Data Processing Agreement
Data Processing Agreement updated on 7 September, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Incubo Labs Private Limited, Lakhshmi Nagar, Delhi 110092, India (“PatentAssist.ai”, “we”, the processor) and the customer using the Services (the controller). It applies whenever we process personal data on your behalf under Article 28 GDPR. You accept it by using the Services; if you need a countersigned copy, write to [email protected].
1. Subject matter and duration
We process personal data solely to provide the Services described in the Terms of Service. Processing lasts for the term of your subscription and ends when your account is closed, subject to clause 8.
2. Nature and purpose of processing
Storing, structuring, analysing and generating patent documentation on your instructions: hosting invention disclosures and uploads, running AI drafting and prior art search, producing draft claims, specifications, abstracts and drawings, and providing support.
3. Categories of data subjects and personal data
Data subjects: your personnel who use the Services, and the inventors, applicants and other individuals named in the content you upload.
Personal data: names, email addresses, postal addresses, nationality, employer, professional qualifications, account and usage data, and any personal data contained in the invention content, documents and correspondence you submit. Do not upload special categories of data (Art. 9 GDPR); the Services are not designed for it.
4. Our obligations
We will:
- process personal data only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we will tell you first, unless the law forbids it;
- ensure everyone we authorise to process the data is bound by confidentiality;
- implement the security measures in clause 6;
- make available the information you need to demonstrate compliance with Art. 28;
- notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need for your own Art. 33 notification.
5. Sub-processors
You give general authorisation for the sub-processors listed at /sub-processors. We will give you at least 30 days’ notice before adding or replacing one, and you may object on reasonable data protection grounds within that period; if we cannot resolve the objection you may terminate the affected Services and receive a pro-rated refund. Every sub-processor is bound by data protection obligations no less protective than these, and we remain fully liable for their performance.
6. Security
We maintain technical and organisational measures appropriate to the risk (Art. 32), including: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control and least privilege, isolated production environments, signed inter-service calls, logging and error monitoring, regular backups, and vendor review. Our infrastructure runs on providers holding SOC 2 and ISO 27001 certifications (Microsoft Azure, Amazon Web Services); PatentAssist.ai does not itself hold those certifications.
7. Assistance with data subject rights
If a data subject contacts us directly about data we process for you, we will refer them to you and will not respond substantively without your instruction. Taking into account the nature of the processing, we will assist you with requests for access, rectification, erasure, restriction, portability and objection, and with your obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation). The Services include self-service export and deletion tools that cover most requests.
8. Return and deletion
On termination, and at your choice, we will delete or return the personal data we process for you, and delete existing copies, unless law requires us to keep it. Local billing history is deleted with the account; payment and invoice records held separately by our merchant of record remain subject to that provider’s legal obligations. Deletion of live data happens within 30 days of termination; backups expire on their normal cycle within 90 days and are not restored without re-applying the deletion.
9. Audits
We will make available the information necessary to demonstrate compliance with this DPA and will allow and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once per twelve months unless a breach or a supervisory authority requires otherwise, must be scheduled at least 30 days in advance, must not disrupt the Services or compromise other customers’ confidentiality, and are subject to confidentiality. Available reports and questionnaires may be provided instead where they answer the question.
10. International transfers
Where we or a sub-processor process personal data outside the EEA or the UK, the transfer is governed by the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor) for onward transfers to sub-processors and Module Two (controller to processor) where you are an EEA controller, together with the UK International Data Transfer Addendum where relevant. Those clauses are incorporated into this DPA by reference; the sub-processors page serves as Annex III, clauses 2 and 3 above as Annex I, and clause 6 as Annex II. Where a provider is certified under the EU-US Data Privacy Framework, we may rely on that instead.
11. Order of precedence
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Everything else in the Terms of Service, including the governing law, continues to apply.