Skip to content

Data Processing Agreement

Last updated: September 21, 2026

This Data Processing Agreement (“DPA”) applies where Infragate processes personal data on your behalf. You do not need to sign it or ask us for it. Accepting the Terms of Use enters you into this DPA, including the Standard Contractual Clauses and the UK Addendum, with effect from the date of that acceptance. See Clause 14.6.

If your procurement process needs a countersigned copy, email privacy@infragate.co and we will provide one.


1.1 In this Data Processing Agreement (“DPA”):

“Agreement” means the Infragate Terms of Use, together with any order form, subscription plan or enterprise agreement between the parties.

“CCPA” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, and its implementing regulations.

“Company”, “we”, “us” means Infragate, LLC, a Delaware limited liability company with its registered address at 1207 Delaware Ave, Suite 679, Wilmington, Delaware 19806, United States.

“Customer”, “you” means the entity that has entered into the Agreement with the Company.

“Customer Personal Data” means Personal Data contained within Customer Data that the Company Processes on the Customer’s behalf in providing the Services.

“Data Protection Law” means, as applicable: the EU General Data Protection Regulation 2016/679 (“EU GDPR”); the EU GDPR as incorporated into the law of the United Kingdom by the European Union (Withdrawal) Act 2018 (“UK GDPR”) together with the Data Protection Act 2018; the Swiss Federal Act on Data Protection (“FADP”); the CCPA; and any other privacy or data protection law applicable to a party’s Processing under this DPA.

“EEA” means the European Economic Area.

“Restricted Transfer” means a transfer of Customer Personal Data from the EEA, the United Kingdom or Switzerland to a country that is not the subject of an adequacy decision applicable to that transfer.

“SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in their Module Two (controller to processor) form.

“Services” means the Infragate products identified in the Agreement and made generally available by the Company, and any successor or additional product the Company makes available. As at the date of this DPA the generally available products are ShareCube, Lanyard and Capa. See Clause 2.6.

“Sub-processor” means any third party engaged by the Company to Process Customer Personal Data.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0 in force 21 March 2022.

1.2 The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process” (and its cognates), “Special Categories of Personal Data” and “Supervisory Authority” have the meanings given in the EU GDPR. “Business”, “Service Provider”, “Sell” and “Share” have the meanings given in the CCPA.


2.1 This DPA applies only where the Company acts as a Processor. The Customer is the Controller of Customer Personal Data and the Company is its Processor. This covers, without limitation, ShareCube organization content, Lanyard audit records, and accounts created through the Customer’s single sign-on.

2.2 The Company is a Controller for a limited set of data. The Company acts as a Controller, not a Processor, in respect of: account and billing records it holds to operate its own business; security, fraud-prevention and abuse-prevention logs; and aggregated or de-identified statistics that do not identify any Data Subject or the Customer. This DPA does not govern that Processing, which is governed by the Privacy Policy.

2.3 Each party will comply with its own obligations under Data Protection Law. The Customer is responsible for establishing a lawful basis for the Processing it instructs, for issuing any notices its own personnel or end users are owed, and for the accuracy and legality of Customer Personal Data.

2.4 This DPA takes effect on the earlier of the Customer’s acceptance of the Agreement and the date the Company first Processes Customer Personal Data, and continues for as long as the Company Processes Customer Personal Data.

2.5 Customer-authored content. The Customer acknowledges that ShareCube artifacts, comments and chat messages are authored by its own Users, that their content is determined entirely by those Users, and that the Company has no control over what Personal Data a User chooses to include.

2.6 Products not generally available.

Cairn is not generally available and the Company Processes no Customer Personal Data through it. References to Cairn in this DPA and its Schedules describe processing that will occur if and when Cairn is made generally available to the Customer, and have no present effect.

Before Cairn is made available to any customer, Schedules 1, 2 and 3 must be reviewed and reissued, and the Customer must be notified of the resulting change in the same manner as a change of Sub-processor under Clause 6.3. Cairn changes the nature of the processing materially: it would store agent telemetry that can contain prompts, assistant responses and tool output, and it would produce per-person analytics amounting to monitoring of the Customer’s workforce.


