Data Processing Agreement (DPA)

Agreement under Art. 28(3) GDPR between the customer (controller) and Lorenz Wieseke (LOVIZ), Roßmarktstraße 37, 04177 Leipzig, Germany (processor, “we”). It is accepted at registration with inboundy and forms part of the Terms. Version date: 8 September 2026.

1. Subject matter and duration

We process personal data on behalf of the customer insofar as the customer uses inboundy to collect, store and organise data of their LinkedIn contacts and to use it for connection requests, messages and post interactions. The duration equals the term of the service contract.

2. Nature, purpose, data categories, data subjects

  • Purpose: initiating and maintaining the customer's business contacts on LinkedIn.
  • Data categories: publicly accessible LinkedIn profile data of contacts (name, profile URL, title, company, location, about text, experience, education, skills, recent posts, contact details published in the profile such as e-mail, phone, website, birthday, address), the message history between customer and contact, reactions and comments on the customer's posts, and notes, tags and statuses recorded by the customer.
  • Data subjects: LinkedIn members whom the customer researches, invites, messages or keeps in lists.

3. Instructions

We process the data only on the customer's documented instructions. The customer gives instructions through the settings and actions in the dashboard (keywords, lists, approval of messages, activation of automations); additional instructions are given in text form to contact@inboundy.app. If we consider an instruction unlawful, we inform the customer.

4. Confidentiality

Only the provider himself has access to the data; there are no employees. Should persons be involved in future, we bind them to confidentiality.

5. Technical and organisational measures

  • Database and authentication at Supabase in Frankfurt am Main (AWS eu-central-1), encrypted transport (TLS), access only with the provider's keys.
  • Website, dashboard and workflow server at Hostinger in Frankfurt am Main; access by SSH key only.
  • Automation server at the business premises in Leipzig, reachable only through an encrypted tunnel with an access key; disk encryption.
  • LinkedIn passwords are not stored; session data is kept until disconnection or account deletion and then removed.
  • Automation logs are deleted after 30 days; credentials in logs are masked.
  • Customer access to their data only after sign-in; customer data is separated by user-bound access rules in the database.

6. Sub-processors

The customer consents to the use of the following sub-processors:

  • Supabase, Inc., San Francisco, USA — database and authentication; processing in Frankfurt am Main.
  • Hostinger International Ltd., Larnaca, Cyprus — hosting of website, dashboard and workflow server in Frankfurt am Main.
  • ngrok, Inc., San Francisco, USA — encrypted tunnel to the automation server (transport only, no storage of content).
  • OpenRouter, Inc., New York, USA — generation of text suggestions; receives the contact's profile details, recent posts and the message history and forwards them to the model provider selected by us (possibly outside the EEA).
  • Resend, Inc., San Francisco, USA — delivery of sign-in and account e-mails (customer data only).
  • Stripe Payments Europe Ltd., Dublin, Ireland — payment processing (customer data only).

For providers outside the EEA, EU standard contractual clauses or a certification under the EU-US Data Privacy Framework are in place. We announce new or changed sub-processors by e-mail at least 14 days in advance; the customer may object for good cause and terminate the contract.

7. Assistance to the customer

We assist the customer with data subject requests (access, rectification, erasure) through export and deletion features in the dashboard and on request in text form, and with data protection impact assessments and supervisory authority enquiries insofar as the information is held by us.

8. Personal data breaches

We notify the customer of a personal data breach affecting their data without undue delay and no later than 48 hours after becoming aware of it, to the e-mail address on file, with the details known to us on nature, scope and measures taken.

9. Deletion and return

The customer can export (CSV) and delete contact data in the dashboard at any time. Upon deletion of the account we delete all data processed on behalf of the customer, including session data on the automation server; statutory retention duties for contract and billing data remain unaffected. Accounts unused for 90 days without an active subscription may be deleted after prior notice by e-mail.

10. Evidence and audits

On request we provide the information necessary to demonstrate compliance with this agreement and allow audits of reasonable scope after prior coordination.

11. Final provisions

German law applies. In case of conflict between this agreement and the Terms, this agreement prevails for the processing on behalf of the customer. Amendments follow the procedure in Section K of the Terms.

Last updated: 2026-09-08