at least as protective as this Addendum.

SubprocessorProcessing activityLocation
Fly.ioApplication hosting and computeFrankfurt (primary), EU
TigrisObject storage for demo recordingsEU / global edge
OpenAILanguage model inference for narration and answersUnited States
GoogleGemini Live for real-time voiceUnited States
ResendTransactional and follow-up emailUnited States / EU
PolarSubscription billing and paymentsEU
CloudflareBot protection and content deliveryGlobal edge
FirecrawlRetrieval of public documentation you designateUnited States
PostHogAnalytics for the indemo.ai marketing websiteFrankfurt, EU

We'll give notice before adding or replacing a subprocessor, and you may object on reasonable data-protection grounds; if we can't resolve the objection, you may terminate the affected part of the service.

7. International transfers

The application, database, and recordings are hosted in the EU, with Frankfurt as the primary region. Language-model inference happens in the United States — narration and answers are generated by OpenAI and Google models hosted there, which means demo audio and transcript content is transferred to the US in the course of running a demo. Transfers rely on the European Commission's Standard Contractual Clauses where applicable.

If EU-only processing is a requirement for you, raise it before you sign up. Today we cannot meet it.

8. Deletion and return

You can delete recordings and account data from within the product at any time, and set a retention period after which recordings are deleted automatically. On termination, we delete your personal data within 30 days, except where retention is required by law. On request before then, we'll provide an export.

9. Assistance

Taking into account the nature of the processing, we'll help you respond to data subject requests, and assist with security, breach notification, and data protection impact assessments as required by Articles 32–36 GDPR.

10. Personal data breach

We'll notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available to us at the time and updates as the picture becomes clear.

11. Audit

On reasonable written request, and no more than once a year unless required by a supervisory authority, we'll make available the information needed to demonstrate compliance with this Addendum.

Contact

Questions, or a request for a signable copy: support@indemo.ai.

Get started

Never miss another lead.

30 free demo minutes · no card