This is the latest revision, scheduled for November 7, 2026. The new consent procedures and deletion features are not yet in effect.

Read the advance notice

Data Processing Addendum (DPA)

Version: 2026-10-07.1

Prepared / Last Updated: October 7, 2026

Scheduled Effective Date: November 7, 2026

Application Date: The later of November 7, 2026, and valid express customer acceptance under Section 2

Advance notice / scheduled changes

This revision is scheduled to take effect on November 7, 2026, with this document prepared on October 7, 2026. Important changes are announced at least 30 days before they take effect. Matters requiring express customer consent apply from the later of the announced effective date and valid consent.

New Terms acceptance records, DPA and subprocessing consent and evidence management, customer permanent deletion, and automatic deletion three years after initial submission are planned for November 7, 2026. They are not considered implemented or applicable until development, verification, and necessary consent are complete. Changes to the schedule will be announced in advance with the required notice and consent procedures. Acknowledging or closing a notice is not consent to the Terms, DPA, subprocessing, or personal data processing.

Unimplemented or unverified safeguards and access records describe performance standards and planned measures, not confirmation that every measure is already implemented. Provider settings were checked on October 1-2, 2026, as stated in the relevant schedules and annexes; this revision does not constitute a new verification. Existing statutory duties and valid deletion requests remain in effect.

Section 1. Parties and Purpose

This Addendum sets out the rights and obligations regarding entrusted processing of personal data between a customer collecting and managing form submissions containing personal data on its sites (the "Customer" or "Controller") and inblog Inc., operator of Neopress (the "Company" or "Processor"). It supplements the Neopress Terms of Service.

The Customer and accepting representative are identified through online checkbox acceptance records retained with this Addendum. It applies to form submissions on all sites currently operated or subsequently created by the Customer through the account. A person accepting for a company or another customer confirms that they have representative or delegated authority to enter into this Addendum.

Undefined terms follow applicable law, including Korea's Personal Information Protection Act (PIPA), its Enforcement Decree, and the Standards for Ensuring the Safety of Personal Information.

Section 2. Application and Processing Term

  1. New customers review this Addendum and the subprocessor list during registration; existing customers review them in a popup when entering the dashboard. They accept by actively selecting a checkbox and pressing the acceptance button. Online acceptance and evidence procedures are planned for November 7, 2026, and will be provided after development and verification. This Addendum applies from the later of November 7, 2026, and confirmed valid express acceptance by the Customer or its authorized representative.
  2. Scope is managed at account level under Section 1; separate consent or records for each site are not required. An employee or collaborator invited to another customer's site is subject to the DPA validly entered into by that site's owner. The invited user's personal acceptance is not treated as the owner's acceptance. An agency's acceptance is effective within the authority delegated by the customer; otherwise the customer or an authorized representative must accept.
  3. This Addendum also applies to submissions remaining on covered sites when it first becomes applicable, but does not retroactively establish consent or legality for past processing.
  4. The processing term covers provision of the form service and the time needed afterward to complete lawful return, destruction, and residual-copy handling. General use of data does not continue after service termination.
  5. Reading a notice or popup, closing it, silence, or continued use is not acceptance of this Addendum or required subprocessing consent. Customers who have not signed in or consented remain pending. Permitted use and any necessary termination and return procedures for non-consenting customers are explained in advance under Terms Section 14.
  6. The Processor retains the accepting account; represented customer and confirmation of representative or delegated authority, if applicable; Addendum and annex versions and contemporaneous copies; separate consent results; and time and method of acceptance. The Customer can read and save the applicable documents. Grounds and periods for retaining consent records follow Section 6.5.

Section 3. Purpose and Scope of Processing

  1. Processing consists of receiving, transmitting, storing, viewing, sending notifications about, returning, and deleting form submissions in Annex 1, and necessary customer support, incident recovery, and security response.
  2. The Processor follows the Customer's lawful, recorded instructions. Form settings, notification-recipient settings, deletion requests, and acceptance records under this Addendum form part of those instructions.
  3. During and after the agreement, the Processor does not use, disclose, or provide data to third parties outside the entrusted purpose. It does not arbitrarily copy or export submissions beyond what the work requires. Backups and lawful return follow the specified purposes and safeguards. This Addendum alone does not authorize use of submissions for separate advertising, general-purpose AI model training, or other customers.
  4. If an unlawful instruction is identified, the Processor informs the Customer and discusses correction, cessation, or other necessary measures. If urgent protection is needed, the Processor may act first and explain the reason afterward.

