Data Processing Addendum
This DPA applies when Intendoris processes personal data on behalf of a customer organisation.
Roles and instructions
The customer is controller and the Intendoris operator is processor for customer content. We process that data only on documented instructions embodied in the agreement, product configuration and authorised requests, unless law requires otherwise.
Confidentiality and security
Authorised personnel are bound by confidentiality. Technical and organisational measures include role-based access, tenant checks, audit trails, encrypted transport, managed storage, file scanning, incident escalation, recovery procedures and human approval for consequential AI-assisted actions.
Subprocessors
Customer authorises subprocessors for hosting, identity, AI, transactional email, billing, monitoring and support. We remain responsible for processor obligations and will provide notice of material changes through the agreed channel.
Assistance
We assist with data-subject requests, security assessments, breach obligations, DPIAs and regulator enquiries, considering the nature of processing and information available to us. Confirmed personal-data breaches are reported without undue delay.
Deletion, return and audits
On termination, customer data is returned or deleted according to the agreement unless retention is legally required. Reasonable compliance information is available; audits are coordinated to protect other customers, security and confidentiality.
Transfers and precedence
Applicable transfer mechanisms, including standard contractual clauses where required, form part of this DPA. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.
Contact
Intendoris
office@intendoris.com