← Back to Home

Data Processing Agreement

Last updated: 21 August 2026

This agreement governs the processing of personal data arising from your use of Newton. It is written to meet the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) where that regulation applies, and Section 40 of Thailand's Personal Data Protection Act B.E. 2562 (PDPA), under which Income in Click Co., Ltd. is established.

This agreement applies to every Newton customer and forms part of our Terms of Service. If you need a countersigned copy, send us your legal entity name and registered address at the contact in section 14 and we will issue one for both parties to sign.

1. The parties and their roles

2. Scope and purpose

We process personal data only as far as necessary to deliver the service: providing and maintaining the server, applying software and security updates, resolving issues you report, managing domains and DNS, taking backups where you have purchased that add-on, and billing.

We do not use your data for any other purpose. We do not analyse it commercially, we do not use it to train artificial intelligence models, and we do not sell it to anyone.

3. Categories of data and data subjects

CategoryExamplesData subjects
Data you place on the serverDatabases, files, website content, records of your own users or customersDetermined entirely by you
Customer account dataName, email, payment detailsYou and your representatives
Technical dataServer IP address, domain, plan, service recordsYou
Data attached to support requestsTicket messages and Newton platform logs collected for diagnosisYou

4. Our obligations as processor

5. Security measures

6. Access to your server

As a managed server provider we hold administrative access to your server, which is necessary to deliver the service. We use that access only in the following situations:

Outside these situations we do not access the content of your server. Our automated monitoring reads only metadata, such as the timestamp of the most recently modified file, to determine whether the server is in use. It does not open file contents. You can review access history at any time in the operating system logs on your own server.

7. Subprocessors

You authorise us to engage subprocessors as necessary to deliver the service. The complete list, with locations and the categories of data involved, is published at Subprocessor List.

We impose data protection obligations on each subprocessor that are no less protective than this agreement, and we remain responsible to you for their performance, subject to section 13. If we add or replace a subprocessor in a way that affects the processing of personal data, we will give at least 30 days notice, and you may object by terminating the service within that period.

8. International transfers

Your server runs in the region you selected at signup, either Falkenstein in Germany or Singapore. We do not move server data out of that region, with the following exceptions, which you acknowledge and accept:

Where a transfer is subject to Chapter V of the GDPR or to Sections 28 and 29 of the PDPA, we rely on the appropriate safeguards offered by the receiving provider, including standard contractual clauses where the provider makes them available.

9. Personal data breach notification

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware. The notification will include the nature of the breach, the data affected, the measures already taken, and a contact point for further information, so that you can meet your own notification deadlines to your supervisory authority and, where required, to affected individuals.

10. Assisting with data subject rights

If a data subject exercises a right such as access, rectification, erasure or objection, we will give you reasonable technical assistance in responding. If a request reaches us directly, we will forward it to you rather than act on it ourselves, unless you instruct otherwise.

11. Return and deletion of data

12. Audits

On written request we will provide the information necessary to demonstrate compliance with this agreement, by way of documentation or a completed security questionnaire, up to once per year, unless a personal data breach has occurred or the law requires otherwise.

13. Liability and term

This agreement remains in force for as long as you use the service and ends once we have deleted or returned your data under section 11.

Limitation of liability: our liability under this agreement, including where the cause originates with a subprocessor under section 7, is limited to the fees you actually paid in the 12 months preceding the event, and excludes indirect loss such as lost revenue, lost business opportunity, loss of data you did not back up yourself, and reputational harm.

Outside our responsibility: for AI services you connect using your own account, such as Claude, Codex or Antigravity, you contract and pay the provider directly. We are neither controller nor processor for data you send through those accounts, and we are not responsible for their processing, retention or any incident on their side, nor for the output those models generate or your use of it.

Where this agreement conflicts with our Terms of Service, this agreement prevails on matters of data protection and the Terms of Service govern everything else.

14. Contact

Income in Click Co., Ltd.
Company registration number 0105564049399
98/299 Soi Pracha Uthit 33 Yaek 7, Pracha Uthit Road, Bang Mot, Thung Khru, Bangkok 10140, Thailand
Email: agent@hirenewton.com