Section 4. Customer Responsibilities

  1. The Customer determines data fields, purposes, and retention periods and meets the legal grounds, notice, and consent requirements for collection, use, and any sensitive-data processing or international transfer.
  2. The Customer collects only necessary information and manages staff accounts and permissions for viewing submissions and notification-recipient addresses.
  3. If earlier deletion is required, including a shorter retention period or fulfillment of the purpose, the Customer acts without delay through available deletion functions or a request to the Processor. The Processor's general retention policy does not give the Customer a statutory basis to retain data.
  4. The Customer manages notification emails received in its mailbox and files it downloads or separately copies. Responsibility for Processor-managed backups and subprocessor copies is not transferred to the Customer.
  5. This section does not exclude statutory obligations directly applicable to the Processor.

Section 5. Processor Safeguards and Staff Access

  1. The Processor implements legally required technical, organizational, and physical safeguards and grants the minimum necessary personnel only necessary access.
  2. Access to submissions is limited to permitted purposes, including support, incident recovery, and security response, and to necessary customer sites, submissions, and fields. The purpose and targets are recorded in related support or incident records. For emergencies, minimum necessary steps may be taken first, with reasons and actions recorded by the next business day for retrospective review.
  3. Individual accounts identify personnel as a rule. Special operations accounts, direct DB access, and service accounts are also managed. Permissions are changed or revoked when no longer needed, including role changes or departure. Manual operations through service accounts must be traceable to the operator.
  4. Infrastructure safeguards include encryption in transit and at rest, authentication, and access controls; their scope follows Annex 2. Encryption at rest does not itself prevent access by authorized operators.
  5. The privacy officer approves access and records personnel, scope, and duration in an authorization register. Grants, changes, and revocations are retained for three years from occurrence. Safe authentication, including multifactor authentication, is applied to administrator and DB access.
  6. The Processor provides privacy training and confidentiality management for staff. Confidentiality continues after role changes, departure, and termination of this Addendum.

Section 6. Access Records and Processing Evidence

  1. The Processor retains and manages personal-data-system access records for two years from creation and protects against unauthorized access, alteration, loss, and similar events.
  2. Records include personnel identifier, time, source location, target identifiers, operation, result, and other information necessary for traceability. Submission contents are not copied into separate audit records.
  3. Recording covers viewing, downloading, changing, and deleting form submissions through administrator and customer dashboards, APIs, and direct DB access. Automated operations link to job identifiers and staff manual operations to personnel identifiers. Lists and bulk actions must enable tracking of actual targets and meet legally required logging standards.
  4. Access records and downloads are reviewed at least monthly, including reasons for downloads and missing records. Anomalies are promptly investigated, access restricted or other necessary steps taken, and reported to the privacy officer. Review results are retained for two years from preparation.
  5. Other evidence, including consent and deletion results, is managed by purpose using minimum necessary fields. Access-log retention does not automatically apply to every record type. Deletion results are kept for two years after the operation is closed to verify deletion, address errors, and re-delete after backup restoration, then destroyed. Agreement acceptance evidence is retained during the agreement and for five years after termination on the grounds of contract formation and performance and the Processor's legitimate interests in proving formation and responding to disputes. Only minimum necessary consent evidence is retained separately and destroyed without delay on expiry. These records are distinct from the three-year automatic deletion of form submissions. Records subject to a separate statutory retention duty are segregated and retained only for that period.
  6. These standards establish performance duties. Verification of per-submission logging and retention across all paths is ongoing. The Processor manages gaps and improvement plans and accurately informs the Customer about actual coverage. This does not defer statutory duties or exempt liability.

