Legal
Data processing.
Last updated: April 2026 · Entity: AdellaInsight, Inc.
This Data Processing & Compliance Policy explains how AdellaInsight, Inc. (“AdellaInsight”, “we”, “us”, or “our”) collects, processes, and protects personal data when you use adellainsight.com and our services (the “Services”).
This policy is designed to support our business customers and reflects our commitment to enterprise-grade data protection, security, and regulatory compliance.
Our role
Depending on how you use our Services, AdellaInsight acts as:
- Data Controller – for account management, billing, and business operations
- Data Processor – when processing customer data on behalf of our clients
When acting as a Data Processor, we process personal data only in accordance with our customers’ instructions and applicable law.
Data we process
We may process the following categories of personal data:
- Account data (name, email, company details)
- Usage data (interactions with the platform, analytics)
- Technical data (IP address, device, browser)
- Customer data uploaded or processed by clients
- Support and communication data
We do not intentionally collect sensitive personal data unless explicitly required and authorized by the customer.
Legal bases for processing
Where applicable, we rely on:
- Contractual necessity – to deliver our Services
- Legitimate interests – to improve and secure our platform
- Consent – for marketing and certain tracking technologies
- Legal obligations – regulatory compliance
GDPR compliance
AdellaInsight is committed to complying with the General Data Protection Regulation (GDPR).
Article 28 (Processor obligations)
When acting as a processor, we:
- Process data only on documented instructions
- Ensure personnel confidentiality obligations
- Implement appropriate security measures
- Assist customers with data subject requests
- Support compliance with Articles 32–36 (security, breach notification, DPIAs)
- Delete or return data upon termination (as requested)
Data Processing Agreement (DPA)
We offer a Data Processing Agreement (DPA) for all business customers.
Our DPA includes:
- Scope and purpose of processing
- Categories of data and data subjects
- Subprocessor obligations
- Security commitments
- International transfer safeguards
To request a DPA, contact us at insight@adelladigital.com
Subprocessors
We may use trusted third-party subprocessors to operate the Services, such as:
- Cloud infrastructure providers
- Analytics services
- Payment processors
- Customer support tools
We:
- Maintain a list of subprocessors (available upon request)
- Require subprocessors to meet strict data protection standards
- Enter into data processing agreements with all subprocessors
International data transfers
AdellaInsight may process data globally.
Where personal data is transferred outside of jurisdictions like the EEA or UK, we implement safeguards such as:
- Standard Contractual Clauses (SCCs)
- Equivalent legal transfer mechanisms
- Vendor risk assessments
Data retention
We retain personal data only as long as necessary to:
- Provide the Services
- Meet contractual and legal obligations
- Resolve disputes
Upon termination of Services, we will:
- Delete or return customer data upon request
- Retain minimal data only where legally required
Security measures (Article 32)
We implement enterprise-grade security controls, including:
Technical safeguards
- Encryption in transit (TLS) and at rest (where applicable)
- Secure cloud infrastructure
- Access controls and role-based permissions
- System monitoring and logging
Organizational safeguards
- Employee confidentiality agreements
- Security training and awareness
- Access limitation on a need-to-know basis
Security certifications and standards
AdellaInsight aligns its practices with industry standards such as:
- SOC 2 (where applicable or in progress)
- ISO 27001 principles (best practices)
- OWASP security guidelines
Details on certifications or audit reports may be available upon request.
Data breach notification
In the event of a personal data breach, AdellaInsight will:
- Notify affected customers without undue delay
- Provide relevant details about the incident
- Assist customers in meeting regulatory obligations
Where applicable, we aim to support breach notifications within 72 hours in alignment with GDPR expectations.
Data subject rights
We assist our customers in responding to data subject requests, including:
- Access
- Correction
- Deletion (“right to be forgotten”)
- Data portability
- Restriction or objection to processing
Requests should be submitted by the data controller (our customer). We will respond promptly in accordance with our contractual obligations.
Privacy by design and default
We incorporate data protection into our systems and processes by:
- Limiting data collection to what is necessary
- Implementing secure defaults
- Regularly reviewing processing practices
- Minimizing access to personal data
Customer responsibilities
Customers using AdellaInsight are responsible for:
- Ensuring they have a lawful basis to process data
- Providing required notices to end users
- Obtaining necessary consents
- Configuring the platform in a compliant manner
Third-party services
Our Services may integrate with third-party tools.
Customers are responsible for reviewing and approving any third-party integrations they enable.
Updates to this policy
We may update this policy periodically to reflect changes in legal, technical, or business requirements.
Updates will be posted with a revised “Last updated” date.
Contact us
For questions, compliance requests, or to obtain a DPA or subprocessor list:
Email: insight@adelladigital.com
Enterprise trust
We are committed to building AdellaInsight with security, transparency, and compliance at its core — so you can confidently use our platform in your business and with your customers.