Insite AI← Back

Data Processing Agreement

Last updated: April 8, 2026

This Data Processing Agreement ("DPA") forms part of and is incorporated into the agreement between the Customer and Insite Labs Ltd. ("Company") governing access to and use of the Insite AI Service (as defined in the Terms and Conditions). In the event of any conflict between this DPA and the Terms and Conditions with respect to the subject matter of data processing obligations, this DPA controls solely to the extent required by applicable data protection law. This DPA applies where the Customer's use of the Service involves the processing of personal data (or personally identifiable information) of the Customer's end users, personnel, or site visitors by the Company on the Customer's behalf. Where applicable data protection law does not apply to a particular processing activity, this DPA does not create obligations beyond those in the main agreement.

1. Definitions

• "Customer Personal Data" means any personal data that the Customer submits to, or that is generated by end users through, the Service and that the Company processes on the Customer's behalf, as more particularly described in Section 4. • "Data Protection Law" means the Israeli Privacy Protection Law, 5741-1981, and regulations made thereunder (including the Privacy Protection Regulations (Data Security), 5777-2017), the EU General Data Protection Regulation (GDPR) 2016/679 to the extent applicable, and any other applicable privacy or data protection legislation binding on the relevant party. • "Controller" (or "Business" under applicable law) means the entity that determines the purposes and means of processing of personal data. • "Processor" (or "Service Provider") means the entity that processes personal data on behalf of a Controller. • "Sub-processor" means any third party engaged by the Company to carry out processing activities on Customer Personal Data. • All other capitalized terms not defined herein have the meanings given to them in the Terms and Conditions.

2. Roles of the Parties

With respect to Customer Personal Data processed under this DPA, and to the extent applicable Data Protection Law applies: • the Customer acts as the Controller (or Business) of Customer Personal Data; and • the Company acts as a Processor (or Service Provider) of Customer Personal Data, processing it solely on the Customer's behalf as documented in this DPA and the Terms and Conditions. Notwithstanding the foregoing, the Company acts as an independent Controller for certain categories of data that it collects and uses for its own purposes, including: account and billing data, security and fraud-prevention data, product analytics and usage statistics derived from the operation of the Service, legal compliance records, and service improvement data. The Company's Privacy Policy applies to its Controller processing activities.

3. Subject Matter and Duration

The subject matter of processing under this DPA is the provision, operation, security, maintenance, and improvement of the Service as described in the Terms and Conditions. The Company will process Customer Personal Data for the duration of the active customer relationship and for any additional period required or permitted by applicable law or the Company's data retention obligations.

4. Nature and Purpose of Processing; Categories of Data; Data Subjects

4.1 Nature and Purpose Processing operations may include collection, recording, organisation, structuring, storage, adaptation, indexing, retrieval, consultation, analysis, ranking, generation, transmission, disclosure by access, alignment, combination, restriction, deletion, and destruction of Customer Personal Data as necessary to provide the Service, including AI search and response generation, analytics, FAQ management, crawling and indexing, suggestion generation, and administrative functionality. 4.2 Categories of Customer Personal Data • website content and textual content submitted by the Customer for indexing and retrieval; • end-user queries, prompts, interactions, conversation history, navigation events, and engagement signals; • end-user metadata such as language, approximate geolocation, device type, browser type, and session identifiers; • administrator account details, settings, and support communications; • technical identifiers, IP-derived metadata, logs, and diagnostic information. 4.3 Categories of Data Subjects Data subjects may include the Customer's personnel, the Customer's site visitors and end users, and any other individuals whose data is included in Customer Content.

5. Customer Instructions

The Company will process Customer Personal Data only on documented instructions from the Customer as set out in this DPA, the Terms and Conditions, and the Customer's use and configuration of the Service, unless otherwise required by applicable law. Where applicable law requires processing beyond the Customer's instructions, the Company will inform the Customer of that legal requirement before processing, unless prohibited from doing so by law. The Customer warrants that it has all necessary rights, consents, and legal bases under applicable Data Protection Law to submit Customer Personal Data to the Service and to instruct the Company to process it as set out in this DPA. The Company may refuse to comply with instructions that are unlawful, technically infeasible, materially harmful to the Service or other customers, or that would cause the Company to violate applicable Data Protection Law.

6. Confidentiality of Processing

The Company will ensure that personnel and contractors authorized to process Customer Personal Data are bound by appropriate confidentiality obligations, whether by contract or applicable professional or statutory duty.

