Data Processing Addendum
Intelligena LLC · Version
dpa-2026-10-01 · Effective 1 October 2026
How this DPA takes effect. This DPA takes effect as the preamble below states — on the earliest of Customer’s acceptance of the Agreement, execution of this DPA by both parties, or Customer’s first submission of Customer Personal Data — and a signature is not needed for it to apply. It is not self-executing as a separate signed instrument: a separately signed copy exists only where both parties sign it. A countersigned copy is available on request. To request a signed copy or an executed version, write to legal@intelligena.com.
This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms of Service and any master subscription agreement, order form, statement of work or other written agreement (together, the “Agreement”) between Intelligena LLC, a California limited liability company (“Intelligena”), and the customer that has entered into the Agreement (“Customer”). It applies to every product and service Intelligena provides under the Agreement, under any brand or trade name, including those listed in Annex IV.
Brand names such as Practiceful, Yoshuko, Yomomi, Thesaurica, Upstratus, Hammersmythe Robotics, Helixseal, QuorumLock, Unforgetabl and Mandelta are trade names of Intelligena LLC. They are not separate legal entities. In every case the contracting party and the processor under this DPA is Intelligena LLC.
The DPA takes effect on the earliest of three events:
- (a) Customer’s acceptance of the Agreement, if the Agreement incorporates this DPA by reference;
- (b) execution of this DPA by both parties; or
- (c) Customer’s first submission of Customer Personal Data to the Services after this version is published.
1. Definitions and interpretation
1.1 Capitalised terms not defined in this DPA have the meaning given in the Agreement. In this DPA:
- “Aggregated Data” means data that has been combined, aggregated or de-identified so that it does not identify, and cannot reasonably be used to infer information about, or otherwise be linked to, Customer, a particular individual, or a device linked to an individual. It meets the de-identification standards in §2.5.
- “Applicable Data Protection Law” means every law and
regulation that applies to the Processing of Customer Personal Data under the
Agreement, as amended or replaced from time to time. This includes, where
applicable:
- (a) the GDPR;
- (b) the UK GDPR and the UK Data Protection Act 2018, as amended (including by the Data (Use and Access) Act 2025);
- (c) the Swiss Federal Act on Data Protection of 25 September 2020 (“FADP”);
- (d) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (“CCPA”);
- (e) every other United States state comprehensive consumer privacy law in force, together with its regulations (“US State Privacy Laws”);
- (f) the Children’s Online Privacy Protection Act and 16 C.F.R. Part 312 (“COPPA”);
- (g) the Family Educational Rights and Privacy Act, 20 U.S.C. §1232g, and 34 C.F.R. Part 99 (“FERPA”), and state student-data privacy laws;
- (h) the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act, and its implementing regulations (“HIPAA”);
- (i) Canada’s PIPEDA and provincial equivalents; and
- (j) any other data-protection, privacy or data-security law of any jurisdiction, to the extent it applies to the Processing.
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” (and “Process”), “Supervisory Authority”, and “Special Categories of Personal Data” have the meanings given in the GDPR. Where another Applicable Data Protection Law uses an equivalent term, the GDPR term includes it. So “Controller” includes “business” and “controller”, “Processor” includes “service provider”, “contractor” and “processor”, “Personal Data” includes “personal information”, and “Data Subject” includes “consumer”.
- “Customer Personal Data” means Personal Data in Customer Content that Intelligena Processes on Customer’s behalf as a Processor in providing the Services. It excludes Intelligena Controller Data.
- “Customer Content” means all data, files, text, images, audio, video, sensor readings, code, submissions, records and other material that Customer, its Authorised Users or its end users submit to, store in, or create within the Services.
- “Authorised User” means any individual Customer permits to access the Services under Customer’s account. This includes Customer’s employees, contractors, students, patients, clients and end users.
- “Intelligena Controller Data” has the meaning given in §2.3.
- “EU SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
- “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018 (version B1.0 in force 21 March 2022), as amended or replaced.
- “Restricted Transfer” means a transfer of Customer Personal Data that would be prohibited by Applicable Data Protection Law without a safeguard under Article 46 of the GDPR or UK GDPR, or the equivalent under the FADP or other law. An onward transfer counts too.
- “Security Incident” means a breach of
Intelligena’s security that leads to the accidental or unlawful destruction,
loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data
in Intelligena’s or its Subprocessors’ possession, custody or control.
Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data. Examples are unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems.
- “Security Practices” means Intelligena’s published Security Practices document, as updated under §6.3. It is incorporated into this DPA by reference.
- “Services” means the products and services Intelligena provides to Customer under the Agreement.
- “Subprocessor” means any third party (not an Intelligena employee) that Intelligena engages to Process Customer Personal Data in providing the Services.
1.2 Several drafting conventions apply throughout:
- “Including” and similar words mean “including without limitation”.
- A reference to a law includes that law as amended, re-enacted or replaced.
- Headings do not affect interpretation.
- A period of days means calendar days unless business days are stated.
- Where a number is stated in words and figures and the two differ, the words control.
2. Scope and roles of the parties
2.1 Intelligena as Processor. For Customer Personal Data, Customer is the Controller (or, where Customer acts for a third-party Controller, a Processor), and Intelligena is a Processor (or, in the second case, a sub-processor).
Where Customer is itself a Processor, Customer warrants three things:
- its Controller has authorised Customer’s instructions and Customer’s appointment of Intelligena;
- Customer will be Intelligena’s sole point of contact; and
- Intelligena has no obligation to deal directly with that Controller unless Applicable Data Protection Law requires it.
2.2 Description of Processing. Annex I sets out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects. Annex IV sets out the product-specific terms.
2.3 Intelligena as independent Controller. Intelligena Processes the following as an independent Controller, for its own legitimate business operations, and not as Customer’s Processor (“Intelligena Controller Data”):
- (a) account, registration, authentication and contact information about Customer and its Authorised Users, used to administer the account and the relationship;
- (b) billing, payment, tax and transaction records;
- (c) service-generated usage, telemetry, diagnostic, log, device and security data, Processed to provide, secure, maintain, troubleshoot and improve the Services, to detect and prevent fraud, abuse and Security Incidents, and to enforce the Agreement;
- (d) communications with Intelligena, including support requests;
- (e) personal data that Intelligena collects directly from individuals through its own public websites, contact, lead and enquiry forms, marketing communications and alpha or beta programmes; and
- (f) Processing required to comply with Intelligena’s own legal obligations, including tax, accounting, sanctions, law-enforcement and regulatory requirements.