3.1 The Company will Process Customer Personal Data only on the Customer’s documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by law to which the Company is subject. Where the Company is so required, it will inform the Customer of that legal requirement before Processing, unless the law prohibits it from doing so on important grounds of public interest.

3.2 The Agreement, this DPA, the Customer’s configuration of the Services, and the Customer’s use of the Services through their documented interfaces together constitute the Customer’s complete and final documented instructions. Additional instructions outside their scope require agreement in writing, and the Company may charge for the reasonable cost of implementing them.

3.3 The Company will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law. The Company is not obliged to conduct a legal review of the Customer’s instructions and gives no advice on them.

3.4 The Company does not use Customer Personal Data to train machine learning models. Where Customer Personal Data is submitted to an artificial intelligence model in order to perform a function the Customer or its Users requested, it is submitted for that request only and is not retained by the model provider for training. This reflects the commitment in Section 5 of the Privacy Policy.

3.5 The Company does not Sell or Share Customer Personal Data, and will not retain, use or disclose it for any purpose other than performing the Services, or otherwise outside the direct business relationship between the parties, except as permitted by Data Protection Law. The Company will not combine Customer Personal Data with Personal Data it receives from another source, except as a Service Provider is permitted to do under the CCPA. See Schedule 5.


4.1 The Company will ensure that each person it authorises to Process Customer Personal Data is subject to an appropriate contractual or statutory duty of confidentiality, and has received appropriate training.

4.2 The Company will limit access to Customer Personal Data to those personnel who require it to perform the Agreement.


5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects, the Company will implement and maintain the technical and organisational measures set out in Schedule 2.

5.2 The Company may update those measures from time to time provided the updates do not materially reduce the overall level of security.

5.3 The Customer is responsible for its own use of the Services, including its configuration choices, its administration of user accounts, roles and sharing settings, and its management of API keys and access tokens.


6.1 The Customer gives the Company general written authorisation to engage Sub-processors, subject to this Clause 6.

6.2 The Sub-processors engaged as at the date of this DPA are listed in Schedule 3. The Company maintains a current list in Section 10 of the Privacy Policy.

6.3 The Company will give the Customer at least thirty (30) days’ notice before engaging a new Sub-processor or replacing an existing one, by email to the Customer’s designated privacy contact and by updating the published list.

6.4 The Customer may object to a new Sub-processor on reasonable data protection grounds by written notice within the notice period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected Services on written notice, and the Company will refund any prepaid fees covering the period after termination. This is the Customer’s sole and exclusive remedy for an objection under this Clause.

6.5 The Company will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Sub-processor’s performance.

6.6 The Company will make the relevant terms of a Sub-processor contract available to the Customer on request, redacted as necessary to protect commercial confidentiality and the information of other customers.


7.1 Taking into account the nature of the Processing, the Company will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise Data Subject rights under Data Protection Law.

7.2 The Services provide the Customer’s administrators with self-service functionality to access, export, correct and delete Customer Personal Data. The Customer will use that functionality in the first instance.

7.3 Where a request cannot be fulfilled through the Services, the Customer may contact privacy@infragate.co and the Company will provide reasonable assistance. The Company may charge for assistance that is unreasonable or repetitive in scope.

7.4 If the Company receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond to the substance of the request other than to acknowledge it and direct the Data Subject to the Customer, and will notify the Customer without undue delay, unless prohibited from doing so by law.


8.1 The Company will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 The notification will describe, to the extent then known: the nature of the breach including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Information the Company does not yet hold will be provided in phases as it becomes available.

8.3 The Company will take reasonable steps to contain, investigate and mitigate the breach, and will assist the Customer with the Customer’s own notification obligations to Supervisory Authorities and Data Subjects.

8.4 The Company’s notification of a Personal Data Breach is not an acknowledgement of fault or liability.


9.1 Taking into account the nature of the Processing and the information available to it, the Company will provide reasonable assistance to the Customer with any data protection impact assessment and any prior consultation with a Supervisory Authority that the Customer is required to carry out under Articles 35 and 36 of the EU GDPR or their equivalents.

