← Back to inkmeplz.com
Data Processing Addendum
Last updated 18 September 2026
This addendum forms part of the Terms of Service between InkMePlz ("Processor") and a studio using InkMePlz ("Controller"). It applies whenever the Controller uses InkMePlz to store or process personal data about its own clients -- names, contact details, and reference images submitted through the booking flow.
This is a standard, self-serve template covering the core commitments a processor agreement needs. If your business requires a negotiated or signed version, contact us at [email protected].
1. Scope of processing
The Processor processes client personal data only as necessary to provide the booking, intake, and deposit-collection service, and only on the Controller's documented instructions (i.e., the actions the Controller takes within InkMePlz). The Processor doesn't use client data for its own purposes, including marketing.
2. Sub-processors
The Processor uses the following sub-processors to deliver the service. The Controller consents to their use, and the Processor will give reasonable notice before adding a new one.
Neon -- Database hosting (Postgres), United Kingdom/EU region.
Cloudflare R2 -- Object storage for uploaded images.
Resend -- Transactional email delivery.
Stripe -- Payment processing (subscriptions and, where used, client deposits).
3. Security
Client data is stored with row-level access isolation per studio, encrypted in transit (HTTPS/TLS), and access to production data is restricted. Passwords are hashed, never stored in plain text.
4. Data subject requests
If the Processor receives a request directly from one of the Controller's clients (access, deletion, correction), it will forward that request to the Controller rather than act on it directly, since the Controller is the one who determines how to respond.
5. Breach notification
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's client data.
6. Deletion on termination
On account closure, the Controller's client data is deleted within a reasonable period, except where retention is required by law (e.g. signed consent/intake forms subject to their own stated retention period).
© 2026 InkMePlz. Run pre-incorporation -- see the Legal Notice for current status.