Intelligena Processes Intelligena Controller Data under its Privacy Policy and Applicable Data Protection Law, and is responsible for that Processing. This DPA’s Processor obligations do not apply to it. Where Intelligena Controller Data also falls within Customer Personal Data, Intelligena will Process it as a Controller only to the extent strictly necessary for the purposes in (a) to (f), and only as Applicable Data Protection Law permits.
2.4 Products where Customer, not Intelligena, hosts the data. Some Services are installed, hosted and operated by Customer on Customer’s own infrastructure. QuorumLock is the main example (Annex IV, Part G). For those Services, Intelligena does not Process Customer Content and is not a Processor of it. This DPA then applies only to Personal Data Intelligena receives in providing licensing, support or professional services. Annex IV, Part G applies to that data.
2.5 Aggregated Data. Intelligena may create and use Aggregated Data for three purposes: to operate, secure and improve the Services; for analytics and benchmarking; and for developing new features. Intelligena is the owner and Controller of Aggregated Data. Where Intelligena holds de-identified data derived from Customer Personal Data, it will:
- (a) take reasonable measures to ensure the data cannot be associated with an individual or household;
- (b) publicly commit to maintain and use the data only in de-identified form and not to attempt to re-identify it, except as Applicable Data Protection Law permits for testing the de-identification;
- (c) contractually require any recipient to comply with (a) and (b); and
- (d) not use Customer Content, de-identified or otherwise, to train any third-party general-purpose or foundation model.
2.6 Exclusions. This DPA does not apply to:
- (a) Intelligena’s internal systems and tools that it offers to no customer;
- (b) third-party products, integrations, payment instruments or services that Customer enables, connects to, or accesses through the Services but that Intelligena does not provide (each a “Third-Party Service”); or
- (c) data that Customer or its Authorised Users choose to make public through the Services.
When Customer enables a Third-Party Service, Customer instructs Intelligena to transmit Customer Personal Data to it as Customer directs. The Third-Party Service is not Intelligena’s Subprocessor, and Customer’s relationship with it is governed by Customer’s own terms with that provider.
3. Order of precedence
3.1 If this DPA conflicts with any other part of the Agreement, this DPA controls, but only for the Processing of Customer Personal Data. In every other respect the Agreement controls. In particular, §16 (Limitation of Liability) of this DPA and the limitation of liability in the Agreement are to be read together as one limitation.
3.2 The following documents control over this DPA, in the order listed, but only to the extent of any conflict and only for the data they govern:
- (a) the EU SCCs, the UK Addendum and the Swiss modifications in Annex V, for Restricted Transfers;
- (b) a Business Associate Agreement executed between the parties, for Protected Health Information;
- (c) a student-data privacy agreement executed under Annex IV, Part C, for Student Data.
3.3 Nothing in this DPA reduces either party’s obligations under the EU SCCs, or limits the rights of Data Subjects under them.
4. Customer’s instructions and Customer’s obligations
4.1 Instructions. Intelligena will Process Customer Personal Data only on Customer’s documented instructions, unless Applicable Data Protection Law to which Intelligena is subject requires otherwise. In that case Intelligena will inform Customer of the legal requirement before Processing, unless the law prohibits that on important grounds of public interest.
The following together are Customer’s complete and final documented instructions:
- (a) the Agreement and this DPA;
- (b) Customer’s and its Authorised Users’ use and configuration of the Services’ features and settings; and
- (c) any further written instructions that both parties sign or otherwise agree in writing.
Any instruction beyond these requires Intelligena’s prior written agreement. It may be subject to additional fees, and it must be consistent with the Agreement and the Services’ functionality.
4.2 Unlawful instructions. If Intelligena becomes aware that an instruction, in its opinion, infringes Applicable Data Protection Law, it will inform Customer, and it may suspend performance of that instruction until Customer confirms or modifies it. Intelligena is not obliged to carry out legal review of Customer’s instructions, and has no liability for failing to identify an infringing instruction.
4.3 Customer’s obligations. Customer is solely responsible for the following, and warrants and represents that it complies with each and will continue to do so:
- (a) the accuracy, quality and legality of Customer Personal Data, and of the means by which Customer acquired it;
- (b) having, and maintaining for the duration of the Processing, a valid lawful basis for the Processing, together with all notices, consents, authorisations and permissions Applicable Data Protection Law requires to let Intelligena Process Customer Personal Data as this DPA contemplates. This covers consents and authorisations from parents, guardians, schools, patients and employees;
- (c) its instructions to Intelligena complying with Applicable Data Protection Law;
- (d) its own compliance with Applicable Data Protection Law as Controller, including responding to Data Subjects and Supervisory Authorities, conducting its own data protection impact assessments, and keeping its own records of processing;
- (e) the security of its own and its Authorised Users’ devices, networks, credentials and accounts. This includes using the multi-factor authentication the Services make available, and promptly removing access for Authorised Users who should no longer have it;
- (f) configuring the Services, including sharing, publication, retention, export and integration settings, appropriately for the data it chooses to submit;
- (g) not submitting Prohibited Data except as §4.4 permits; and
- (h) keeping its own copies of Customer Content it needs to retain. The Services are not an archive or a system of record for Customer’s legal retention obligations unless the Agreement expressly says otherwise.
4.4 Prohibited Data. Unless Annex IV expressly permits a category for a specific Service, and any additional agreement Annex IV requires has been executed, Customer will not submit any of the following to the Services (“Prohibited Data”):
- (a) Protected Health Information as defined by HIPAA;
- (b) full payment-card numbers, card verification codes, or other data within the scope of the PCI DSS. Payments go only through the payment processor’s own hosted fields;
- (c) government identification numbers, including Social Security, driver’s licence and passport numbers, unless a Service field expressly asks for one;
- (d) biometric identifiers or biometric information, except as Annex IV, Part E permits;
- (e) precise geolocation, financial account credentials, or Special Categories of Personal Data, except as a Service is expressly designed to Process; or
- (f) Personal Data of children under thirteen (13) years of age, except as Annex IV, Part C permits.
