Effective 22 July 2026
This Data Processing Addendum forms part of the Conduit Terms of Service between Infivector Technologies Private Limited, called Infivector. The other party is the Team or Enterprise customer identified by its Conduit account, called Customer. It applies when Infivector processes personal data on Customer's behalf to provide Conduit.
Customer is controller and Infivector is processor for Team-member account, seat and organization data submitted by Customer. Customer instructs Infivector to process that data to provide, maintain, protect and support Conduit. Customer will provide lawful instructions and a lawful basis for the data. Infivector will tell Customer if an instruction appears to violate applicable data-protection law, unless law prevents that notice.
Infivector is an independent controller for its own account, contracting, billing-support, service-protection and legal-compliance records as described in the Privacy Policy. Dodo Payments acts as an independent controller for merchant-of-record processing.
The processing lasts for the subscription and any retention period required by the agreement or law. Its purpose is authentication, licensing, entitlement delivery, organization administration, seat assignment, device activation, signed policy delivery, downloads and support.
Data subjects are Customer's owners, administrators and Team members. Data includes account email, account identifier, sign-in provider subject, hosted domain, organization role, seat assignment, random installation identifier, activation time, entitlement, policy metadata and support contact information. It does not include repository content, prompts, responses, tool output or worktree content because the Infivector hosted service does not receive them.
Infivector limits personal-data access to people and providers who need it for the service. They must protect confidentiality through contract or another binding duty. Infivector will process the data only on documented instructions, except where law requires otherwise.
Infivector maintains safeguards appropriate to the limited licensing data, including encryption in transit, restricted cloud roles, separation of signing duties, non-exportable signing keys, owner-scoped account routes, one-use authentication records, short authentication expiry, provider-secret storage and tested recovery or rollback procedures.
Customer authorizes the providers on the Subprocessor and Provider List. Infivector remains responsible for a subprocessor's duties to the extent required by applicable law. We will give at least 30 days' notice before adding a subprocessor that materially changes Team data processing. Customer may object on reasonable data-protection grounds during that period. We will work toward a practical alternative. If none is available, either party may end the affected service and we will refund the unused prepaid portion.
Taking account of the processing and information available to us, we will reasonably help Customer respond to data-subject requests, regulator inquiries, impact assessments and prior consultations. If a person contacts us about data controlled by Customer, we will refer the request to Customer unless law requires a direct response.
Infivector will notify Customer without undue delay after confirming unauthorized access to Customer personal data. The notice will include available information about the nature of the incident, affected data and subjects, likely consequences, containment and contact point. Early notice may be incomplete and updated as facts become available.
At the end of the service or on a verified instruction, Infivector will delete or de-identify Customer personal data within 30 days, except for data that law, billing, dispute resolution or service protection requires us to keep. Retained data remains protected and is used only for that purpose. Backup deletion follows the normal provider cycle.
The licensing service uses AWS in the United States. If EU GDPR transfer restrictions apply, the 2021 European Commission Standard Contractual Clauses, Module Two, are incorporated with Customer as exporter and Infivector as importer. This DPA and the processing details above complete the relevant annexes. The optional docking clause applies. For UK restricted transfers, the current UK International Data Transfer Addendum applies to those clauses. The governing law and courts for the clauses are selected as required by the clauses and applicable law.
On reasonable request, Infivector will provide information needed to demonstrate compliance with this DPA. Customer may review relevant documentation once per year and after a confirmed personal-data incident. A broader audit requires reasonable advance notice, must avoid exposing another customer's data and is at Customer's cost unless it identifies a material breach by Infivector.
This DPA controls if it conflicts with the Terms of Service about processing Customer personal data. The Terms of Service liability provisions apply to this DPA, subject to liability that applicable data-protection law does not permit a party to limit.
Privacy contact: [email protected]. Registered office: Infivector Technologies Private Limited, Om Chambers, 648/A, 1st Stage, 4th Floor, Binnamangala, Indiranagar, Bangalore North, Bangalore 560038, Karnataka, India.