Legal
Data processing agreement
Version 2026-08-27. Last updated 27 August 2026. Accepting it is part of creating a workspace, and the version you accepted is recorded and shown in your settings.
1. Who is who
You are the controller of the personal data you put into Indraft. O'Shea & Sons, LLC is the processor, and acts only on your documented instructions. Using the product is such an instruction. Where you are yourself a processor for your own client, we are a sub-processor and this agreement passes through to them. Which of those two you are decides which module of the Standard Contractual Clauses applies to transfers, and section 5 sets that out.
“Customer personal data” means personal data contained in or generated from the CRM records you submit to Indraft. It does not include the account, billing, or business-contact information O'Shea & Sons processes for its own service administration and legal obligations, which is covered by the privacy policy.
This matters more here than in most products. Indraft holds personal data about people who never chose us: your customers and prospects. They exercise their rights through you, and we have to be able to help you answer them.
2. What we process, and what we refuse
CRM records you or your agents create, interaction summaries with their author and assertion kind, a bounded evidence snippet, the change ledger, and a control plane holding your organization mapping, credential hashes, billing state, and usage counters.
The people represented in customer personal data may include your users and employees, your customers and prospective customers, your vendors and counterparties, and other people whose information you choose to maintain in the CRM.
Indraft provides no dedicated storage or ingestion for email bodies, call transcripts, recordings, attachments, or arbitrary files. The product is deliberately designed not to collect or retain those source materials, and it makes no model calls in any code path. Free-text summaries and custom fields accept whatever you write, so we do not claim it is impossible to paste something into a field we did not design for it. We claim that we built no place for it and ask for none.
3. Duration and purpose
We process for as long as your workspace exists, for the sole purpose of providing the product. We do not use your data to train models, to build a profile of you or the people in your records, or for any purpose of our own. Indraft makes no model calls in any code path, so no part of your data reaches a model provider through us.
4. Our obligations as processor
People authorized by O'Shea & Sons to process customer personal data are bound by confidentiality obligations that survive the end of their engagement. We maintain technical and organizational measures appropriate to the risk of the processing, and we describe them in the SCC appendix. Taking into account the nature of the processing and the information available to us, we will reasonably assist you with data-subject requests and with your own obligations concerning security, personal data breaches, data protection impact assessments, and consultations with supervisory authorities. If we believe an instruction from you infringes applicable data protection law, we will tell you before carrying it out, unless the law prohibits us from doing so.
5. Sub-processors
We give thirty days' written notice by email to every workspace owner before a new subprocessor starts processing customer data, and you may object in that window. Updating this page is not notice on its own.
| Sub-processor | Processes | Why |
|---|---|---|
| Cloudflare | All CRM data, at rest and in transit, and the email address we send service notices to | Hosting, application compute, content delivery, and the transactional email we send you about your own workspace. Your workspace data is stored and processed on Cloudflare infrastructure, and mail goes through Cloudflare's own service rather than a separate provider, so this list stays as short as it is. |
| WorkOS | Identity: user, organization, membership, and role | Authentication and MCP authorization. Indraft implements no passwords and issues no sessions of its own. |
| Stripe | Billing contact and payment data | Subscriptions, hosted Checkout, and the Customer Portal. No CRM record reaches Stripe. |
No model provider is on that list, and that is not an omission.
Each sub-processor is bound by written data protection obligations no less protective than the relevant obligations in this agreement. We remain responsible to you for each sub-processor's performance of those obligations.
6. Where processing happens
Your workspace runs on Cloudflare's global network and is not pinned to a region. O'Shea & Sons, LLC is a United States company, so treat processing as taking place in the United States and wherever Cloudflare operates.