If Customer submits Prohibited Data in breach of this §4.4, Intelligena’s obligations regarding that data are limited to the obligations this DPA states generally for Customer Personal Data. Intelligena has no liability for failing to apply any additional safeguard, notice, consent mechanism or contractual term that the data’s character would have required. Intelligena may delete Prohibited Data on discovery.
4.5 Customer indemnity. Customer will defend, indemnify and hold harmless Intelligena, and its members, managers, officers, employees and agents, against all claims, regulatory proceedings, fines, penalties, losses, damages, liabilities, costs and expenses, including reasonable attorneys’ fees, arising from any of the following:
- (a) Customer’s breach of §4.3 or §4.4;
- (b) Customer’s instructions;
- (c) Customer’s failure to obtain any notice, consent or authorisation required for the Processing; or
- (d) any claim by a third-party Controller for which Customer acts as Processor.
This §4.5 is not subject to the limitation of liability in §16, except as Applicable Data Protection Law requires.
5. Intelligena’s obligations as Processor
5.1 Purpose limitation. Intelligena will Process Customer Personal Data only to provide, maintain, support, secure and improve the Services under the Agreement, and in accordance with §4.1. Intelligena will not Process Customer Personal Data for its own purposes except as §2.3 and §2.5 permit.
5.2 Confidentiality of personnel. Intelligena will ensure that every person it authorises to Process Customer Personal Data:
- (a) has committed to confidentiality, or is under an appropriate statutory duty of confidentiality, that survives the end of their engagement;
- (b) accesses Customer Personal Data only to the extent necessary to perform the Services; and
- (c) receives security and privacy training appropriate to their access.
5.3 No sale; no training of third-party models. Intelligena will not:
- sell Customer Personal Data;
- share it for cross-context behavioural advertising;
- use Customer Content to train, fine-tune or improve any third-party general-purpose or foundation model; or
- allow any Subprocessor to do any of these things.
5.4 Records. Intelligena will maintain the records of processing activities that Applicable Data Protection Law requires of a Processor, and will make them available to a Supervisory Authority on request.
5.5 Disclosure requests. If Intelligena receives a subpoena, court order, warrant or other legal demand from a law-enforcement or government authority for Customer Personal Data, Intelligena will do each of the following unless the law prohibits it:
- (a) try to redirect the requester to Customer;
- (b) promptly notify Customer and provide a copy of the demand, so that Customer can seek a protective order or other remedy; and
- (c) disclose only the minimum Customer Personal Data the demand legally requires, after assessing its lawfulness and challenging it where there are reasonable grounds to consider it unlawful.
Intelligena will not voluntarily give any government authority access to Customer Personal Data, and will not build any back door or similar mechanism for doing so. §12.6 adds further commitments for Restricted Transfers.
6. Security
6.1 Security measures. Intelligena will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against Security Incidents. The measures will be appropriate to:
- the state of the art;
- the costs of implementation;
- the nature, scope, context and purposes of the Processing; and
- the risks to individuals’ rights and freedoms.
At a minimum, the measures are those described in Annex II and the Security Practices (“Security Measures”).
6.2 Shared responsibility. Customer acknowledges that the Security Measures are a description of what Intelligena does, and not a warranty of any result. No set of controls secures a service against every attack. Customer is responsible for the matters in §4.3(e) and (f). Customer has assessed the Security Measures and agrees that, for the Customer Personal Data it submits, they provide a level of security appropriate to the risk.
6.3 Updates. Intelligena may update the Security Measures from time to time, but will not materially reduce the overall protection they provide to Customer Personal Data during a subscription term.
6.4 Attestations. Intelligena does not currently hold a SOC 2 Type I or Type II report, an ISO/IEC 27001 certification, or a HITRUST certification. Nothing in this DPA is a representation that it does. If Intelligena obtains any such report or certification, §11.2 applies to it.
7. Security Incidents
7.1 Notification. Intelligena will notify Customer without undue delay after it becomes aware of a Security Incident affecting Customer Personal Data, and in any event within seventy-two (72) hours of becoming aware of it. Notice goes to the email address of Customer’s account owner or administrator, or to any security contact Customer has designated in writing. Customer is responsible for keeping those addresses current.
7.2 Content. Intelligena will provide the following, to the extent it is known at the time, and will supplement the notice as more information becomes available:
- (a) the nature of the Security Incident, including, where possible, the categories and approximate number of Data Subjects and records concerned;
- (b) a contact point for more information;
- (c) the likely consequences; and
- (d) the measures taken or proposed to address the incident and mitigate its effects.
7.3 Response. Intelligena will:
- (a) promptly take reasonable steps to contain, investigate and remediate the Security Incident;
- (b) cooperate reasonably with Customer’s investigation; and
- (c) provide the forensic findings it holds about the incident, with redactions limited to protecting other customers’ data and the security of Intelligena’s systems.
7.4 Notifications to third parties. Customer is responsible for deciding whether to notify Data Subjects, Supervisory Authorities, regulators or others, and for making any such notice, unless Applicable Data Protection Law requires Intelligena to notify them directly. Intelligena will not notify Customer’s Data Subjects or regulators about a Security Incident affecting Customer Personal Data, or name Customer publicly, without Customer’s prior written consent. Two exceptions apply: where the law requires it, or where it is necessary to protect any person from imminent harm.
7.5 Costs. Where a Security Incident is caused by Intelligena’s or its Subprocessors’ breach of this DPA, Intelligena will reimburse Customer’s reasonable, documented, out-of-pocket costs of the following, to the extent the law requires them or they are reasonably necessary:
- (a) notifying affected individuals and regulators;
- (b) credit monitoring or identity-protection services for affected individuals, for up to twelve (12) months, where the incident involves data for which such services are customary; and
- (c) operating a call centre.
These costs are direct damages and count toward the cap in §16.3.
7.6 NO ADMISSION. INTELLIGENA’S NOTIFICATION OF, OR RESPONSE TO, A SECURITY INCIDENT IS NOT AN ACKNOWLEDGEMENT BY INTELLIGENA OF ANY FAULT OR LIABILITY FOR THE SECURITY INCIDENT.
