Skip to content
Legal

Data Processing Addendum

Last updated: August 1, 2026

This Data Processing Addendum (“DPA”) forms part of the Ion Terms of Service and reflects the parties' agreement with respect to the processing of personal data under the GDPR, CCPA, and other applicable data protection laws.

1. Definitions

  • “Controller” means the customer who determines the purposes and means of processing personal data.
  • “Processor” means Ion, which processes personal data on behalf of the Controller.
  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Sub-processor” means a third party engaged by Ion to process Personal Data.

2. Roles and scope

Ion acts as Processor on behalf of the Controller (customer). The subject matter, duration, nature, and purpose of processing, types of Personal Data, and categories of data subjects are described in the Terms of Service and this DPA.

3. Processing instructions

Ion will process Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required by law. Ion will not process Personal Data for its own purposes.

4. Confidentiality

Ion ensures that personnel authorized to process Personal Data are bound by confidentiality obligations and have received appropriate training on data protection.

5. Security measures

Ion implements appropriate technical and organizational measures, including:

  • AES-256 encryption at rest, TLS 1.3 in transit.
  • Strict access controls with least-privilege defaults.
  • Regular security assessments and penetration testing.
  • Incident detection and response procedures.
  • Employee background checks and security training.

See our Security page for full details.

6. Sub-processors

Ion engages the following categories of sub-processors: cloud hosting (AWS), email delivery, error monitoring, and analytics. The current list of sub-processors is maintained at our security pageand is updated with 30 days' notice for new additions.

Ion is liable for the performance of its sub-processors to the same extent as if Ion were performing the services directly.

7. Data subject rights

Ion assists the Controller in responding to data subject requests (access, correction, deletion, portability) by providing tools to export and delete data via the Ion API and dashboard. Additional assistance is available on request.

8. Personal data breach

Ion will notify the Controller of a personal data breach without undue delay, and in any case within 72 hours of becoming aware of it. Notification will include the nature of the breach, likely consequences, and measures taken or proposed.

9. Data protection impact assessments

Ion provides reasonable assistance to the Controller in conducting data protection impact assessments, where required by the GDPR.

10. Return and deletion

Upon termination of the Service, Ion will, at the Controller's choice, return or delete all Personal Data. Deletion occurs within 30 days of account closure, with backups purged within 90 days.

11. Audit rights

The Controller may audit Ion's compliance with this DPA, upon reasonable notice and not more than once per year. Ion will provide relevant documentation (including our SOC 2 Type II report) to reduce the need for direct audits.

12. International transfers

For transfers of Personal Data outside the EEA, UK, or Switzerland, Ion relies on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other recognized transfer mechanisms.

13. Contact

Our Data Protection Officer can be reached at dpo@ion.app.