9.2 That assistance is limited to information about the Company’s own Processing, its security measures and its Sub-processors, and does not extend to assessing the Customer’s own purposes or lawful basis.


10.1 On termination or expiry of the Agreement, the Company will, at the Customer’s election, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by law.

10.2 The Customer may make that election by written notice at any time up to thirty (30) days after termination. If no election is made, the Company will delete.

10.3 Deletion will be completed within thirty (30) days of termination or of the Customer’s election, whichever is later, subject to Clauses 10.4 and 10.5.

10.4 Backups. Customer Personal Data may persist in encrypted database backups for up to thirty-five (35) days after deletion from live systems, consistent with the point-in-time recovery window described in Section 11 of the Privacy Policy. Backup copies are not accessible to the Company in the ordinary course, are not used for any purpose other than disaster recovery, and expire automatically.

10.5 Records the Company must keep. The Company and its payment Sub-processor will retain billing records and invoices for as long as tax, accounting and anti-money-laundering law requires. The Company may retain Customer Personal Data to the extent and for as long as required by applicable law, and will continue to protect it in accordance with this DPA for as long as it is retained.

10.6 The Company will certify deletion in writing on the Customer’s request.


11.1 The Company will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the EU GDPR and this DPA.

11.2 The Company will satisfy its obligation under Clause 11.1, and any audit right the Customer has under Data Protection Law, by providing: this DPA and its Schedules; its then-current security documentation; and a completed response to a reasonable written security questionnaire, once in any twelve (12) month period.

11.3 Where the information provided under Clause 11.2 is demonstrably insufficient, or where a Supervisory Authority requires it, or following a Personal Data Breach affecting the Customer, the Customer may conduct an on-site audit on at least thirty (30) days’ written notice, during normal business hours, no more than once in any twelve (12) month period, subject to reasonable confidentiality undertakings, and at the Customer’s own cost. An audit must not unreasonably disrupt the Company’s business or compromise the confidentiality, security or availability of any other customer’s data.

11.4 The Customer will bear the Company’s reasonable costs of assistance with any audit beyond the response provided under Clause 11.2.


12.1 The Customer acknowledges that the Company Processes Customer Personal Data in the United States, in the AWS us-east-1 region, with some processing at AWS edge locations worldwide, as described in Section 12 of the Privacy Policy.

12.2 EEA transfers. Where Processing of Customer Personal Data by the Company constitutes a Restricted Transfer from the EEA, the SCCs are incorporated into this DPA by reference and apply, on the following basis:

  • (a) Module Two (controller to processor) applies. The Customer is the data exporter and the Company is the data importer.
  • (b) Clause 7 (docking clause) is incorporated.
  • (c) In Clause 9, Option 2 (general written authorisation) applies, with the notice period specified in Clause 6.3 of this DPA.
  • (d) In Clause 11, the optional independent dispute resolution paragraph is not incorporated.
  • (e) In Clause 17, the SCCs are governed by the law of Ireland.
  • (f) In Clause 18(b), the courts of Ireland have jurisdiction.
  • (g) Annex I, Annex II and Annex III to the SCCs are populated by Schedules 1, 2 and 3 to this DPA respectively.

12.3 UK transfers. Where the transfer is subject to UK GDPR, the SCCs as incorporated by Clause 12.2 apply as varied by the UK Addendum, which is incorporated by reference and completed as set out in Schedule 4.

12.4 Swiss transfers. Where the transfer is subject to the FADP, the SCCs apply with the following modifications: references to the GDPR are to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; the term “member state” must not be interpreted to exclude Data Subjects in Switzerland from suing in their place of habitual residence; and the SCCs also protect the data of legal entities until the FADP no longer affords that protection.

12.5 In the event of a conflict between this DPA and the SCCs, the SCCs prevail.

12.6 If the Company adopts an alternative transfer mechanism recognised under Data Protection Law, that mechanism will apply in place of the SCCs to the extent it lawfully covers the transfer, on notice to the Customer.