8. Subprocessors
8.1 General authorisation. Customer gives Intelligena a general written authorisation to engage Subprocessors. This includes the Subprocessors (and categories of Subprocessor) listed in Annex III and in the current named schedule Intelligena provides on request to privacy@intelligena.com.
8.2 Subprocessor obligations. Before a Subprocessor Processes Customer Personal Data, Intelligena will:
- (a) carry out reasonable due diligence on the Subprocessor’s security and privacy practices, and repeat it periodically;
- (b) enter into a written agreement with the Subprocessor that imposes
data-protection obligations no less protective than this DPA, as appropriate to the
service the Subprocessor provides. This includes:
- the data-residency requirement in §12.1;
- the prohibition in §5.3; and
- where the Subprocessor Processes Customer Personal Data subject to the CCPA, the terms §14 requires.
8.3 Liability. Intelligena remains responsible to Customer for its Subprocessors’ performance of their obligations, to the same extent Intelligena would be liable if it had performed the services itself. That liability is subject to §16.
8.4 Notice of new Subprocessors. Intelligena will give Customer at least thirty (30) days’ notice before a new Subprocessor begins Processing Customer Personal Data. Notice is given by updating the Subprocessors page and by email to Customers who subscribe to updates through privacy@intelligena.com.
8.5 Emergency replacement. Intelligena may replace a Subprocessor on shorter notice where the replacement is urgently needed for security, legal or service-continuity reasons that are outside Intelligena’s reasonable control, for example where a Subprocessor ceases business or suffers a Security Incident. Intelligena will then give notice as soon as reasonably practicable, and the objection right in §8.6 runs from that notice.
8.6 Objection. Customer may object to a new Subprocessor on reasonable grounds relating to data protection. To do so, Customer gives written notice to privacy@intelligena.com within fifteen (15) days of the notice under §8.4, explaining the grounds. The parties will then discuss Customer’s concerns in good faith. Intelligena may, at its option:
- (a) make the Services available without the objected-to Subprocessor Processing Customer Personal Data; or
- (b) recommend a commercially reasonable change to Customer’s configuration or use of the Services that avoids that Processing.
If neither is reasonably available within thirty (30) days of the objection, either party may terminate the affected Service by written notice. Intelligena will then refund any prepaid fees for the terminated Service covering the period after termination.
THIS TERMINATION AND REFUND IS CUSTOMER’S SOLE AND EXCLUSIVE REMEDY FOR AN OBJECTION TO A SUBPROCESSOR.
If Customer does not object within the period above, Customer is deemed to have authorised the new Subprocessor.
8.7 Copies of agreements. Where the EU SCCs require Intelligena to provide a copy of a Subprocessor agreement, Intelligena may first remove commercial information and terms unrelated to data protection. It may provide a summary where the Subprocessor’s confidentiality terms prohibit disclosing the full text. Customer agrees that this satisfies Clause 9(c) of the EU SCCs.
9. Data Subject requests and assistance
9.1 Self-service. The Services give Customer functionality to access, correct, export, restrict and delete Customer Personal Data. Customer will use that functionality first to respond to Data Subject requests.
9.2 Requests received by Intelligena. If Intelligena receives a request from a Data Subject about Customer Personal Data and can reasonably identify Customer from it, Intelligena will refer the Data Subject to Customer and will forward the request to Customer within five (5) business days. Intelligena will not respond to the request itself, except to:
- confirm that it has been forwarded; or
- comply with Applicable Data Protection Law, such as by honouring a global privacy control signal at the browser level where the law requires it.
9.3 Assistance. Taking into account the nature of the Processing, Intelligena will give Customer reasonable assistance, by appropriate technical and organisational measures, to fulfil Customer’s obligation to respond to Data Subject requests, where Customer cannot do so through the Services. Where the assistance goes beyond the Services’ standard functionality, or beyond what Applicable Data Protection Law requires of a Processor, Intelligena may charge its then-current professional-services rates, notified in advance.
10. Impact assessments, consultations and regulators
10.1 Intelligena will give Customer reasonable assistance with the following, where Customer does not otherwise have access to the information it needs:
- data protection impact assessments under Article 35 of the GDPR (or its equivalent);
- risk assessments under the CCPA regulations or US State Privacy Laws; and
- prior consultations with Supervisory Authorities.
The assistance is limited to information about the Services and the Processing that is available to Intelligena. Intelligena meets this obligation primarily by providing the Security Practices, this DPA, Annex I, and responses to a reasonable security questionnaire as §11.3 describes.
10.2 Intelligena will cooperate, on request, with a Supervisory Authority in the performance of its tasks, to the extent Applicable Data Protection Law requires.
10.3 Automated decision-making. Where Customer uses a feature of the Services that is automated decision-making technology within the meaning of Applicable Data Protection Law, Intelligena will provide information reasonably available to it about the logic involved and about the feature’s intended purpose and limitations. This supports Customer’s own pre-use notices, opt-out and access obligations.
The AI features of the Services produce recommendations to a human being. Customer, not Intelligena, decides whether any output is used to make a decision producing legal or similarly significant effects about an individual, and is responsible for that decision.
10.4 Cybersecurity audits. Where Customer must complete a cybersecurity audit under the CCPA regulations, Intelligena will make available information reasonably necessary for that audit in the manner §11 describes.
11. Audits
11.1 Information first. Intelligena will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and with the Processor obligations of Applicable Data Protection Law. Customer agrees to exercise its audit rights first by reviewing the information described in §11.2 and §11.3, and to request an audit under §11.4 only if that information does not reasonably satisfy the purpose the audit is required for.
11.2 Reports. If Intelligena obtains a third-party audit report or certification (such as a SOC 2 Type II report or ISO/IEC 27001 certification) covering the Services, it will provide a copy, or the relevant part, on request and under confidentiality. Customer agrees that such a report satisfies any audit or inspection request covering the controls in its scope.
11.3 Questionnaires and test summaries. Once in any twelve (12) month period, on written request, Intelligena will:
- (a) complete a reasonable written security and privacy questionnaire; and
- (b) provide a summary of its most recent vulnerability assessment or penetration test, where one has been carried out.
