Data Processing Addendum
Last updated on May 1, 2026
This Data Processing Addendum (the DPA) forms part of the agreement governing the Customer's use of any service provided by Ingram Technologies SRL that refers to this DPA (the Agreement). The parties are:
- Ingram Technologies SRL, a Belgian private limited liability company with company number 0766280697, VAT number BE0766280697, and registered office at Rue du Poinçon 51A, 1000 Brussels, Belgium (Ingram, we, us); and
- the person or entity that has entered into the Agreement with Ingram (Customer, you).
This DPA takes effect when the Customer accepts it electronically, enters into an Agreement that incorporates it, or begins using a Service whose terms incorporate it. A person accepting for an entity represents that they have authority to bind it.
This DPA applies to every Ingram Service. Each Service publishes its own Product Annex, linked from that Service's terms or legal pages, setting out the service-specific processing detail Article 28(3) GDPR requires. The applicable Product Annex forms part of this DPA.
The Privacy Policy describes the personal data Ingram processes as an independent Controller for its own account, and the rights of the individuals concerned. The Security & Compliance page describes Ingram's technical and organizational measures, and is incorporated as set out in section 6.2.
1. Definitions
- Applicable Data Protection Law — the GDPR, the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, and any other privacy or data-protection law applicable to processing under the Agreement.
- Customer Personal Data — Personal Data that Ingram processes on the Customer's behalf in providing a Service.
- Data Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data on systems controlled by Ingram or its Subprocessors. Unsuccessful attempts that do not compromise Customer Personal Data are not Data Incidents.
- GDPR — Regulation (EU) 2016/679.
- Product Annex — the service-specific processing annex published for a Service, or that the Agreement otherwise identifies.
- SCCs — the European Commission's standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
- Service — a product or service supplied by Ingram under the Agreement.
- Subprocessor — a third party appointed by or on behalf of Ingram to process Customer Personal Data in connection with a Service.
Controller, Data Subject, Personal Data, Personal Data Breach, Process, Processor, and Supervisory Authority have the meanings given in the GDPR.
2. Scope and roles
2.1. This DPA applies only where Ingram processes Customer Personal Data as a Processor on the Customer's behalf. The Customer is the Controller of that data, or a Processor acting for another Controller. Where the Customer is a Processor, Ingram is its Subprocessor. Each party complies with the obligations that apply to it under Applicable Data Protection Law.
2.2. A Customer acting as a Processor warrants that the relevant Controller has authorized its instructions, Ingram's appointment, and the Subprocessors authorized under this DPA, and will act as Ingram's sole point of contact for that Controller unless the law requires otherwise.
2.3. Ingram also processes information as an independent Controller, for account administration, billing, fraud prevention, security, legal compliance, and business communications. That processing is outside this DPA and is described in the Privacy Policy.
3. Documented instructions
3.1. Ingram processes Customer Personal Data only on the Customer's documented instructions, unless Union or Member State law requires otherwise. Those instructions are the Agreement, this DPA, the applicable Product Annex, the Customer's configuration and use of the Service, and any further written instruction Ingram accepts. They authorize Ingram to process Customer Personal Data as necessary to provide, maintain, secure, troubleshoot, and support the Service and to perform the Agreement.
3.2. If law requires processing outside those instructions, Ingram will inform the Customer beforehand unless the law prohibits it on important grounds of public interest.
3.3. Ingram will promptly tell the Customer if an instruction appears to infringe Applicable Data Protection Law, and may suspend the affected processing until the Customer confirms or modifies it.
3.4. The Customer is responsible for the lawfulness, accuracy, and content of Customer Personal Data and its instructions, including giving required notices, establishing a lawful basis, and obtaining any authorization Ingram and its Subprocessors need.
3.5. Unless a Product Annex says otherwise, the Customer will not intentionally submit special categories of Personal Data under Article 9 GDPR, or data relating to criminal convictions and offences under Article 10 GDPR.
3.6. Where a Service uses AI-assisted processing, Ingram warrants that its agreement with each AI provider prohibits the provider from using Customer Personal Data to train, fine-tune, or otherwise develop or improve its models. Ingram will not use Customer Personal Data for those purposes itself.
4. Processing details
The applicable Product Annex sets out the subject matter, nature, purpose, duration and frequency of processing; the categories of Data Subjects and of Customer Personal Data; any special-category restrictions; the retention and deletion arrangements; the relevant international transfers; and where to find the current Subprocessor list.
5. Confidentiality and personnel
Everyone Ingram authorizes to process Customer Personal Data is bound by a duty of confidentiality, gets access only where their duties require it, and is trained on Ingram's security and privacy practices. Ingram remains responsible for its personnel's compliance with this DPA.