Section 7. Subprocessing and International Transfers

  1. When accepting this Addendum, the Customer reviews the providers, work, data, and countries in Annex 3 and consents to subprocessing within that scope. The version and content of the annex at acceptance are retained with the acceptance record.
  2. Before adding a subprocessor or changing work, data, or countries beyond the consented scope, the Processor provides details in advance and obtains any customer consent required by law. The procedure uses a dashboard-entry popup and checkbox acceptance and preserves the accepted content and records. The changed scope does not apply to that Customer until required consent is confirmed.
  3. The Processor contractually imposes necessary protection duties on subprocessors and performs legally required management and supervision. Subprocessing does not exempt its responsibility.
  4. International transfers meet the purpose-specific legal grounds and disclosure, notice, and consent requirements in Privacy Policy Section 5. For entrusted form reception and storage necessary to form or perform a contract between the Customer and submitter, the Customer discloses statutory transfer details in its privacy policy and applies PIPA Article 28-8(1)(3)(a). Transfers for purposes not meeting those criteria require a lawful ground, such as the submitter's separate consent under Article 28-8(1)(1). Form-notification emails use that disclosure approach only where necessary for contract formation or performance; internal convenience alone does not establish necessity. If requirements are not met, separate international-transfer consent must be obtained or email notifications must not be used. Customer DPA or subprocessing acceptance does not replace data-subject transfer consent.
  5. The Processor supplies accurate processing details and changes so the Customer can reflect them in its privacy policy and forms. Annex 3 specifies subprocessor names, information and purposes, operational DB location, request-processing locations, mail storage and sending countries, and retention and deletion criteria.
  6. Refusal or suspension of international transfers, or withdrawal of transfer consent, may be requested at contact@email.neopress.ai; submitters may also contact the site operator's privacy contact. Refusal of transfers needed for form reception and storage restricts online reception through that form. The Customer explains whether phone, in-person, or other alternatives are available. If notification-email transfers are refused, the Customer can disable notifications and view submissions in the dashboard, although that still relies on Supabase and Vercel. Unrelated functions are not restricted indiscriminately. Previously transferred data follows applicable retention and deletion criteria.

Section 8. Retention, Deletion, and Return

  1. The Processor retains information only as necessary for the entrusted purpose and lawful Customer instructions. Data is destroyed without delay as required by law upon a deletion request, fulfillment of purpose, termination, or when otherwise unnecessary. If prompt handling is difficult, the Processor explains the reason, measures, and expected completion time.
  2. Before customer permanent deletion is available, requests are accepted at contact@email.neopress.ai and processed after authority and target verification. Hiding a record or merely marking it deleted is not described as permanent destruction.
  3. Customer permanent deletion and automatic deletion three years after initial submission are planned for November 7, 2026. After development and verification and before each feature takes effect, service notices and dashboard-entry popups explain the date, scope, method, irreversibility, and backup treatment. Following necessary consent, they apply from the announced date under Annex 2. Before then, deletion follows paragraph 2; feature rollout is not a reason to defer valid destruction requests.
  4. At service termination or a lawful Customer request, data is returned in a commonly available electronic format or deleted, at the Customer's choice. If return is needed, the parties arrange timing and a secure delivery method before deletion; return does not automatically create a grace period delaying statutory destruction. Remaining copies after return follow the deletion criteria.
  5. Where law requires separate retention, the Processor identifies the ground, scope, and period to the Customer, segregates necessary data, and uses it only for that purpose.
  6. Deletion management distinguishes operational DB submissions, Processor-managed replicas, and subprocessor copies. Deleting operational data does not immediately delete individual records in existing backups. Access and use of residual copies are restricted and provider retention and deletion procedures apply. Provider-specific periods and backup handling follow Annex 3. On restoration, previously deleted submissions are removed before service exposure. Identifiers needed for re-deletion are retained separately from the backup being restored.
  7. The Processor records requester or automated job, target identifiers and count, request and processing times, success, failure, and retries. Customers can check the outcome of direct deletion on the processing screen. Results of separately requested or end-of-processing return or destruction are reported without delay. Automatic deletion results are supplied to the necessary extent on request. If backup handling remains, operational deletion completion and destruction of all copies are distinguished.

Section 9. Assistance with Data-Subject Rights

The Processor assists with searches, provision, deletion, and related materials so the Customer can respond to access, correction, deletion, suspension, and consent-withdrawal requests. If contacted directly, it takes necessary steps, including identity and authority verification and secure referral to the Customer, and cooperates without delay considering statutory deadlines. Unless law requires otherwise, it does not arbitrarily replace the Customer's substantive decisions.

