InsideGroup
Data Processing Addendum
Last Updated: August 7, 2026 · Current version: https://insidegroup.ai/legal/dpa
This Data Processing Addendum ("DPA") sets forth the terms relating to the privacy, confidentiality, and security of Personal Data processed by Zeitlos Ventures LLC ("InsideGroup," "we," "us," or "our") on behalf of a Group Owner in connection with the Services.
This DPA is incorporated into the InsideGroup Terms of Service, Privacy Policy, order form, services agreement, or other applicable agreement between you and InsideGroup (the "Agreement") where InsideGroup processes Personal Data on your behalf. In this DPA, "you" and "Group Owner" mean the applicable Group Owner, and "InsideGroup," "we," "us," or "our" mean Zeitlos Ventures LLC. Capitalized terms not defined here have the meanings given in the Agreement, Terms of Service, or Privacy Policy.
Parties and Roles
Group Owner: the Group Owner that entered into the Agreement, together with any affiliates it is authorized to bind. The Group Owner's identity, address, and contact details are those associated with its account and the Agreement.
InsideGroup: Zeitlos Ventures LLC (InsideGroup), 244 Fifth Avenue, Suite V244, New York, NY 10001, USA; [email protected].
Roles: The Group Owner acts as Controller (or "Business") and InsideGroup acts as Processor (or "Service Provider") in respect of Personal Data processed on the Group Owner's behalf. Where the Group Owner itself acts as a Processor on behalf of a third-party controller, InsideGroup acts as a sub-processor.
Definitions
“Business,” “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Service Provider,” “Sell,” and “Share” have the meanings given to them under applicable Data Protection Laws.
“CCPA” means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.
“Data Protection Laws” means all applicable laws and regulations relating to the privacy, confidentiality, protection, or security of Personal Data.
“Data Security Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Data processed by InsideGroup on behalf of a Group Owner.
“EU SCCs” means the standard contractual clauses issued under Commission Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries.
“Group” means a group, community, channel, directory, list, event group, WhatsApp group, WhatsApp community, subgroup, or similar collection of people, profiles, messages, or related information managed, organized, accessed, or analyzed through the Services. A Group may contain, be associated with, or be connected to other Groups.
“Group Owner” means the person or organization that creates, connects, controls, administers, subscribes to, or otherwise manages one or more Groups through the Services.
“Member” means an individual who is added to, invited to, participates in, claims a profile in, connects an account for, appears in, or otherwise uses the Services in connection with a Group.
“Services” means the InsideGroup platform, websites, applications, group management tools, directories, messaging integrations, analytics tools, AI-enabled features, and related services provided under the Agreement.
“Subprocessor” means any third party engaged by InsideGroup to process Personal Data on behalf of a Group Owner.
“Technical and Organizational Security Measures” means commercially reasonable technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure.
“UK Addendum” means the United Kingdom International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, as issued by the UK Information Commissioner and updated, amended, or replaced from time to time.
1. Applicability of this DPA
1.1 Group Owner Role
In using the Services to create, connect, control, administer, or manage Groups, the Group Owner acts as Controller or Business with respect to Personal Data associated with Members and other individuals in or connected to those Groups.
Group Owner represents and warrants that it has provided all necessary notices, obtained all necessary consents or permissions, and has all rights and authority required to provide Personal Data to InsideGroup and to instruct InsideGroup to process such Personal Data.
1.2 InsideGroup Processor Role
Where InsideGroup processes Personal Data on behalf of a Group Owner as part of the Services, InsideGroup acts as Processor or Service Provider, and Group Owner acts as Controller or Business.
This may include processing Personal Data to provide Group management, directory, onboarding, messaging, search, analytics, summarization, classification, member profile, integration, or related services at the direction of the Group Owner. To the extent InsideGroup processes Personal Data as Processor or Service Provider on behalf of a Group Owner, Section 2 of this DPA applies.
1.3 InsideGroup Independent Controller Role
In some circumstances, InsideGroup may process Personal Data as an independent Controller or Business, for example where Members or other individuals engage with aspects of the Services beyond a particular Group Owner's Group, such as platform accounts, authentication, security, fraud prevention, support, and billing.
Where InsideGroup acts as an independent Controller or Business, it does so as an independent and not a joint Controller with Group Owner. InsideGroup does not process Group Owner's Group Data or Member Data as an independent Controller for its own product analytics, member profiling, or to train third-party foundation models, except as permitted by applicable law and as described in the Privacy Policy and AI Policy. Such independent-controller Processing is governed by the Privacy Policy and applicable law and is not subject to this DPA.
