Legal · Data Processing Addendum

Data Processing Addendum

Last updated: April 17, 2026 · GDPR Art. 28 compliant

1. Parties + roles

This DPA applies when IBHQ processes personal data on behalf of your workspace ("Controller") in the course of providing our service ("Services"). IBHQ acts as Processor under GDPR Article 28.

2. Subject-matter + duration

We process data for as long as your workspace is active, plus a 30-day grace after deletion. Subject matter is limited to what's necessary to operate the IBHQ Services you've activated — CRM, signal forwarding, onboarding bots, outreach, billing.

3. Categories of data subjects + data

  • Data subjects: your leads, your traders, your team members, your sub-IBs.
  • Data categories: contact identifiers (name, email, phone, Telegram ID), profile metadata, activity history, conversation logs, commission attribution records.

4. Our obligations as Processor

  • Process only on your documented instructions.
  • Keep data confidential (staff signed NDAs).
  • Implement the security measures listed in our Security page.
  • Use only approved sub-processors (list in §7); notify you 30 days before adding a new one.
  • Assist you with data-subject rights requests within 10 business days.
  • Notify you of any confirmed breach within 4 hours (GDPR Art. 33 requires 72; we set ourselves a faster bar).

5. International transfers

Primary processing is in the EU (Frankfurt). Any transfer outside the EEA is covered by the European Commission's Standard Contractual Clauses (SCCs), incorporated herein by reference. Enterprise tenants can request EU-only processing with no cross-border transfers; we enable this by pinning your workspace to our EU region.

6. Your rights to audit

Enterprise tenants can request an audit of our processing operations once per 12-month period. We provide: SOC 2 Type II report (once certified, targeted Q4 2026), a questionnaire response within 30 days, and, for Enterprise tier, a 90-min video walkthrough with our CTO. On-site audits require 30 days' notice and are at Controller's cost.

7. Sub-processors

  • DigitalOcean — hosting (EU / US regions)
  • Groq — AI inference for classification + rewriting
  • Anthropic — AI inference for high-quality outreach drafts
  • Google Cloud — Gemini Flash for image generation
  • TronGrid — on-chain USDT transaction monitoring
  • Twilio — SMS delivery (only if tenant enables SMS)

Each has been assessed for GDPR / SCC compliance. The full up-to-date list lives at /integrations.

8. Termination

On termination, we delete your processed data within 30 days (verifying backups are purged within 90), unless you request earlier deletion or a final export. Records we're legally required to retain (e.g., payment tax records) are kept encrypted for the statutorily mandated period and nothing longer.

To counter-sign this DPA for your workspace, email legal@ibhq.io with your workspace slug and legal entity name.