7. Security Measures

The Company will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or disclosure. These measures are aligned with the requirements of the Israeli Privacy Protection Regulations (Data Security), 5777-2017, and, where applicable, Article 32 of the GDPR. Such measures may include, without limitation: access controls and role-based permissions; authentication mechanisms; encryption of data in transit; secure development practices; audit logging; backup and recovery procedures; and incident detection and response processes.

8. Sub-processors

The Customer hereby grants the Company a general written authorisation to engage affiliates and third-party Sub-processors to assist in providing the Service, including providers of cloud hosting, infrastructure, object storage, communications, analytics, AI and language model services, monitoring, and technical support. The Company will: • require Sub-processors to undertake data protection obligations that are materially protective of Customer Personal Data; • remain liable to the Customer for the performance of Sub-processors' data protection obligations to the same extent as if the Company itself were performing them. A list of current Sub-processors is available on request by contacting legal@insitelabs.ai. The Company will provide reasonable advance notice of material changes to the Sub-processor list. If the Customer objects to the addition of a new Sub-processor on reasonable grounds relating to data protection, it must notify the Company in writing within 14 days of receiving notice.

9. Assistance with Data Subject Rights and Regulatory Obligations

Taking into account the nature of processing and the information available to it, the Company will provide reasonable assistance to the Customer with: • responding to data subject requests (access, correction, deletion, restriction, objection, portability) to the extent the Company has the technical ability to assist; • conducting data protection impact assessments where required by applicable Data Protection Law; • prior consultations with supervisory authorities where required. The Customer remains solely responsible for its own data protection obligations and for responding to data subjects in the first instance. Note: the obligation to notify a supervisory authority of a personal data breach within the timeframes required by applicable law (e.g., 72 hours under GDPR Article 33) rests with the Customer as Controller, subject to the Company's obligations in Section 10 below.

10. Personal Data Breach Notification

The Company will notify the Customer without undue delay after becoming aware of a confirmed personal data breach that affects Customer Personal Data, providing such information as is reasonably available to enable the Customer to meet its breach-notification obligations under applicable Data Protection Law, including the nature of the breach, the approximate number of data subjects affected, the categories and approximate volume of Customer Personal Data involved, the likely consequences, and measures taken or proposed. Such notification may be delayed or limited where necessary to protect the integrity of the Company's investigation, prevent further harm, coordinate with law enforcement, or comply with applicable legal requirements. Notification does not constitute an admission of fault or liability.

11. International Transfers of Customer Personal Data

The Customer authorizes the Company to transfer Customer Personal Data to Sub-processors or other parties in countries outside Israel or the European Economic Area as necessary to provide the Service. Where such transfers require specific safeguards under applicable Data Protection Law, the Company will implement appropriate measures, which may include standard contractual clauses approved by the European Commission, adequacy decisions, or equivalent mechanisms recognized under the applicable law.

12. Deletion and Return of Customer Personal Data

Upon termination of the applicable customer relationship, the Company may delete, anonymize, or render inaccessible Customer Personal Data in accordance with its standard retention practices, backup cycles, applicable legal obligations, and technical constraints. The Company is not obligated to return Customer Personal Data to the Customer except where expressly agreed in writing and technically feasible. Anonymized or aggregated data may be retained indefinitely.

13. Records and Audits

The Company will maintain reasonable records of its processing activities concerning Customer Personal Data as required by applicable Data Protection Law. Any right to audit the Company's processing shall be subject to: no more than one audit per calendar year; at least 30 days' written notice specifying the intended scope; the Customer's execution of a confidentiality agreement on the Company's standard terms; the audit being conducted during normal business hours with minimal disruption; and any audit right being exercisable at the Customer's cost. The Company may satisfy any such audit right by providing documentation, third-party audit reports (e.g., SOC 2, ISO 27001 where available), or other reasonable evidence of compliance.

14. Liability

This DPA is subject to the limitations of liability, exclusions, disclaimers, and caps set out in the Terms and Conditions. Nothing in this DPA expands, modifies, or supersedes the Company's liability beyond the limits agreed in the Terms and Conditions, except to the extent mandatory applicable Data Protection Law imposes non-waivable liability.

15. Governing Law

This DPA is governed by the laws of the State of Israel. Disputes arising out of or relating to this DPA are subject to the jurisdiction provisions in the Terms and Conditions.

16. Contact for Data Protection Matters

Insite Labs Ltd. Email: legal@insitelabs.ai Website: insiteai.app