Data Processing Agreement
Last updated: 2026-06-18
This Data Processing Agreement ("DPA") forms part of the agreement between [Legal entity name — e.g. ilion, Inc.] ("ilion", the processor) and the customer organization ("Customer", the controller) for the use of ilion. It reflects the requirements of Article 28 GDPR and the equivalent provisions of KVKK.
1. Roles and scope
The Customer is the data controller of the personal data it stores and processes in ilion(its leads, contacts, accounts, communications, and related records). ilion is a data processor acting on the Customer's documented instructions. Using the service's features constitutes the Customer's instruction to process the data those features require.
2. Subject matter, duration, nature and purpose
Processing covers the operation of an agentic revenue platform: storing CRM records, syncing connected email/calendar/telephony data, generating AI analyses and drafts, and sending communications the Customer approves. Processing lasts for the term of the subscription plus the deletion window in Section 8.
3. Categories of data and data subjects
Data subjects: the Customer's prospects, customers, business contacts, and its own users. Categories: business contact details (name, email, phone, title, employer), communication content and metadata the Customer connects (email, calendar, call recordings and transcripts), commercial records (deals, quotes, contracts, invoices), and usage/audit records. The service is not designed for special categories of data (Art. 9 GDPR) and the Customer agrees not to submit them.
4. Subprocessors
The Customer grants general authorization for the subprocessors listed at /legal/subprocessors, which distinguishes the always-on core stack from integrations that only receive data when the Customer explicitly connects them. ilion will update that page before adding or replacing a subprocessor and notify the Customer, who may object on reasonable data-protection grounds within [30] days; ilion will then work with the Customer in good faith on an alternative, including termination of the affected feature.
5. Security measures
ilion implements the technical and organizational measures described at /security, including: per-organization data isolation enforced in the database and application layers, encryption in transit (TLS) and at rest, role-based access within the Customer's organization, audit trails of record changes and administrative actions, automated PII minimization of operational logs, and an outbound kill-switch. That page is incorporated by reference; material reductions of the measures require notice.
6. AI processing
AI features send relevant record context to the model provider (Anthropic) to generate output. Model providers are bound as subprocessors and do not use Customer data to train models. AI-proposed changes to Customer data pass through an approval queue under the Customer's control; outbound communications drafted by AI are sent only on a human's explicit action.
7. Assistance, data subject rights and breach notification
ilion will assist the Customer in responding to data-subject requests (access, rectification, erasure, portability) — the service provides in-app deletion and a full-organization export. ilion will notify the Customer without undue delay, and at the latest within [48 hours], after becoming aware of a personal data breach affecting Customer data, with the information Art. 33 GDPR requires as it becomes available.
8. Retention, return and deletion
Operational logs containing personal data are automatically minimized on a schedule (AI-run inputs/outputs redacted after [90] days; error logs deleted after [90] days; record-change and administrative audit trails retained [2 years] for accountability, then deleted). On termination, the Customer may export all organization data via the built-in export; ilion deletes the organization's data within [30] days of a deletion request, except where law requires longer retention.
9. International transfers
Primary storage and hosting are in the EU (Ireland). Where a subprocessor processes data outside the EU/EEA (see the subprocessor list), the transfer is covered by the European Commission's Standard Contractual Clauses or another valid Chapter V transfer mechanism maintained by that subprocessor.
10. Audits
ilion will make available the information reasonably necessary to demonstrate compliance with this DPA — the security page, subprocessor list, and answers to the Customer's security questionnaires — and will allow audits as required by Art. 28(3)(h) GDPR, no more than [once per 12 months], on [30] days' notice, at the Customer's cost, in a manner that does not endanger other customers' data.
11. Confidentiality and personnel
Persons authorized to process Customer data are bound by confidentiality. Vendor administrative access to a Customer organization requires a stated reason and is recorded in an audit log.
12. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms regarding processing of personal data, this DPA prevails.
How to execute this DPA
For a countersigned copy, contact hello@ilionos.com. Enterprise agreements may attach this DPA as a schedule.