Section 10. Personal Data Incident Response

  1. Upon learning of an incident, including disclosure of entrusted personal data, the Processor promptly informs the Customer's designated contact and takes containment, investigation, and recovery measures. Initial notice is not deferred until the whole investigation is complete.
  2. Notice includes known occurrence and detection times, data fields, scale and impact, current measures, recommendations, and a contact person. Unconfirmed facts are supplemented later.
  3. The Processor assists with data-subject notification and regulator reporting and fulfills directly applicable statutory duties. Incident evidence is protected against damage and lawfully preserved.

Section 11. Supervision and Review

  1. The Processor supplies materials necessary to review safeguards, access permissions, records, subprocessing, and deletion, and cooperates with training and supervision.
  2. Reviews prioritize documents while protecting other customers' information and security. Methods and schedules may be agreed where needed; that coordination must not unduly restrict statutory supervision or incident response.
  3. Identified gaps are managed with improvement actions, owners, deadlines, and results.

Section 12. Responsibility

Each party bears liability under applicable law for loss caused by its violation of law or this Addendum. The Processor also bears legally attributable responsibility for loss caused by its personnel or subprocessors. Where the Customer compensates a data subject or third party for loss attributable to the Processor's side, it may seek recourse to the extent recognized by law. Use of subprocessors does not exempt statutory responsibility. This Addendum does not restrict data subjects' damages rights or duties that cannot be excluded by agreement. Disclaimers, liability limitations, and indemnification in the Terms do not apply to the extent they conflict with mandatory law or this Addendum.

Section 13. Document Priority and Changes

This Addendum prevails over the Terms in a conflict about entrusted processing of form submissions. The Privacy Policy's statutory effect and legal standards, including contract terms favorable to data subjects, remain applicable. Important changes are announced with their content, reasons, and application date through service notices and dashboard-entry popups from at least 30 days before application through that date. Changes requiring consent by law or contract apply after checkbox consent by an authorized Customer representative. Silence or continued use is not consent. Terms Section 14 also governs advance-notice periods and treatment of non-consenting customers. Any separate statutory notice method or procedure must also be followed.

Section 14. Contact

Processor privacy and DPA inquiries: contact@email.neopress.ai / +82-503-7150-2997

Customer representative and incident contact: the contact registered in the customer account or otherwise designated by the Customer

Annex 1. Entrusted Information and Processing

ItemDetails
Covered customer and sitesAll sites currently operated or subsequently created by the accepting Customer through the account. Invitations and representative acceptance follow Section 2
Data subjectsSubmitters of appointment, consultation, and inquiry forms on customer sites
Form inputFields actually configured, including name, date of birth, contact details, email, messenger ID, selections, inquiry text, and consent responses
Submission-management informationSite, form, and submission identifiers, submission time, and form-field configuration
Sensitive informationProcessed only where actually collected by the Customer's form and within the lawful grounds, notice, and consent requirements of Section 4
PurposesReception, transmission, storage, viewing, notification, return, deletion, and necessary support, incident recovery, and security response
FrequencyDuring submission, viewing, notification, support, deletion, and backup operations
PeriodSection 8 and Annex 2; earlier deletion grounds applicable to the Customer are not excluded

Annex 2. Protection and Deletion Standards

Safeguards and Processing Evidence

This table specifies the performance standards in Sections 5 and 6. Actual implementation and gaps are described according to verification results. Unimplemented or unverified measures are not marked complete.

