Data Processing Agreement
Last updated: 21 August 2026
This agreement governs the processing of personal data arising from your use of Newton. It is written to meet the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) where that regulation applies, and Section 40 of Thailand's Personal Data Protection Act B.E. 2562 (PDPA), under which Income in Click Co., Ltd. is established.
This agreement applies to every Newton customer and forms part of our Terms of Service. If you need a countersigned copy, send us your legal entity name and registered address at the contact in section 14 and we will issue one for both parties to sign.
1. The parties and their roles
- Controller: you, the customer. You decide what personal data is placed on the server and for what purpose.
- Processor: Income in Click Co., Ltd., providing the managed server service known as Newton.
- We act as controller only for our own customer account data, such as your name, email and payment history, which is covered by our Privacy Policy.
2. Scope and purpose
We process personal data only as far as necessary to deliver the service: providing and maintaining the server, applying software and security updates, resolving issues you report, managing domains and DNS, taking backups where you have purchased that add-on, and billing.
We do not use your data for any other purpose. We do not analyse it commercially, we do not use it to train artificial intelligence models, and we do not sell it to anyone.
3. Categories of data and data subjects
| Category | Examples | Data subjects |
|---|---|---|
| Data you place on the server | Databases, files, website content, records of your own users or customers | Determined entirely by you |
| Customer account data | Name, email, payment details | You and your representatives |
| Technical data | Server IP address, domain, plan, service records | You |
| Data attached to support requests | Ticket messages and Newton platform logs collected for diagnosis | You |
4. Our obligations as processor
- Process personal data only on your instructions and as necessary to provide the service. Where law compels processing beyond this, we will tell you first unless the law forbids it.
- Keep your data confidential and place the same duty on everyone who handles it.
- Limit access to those who need it to perform their duties.
- Maintain the security measures set out in section 5.
- Assist you in meeting your own obligations under applicable data protection law.
5. Security measures
- Each customer runs on a separate virtual server. Resources are not shared between customers.
- All connections to the service are encrypted with HTTPS (TLS).
- Administrative access to servers uses SSH keys only. Password login is disabled and fail2ban protects against brute-force attempts.
- User passwords are stored as hashes, never in plain text.
- Operating system security patches are applied automatically.
- We never store card details. Payments are handled by a PCI DSS compliant payment provider.
6. Access to your server
As a managed server provider we hold administrative access to your server, which is necessary to deliver the service. We use that access only in the following situations:
- When you report a problem and we need to investigate in order to fix it.
- When we need to update, maintain or repair the platform itself.
- When there is a security incident that must be contained.
- When required by law or by a competent authority.
Outside these situations we do not access the content of your server. Our automated monitoring reads only metadata, such as the timestamp of the most recently modified file, to determine whether the server is in use. It does not open file contents. You can review access history at any time in the operating system logs on your own server.
7. Subprocessors
You authorise us to engage subprocessors as necessary to deliver the service. The complete list, with locations and the categories of data involved, is published at Subprocessor List.
We impose data protection obligations on each subprocessor that are no less protective than this agreement, and we remain responsible to you for their performance, subject to section 13. If we add or replace a subprocessor in a way that affects the processing of personal data, we will give at least 30 days notice, and you may object by terminating the service within that period.
8. International transfers
Your server runs in the region you selected at signup, either Falkenstein in Germany or Singapore. We do not move server data out of that region, with the following exceptions, which you acknowledge and accept:
- Support system: when you open a ticket, your message and technical diagnostic data from the Newton platform are processed by an artificial intelligence provider in the United States in order to prepare a response.
- AI agents you connect yourself: prompts and files you instruct the agent to read or modify are sent to the AI provider whose account you connected, located in the United States. For that processing you contract directly with the AI provider.
- Account and billing data: processed by our payment and email providers as listed in the Subprocessor List.
Where a transfer is subject to Chapter V of the GDPR or to Sections 28 and 29 of the PDPA, we rely on the appropriate safeguards offered by the receiving provider, including standard contractual clauses where the provider makes them available.
9. Personal data breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware. The notification will include the nature of the breach, the data affected, the measures already taken, and a contact point for further information, so that you can meet your own notification deadlines to your supervisory authority and, where required, to affected individuals.
10. Assisting with data subject rights
If a data subject exercises a right such as access, rectification, erasure or objection, we will give you reasonable technical assistance in responding. If a request reaches us directly, we will forward it to you rather than act on it ourselves, unless you instruct otherwise.
11. Return and deletion of data
- You can export your data at any time while the service is active.
- When the agreement ends and the paid period expires, the server is destroyed together with its disk.
- If you purchased the backup add-on, which is available only through the Newton Dashboard, all of your snapshots are deleted when that add-on ends.
- Account data and payment records we must retain are covered by our Data Retention Policy.
12. Audits
On written request we will provide the information necessary to demonstrate compliance with this agreement, by way of documentation or a completed security questionnaire, up to once per year, unless a personal data breach has occurred or the law requires otherwise.
13. Liability and term
This agreement remains in force for as long as you use the service and ends once we have deleted or returned your data under section 11.
Limitation of liability: our liability under this agreement, including where the cause originates with a subprocessor under section 7, is limited to the fees you actually paid in the 12 months preceding the event, and excludes indirect loss such as lost revenue, lost business opportunity, loss of data you did not back up yourself, and reputational harm.
Outside our responsibility: for AI services you connect using your own account, such as Claude, Codex or Antigravity, you contract and pay the provider directly. We are neither controller nor processor for data you send through those accounts, and we are not responsible for their processing, retention or any incident on their side, nor for the output those models generate or your use of it.
Where this agreement conflicts with our Terms of Service, this agreement prevails on matters of data protection and the Terms of Service govern everything else.
14. Contact
Income in Click Co., Ltd.
Company registration number 0105564049399
98/299 Soi Pracha Uthit 33 Yaek 7, Pracha Uthit Road, Bang Mot, Thung Khru, Bangkok 10140, Thailand
Email: agent@hirenewton.com