Policies & Guidelines

Community standards, challenge and judging rules, and additional legal and compliance documents. For our core legal documents, see Terms of Service, Privacy Policy, Cookie Policy, and IP Policy.

Data Processing Agreement (DPA)

Last updated: July 2026

This document reflects InnoBee's current features and practices as of the date above. We update it regularly as the platform changes.

1. Purpose and Applicability

This Data Processing Agreement ("DPA") applies where your organization ("Customer," the data controller) uses InnoBee ("Processor") to process personal data of your employees, contractors, or other individuals in connection with running challenges, learning programs, or related activity on the Platform — for example, an internal innovation program with employee participants.

This DPA supplements our Terms of Service and forms part of the agreement between Customer and InnoBee for such processing. It does not apply to InnoBee's processing of individual users' own data as described in our Privacy Policy, where InnoBee is the controller.

This is a standard-form DPA. Enterprise customers with specific regulatory requirements (for example, healthcare or financial services customers) should contact legal@innobee.buzz to discuss additional terms before executing.

2. Roles of the Parties

For personal data covered by this DPA, Customer is the data controller and InnoBee is the data processor. InnoBee will process personal data only on Customer's documented instructions, including regarding international transfers, unless required to do otherwise by law — in which case InnoBee will inform Customer of that legal requirement before processing, unless the law prohibits such notice.

3. Details of Processing

3.1 Subject matter and duration

Provision of the InnoBee platform to Customer for the duration of the underlying subscription agreement.

3.2 Nature and purpose

Hosting, storage, and processing of personal data submitted by Customer or its authorized users in the course of creating and participating in challenges, learning activity, and related Platform features.

3.3 Categories of data subjects

Customer's employees, contractors, and other individuals it authorizes to use the Platform under its account.

3.4 Categories of personal data

Name, email, profile information, submission content, activity and performance data, and technical/usage data as described in our Privacy Policy.

4. Sub-processors

Customer authorizes InnoBee to engage the following sub-processors, and any additional sub-processor InnoBee provides at least 30 days' notice of before engagement (during which Customer may object on reasonable data-protection grounds):

  • Supabase — database hosting and authentication infrastructure
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Anthropic — AI features (InnoBee Queen), where Customer's users choose to use them
  • [Hosting/CDN provider — to be named]

5. Security Measures

InnoBee implements technical and organizational measures appropriate to the risk, including encryption in transit and at rest, row-level access controls, role-based internal access, regular internal production audits across 13 layers (authentication, database, security, and others — see our Trust Center), and periodic external penetration testing.

On reasonable written request, and no more than once per 12 months absent a security incident, InnoBee will make available a summary of its current security practices or relevant audit/pentest documentation, subject to confidentiality, via the Trust Center request process at innobee.buzz/trust.

6. Confidentiality

InnoBee ensures that persons authorized to process personal data under this DPA are subject to an appropriate duty of confidentiality.

7. Assistance with Data Subject Rights and DPIAs

InnoBee will provide reasonable assistance to Customer, taking into account the nature of processing, to help Customer respond to data subject requests (access, deletion, portability, etc.) and, where required, to conduct data protection impact assessments and consult with supervisory authorities.

8. Personal Data Breach Notification

InnoBee will notify Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting Customer's data, providing available details of the nature of the breach, likely consequences, and measures taken or proposed, consistent with our Incident Response Plan.

9. Deletion or Return of Data

On termination of the underlying subscription agreement, InnoBee will, at Customer's choice, delete or return all personal data processed under this DPA, except to the extent retention is required by law, consistent with the retention practices described in our Privacy Policy.

10. Audit Rights

InnoBee will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality, and no more than once per 12 months absent a specific compliance concern. Standard audit requests can often be satisfied through documentation available via our Trust Center without an on-site audit.

11. International Data Transfers

Where personal data is transferred outside the EEA/UK to a sub-processor, InnoBee relies on Standard Contractual Clauses or another lawful transfer mechanism, incorporated by reference into this DPA.

12. Liability

Liability under this DPA is subject to the limitations of liability set out in the underlying agreement between Customer and InnoBee (our Terms of Service or a separately negotiated enterprise agreement), except where applicable law prohibits limiting liability for a data protection violation.

13. Executing This DPA

To execute this DPA for your organization, contact legal@innobee.buzz. Enterprise/Diamond customers may request a countersigned copy; this published version otherwise applies by reference to organization accounts that process personal data on the Platform.