DataInlet Privacy Policy
Legal document bodies are currently available in English only.
On this page
Effective date: September 1, 2026
Last updated: September 2, 2026
This Privacy Policy explains how Chang Wu, an individual operating the DataInlet service (DataInlet, we, us, or our), handles personal information in connection with the DataInlet website, accounts, hosted application, communications, and related services.
For privacy questions or requests, contact [email protected]. General support is also available at [email protected] or +86 131 2100 9003.
DataInlet is a business-oriented service. It is not directed to children and is not intended primarily for personal, family, or household use.
1. Our privacy roles
DataInlet handles personal information in two different roles.
1.1 DataInlet as controller
We determine the purposes and means of processing for information used to operate our own business, such as:
- account and profile information;
- website and application security information;
- billing and subscription metadata;
- service administration and usage information;
- sales, support, partnership, and contact inquiries;
- legal and compliance records.
For this information, DataInlet acts as a controller or equivalent business under applicable privacy law.
1.2 DataInlet as processor
Customers may submit files, records, target-system data, prompts, instructions, and other content that contains personal data. When we process that information on behalf of a business customer to provide the Service, the customer generally determines the purpose of the processing and DataInlet acts as a processor or service provider.
That processing is governed by our Data Processing Addendum where applicable. Individuals whose information appears in Customer Content should generally direct privacy requests to the customer that provided the information to DataInlet.
2. Information we collect
Depending on how you interact with DataInlet, we may collect the following categories of information.
2.1 Account and identity information
This may include name, email address, organization membership, authentication identifiers, role or permission information, account preferences, and related identity metadata.
2.2 Business contact and communications
If you contact us, we may collect your name, work email, company, inquiry topic, message, support details, and other information you choose to provide.
We may use communications service providers to deliver or organize these messages. For example, a website contact submission may be forwarded to a business communications service so that we can receive and respond to it.
2.3 Billing and subscription information
We may receive information about your subscription, plan, billing status, transaction identifiers, invoice status, credits, refunds, or payment events from Paddle, our authorized reseller and Merchant of Record for self-service purchases. We do not need to store full payment-card numbers to operate the Service.
Paddle independently processes payment and transaction information in its role as Merchant of Record. Paddle's own privacy notice applies to information it processes in that role.
2.4 Service, device, and security information
We may collect IP address, request timestamps, browser or device information, authentication events, error information, audit identifiers, usage events, and other technical data reasonably necessary to operate, secure, diagnose, and improve the reliability of the Service.
2.5 Customer Content
Customer Content may include Excel or CSV files, attachments, product information, customer or supplier records, employee or organizational information, target-system records, import instructions, prompts, source facts, previews, run state, validation results, and generated import or export results.
The specific personal data in Customer Content is determined by the customer, not DataInlet.
3. How we use personal information
We use personal information as reasonably necessary to:
- provide, maintain, secure, and administer the Service;
- authenticate users and manage permissions;
- analyze source data and connected-system evidence and produce import results;
- perform Customer-authorized imports, exports, validations, and related operations;
- process subscriptions, Credits, payments, refunds, and account status;
- respond to sales, support, product, partnership, and other inquiries;
- troubleshoot failures and maintain service reliability;
- prevent fraud, abuse, unauthorized access, and security incidents;
- comply with legal obligations and enforce our agreements;
- create aggregated operational metrics that do not contain Customer Content and cannot reasonably identify a customer or reconstruct Customer Content.
4. AI processing, zero retention, and training
DataInlet uses third-party AI routing and inference services to perform parts of the import workflow, including source understanding, target-system reasoning, and generation of structured decisions.
We do not use Customer Content to train or fine-tune general-purpose AI models.
For production AI inference, DataInlet applies a zero-data-retention (ZDR) policy at the third-party AI boundary. Customer Content is sent only through approved AI routing and inference services or endpoints configured so that prompt and model-response content is not retained after inference, except where retention is strictly required by applicable law, and is not used for general-purpose model training or product improvement.
When DataInlet uses OpenRouter, production requests are configured to require ZDR-capable providers, deny data-collecting providers, and disable provider fallbacks. DataInlet does not intentionally enable provider-side prompt logging, feedback, dataset contribution, or similar optional features that would retain Customer Content or use it for model or product improvement.
This ZDR commitment applies to third-party AI routing and inference processing. It does not mean that DataInlet itself stores no Customer Content. DataInlet retains Customer Content in accordance with Section 8, Customer-configured retention settings, deletion requests, and applicable law.