6. Security
6.1. Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Ingram implements and maintains technical and organizational measures designed to provide a level of security appropriate to the risk, as Article 32 GDPR requires.
6.2. Those measures are described on the Security & Compliance page. That page, with any additional measures in the applicable Product Annex, is Ingram's description of its technical and organizational measures for the purposes of Article 28(3)(c) GDPR and Annex II of the SCCs, as it reads on the date this DPA takes effect. Ingram may update them to reflect technical development or changes to a Service provided the overall level of protection is not materially reduced, and will supply a point-in-time copy of the measures then in force on request.
6.3. The Customer is responsible for securing its own credentials, accounts, systems, devices, and integrations, controlling its authorized users, and configuring the Service appropriately for its risk.
7. Data Incidents
7.1. Ingram notifies the Customer without undue delay after becoming aware of a Data Incident affecting Customer Personal Data, at the Customer's designated privacy contact or account email. The notice contains the information listed in Article 33(3) GDPR to the extent known, and a contact point; Ingram may provide it in phases without undue further delay.
7.2. Ingram takes reasonable steps to contain, investigate, mitigate, and remediate the Data Incident, and cooperates reasonably with the Customer. Notification is not an admission of fault or liability, and the Customer remains responsible for the notifications it must make as Controller.
8. Data Subject requests
Taking into account the nature of the processing, Ingram assists the Customer through appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise Data Subject rights. If Ingram receives such a request directly, it promptly refers it to the Customer and does not respond substantively unless the Customer instructs it to or the law requires it.
9. Compliance assistance
Taking into account the nature of processing and the information available to it, Ingram provides reasonable assistance with the Customer's obligations under Articles 32 to 36 GDPR, including security assessments, Personal Data Breach notifications, data protection impact assessments, and prior consultations.
If assistance requires material work beyond ordinary support, the parties may agree reasonable fees in advance. No fee applies where the assistance is needed because Ingram breached this DPA.
10. Subprocessors
10.1. The Customer gives Ingram general written authorization to appoint Subprocessors in accordance with this section. The current Subprocessors for each Service are identified on the page the applicable Product Annex references.
10.2. Ingram enters into a written agreement with each Subprocessor imposing data-protection obligations no less protective in substance than those this DPA imposes on Ingram, to the extent relevant to that Subprocessor's services.
10.3. For a planned appointment or replacement, Ingram gives at least 30 days' advance notice, by updating the relevant Subprocessor page and sending notice to the Customer's account email, before the new Subprocessor begins processing Customer Personal Data.
10.4. Where an urgent replacement is reasonably necessary to address a security risk, service failure, legal requirement, or material threat to service continuity, Ingram may appoint it sooner. Ingram will notify the Customer as soon as reasonably practicable, explain the reason, and preserve the objection right in section 10.5.
10.5. The Customer may object to a new or replacement Subprocessor on reasonable, documented data-protection grounds. The parties will work in good faith to resolve the objection; if no commercially reasonable solution is available, the Customer may terminate the affected Service by written notice, and Ingram will refund prepaid fees for the unused period where applicable.
10.6. Ingram remains responsible to the Customer for a Subprocessor's performance of its data-protection obligations to the same extent Ingram would be if it performed the processing itself.
11. International transfers
11.1. Ingram does not transfer Customer Personal Data outside the EEA unless it has a transfer mechanism valid under Chapter V GDPR and any supplementary measures the assessment shows to be required. The mechanisms Ingram relies on are described under "International Data Transfers" in the Privacy Policy; transfers specific to a Service are identified in its Product Annex. The same applies to onward transfers to a Subprocessor.
11.2. Where the SCCs are required for a transfer from the Customer to Ingram, they are incorporated by reference and completed as follows:
- Module Two applies where the Customer is a Controller and Ingram is a Processor.
- Module Three applies where the Customer is a Processor and Ingram is a Subprocessor.
- Module Four applies where Ingram, acting as a Processor in the EEA, transfers or returns Personal Data to a Customer acting as a Controller in a third country and the transfer requires the SCCs.
- Clause 7, the docking clause, applies.
- Option 2 in Clause 9(a) applies, with the 30 days' notice period set out in section 10.3.
- The optional language in Clause 11 does not apply.
- For the purposes of Clause 13(a), the competent supervisory authority is the Belgian Data Protection Authority.
- In Clause 17, Option 1 applies and Belgian law governs.
- The courts of Brussels, Belgium are selected under Clause 18(b).
- Annex I is completed by this DPA and the applicable Product Annex; Annex II by the measures referenced in section 6.2; and Annex III by the relevant Subprocessor page.
