Data Processing Addendum
Effective: May 2026
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer" or "Controller") and Inceptivate, operated by Point Clear, LLC ("Inceptivate", "we", "us", or "Processor"), governing the processing of Personal Data in connection with the Inceptivate Service. In the event of any conflict between this DPA and our Terms & Conditions, this DPA controls with respect to the processing of Personal Data.
1. Definitions
- Controller: the entity that determines the purposes and means of processing Personal Data. In this DPA, the Controller is the Customer.
- Processor: the entity that processes Personal Data on behalf of the Controller. In this DPA, the Processor is Inceptivate.
- Data Subject: the identified or identifiable natural person to whom Personal Data relates.
- Personal Data: any information relating to a Data Subject, as defined under applicable data protection law.
- Subprocessor: a third party engaged by Inceptivate to process Personal Data on behalf of the Customer.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Categories of Personal Data Processed
Inceptivate processes the following categories of Personal Data:
- Business contact information from public records: business names, registered addresses, filing dates, agent and officer names, and other information published by state Secretary of State agencies as a matter of public record.
- Subscriber account data: name, email address, billing address, payment method tokens (held by Stripe, not by Inceptivate), authentication credentials, and account preferences.
- Usage data: pages visited, search queries, alert configurations, watchlist contents, and other product-interaction telemetry collected during normal Service use.
3. Subprocessors
Inceptivate engages the following Subprocessors to deliver the Service. Each Subprocessor is bound by contractual obligations consistent with this DPA:
- Google LLC (Firebase / Google Cloud Platform): hosting, authentication, database, and serverless compute.
- Stripe, Inc.: payment processing and subscription management. Stripe holds card data; Inceptivate stores only customer and subscription identifiers.
- Resend Technologies, Inc.: transactional and outbound email delivery.
Inceptivate will provide reasonable notice of any intended addition or replacement of Subprocessors and will give Customer the opportunity to object on reasonable grounds.
4. Security Measures
Inceptivate implements appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of Personal Data in transit (TLS 1.2+) and at rest.
- Role-based access controls limiting administrative access to authorized personnel.
- Multi-factor authentication required on all administrative accounts.
- Audit logging of administrative actions and access to production data.
- Regular review of access privileges and prompt revocation upon role change or departure.
- Vendor security review for all Subprocessors.
5. Personal Data Breach Notification
In the event of a Personal Data Breach affecting Customer Personal Data, Inceptivate will notify Customer without undue delay, and in any case within seventy-two (72) hours of becoming aware of the breach. Notification will include, to the extent known: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach and mitigate its effects.
6. Data Retention
- Business records sourced from public filings: retained indefinitely as a matter of historical record. These records originate from publicly available state Secretary of State filings and are not subject to deletion on subscriber request.
- Subscriber account data: retained for the duration of the Customer's account. Upon written deletion request, account data is deleted within thirty (30) days, except where retention is required by law (e.g., tax records) or for the establishment, exercise, or defense of legal claims.
7. Data Subject Rights
To the extent required by applicable law, Inceptivate will assist Customer in fulfilling requests from Data Subjects to exercise their rights, including:
- Right of access to Personal Data we hold about them.
- Right to rectification of inaccurate Personal Data.
- Right to erasure (subject to the retention rules above).
- Right to data portability — receiving Personal Data in a structured, machine-readable format.
- Right to object to or restrict certain processing.
Data Subjects or Customers may submit requests to support@inceptivate.com.
8. International Data Transfers
Personal Data is processed and stored on infrastructure located in the United States. Where Personal Data is transferred from a jurisdiction with restrictions on cross-border data transfers, Inceptivate will use reasonable measures, including appropriate contractual safeguards with Subprocessors, to ensure an adequate level of protection.
9. Governing Law
This DPA is governed by the laws of the State of Louisiana, without regard to conflict of law principles. Any disputes arising from this DPA shall be resolved in the state or federal courts located in Orleans Parish, Louisiana.
10. Contact
For questions about this DPA or to exercise any of the rights described above, please contact support@inceptivate.com.
Inceptivate is operated by Point Clear, LLC, based in New Orleans, Louisiana.