5. Legal bases for processing
Where the EU GDPR, UK GDPR, or similar law requires a legal basis, we generally rely on:
- performance of a contract to provide accounts and the Service requested by a business user;
- legitimate interests in securing, operating, supporting, and improving the reliability of our business service, where those interests are not overridden by applicable rights;
- legal obligations where we must retain or disclose information by law;
- consent where a specific activity legally requires consent.
When DataInlet processes Customer Content as a processor, the customer is responsible for determining the applicable legal basis for that processing.
6. How we disclose information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
We may disclose information to:
- cloud infrastructure providers that host the Service and Customer Content;
- AI routing and inference providers used to perform the Service;
- identity and security services used to authenticate users or protect accounts;
- Paddle, our authorized reseller and Merchant of Record, for transactions, billing, taxes, refunds, and related payment administration;
- communications and support services used to receive and respond to inquiries;
- professional advisers, auditors, insurers, or prospective transaction counterparties where reasonably necessary and subject to appropriate confidentiality obligations;
- government authorities or other parties where disclosure is required by law or reasonably necessary to protect legal rights, security, or safety.
A current list of subprocessors that may process Customer Content on behalf of DataInlet is available in the DataInlet Subprocessor List.
7. Infrastructure and international processing
DataInlet uses Google Cloud Platform (GCP) for production cloud infrastructure and stores production Customer Content in the United States unless a separate written agreement states otherwise.
Personal information may also be processed from the location of DataInlet's operator and in other countries where our service providers operate. Privacy and data-protection laws in those countries may differ from the laws where you live.
Where applicable law requires a transfer mechanism for Customer personal data, DataInlet uses contractual or other safeguards described in the Data Processing Addendum, including applicable standard contractual clauses.
8. Retention and deletion
8.1 Customer Content
The default Managed Service retention mode does not automatically expire an Inlet solely because time has passed. Customers may configure an inactivity-based retention period where that feature is available, and may explicitly request deletion of an Inlet and its DataInlet-controlled content.
An Inlet deletion is designed to remove DataInlet-controlled source content and derived content associated with that Inlet, including applicable run content and generated artifacts. It does not automatically delete business records already written to a Customer-controlled target system such as Odoo.
Deletion may not immediately remove data from disaster-recovery backups. Deleted content may remain in protected backups until those backups are overwritten or expire through the ordinary backup-rotation process. Backups are not intended to be used as an active source of deleted Customer Content.
8.2 Account and business records
We retain account, security, billing, tax, support, and legal records for as long as reasonably necessary for the purpose for which they were collected, to maintain legitimate business records, resolve disputes, prevent abuse, or comply with law.
Contact inquiries may be retained as part of ordinary business correspondence for as long as reasonably necessary to respond and maintain the business relationship.
9. Cookies and local storage
DataInlet may use cookies, browser storage, or similar technologies that are reasonably necessary for authentication, account security, session continuity, preferences, billing return flows, and core application functionality.
DataInlet does not currently use these technologies for third-party behavioral advertising. If we introduce non-essential analytics or advertising technologies that require consent under applicable law, we will update this Policy and provide appropriate controls.
10. Security
We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, encryption in transit, controlled secret handling, service isolation, logging, backups, and incident-response procedures appropriate to the Service.
No security measure can guarantee absolute security.
11. Your privacy rights
Depending on where you live and the law that applies, you may have rights to request access to personal information, correction, deletion, restriction, objection, portability, or information about processing.
Where applicable, you may also have rights regarding the sale or sharing of personal information or the use of sensitive personal information. DataInlet does not sell personal information or use it for cross-context behavioral advertising.
To exercise a right relating to information that DataInlet controls, contact [email protected]. We may need to verify your identity before completing a request.
If your request concerns Customer Content that DataInlet processes for a business customer, please contact that customer first. We will reasonably assist the customer as required by our DPA and applicable law.
EEA and UK individuals may also have the right to complain to the competent data-protection authority.
12. Children
The Service is intended for business users age 18 or older. Customers must not intentionally use self-service DataInlet plans to submit personal data about children unless DataInlet has expressly agreed in writing to the applicable processing requirements.
13. Changes to this Policy
We may update this Privacy Policy as our Service, subprocessors, legal obligations, or practices change. We will update the effective or last-updated date and provide additional notice when required by law or when a change materially affects how we handle personal information.
14. Contact
DataInlet
Operated by: Chang Wu
Privacy and support: [email protected]
Phone: +86 131 2100 9003