13.1 Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement.

13.2 Clause 13.1 does not apply to, and nothing in the Agreement or this DPA limits or excludes: (a) either party’s liability to a Data Subject under Clause 12 of the SCCs or under the third-party beneficiary rights the SCCs confer; (b) any liability that cannot lawfully be limited or excluded; or (c) the Company’s obligation to pay compensation under Article 82 of the EU GDPR or UK GDPR where liability is established.


14.1 This DPA forms part of the Agreement.

14.2 Order of precedence. In the event of a conflict, the following order applies, highest first: (a) the SCCs and the UK Addendum; (b) this DPA; (c) the Agreement; (d) the Privacy Policy.

14.3 Governing law. Except as provided in Clauses 12.2(e), 12.3 and 12.4, this DPA is governed by the law that governs the Agreement.

14.4 Severance. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect.

14.5 Entire agreement. This DPA supersedes any prior data processing terms between the parties in respect of its subject matter.

14.6 Signature. Where the Customer accepts the Agreement, the Customer is taken to have entered into this DPA, including the SCCs and the UK Addendum, with effect from the date of that acceptance. Where a signed copy is required, either party may request one and the other will not unreasonably refuse.


This Schedule describes the generally available Services: ShareCube, Lanyard and Capa. Cairn is not generally available and no processing occurs through it. This Schedule will be reissued before Cairn is made available. See Clause 2.6.

Data exporter

NameThe Customer identified in the Agreement
AddressAs stated in the Agreement
ContactThe Customer’s administrator or privacy contact as notified to the Company
Activities relevant to the transferUse of the Services as a Controller
RoleController
Signature and dateAs per Clause 14.6

Data importer

NameInfragate, LLC
Address1207 Delaware Ave, Suite 679, Wilmington, Delaware 19806, United States
Contactprivacy@infragate.co
Activities relevant to the transferProvision of the ShareCube, Lanyard and Capa services
RoleProcessor
Signature and dateAs per Clause 14.6
  • The Customer’s employees, contractors, agents and other individuals the Customer authorises to use the Services (“Users”)
  • Individuals whose Personal Data a User includes in an artifact, a comment, a chat message or a package manifest
  • Individuals identified in a reporting hierarchy file the Customer uploads
  • The Customer’s billing and administrative contacts

Account and identity, all Services. Name; email address; profile photograph; authentication identifier (password hash, Google or GitHub identifier, or an identifier issued by the Customer’s SAML identity provider); organization and group membership; role and permissions; multi-factor enrolment state; session records; IP address; user agent; and, where the Customer uploads one, manager and direct-report relationships.

ShareCube. Artifact content in HTML or Markdown, authored by Users, which may contain Personal Data of any category the User chooses to include; comment text and authorship; mentions; chat transcripts between a User and the AI assistant; notification records containing up to 280 characters of comment text together with the artifact name; activity timeline entries; live presence indications; and derived data generated by the Company from the foregoing, namely a full-text search index, an extracted concept and entity graph, and preview images and summaries generated for publicly shared artifacts.

Lanyard. Credentials issued by third-party services that a User connects, held envelope-encrypted; tool call metadata comprising the acting User, timestamp, project, target server, tool name and outcome; and edge access logs. The content of tool calls is not stored or logged.

Capa. Publisher identity in package manifests (name and email), stars, and issue authorship. This data is published publicly by design.

Billing. Billing contact name and email, billing address, tax identification number, and subscription and invoice records. Payment card data is transmitted directly to the payment Sub-processor and is not stored by the Company.

Cairn (not generally available, no present effect). If and when Cairn is made available, it would ingest OpenTelemetry spans, events and metrics emitted by the Customer’s agents, including unrecognised attributes, which depending on the Customer’s configuration can contain user prompts, assistant responses and tool inputs and outputs. It would also produce per-User session analytics comprising name, email, cost, usage patterns and points at which sessions stall. This paragraph is descriptive only and this Schedule will be reissued before any such processing begins.

