INTENDORIS
ProductMethodDecision intelligenceFor providers · FreePricingTrust
Sign in
Product↗Method↗Decision intelligence↗For providers · Free↗Verified network↗Resources↗Pricing↗Trust↗Status↗Support↗
Sign in
LEGAL · EFFECTIVE 2 AUGUST 2026

Data Processing Addendum

This DPA applies when Intendoris processes personal data on behalf of a customer organisation.

Roles and instructions

The customer is controller and the Intendoris operator is processor for customer content. We process that data only on documented instructions embodied in the agreement, product configuration and authorised requests, unless law requires otherwise.

Confidentiality and security

Authorised personnel are bound by confidentiality. Technical and organisational measures include role-based access, tenant checks, audit trails, encrypted transport, managed storage, controlled file types and sizes, incident escalation, recovery procedures and human approval for consequential AI-assisted actions. Malware scanning is not represented as active until a private scanner has been connected and verified.

Subprocessors

Customer authorises subprocessors for hosting, identity, AI, transactional email, billing, monitoring and support. We remain responsible for processor obligations and will provide notice of material changes through the agreed channel.

Assistance

We assist with data-subject requests, security assessments, breach obligations, DPIAs and regulator enquiries, considering the nature of processing and information available to us. Confirmed personal-data breaches are reported without undue delay.

Deletion, return and audits

On termination, customer data is returned or deleted according to the agreement unless retention is legally required. Reasonable compliance information is available; audits are coordinated to protect other customers, security and confidentiality.

Transfers and precedence

Applicable transfer mechanisms, including standard contractual clauses where required, form part of this DPA. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.

Annex A — processing description

Subject matter: operating a B2B decision and provider-discovery workspace. Duration: the customer term plus configured retention and legally required periods. Data subjects may include customer users, provider personnel and business contacts. Data may include account identity, professional contact details, decision content, provider proposals, communications, audit metadata and outcome measurements.

Annex B — technical and organisational measures

Measures include tenant-scoped server authorization, least-privilege roles, immutable audit records, encrypted transport, private storage architecture, secrets separation, signed billing and webhook events, SSRF controls, retry/dead-letter processing, recovery drills, incident handling, AI budgets and human review for consequential decisions. File uploads remain disabled until malware scanning is verified.

Legal review required

This technical structure must be completed with the customer-specific processing details, transfer mechanism, subprocessor schedule and legal-entity information approved by qualified counsel. It is not legal advice.

Contact

Intendoris
office@intendoris.com

TermsPrivacyRefundsCookiesDPASupportService statusPricing