11.4 On-site or remote audit. Where any of the following apply, Customer may conduct an audit, including an inspection:
- (a) the information in §11.2 and §11.3 is not reasonably sufficient to demonstrate compliance;
- (b) a Supervisory Authority or regulator requires it;
- (c) Applicable Data Protection Law (including Clause 8.9 of the EU SCCs) entitles Customer to it; or
- (d) a Security Incident involving Customer Personal Data has occurred.
Every such audit is subject to these conditions:
- (i) Customer gives at least forty-five (45) days’ written notice, or such shorter notice as a regulator requires. The notice includes a proposed scope, which the parties agree in good faith before the audit begins;
- (ii) only one audit takes place in any twelve (12) month period, except under (b) or (d);
- (iii) the audit is conducted during normal business hours, without unreasonable disruption to Intelligena’s operations, for no more than two (2) business days, and remotely where practicable;
- (iv) the audit is conducted by Customer or an independent auditor that is not an Intelligena competitor, that Intelligena has approved (approval not to be unreasonably withheld), and that is bound by written confidentiality obligations no less protective than the Agreement’s;
- (v) the audit does not give access to other customers’ data, to Intelligena’s privileged or trade-secret information, or to systems whose access would compromise their security. Any access to Subprocessor facilities is governed by the Subprocessor’s own audit terms;
- (vi) Customer bears its own costs and reimburses Intelligena’s reasonable costs at its then-current professional-services rates, notified in advance. This does not apply where the audit reveals a material breach of this DPA by Intelligena; and
- (vii) Customer provides Intelligena with a copy of any audit report free of charge. The report is Intelligena’s Confidential Information.
11.5 Remediation. If an audit identifies a material non-compliance with this DPA, Intelligena will remediate it within a reasonable period agreed in good faith.
12. Data location and international transfers
12.1 Data residency. Intelligena will store Customer Personal Data at rest only within the United States and its territories. This includes every backup, archive, replica, cache and disaster-recovery copy, and it applies where the data is held by a subcontracted hosting, storage or content-delivery facility.
Network edge services may terminate transport encryption and route traffic at points of presence outside the United States. They are configured not to store, copy or cache Customer Content, and do not hold Customer Personal Data at rest.
Personnel or Subprocessors may access Customer Personal Data from outside the United States only where Annex III permits it, and only under §12.2–§12.6.
12.2 Authorisation. Customer authorises Intelligena and its Subprocessors to transfer and Process Customer Personal Data in the United States, and wherever else Annex III permits, subject to this §12.
12.3 EEA transfers. For a Restricted Transfer subject to the GDPR, the EU SCCs are incorporated into this DPA as completed in Annex V, and apply as follows:
- (a) Module Two (Controller to Processor), where Customer is a Controller; and
- (b) Module Three (Processor to Processor), where Customer is a Processor.
12.4 UK and Swiss transfers. For a Restricted Transfer subject to the UK GDPR, the EU SCCs apply as amended by the UK Addendum, completed as Annex V sets out. For a Restricted Transfer subject to the FADP, the EU SCCs apply with the modifications in Annex V.
12.5 Alternative mechanisms and continuity. If the transfer mechanism in this §12 is invalidated, amended or replaced, or if a Supervisory Authority or court of competent jurisdiction rules that it does not provide an adequate safeguard:
- (a) the parties will promptly cooperate in good faith to adopt a valid alternative transfer mechanism. This includes any successor standard contractual clauses or any adequacy framework under which Intelligena or the relevant Subprocessor certifies; and
- (b) until one is adopted, Intelligena will continue to apply the substantive protections of the EU SCCs to the affected Customer Personal Data.
Where no alternative mechanism can lawfully be adopted, either party may terminate the affected Service under §8.6, with the refund it provides, as its sole remedy.
Intelligena does not rely on, and does not represent that it is certified under, the EU–US Data Privacy Framework.
12.6 Government-access commitments (supplementary measures). For any Restricted Transfer, in addition to §5.5, Intelligena:
- (a) has not received, as at the effective date, any order under Section 702 of the US Foreign Intelligence Surveillance Act, or any similar order, requiring disclosure of customer personal data, and is not aware of any reason to expect one;
- (b) will use every reasonable legal mechanism to challenge any request for Customer Personal Data that it reasonably considers overbroad or unlawful;
- (c) will encrypt Customer Personal Data in transit and at rest as Annex II describes; and
- (d) will document and periodically review its assessment of the laws and practices of the destination country under Clause 14 of the EU SCCs, and make that assessment available to Customer on request.
12.7 Other jurisdictions. Where Applicable Data Protection Law outside the EEA, UK and Switzerland requires a transfer safeguard, the EU SCCs as completed in Annex V apply, with the references to the GDPR and its institutions read as references to the equivalent law and institutions. This applies unless a mechanism that law specifically prescribes is required, in which case the parties will execute it on request.
13. Return and deletion
13.1 During the term. Customer can export and delete Customer Personal Data at any time using the Services’ functionality.
13.2 On termination. On expiry or termination of the Agreement or the relevant Service, Customer may export Customer Personal Data for thirty (30) calendar days using the Services’ export functionality, or on written request in a commonly used, machine-readable format.
After that, Intelligena will delete Customer Personal Data from its active systems within ninety (90) days of the end of the term. This period includes the account-recovery window in the Privacy Policy. Intelligena will certify the deletion in writing on request.
13.3 Backups. Copies held in routine encrypted backups are not extracted individually. They are overwritten as the backups age out on their normal cycle, which is no longer than thirty-five (35) days after deletion from active systems. Until then they remain protected by this DPA and are not restored to active use except to recover from a disaster or a Security Incident. If they are restored, the restored Customer Personal Data is deleted again under this §13.
13.4 Retention required by law. Intelligena may retain Customer Personal Data where Applicable Data Protection Law or other applicable law requires it. In that case Intelligena will:
- keep it confidential;
- keep it protected under this DPA;
- Process it only for the purpose the law requires; and
- delete it when the obligation ends.
Intelligena Controller Data is retained under the Privacy Policy.