None. The Customer must not submit Special Categories of Personal Data, personal data relating to criminal convictions and offences, protected health information, payment card data, or government-issued identifiers to the Services. This reflects Section 4.7 of the Terms of Use.

Continuous, for the duration of the Agreement.

Hosting, storage, transmission, display, indexing, analysis and generation of derivative material such as previews, summaries and search indexes, in each case solely to provide, secure, support and improve the operation of the Services for the Customer.

For the duration of the Agreement and thereafter as set out in Clause 10. Individual retention periods are set out in Section 11 of the Privacy Policy, which forms part of this description. Of particular note:

DataRetention
ShareCube artifacts, comments, projectsUntil deleted by the Customer; deletion purges the content
ShareCube previous versions90 days
ShareCube chat transcripts90 days
Lanyard credentialsUntil the connection is deleted or the User leaves the organization
Lanyard audit history7 days (Free), 30 days (Pro and Team), 365 days (Enterprise)
Sessions30 days
Database backupsUp to 35 days

As set out in Schedule 3, for the subject matter, nature and duration described there.

The Supervisory Authority of the EEA member state in which the data exporter is established. Where the data exporter is not established in the EEA but has designated a representative under Article 27 of the EU GDPR, the Supervisory Authority of the member state in which that representative is established. Where neither applies, the Supervisory Authority of the member state in which the Data Subjects whose Personal Data is transferred are located.


Schedule 2: Technical and Organisational Measures

Section titled “Schedule 2: Technical and Organisational Measures”

The Company maintains the following measures across the generally available Services. They are described as they are actually implemented; where a measure is partial or is a work in progress, that is stated.

  • All traffic between Users and the Services, and between Services and Sub-processors, is encrypted in transit using TLS.
  • Data at rest is stored with server-side encryption: S3 managed keys for object storage, and encryption at rest for all DynamoDB tables.
  • Lanyard third-party credentials receive an additional layer of envelope encryption, using per-record data keys derived from a rotating AWS KMS customer master key. A compromise of the database alone does not yield usable credentials.
  • Access to production data is governed by AWS IAM policies applied on the principle of least privilege.
  • Each compute component runs under a dedicated role scoped to the resources it needs.
  • Authorisation within the Services is enforced organization-by-organization at a single code path per product, so that a permission decision cannot be bypassed by reaching a resource through a different route.
  • Customer administrators control session length, domain verification, organization membership, group membership and role assignment.
  • Multi-factor authentication is available to all Users. SAML single sign-on is available so that the Customer can enforce its own authentication policy, including its own MFA requirement.
  • Lanyard does not store or log the content of tool calls, only their metadata.
  • Artifact uploads are restricted to HTML and Markdown.
  • Operational logs do not contain artifact bodies.
  • The Services run on AWS managed, multi-availability-zone infrastructure.
  • Point-in-time recovery is enabled on the primary databases, giving a 35 day restore window.
  • Object storage is versioned.
  • All infrastructure is defined as code and deployed through an automated pipeline. There is no manual production provisioning.
  • Changes are reviewed before merge and an automated test suite runs on every change.
  • Deployment to production is a separate, explicit promotion step from deployment to the development environment.
  • Security-relevant actions are written to an audit log stream, separately from application logs.
  • Application log groups carry a defined retention period. Standardisation of retention across all components is in progress; see Section 11 of the Privacy Policy.
  • Public-facing APIs are fronted by a web application firewall.
  • Deleting a ShareCube artifact or project purges its content, its stored versions, its comments, its chat turns and its search and graph index entries.
  • Lanyard credentials are deleted when a connection is removed or a User leaves the organization.
  • Deleted records remain restorable from encrypted backups for up to 35 days, after which they expire automatically.
  • Vulnerability reports are received at security@infragate.co.
  • The Company notifies affected customers and, where required, Supervisory Authorities of a Personal Data Breach without undue delay, and within 72 hours of becoming aware where the law requires it.
  • Personnel with access to Customer Personal Data are subject to a duty of confidentiality.
  • Access is limited to those who require it to perform their role.
  • Sub-processors are engaged under written contract with data protection terms no less protective than this DPA.
  • The current list is published and maintained in Section 10 of the Privacy Policy.