1.4 Details of Processing
The details of Processing performed under this DPA are as follows:
Duration: As set out in the Agreement, unless otherwise required by applicable law.
Nature, purpose, and subject matter: To provide the Services to Group Owner, including enabling Group Owner to create, connect, control, administer, organize, search, analyze, summarize, classify, message, onboard, and manage Groups and Members.
Categories of Personal Data: Name, phone number, email address, profile information, membership information, roles, directory fields, messages, message metadata, activity data, preferences, connected account information where applicable, custom fields, analytics, summaries, classifications, files, and any other Personal Data that Group Owner provides to or requests InsideGroup to process.
Categories of Data Subjects: Members, Group Owner personnel, invitees, contacts, group participants, and other individuals whose Personal Data is processed in connection with Group Owner's use of the Services.
2. Data Processing Obligations
Whenever InsideGroup processes Personal Data on behalf of Group Owner, InsideGroup shall:
2.1 Instructions
Process Personal Data only on documented instructions from Group Owner, unless required to do otherwise by applicable law. Group Owner's documented instructions include the Agreement, this DPA, applicable order forms, Group Owner's configuration and use of the Services, and any other written instructions agreed by the parties.
InsideGroup will inform Group Owner if, in its opinion, an instruction infringes applicable Data Protection Laws, unless prohibited from doing so by law. Group Owner is responsible for ensuring that its instructions comply with Data Protection Laws and that InsideGroup's Processing in accordance with those instructions will not violate applicable law.
2.2 Compliance with Laws
InsideGroup will comply with Data Protection Laws applicable to its Processing of Personal Data as Processor or Service Provider, and will process Personal Data only as necessary to provide the Services, comply with the Agreement, follow Group Owner's documented instructions, or as otherwise permitted or required by Data Protection Laws.
2.3 CCPA Service Provider Terms
To the extent the CCPA applies and InsideGroup processes Personal Data as a Service Provider or Contractor on behalf of Group Owner, InsideGroup will not:
Sell or Share such Personal Data;
retain, use, or disclose such Personal Data outside of the direct business relationship between InsideGroup and Group Owner, except as permitted by the CCPA;
retain, use, or disclose such Personal Data for any purpose other than the business purposes specified in the Agreement, this DPA, or as otherwise permitted by the CCPA; or
combine such Personal Data with Personal Data obtained from other sources except as permitted by the CCPA.
InsideGroup certifies that it understands and will comply with these restrictions and will provide the same level of privacy protection for such Personal Data as is required of Group Owner under the CCPA.
2.4 Security Measures
InsideGroup will maintain Technical and Organizational Security Measures appropriate to the nature of the Personal Data and the Services. Such measures may include, as appropriate:
access controls;
authentication controls;
encryption in transit;
encryption at rest where supported;
logging and monitoring;
backup and recovery procedures;
personnel confidentiality obligations;
vendor security review;
incident response procedures; and
reasonable administrative, technical, and physical safeguards.
An overview of InsideGroup's current security practices is available at https://insidegroup.ai/legal/security. Security measures may change over time as the Services and InsideGroup's infrastructure evolve, provided that InsideGroup does not materially reduce the overall level of security.
2.5 Confidentiality
InsideGroup will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
2.6 Subprocessors
Group Owner authorizes InsideGroup to engage Subprocessors to process Personal Data on Group Owner's behalf. InsideGroup will impose contractual obligations on Subprocessors, by way of written contract, that are the same as or equivalent to those imposed on InsideGroup under this DPA, and remains responsible to Group Owner for its Subprocessors' processing of Personal Data as described in this DPA.
InsideGroup may add or replace Subprocessors from time to time. InsideGroup will provide notice of material Subprocessor changes by updating its subprocessor page or through another reasonable method. Group Owner is responsible for regularly reviewing the subprocessor page.
2.7 Data Security Breach
InsideGroup will notify Group Owner without undue delay after becoming aware of a Data Security Breach, unless prohibited by law. The notice will include information reasonably available to InsideGroup to help Group Owner meet its obligations under Data Protection Laws. InsideGroup may provide notice directly to affected individuals where required by law, where appropriate, or where InsideGroup determines that direct notice is reasonably necessary.
2.8 Assistance
Taking into account the nature of the Processing and information available to InsideGroup, InsideGroup will provide reasonable assistance to Group Owner with:
responding to Data Subject requests;
data protection impact assessments;
consultations with supervisory authorities;
security obligations; and
breach notification obligations.