14. United States state privacy laws
14.1 CCPA. To the extent Customer Personal Data is “personal information” subject to the CCPA, Intelligena is a “service provider” or “contractor”, and Customer discloses the Customer Personal Data to Intelligena only for the limited and specified business purposes of providing the Services described in the Agreement and Annex I. Intelligena:
- (a) will not sell or share Customer Personal Data;
- (b) will not retain, use or disclose Customer Personal Data:
- (i) for any purpose, including any commercial purpose, other than the business purposes specified in the Agreement, or as the CCPA otherwise permits; or
- (ii) outside the direct business relationship between Customer and Intelligena;
- (c) will not combine Customer Personal Data with personal information it receives from or on behalf of another person, or collects from its own interaction with a consumer, except as the CCPA and its regulations permit for a service provider;
- (d) will comply with the CCPA’s obligations that apply to it, and will provide the same level of privacy protection the CCPA requires of businesses;
- (e) grants Customer the right to take reasonable and appropriate steps to ensure Intelligena uses Customer Personal Data consistently with Customer’s CCPA obligations. These steps are exercised through §11;
- (f) will notify Customer if it determines it can no longer meet its CCPA obligations;
- (g) grants Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data;
- (h) will engage any subcontractor that Processes Customer Personal Data only under a written contract binding it to obligations no less protective than this §14.1;
- (i) will cooperate with Customer, as §9 and §10 describe, in responding to verifiable consumer requests, in honouring opt-out preference signals, and in Customer’s risk assessments and automated-decision-making obligations under the CCPA regulations; and
- (j) certifies that it understands and will comply with the restrictions in this §14.1.
14.2 Other US State Privacy Laws. To the extent a US State Privacy Law other than the CCPA applies to Customer Personal Data, Intelligena will:
- (a) Process Customer Personal Data only on Customer’s instructions;
- (b) ensure each person Processing it is subject to a duty of confidentiality;
- (c) at Customer’s direction, delete or return all Customer Personal Data at the end of the provision of services, unless retention is required by law (§13);
- (d) on reasonable request, make available all information in its possession necessary to demonstrate compliance with that law;
- (e) allow and cooperate with reasonable assessments by Customer or Customer’s designated assessor. Alternatively, with Customer’s consent (not to be unreasonably withheld), Intelligena may arrange for a qualified and independent assessor to assess its policies and technical and organisational measures, using an appropriate and accepted control standard or framework, and provide the report to Customer on request. §11 governs how assessments are conducted; and
- (f) engage a subcontractor only under a written contract requiring it to meet the processor obligations of that law, after giving Customer notice and an opportunity to object under §8.
14.3 Health data laws. Where Customer Personal Data is “consumer health data” under Washington’s My Health My Data Act, or under an equivalent law in Nevada, Connecticut or another state, Intelligena will Process it only to provide the Services on Customer’s instructions. Customer is responsible for obtaining every consent those laws require.
15. Sector-specific terms
The sector-specific terms for health information (HIPAA), children’s and student data (COPPA, FERPA and state student-privacy laws), artificial intelligence features, and biometric data are in Annex IV and are part of this DPA.
16. Limitation of liability
16.1 ONE LIMITATION, NOT TWO. EACH PARTY’S AND ITS AFFILIATES’ LIABILITY, TAKEN TOGETHER IN THE AGGREGATE, ARISING OUT OF OR RELATED TO THIS DPA (INCLUDING THE EU SCCS, THE UK ADDENDUM AND THE SWISS MODIFICATIONS IN ANNEX V, AND WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE OR UNDER ANY OTHER THEORY) IS SUBJECT TO THE EXCLUSIONS AND LIMITATIONS OF LIABILITY IN THE AGREEMENT. ANY REFERENCE IN THE AGREEMENT TO A PARTY’S LIABILITY MEANS THAT PARTY’S AGGREGATE LIABILITY UNDER THE AGREEMENT AND ALL DPAS AND OTHER ADDENDA TOGETHER. THIS DPA CREATES NO SEPARATE OR ADDITIONAL CAP.
16.2 NO INDIRECT LOSS. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE UNDER THIS DPA FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, GOODWILL OR ANTICIPATED SAVINGS, HOWEVER CAUSED. THIS IS SO EVEN IF THE PARTY HAS BEEN ADVISED OF THEIR POSSIBILITY.
16.3 THE HIGHER CAP FOR A SECURITY INCIDENT. FOR A CLAIM ARISING OUT OF A SECURITY INCIDENT, OR OUT OF INTELLIGENA’S BREACH OF §5, §6, §7, §8, §12 OR §14 OF THIS DPA, INTELLIGENA’S TOTAL AGGREGATE LIABILITY IS LIMITED TO THE GREATER OF:
- (A) THREE (3) TIMES THE TOTAL AMOUNTS CUSTOMER ACTUALLY PAID INTELLIGENA LLC FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR
- (B) FIFTY THOUSAND U.S. DOLLARS (US$50,000).
THIS LIMIT IS THE “SUPER-CAP” IN THE TERMS OF SERVICE (SECTION 12.6). IT APPLIES IN PLACE OF, AND NOT IN ADDITION TO, THE ORDINARY CAP FOR SUCH A CLAIM, AND IT IS NOT A SEPARATE OR ADDITIONAL LIMIT FOR EACH INCIDENT, CLAIM OR SERVICE. §16.2 STILL APPLIES TO SUCH A CLAIM, EXCEPT THAT THE COSTS DESCRIBED IN §7.5 ARE DIRECT DAMAGES.
16.4 What is not limited. Nothing in this DPA or the Agreement limits or excludes either party’s liability for any of the following:
- (a) its fraud or fraudulent misrepresentation, wilful injury to the person or property of another, or violation of law, to the extent California Civil Code §1668 forbids it;
- (b) death or personal injury caused by its negligence;
- (c) Customer’s obligations under §4.5 and its payment obligations; or
- (d) any liability that Applicable Data Protection Law does not permit to be limited.
Nothing in this §16 limits either party’s liability to Data Subjects under Clause 12 of the EU SCCs, Article 82 of the GDPR, or their equivalents, to the extent those provisions prohibit it.
16.5 Regulatory fines. An administrative fine or penalty that a Supervisory Authority or regulator imposes on a party is that party’s own liability, and that party bears it. The exception is a fine or penalty imposed because of the other party’s breach of this DPA. In that case it is recoverable from the other party as direct damages, subject to this §16, but only to the extent the law permits such an allocation.