The Company does not currently hold SOC 2, ISO/IEC 27001 or any comparable third-party security certification, and does not currently undergo third-party penetration testing on a scheduled basis. The Company will update this Schedule if that changes.


Sub-processorPurposeLocation of Processing
Amazon Web Services, Inc.Hosting, compute, object and database storage, transactional email (SES), and foundation models for AI features (Bedrock)United States (us-east-1), with edge processing at AWS locations worldwide
Stripe, Inc.Subscription and credit payments; billing address, tax identifier and card dataUnited States and Ireland
Slack Technologies, LLCInternal notification of waitlist sign-ups and content reports to the Company’s own workspaceUnited States
Google LLCWeb fonts and favicons served to Users’ browsers. Receives Users’ IP addresses.Global CDN
Google LLC; GitHub, Inc.Federated sign-in, where a User chooses social loginUnited States

The Company maintains the current version of this list in Section 10 of the Privacy Policy. Changes are notified in accordance with Clause 6.3.


Schedule 4: UK International Data Transfer Addendum

Section titled “Schedule 4: UK International Data Transfer Addendum”

The UK Addendum is incorporated and completed as follows.

Table 1: Parties. As set out in Schedule 1, Part A. Start date: the date this DPA takes effect under Clause 2.4.

Table 2: Selected SCCs, Modules and Selected Clauses. The SCCs as incorporated by Clause 12.2 of this DPA, Module Two, with the options selected in Clause 12.2(b) to (g).

Table 3: Appendix Information.

  • Annex 1A (List of Parties): Schedule 1, Part A.
  • Annex 1B (Description of Transfer): Schedule 1, Part B.
  • Annex II (Technical and Organisational Measures): Schedule 2.
  • Annex III (List of Sub-processors): Schedule 3.

Table 4: Ending this Addendum when the Approved Addendum changes. Neither party may end the Addendum as set out in Section 19 of the Addendum.


Schedule 5: United States State Privacy Laws Addendum

Section titled “Schedule 5: United States State Privacy Laws Addendum”

This Schedule applies where the Company Processes Personal Data subject to the CCPA or to a comparable state privacy law, including those of Virginia, Colorado, Connecticut, Utah and Texas.

  1. The Customer is the Business (or Controller) and the Company is a Service Provider (or Processor).
  2. The Company Processes Personal Data solely to perform the Services specified in the Agreement, which is the business purpose for which it is disclosed.
  3. The Company does not Sell or Share Personal Data, and receives no monetary or other valuable consideration for it beyond the fees payable under the Agreement.
  4. The Company will not retain, use or disclose Personal Data for any purpose other than performing the Services, or outside the direct business relationship between the parties, except as the CCPA expressly permits.
  5. The Company will not combine Personal Data received under the Agreement with Personal Data it receives from or on behalf of any other person, except as permitted for a Service Provider under the CCPA.
  6. The Company certifies that it understands and will comply with the restrictions in paragraphs 2 to 5.
  7. The Company will notify the Customer promptly if it determines it can no longer meet its obligations under the CCPA, and the Customer may take reasonable steps to stop and remediate unauthorised use.
  8. The Customer may, on reasonable notice and no more than once in any twelve month period, take reasonable and appropriate steps to verify that the Company uses Personal Data consistently with the Customer’s obligations, by the means set out in Clause 11.
  9. The Company will assist the Customer in responding to verifiable consumer requests to know, delete, correct, opt out and limit, in the manner set out in Clause 7.
  10. Where the Company engages a Sub-processor, it will do so by written contract imposing equivalent obligations, in accordance with Clause 6.

Questions about this DPA, or a request for a countersigned copy: privacy@infragate.co

Infragate, LLC 1207 Delaware Ave, Suite 679 Wilmington, Delaware 19806 United States