12. Return and deletion
12.1. During the Agreement, the Customer may request export or deletion to the extent the Service supports it.
12.2. On termination of the affected Service or the Customer's written request, Ingram will, at the Customer's choice, delete or return Customer Personal Data and delete remaining copies, unless the law requires retention. The periods within which deletion takes effect, including for backups, are those published under "Data Retention" and "Data Removal" on the Security & Compliance page as it reads on the date this DPA takes effect, as varied by the applicable Product Annex. Ingram may update those periods to reflect technical development or changes to a Service provided the overall level of protection is not materially reduced.
12.3. Where retention is legally required, Ingram isolates and protects the retained data, processes it only for that purpose, and deletes it when the requirement ends.
13. Information and audits
13.1. Ingram makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. That includes the published Security & Compliance documentation, a summary of Ingram's most recent independent penetration test findings on request, an overview of Ingram's security policies on request for enterprise customers, and responses to reasonable questionnaires, subject to confidentiality and security restrictions.
13.2. The Customer may request an audit once in any 12-month period, unless a Supervisory Authority requires otherwise or a Data Incident reasonably warrants another. The parties will first seek to satisfy the request through documents and remote review.
13.3. If an on-site or independent audit remains reasonably necessary, it takes place on reasonable prior notice, during business hours, without unreasonable disruption, under confidentiality obligations, and limited in scope to systems and records relevant to Customer Personal Data. The Customer bears its audit costs unless the audit identifies a material breach by Ingram. An audit may not expose another customer's data, trade secrets, or anything that would create a security risk.
14. Liability and precedence
14.1. The liability provisions of the Agreement apply to this DPA, except to the extent Applicable Data Protection Law or the SCCs prohibit limiting or excluding liability. Nothing here limits a Data Subject's rights.
14.2. On the processing or protection of Customer Personal Data, this DPA prevails over the Agreement, and over any page it incorporates, to the extent of a conflict. The applicable Product Annex prevails over this DPA where it expressly varies it. Where the SCCs apply, they prevail over all of them.
14.3. This DPA supersedes any earlier data processing addendum between the parties for the same Service, unless a later bilateral addendum expressly says otherwise.
15. Term and changes
15.1. This DPA continues for as long as Ingram processes Customer Personal Data, and survives termination to the extent necessary to protect that data.
15.2. Ingram may amend this DPA where reasonably necessary to comply with Applicable Data Protection Law, a binding decision, or a material change to a Service, giving advance notice of a material change where practicable. No amendment will materially reduce the protection of Customer Personal Data.
15.3. This DPA is in writing in electronic form for the purposes of Article 28(9) GDPR, and electronic acceptance records are evidence of agreement. The parties may execute a bilateral counterpart on request; the counterpart does not change the terms of this DPA unless it expressly says so.
15.4. This DPA is governed by Belgian law, and disputes go to the courts specified in the Agreement, without prejudice to mandatory rights under Applicable Data Protection Law or the SCCs.
16. Contact
Privacy and data-protection enquiries, including Data Subject requests: privacy@ingram.tech
Contractual notices under this DPA: legal@ingram.tech
Data Incident and vulnerability reports: security@ingram.tech
Ingram Cloud Product Annex
Last updated: 29 July 2026
This Product Annex forms part of the Ingram Technologies Data Processing Addendum (DPA) when the Customer uses Ingram Cloud. Capitalized terms not defined here have the meanings given in the DPA, and the measures protecting the data described below are on the Security & Compliance page.
1. Subject matter and purpose
Ingram Cloud is a platform for building and running AI agents. The Customer designs an agent, and runs one clone of that agent per end user, a smith, through the Ingram Cloud interfaces.
Ingram processes Customer Personal Data to sign the Customer's users in, store the agents and smiths the Customer creates, run each conversation against the AI model the Customer selects, carry out the actions the Customer enables an agent to take, keep each smith's conversation history and memory, record what the Service did on the Customer's behalf, meter and bill usage, and support and secure the Service.
The Customer determines the instructions an agent follows, the models it uses, the actions it may take, the systems it connects to, and the end users it serves, and is the Controller in respect of the Personal Data processed through them.
2. Nature, frequency, and duration
Processing occurs for as long as the Customer uses Ingram Cloud: whenever the Customer or an end user uses the Service, and automatically without a person present, where the Customer has configured the Service to act on a schedule or in response to an incoming message or event.
It consists of storing, retrieving, transmitting to the recipients identified in section 4, and recording the data described in section 3, until deletion under section 5.
3. Data Subjects and Personal Data
The data can relate to the Customer's own users and staff, to the end users each smith serves, and to anyone identified in the content an agent receives or produces.