16.6 Reformation, not severance. If any part of this §16 is held unenforceable as to any claim, the court or arbitrator will reform it to the minimum extent necessary to make it enforceable, and will enforce it as reformed. This DPA does not stand or fall on the validity of any single limitation, and the remainder of this §16 continues to apply in full.
16.7 NO PERSONAL LIABILITY. NO MEMBER, MANAGER, OFFICER, EMPLOYEE OR AGENT OF INTELLIGENA LLC HAS ANY PERSONAL LIABILITY, JOINTLY OR SEVERALLY, UNDER OR IN CONNECTION WITH THIS DPA, THE EU SCCS OR ANY PROCESSING OF CUSTOMER PERSONAL DATA. INTELLIGENA LLC ALONE IS THE PROCESSOR, THE DATA IMPORTER AND THE CONTRACTING PARTY. EACH SUCH PERSON IS AN INTENDED THIRD-PARTY BENEFICIARY OF THIS §16.7 AND MAY ENFORCE IT DIRECTLY. This §16.7 does not apply to any liability that cannot lawfully be excluded.
17. Term and survival
17.1 This DPA remains in force for as long as Intelligena Processes Customer Personal Data on Customer’s behalf. That may be longer than the term of the Agreement, for example during the periods in §13.
17.2 The following sections survive termination for as long as Intelligena holds any Customer Personal Data, and §4.5 and §16 survive indefinitely: §4.5, §5.2, §5.5, §6, §7, §12, §13, §16, §18 and §19.
18. Governing law and disputes
18.1 This DPA is governed by the laws of the State of California, without regard to its conflict-of-laws rules. There are two exceptions:
- (a) the EU SCCs, the UK Addendum and the Swiss modifications are governed by the law Annex V specifies; and
- (b) any provision that Applicable Data Protection Law requires to be governed by another law is governed by that law, to that extent.
18.2 Disputes under this DPA are resolved under the dispute-resolution provisions of the Agreement. Where the Agreement provides none, they are resolved in the state and federal courts located in San Diego County, California, to whose exclusive jurisdiction the parties submit. This §18.2 does not apply to disputes the EU SCCs or UK Addendum require to be brought elsewhere.
19. General
19.1 Changes in law. Intelligena may amend this DPA by notice to Customer to the extent reasonably necessary to comply with a change in Applicable Data Protection Law, or with the order or guidance of a Supervisory Authority or court. An amendment under this §19.1 may not materially reduce the protection this DPA gives Customer Personal Data.
Any other amendment requires the parties’ written agreement. Intelligena may also publish a new version of this DPA, which applies to Customers who accept it. The version stamped on this DPA records which text a Customer agreed to.
19.2 Severability. If any provision of this DPA is held invalid or unenforceable, it is reformed to the minimum extent necessary (and, for §16, under §16.6), and the remainder of the DPA continues in full force.
19.3 Notices. Notices to Intelligena under this DPA go to: Intelligena LLC, Republic Registered Agent Inc., 3400 Cottage Way Ste G2, Sacramento CA 95825, United States of America, with a copy by email to legal@intelligena.com. Privacy and data-protection requests go to privacy@intelligena.com. Security matters go to security@intelligena.com.
Notices to Customer go to the account owner’s email address, or to any address Customer designates in writing.
19.4 No third-party beneficiaries. No person other than the parties has any right to enforce any term of this DPA, except as follows:
- Data Subjects, to the extent the EU SCCs grant them rights; and
- the persons named in §16.7.
19.5 Entire agreement; counterparts. This DPA, together with the Agreement, is the parties’ entire agreement on its subject matter. It supersedes all prior data-processing terms between them for the Services. It may be executed in counterparts and by electronic signature, and acceptance by click-through or by use under §1 (Preamble) is as binding as a signature.
Annex I — Description of the Processing
A. List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer, as identified in the Agreement | Intelligena LLC |
| Address | As stated in the Agreement or account | Republic Registered Agent Inc., 3400 Cottage Way Ste G2, Sacramento CA 95825, United States of America |
| Contact | Customer’s account owner or designated privacy contact | privacy@intelligena.com |
| Activities | Use of the Services under the Agreement | Provision of the Services under the Agreement |
| Role | Controller (Module Two) or Processor (Module Three) | Processor (Module Two) or sub-processor (Module Three) |
| Signature and date | By accepting or executing the Agreement or this DPA | By accepting or executing the Agreement or this DPA |
B. Description of the transfer and Processing
Categories of Data Subjects. These are determined by Customer, and may include:
- Customer’s personnel, contractors and Authorised Users;
- Customer’s own clients, patients, students, learners, parents and guardians, course purchasers, website visitors and end users; and
- any individual whose Personal Data appears in Customer Content.
Categories of Personal Data. These are determined by Customer, and may include:
- identification and contact data (name, email, telephone, postal address, username);
- account and authentication data;
- professional data (employer, title, practice details);
- educational data (enrolments, submissions, grades, attendance, progress);
- content data (any Personal Data within files, messages, recordings, images, forms, signed documents, code and other Customer Content);
- scheduling and transaction records; and
- device and usage data relating to Authorised Users’ use of the Services.
Special categories and sensitive data. Only where a Service is designed for it and Annex IV permits it:
- health information (Practiceful, under an executed BAA); and
- data about children and students (Yoshuko, Yomomi and other education Services, under Annex IV, Part C).
Restrictions and safeguards apply as follows:
- the Security Measures in Annex II;
- access restricted to personnel with a need to know;
- audit logging of access to health information;
- multi-factor authentication required for accounts that can reach protected health information; and
- no use for training third-party models.
Frequency of the transfer. Continuous, for the duration of the Agreement.
Nature of the Processing. Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, analysis (including by machine-learning models on Customer’s request), transmission, disclosure by transmission to Authorised Users and Third-Party Services at Customer’s direction, alignment, restriction, erasure and destruction.
Purpose of the Processing. To provide, maintain, support, secure and improve the Services under the Agreement, as described for each Service in Annex IV, and for no other purpose.
Duration and retention. For the term of the Agreement, plus the periods in §13.
Transfers to Subprocessors. As described in Annex III, for the purposes and duration above.