InsideGroup may charge reasonable fees for assistance that requires material time or resources, unless such assistance is required due to InsideGroup's breach of this DPA.
2.9 Data Subject Requests
If InsideGroup receives a request from a Data Subject relating to Personal Data processed on behalf of Group Owner, InsideGroup may respond directly where permitted or required by law, direct the Data Subject to Group Owner, notify Group Owner of the request, or take other reasonable action consistent with the nature of the request and applicable law.
Group Owner instructs and authorizes InsideGroup to delete, anonymize, export, correct, or restrict Personal Data where necessary to respond to valid Data Subject requests or as required by applicable law, subject to InsideGroup's role and available functionality.
2.10 Audits and Compliance Information
Upon Group Owner's written request, InsideGroup will make available information reasonably necessary to demonstrate compliance with this DPA. Any audit or inspection must be:
limited to information reasonably necessary to assess compliance with this DPA;
conducted no more than once every three years, unless required by Data Protection Laws or following a confirmed Data Security Breach;
subject to reasonable advance notice;
subject to appropriate confidentiality obligations; and
conducted in a manner that does not unreasonably interfere with InsideGroup's business operations or compromise security, confidentiality, or other customers' data.
InsideGroup may satisfy audit obligations by providing security documentation, summaries, third-party certifications, audit reports, or written responses, where appropriate.
2.11 Return or Deletion
Upon Group Owner's written request, and except for Personal Data with respect to which InsideGroup acts as an independent Controller or Business, InsideGroup will return, delete, anonymize, or destroy Personal Data processed on behalf of Group Owner, unless applicable law requires the storage of such Personal Data. Personal Data residing in routine backups is deleted in the ordinary course of InsideGroup's backup rotation.
2.12 Inability to Comply
InsideGroup will notify Group Owner if InsideGroup makes a determination that it can no longer meet its obligations under applicable Data Protection Laws.
2.13 Right to Stop and Remediate
Group Owner has the right, upon fourteen (14) business days' notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data by InsideGroup.
3. Group Owner Obligations
Group Owner shall:
comply with all Data Protection Laws applicable to its use of the Services;
provide all required notices and obtain all required consents or permissions;
ensure it has authority to provide Personal Data to InsideGroup;
ensure its instructions to InsideGroup comply with applicable law;
use the Services in accordance with applicable law, third-party platform rules, and the Agreement;
respond to Data Subject requests where required;
determine whether its use of the Services involves the transfer of Personal Data subject to cross-border transfer restrictions, and whether the safeguards described in Section 4 are appropriate for its use case; and
ensure that individuals it authorizes to use the Services comply with the Agreement and applicable law.
4. Cross-Border Transfers
4.1 United States Operations
InsideGroup is a United States company and the Services are provided from the United States. Group Owner acknowledges that InsideGroup and its Subprocessors may process Personal Data in the United States and in other countries where InsideGroup or its Subprocessors operate.
4.2 Transfer Mechanisms
Where Data Protection Laws require a transfer mechanism for international transfers of Personal Data, the parties will rely on appropriate lawful transfer mechanisms, which may include adequacy decisions, the EU SCCs, the UK Addendum, the EU-U.S. Data Privacy Framework, or other mechanisms recognized under applicable Data Protection Laws.
4.3 Transfer Terms on Request
Group Owners subject to European Economic Area, United Kingdom, or Swiss data protection law that require the EU SCCs, the UK Addendum, or equivalent transfer terms may request them by contacting [email protected]. Such clauses, and any completed annexes or transfer documentation, apply only where separately agreed in writing between InsideGroup and the applicable Group Owner, and are not incorporated into this DPA by default.
5. Conflict
If there is a conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Personal Data on behalf of Group Owner. Where the parties have separately agreed in writing to the EU SCCs, the UK Addendum, or other transfer terms as described in Section 4.3, and there is a conflict between those terms and this DPA, those terms control to the extent required by applicable law.
6. Liability
Liability under this DPA, including in connection with Data Security Breaches and international transfers, is governed by the Agreement, including any limitation of liability, exclusion of damages, indemnity, or other risk-allocation terms agreed by the parties. This DPA does not create separate liquidated damages, fixed penalties, or special breach penalties.
7. Term
This DPA will remain in effect for as long as InsideGroup processes Personal Data on behalf of Group Owner. Sections that by their nature should survive termination will survive, including confidentiality, security, return or deletion, audit, liability, and international transfer provisions.
8. Contact
Questions about this DPA may be sent to:
InsideGroup (Zeitlos Ventures LLC)
244 Fifth Avenue, Suite V244, New York, NY 10001, USA