ItemStandard
Safeguard principleLegally required technical, organizational, and physical safeguards; minimum necessary personnel and permissions
Access purposes and scopePermitted purposes, including support, incident recovery, and security response; limited to necessary sites, submissions, and fields
Access-purpose records and emergenciesPurpose and targets recorded in related support or incident records. Minimum emergency steps may precede recording; reasons and actions documented by the next business day for review
Accounts and operator identificationIndividual accounts as a rule; special operations accounts, direct DB access, and service accounts managed. Staff manual operations through service accounts linked to the operator
Permission approval and revocationPrivacy officer approval with personnel, scope, and period recorded. Permissions changed or revoked when unnecessary, including role changes or departure. Grant, change, and revocation records retained for three years from occurrence
Administrator authentication and accessSafe authentication, including multifactor authentication, and access controls for administrator and DB access, distinct from dashboard 2FA availability
Training and confidentialityPrivacy training and confidentiality management; confidentiality continues after role changes, departure, and Addendum termination
EncryptionHTTPS for form submissions and Resend API transmission. AES-256 encryption at rest for Supabase operational DB and scheduled backups under official policy. Resend-to-mail-server delivery uses Annex 3 TLS settings. At-rest encryption does not prevent authorized operator access
Customer accountsIndividual staff invitations and permissions supported. Built-in dashboard 2FA configuration or organization-wide enforcement is not currently provided
Recording paths and actionsViewing, downloads, changes, and deletions via administrator and customer dashboards, APIs, and direct DB access. Automated jobs linked to job identifiers; staff manual operations to personnel identifiers. Actual targets traceable for list and bulk actions
Access records and retentionPersonnel or job identifier, time, source location, target identifiers, action, result, and traceability information retained for two years from creation. No separate audit copy of submission contents
Record protectionProtection against unauthorized access, alteration, loss, and similar events
Record reviews and anomaliesAt least monthly review of access records and downloads, reasons for downloads, and missing records. Anomalies promptly investigated, access restricted or other measures taken, and reported to privacy officer. Review results kept for two years from preparation
Deletion evidenceRequester or job, target identifiers and count, request and processing times, success, failure, and retry results. Retained for two years after operation closure to verify deletion, address errors, and re-delete after restoration. Submission contents excluded
Acceptance evidenceSection 2.6 account, represented customer and authority confirmation where applicable, versions and contemporaneous copies, separate consent results, time and method. Minimum evidence retained separately during the agreement and five years after termination for formation, performance, proof, and legitimate interests in dispute response
Record-specific expiryTwo-year access-log retention is not applied indiscriminately to other evidence. Consent and deletion-result records are separate from three-year automatic deletion of form submissions. Destroyed without delay on expiry; only records subject to a separate statutory retention duty are segregated for that period
Verification and customer noticePer-submission logging and retention across all paths remain under verification. Gaps and improvements managed and actual coverage explained. Gaps do not defer statutory duties or exempt liability

Direct and Automatic Deletion

ItemStandard
ScopeSubmissions from all forms
Direct deletion startPlanned for November 7, 2026; applies after development, verification, and necessary consent
Direct deletion methodAuthorized customer confirms targets, count, and irreversibility before execution
Direct deletion completionWork starts immediately on confirmation. Marked complete only after removal from operational DB and Company-managed service replicas. Partial deletion or failure is not completion; completion does not mean final destruction of backups or email-provider copies
Automatic deletion startPlanned for November 7, 2026; applies after development, verification, advance notice, and necessary consent
Automatic deletion thresholdThree years from initial submission; editing or viewing does not extend the period. No customer-specific retention setting
FrequencyDaily execution; deletion from operational DB and Company-managed service replicas within 24 hours of the three-year threshold. Times use UTC; February 29 is mapped to the same time on the final day of February three years later
Existing dataInitial submission time also governs pre-rollout data. Submissions already over three years old when application begins are deleted within 24 hours of lawful application to the relevant Customer
Earlier deletionDirect deletion or a Company request where a shorter customer retention period, fulfilled purpose, or other deletion ground applies
FailuresDetect failures, missed jobs, and interruptions; automatic retry, operator alerts, and reprocessing. Automatic retries start with each feature. Detect missing or delayed operations beyond 24 hours; staff check and reprocess incomplete items each business day
Rollout noticeAdvance service notices and dashboard-entry popups explain date, scope, methods, irreversibility, and backups. Any legally or contractually required consent is separate
BackupsSupabase daily DB backups cover the latest seven days. Operational deletion and backup expiry are distinct; provider-specific standards follow Annex 3
RestorationReapply deletion identifiers held separately from the backup and remove deleted submissions before service exposure
Customer copiesCustomers separately manage received emails and downloaded files

Records requiring longer statutory retention by the Customer must be moved to a lawful separate retention system before deletion. The form service does not replace a statutory medical-record system.

Annex 3. Subprocessors and International Transfers

Annex Version: 2026-10-07.1

These details define the scope of Customer subprocessing consent. International transfers follow the legal grounds and disclosure, notice, and consent requirements in Section 7. The text and annexes accepted by each Customer are preserved together.