Transfers out of the UK and EEA
Where a restricted transfer is subject to the GDPR, the European Commission's 2021 Standard Contractual Clauses apply: Module Two where you are a controller and O'Shea & Sons is your processor, and Module Three where you are a processor and O'Shea & Sons is your sub-processor. The applicable module and the annex information those clauses require are completed by the SCC appendix to this agreement. For restricted transfers subject to UK data protection law, the UK International Data Transfer Addendum to those clauses also applies. We do not hold a Data Privacy Framework certification and do not rely on one.
The completed annex information, the module selections, and the UK Addendum tables are in the SCC appendix, which forms part of this agreement.
7. Security
Each workspace uses a separate database rather than storing every customer's records in shared tables. This removes any dependence on row-level tenant filters for workspace isolation and reduces the blast radius of an application-layer query error. It is a significant reduction in risk rather than a mathematical guarantee, and we would rather describe it accurately than oversell it. Data is encrypted in transit and at rest by our infrastructure provider. Access to production is limited to the people who operate it. Credentials are stored only as hashes and are shown once. The measures are set out in full in the SCC appendix.
We describe controls rather than claiming an outcome. We hold no SOC 2 report and no ISO certification, and we will say so plainly rather than implying otherwise.
8. Personal data breaches
We notify you without undue delay and, where feasible, within 24 hours of becoming aware of a personal data breach affecting your workspace, with what we know, what we are doing, and what we do not yet know. A notice that waits for certainty is a notice that arrives too late to be useful to you.
Seventy-two hours is your deadline as controller, not ours as processor. If we took that long you would have no time left to make your own decision, which is why the number here is shorter than the one you may be used to seeing in a processor's terms.
9. Helping you answer the people in your records
You can export everything in your workspace yourself, at any time, from Settings. Erasure of one person's record is within thirty days of your request. Workspace deletion is scheduled immediately and destroyed within seven days, with backups and replicas expiring within thirty-five. The commitments and the reasoning are on the deletion and portability page.
10. United States state privacy laws
Where applicable United States state privacy law treats O'Shea & Sons as a service provider, contractor, or processor, we act in that role. The limited purposes for which we process customer personal data are storing, organizing, retrieving, transmitting, securing, and otherwise operating the CRM functionality you direct us to provide, together with related support and security.
We do not sell or share customer personal data. We do not retain, use, or disclose it outside those purposes or outside the direct business relationship with you, except as applicable law permits. We do not combine it with personal data obtained from another customer or from our own interaction with the person, except where applicable law permits it. We provide the level of privacy protection required of a service provider or processor under applicable law, we will tell you if we determine that we can no longer meet those obligations, we will reasonably assist you with applicable consumer requests, audits, and risk assessments, and we will allow you to take reasonable steps to stop and remediate unauthorized processing.
11. Audit
We provide the information reasonably necessary to demonstrate our compliance with this agreement. An audit should ordinarily be satisfied through our written responses, our documentation, and remote review. Where those materials are not sufficient to satisfy a requirement of applicable data protection law, you or an independent auditor appointed by you may carry out a further audit, on reasonable advance notice and subject to appropriate confidentiality, security, scope, frequency, and non-disruption conditions.
In practice we expect written answers and documentation to settle almost every review, and we would rather say now than during procurement that we are a small company: an inspection is available where the law requires one, and it is not the cheap first step for either of us.
12. Ending
On termination you may export your workspace data yourself, or instruct us to delete it. If you do neither before access ends, we delete it on the timetable above. We do not retain a copy beyond backup expiry.
13. Governing law
Illinois, United States, and the courts of Illinois. This agreement forms part of the terms of service and prevails over them on anything concerning personal data.
One exception, and it is not ours to waive. Where the Standard Contractual Clauses apply, their own governing law and forum provisions govern those clauses, together with the third-party beneficiary rights they give the people whose data is transferred. The selections are recorded in the SCC appendix. Illinois law governs the rest of this agreement and does not displace them.
What this page does not do
It describes what the system does and what we commit to. It does not award us a compliance verdict, a certification, or a coverage claim, because those are not ours to award and your counsel is better placed to judge than our marketing is.