It can include:
- account data: names, business contact details, and sign-in credentials for the Customer's users;
- the Customer's own identifier for an end user, and any name or contact address the Customer supplies with it;
- conversation content: messages, attachments, and the results of actions an agent takes, together with the model's responses;
- the memory, conversation history, and reference material the Customer or its end users give a smith to work from;
- content an agent retrieves from or writes to the systems the Customer connects it to;
- records of what the Service did: activity and audit records, approval decisions, and usage and billing records; and
- technical data generated by use of the Service, such as sign-in events, IP addresses, and logs.
The Customer must not submit special categories of Personal Data under Article 9 GDPR, or data relating to criminal convictions and offences under Article 10 GDPR, in agent instructions, conversations, uploaded material, or support requests. Ingram Cloud applies no controls specific to such data.
4. Subprocessors, models, and connected systems
The current list of Ingram Cloud Subprocessors is published at https://cloud.ingram.tech/legal/subprocessors. The authorization, notice, urgent-replacement, and objection arrangements in section 10 of the DPA apply to it.
Model providers. Every conversation sends the Customer's instructions and content to the provider serving the AI model the Customer selected. Where the Customer uses model access provided by Ingram, that provider is an Ingram Subprocessor, appears on the Subprocessor page, and is bound by written terms prohibiting the use of Customer Personal Data to train or improve its models, as section 3.6 of the DPA requires. Where the Customer supplies its own account or key with a provider, that provider processes the data under the Customer's own agreement with it, on the Customer's instruction; it is not an Ingram Subprocessor, and Ingram gives no undertaking as to its terms.
Connected systems. The systems, applications, and messaging channels the Customer connects to an agent are the Customer's own systems or its own relationships with third parties. Ingram Cloud reads from and writes to them on the Customer's instruction. They are not Ingram Subprocessors, and the Customer is responsible for the lawfulness of what it routes through them.
5. Retention and deletion
Except as set out below, Ingram retains Customer Personal Data for as long as the Customer's account exists.
- Conversations, uploaded material, reference material, and connections to other systems persist until the Customer deletes them, which it can do at any time through the Service. A smith's memory can be replaced or cleared the same way.
- Deleting a smith archives it: the smith stops running, and its data is deleted with the account or on the Customer's written request under section 12 of the DPA.
- Activity, audit, and usage records are retained for as long as the account exists.
- Billing records are retained for the period applicable accounting and tax law requires, and are processed by Ingram as an independent Controller under section 2.3 of the DPA.
On deletion of the Customer's account, Ingram deletes the account and the Customer Personal Data described in this Annex, within the periods published under "Data Retention" and "Data Removal" on the Security & Compliance page. Deleted records may persist in encrypted backups until those backups expire.
Model providers may retain the content sent to them for abuse monitoring under their own terms. Ingram turns off provider-side retention of conversation content wherever the provider offers that setting.
Marketing contacts and preferences are handled by Ingram as an independent Controller under the Privacy Policy, not under the DPA.
6. Location and international transfers
Ingram stores the Customer Personal Data described in this Annex in the European Union. Ingram will give notice under section 10 of the DPA before storing it elsewhere.
Running a conversation against an AI model is the exception to that commitment. Ingram routes model access it provides to the European Union where the selected model is served from there. Some models are served only from outside the EEA, and selecting such a model is the Customer's instruction to transmit that conversation to the model and receive its response across that border. For those transfers Ingram relies on the mechanisms in section 11 of the DPA: an adequacy decision or the provider's Data Privacy Framework certification where available, otherwise the SCCs with the supplementary measures Ingram's transfer assessment requires. A Customer that needs every conversation to stay within the European Union may restrict its agents to the models Ingram serves from there; Ingram will identify those models within 10 business days of a written request.
Some Subprocessors, principally those providing hosting and email, are globally operated or contract through a non-EEA entity. They are identified on the Subprocessor page and are covered by the same mechanisms.
7. Service-specific commitments
In addition to the measures referred to above, Ingram commits under this Annex that:
- each smith's conversations, memory, uploaded material, and connections are accessible only through that smith, and each access credential the Customer issues works only within the scope the Customer gives it;
- secrets the Customer stores, such as its credentials for another system, are not returned by the Service once stored; it reports only whether a secret is set;
- an action the Customer has marked as requiring approval is not carried out until the Customer approves it;
- Customer Personal Data is not used to train or improve any Ingram model; and
- Ingram personnel access conversation content only where it is necessary to support or secure the Service, under the confidentiality obligations in section 5 of the DPA.
8. Competent Supervisory Authority
The Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit) is the competent Supervisory Authority for Ingram, without prejudice to another authority competent under Applicable Data Protection Law or the SCCs.