The following reflects operational settings and official provider materials checked on October 1-2, 2026. Deleting operational DB submissions is distinct from final destruction of existing backups or email copies. Unless stated otherwise, the retention periods below are not deadlines measured from a Customer's deletion request.

Supabase

ItemDetails
Subprocessor and contactSupabase Pte. Ltd. / privacy@supabase.io; contracting entity in the public standard DPA
Operational DB storageSingapore (ap-southeast-1); form submissions stored in that region
DataForm inputs, site, form and submission identifiers, submission time, and form-field configuration
Work and purposeStorage, viewing, management, and DB backup of form submissions
Transfer timing and methodEncrypted network communications during submission, viewing, and management. Backup copies created during scheduled provider backups
Operational retentionSection 8 and Annex 2. Three-year automatic deletion and customer permanent deletion apply from their respective commencement dates
Backup retentionDaily DB backups covering the latest seven days. Seven completed daily backups and disabled point-in-time recovery (PITR) were verified in the operational project
Deletion and backupsIndividual operational DB deletion does not immediately delete existing backups. Backups expire on their retention cycle; restored copies of previously deleted submissions are deleted again before service exposure
Email copiesNotification email sending is not entrusted to this provider; see Resend
Verification sourcesOperational project and backup list (2026-10-01), official backup documentation, public DPA

Resend

ItemDetails
Subprocessor and contactPlus Five Five, Inc. (Resend) / privacy@resend.com
Storage and processing countriesStorage and main processing of email bodies and sending records: United States. Sending processing: Tokyo, Japan (ap-northeast-1). Domain authentication and Tokyo region for send.neopress.ai, the operational code's default sending domain, were verified in Resend. Sending region and storage country differ
DataNotification-recipient email addresses, form and site names, submission time, and form inputs
Work and purposeNew-submission notifications to customer-configured recipients
Transfer timing and methodFor forms with notifications enabled, transmitted to Resend through HTTPS API at submission, then emailed. Delivery to receiving mail servers used Opportunistic TLS: TLS is attempted first, but mail may be sent unencrypted if it cannot connect using TLS
Email and sending-record retentionPro plan as verified in Resend Billing for transactional email. Official Pro retention is 30 days
Backup retentionSeven days under official security policy; distinct from the 30-day email and sending-record retention
Deletion and backupsDeleting a submission in Neopress DB does not also delete sent emails or Resend records. Emails, sending records, and backups follow their respective retention policies. Individual early email deletion may be requested from Resend support
Resend contract terminationOfficial guidance provides deletion of residual customer data within 90 days after account termination following service termination, subject to DPA statutory-retention exceptions. This is not 90 days from a clinic's or Neopress's deletion of an individual submission
Customer mailbox copiesEmails delivered to recipients' mailboxes are outside the above 30-, seven-, and 90-day periods and are separately managed and deleted by the Customer
Verification sourcesRetention and storage countries, security policy, DPA, sending regions. Operational code and sending-domain DNS checked 2026-10-01; Resend Billing and send.neopress.ai domain and TLS settings checked 2026-10-02

Vercel

ItemDetails
Subprocessor and contactVercel Inc. / privacy@vercel.com
Form-request processing locationsSeoul, Republic of Korea (icn1), and Washington, D.C. area, United States (iad1), based on function regions configured in the operational project
DataForm-submission request bodies
Work and purposeReceiving and processing form requests and hosting the Service; storing submissions in Supabase and forwarding them for notifications
Transfer timing and methodHTTPS during form-submission request processing
Request-body retentionUsed during request processing. The reviewed operational form and mail-sending code contained no code separately storing request bodies in Vercel storage or logs. This is not a guarantee that every internal provider copy is immediately deleted
Log retentionPro plan, Observability Plus disabled, and no project Log Drains connected at verification. Official Pro runtime-log retention is one day after creation. This is not a final-deletion deadline for form bodies or backups
Deletion and backupsNeopress DB deletion is distinct from deletion of Vercel logs and internal copies; data remaining with Vercel follows its retention and deletion policies
Email copiesResend sends emails and its criteria apply. See above for Vercel's internal processing and copies
Verification sourcesOperational project settings (2026-10-01), runtime logs, DPA