C. Competent Supervisory Authority
This is determined under Clause 13 of the EU SCCs:
- where Customer is established in an EU Member State, the authority of that Member State;
- where Customer has appointed an EU representative under Article 27 GDPR, the authority of the Member State where the representative is established; and
- otherwise, the authority of the Member State where the Data Subjects whose Personal Data is transferred are located. Where that cannot be determined, the Irish Data Protection Commission.
For the UK, it is the Information Commissioner’s Office. For Switzerland, it is the Federal Data Protection and Information Commissioner.
Annex II — Technical and organisational security measures
These are the minimum Security Measures. The Security Practices describe them in more detail and are incorporated by reference.
- Encryption in transit. TLS 1.2 or higher for all traffic between users and the Services. Plain HTTP is redirected to HTTPS, and HSTS is served. Administrative and inter-site traffic travels over authenticated, encrypted tunnels.
- Encryption at rest. AES-256 or equivalent for databases, object storage and backups. Off-site backups are encrypted before they leave the source system.
- Secrets management. Application credentials are encrypted at rest, and decrypted only into the memory of the process that needs them. They are never committed to source control in plaintext. Log output is redacted by value.
- Payment data. Intelligena does not receive or store full payment-card numbers. Card data goes directly to a PCI DSS Level 1 payment processor.
- Access control. The following apply:
- least-privilege access to production, reviewed periodically;
- multi-factor authentication for administrative access;
- key-based administrative authentication, from restricted source addresses, with password authentication disabled;
- prompt de-provisioning; and
- separate hosts and credentials for development, test and production. Production Customer Personal Data is not copied into development or test environments.
- Pre-release environments. Quality-assurance environments reachable from the internet are restricted, at the proxy and at the host firewall, to known source addresses and to the authenticated VPN.
- Audit logging. The following are logged:
- access to health information, in an append-only log identifying who, what and when; and
- administrative actions on production infrastructure.
Logs are retained for at least twelve (12) months and protected against alteration by the people whose actions they record.
- Vulnerability management. Dependencies and container images are
scanned for known vulnerabilities. Application source is scanned for insecure
patterns. Host configuration is measured against a versioned benchmark derived from
the CIS Ubuntu Linux Benchmark. Before a production deployment, an automated security
gate refuses findings rated High or above.
Confirmed vulnerabilities are remediated, or mitigated to equivalent risk, within these periods:
Severity Period Critical 7 days High 30 days Medium 90 days Low Next scheduled maintenance A vulnerability that is being actively exploited is treated as Critical.
- Application security. The following are in place:
- a Content Security Policy on every public web application, without
unsafe-inlinescript or style sources; - CSRF protection;
- rate limiting and bot challenges on authentication and public forms; and
- secure-cookie and HSTS settings in production.
- a Content Security Policy on every public web application, without
- Network security. Host firewalls default to deny. SSH is protected by brute-force controls. Backend data stores are not exposed to the public internet.
- Backup and recovery. Encrypted backups are taken on a regular schedule, held off-site within the United States, and restored in periodic tests. Backups are overwritten on a rolling schedule of no more than thirty-five (35) days.
- Incident response. A documented process covers detection, containment, investigation, notification within the period in §7, and post-incident review. Vulnerability reports sent to security@intelligena.com are acknowledged within two (2) business days.
- Personnel. Written confidentiality obligations, security and privacy training, and access removed when it is no longer needed.
- Subprocessor management. Due diligence before engagement and periodically afterwards. Written data-protection terms, including data residency and no model training.
- Data minimisation and deletion. Features collect only the data they need. Deletion and retention follow §13 and Customer’s configuration.
- AI features. Content is submitted to a model only when a user invokes a feature that needs it. Model providers are contractually prohibited from training on it. Where practicable, inference runs on infrastructure Intelligena operates itself.
Annex III — Subprocessors
Intelligena engages Subprocessors in the categories below. The current named schedule (entity, service, location and transfer mechanism) is provided on request to privacy@intelligena.com, and is attached to any executed copy of this DPA. The categories are also published on the Subprocessors page.
| Category | What it may Process | Location of data at rest |
|---|---|---|
| Infrastructure hosting and compute (including Intelligena-operated servers and contracted virtual-server providers) | All Customer Personal Data, at rest and in transit | United States |
| Object storage, off-site backup and content delivery | Uploaded files, media, exports, published assets and encrypted backups | United States |
| Payment processing | Name, email, billing address, card details (never received by Intelligena), transaction records | United States |
| Transactional email delivery | Recipient address, message content, delivery metadata | United States |
| SMS and voice delivery (where enabled) | Telephone number, message content, delivery metadata | United States |
| Machine-learning model providers (where a feature uses a third-party model) | Only the content submitted to an AI feature at the moment it is used; never used for training | United States |
| Error monitoring and observability | Diagnostic and log data, which may incidentally contain identifiers | United States |
| Domain, DNS and network edge security | IP addresses and request metadata only; configured to store no Customer Content | Edge points of presence worldwide; no Customer Personal Data at rest outside the United States |
Intelligena’s own affiliates, if any are formed, may act as Subprocessors under §8.
Annex IV — Product-specific terms
Each Part applies to the Service(s) it names, in addition to the rest of this DPA. Where a Part conflicts with the body of this DPA, the Part controls for that Service.
Part A — Product schedule
| Service (brand) | What it does | Intelligena’s role for Customer Content | Parts that apply |
|---|---|---|---|
| Practiceful (practiceful.com) | Practice management, client records, scheduling, billing, forms and websites for practitioners | Processor; Business Associate where a BAA is executed | B, D, E, F |
| Yoshuko (yoshuko.com) | Learning management, course creation and sale, attendance, grading, alpha programme | Processor for institutions and creators; independent Controller for learners who contract with Intelligena directly | C, D, F |
| Yomomi (yomomi.com) | Self-paced coding courses; teacher classes and gradebook; sandboxed code execution | Processor for schools and teachers; independent Controller for learners who contract directly | C, D, F |
| Thesaurica (thesaurica.com) | Curriculum site and sales enquiries | Independent Controller for enquiry and lead data; Processor only for institutional deployments with user accounts | C (institutional only), F |
| Hammersmythe Robotics (hammersmythe.com) | Browser-based robot simulation for grades 6–12 | No accounts and no Customer Personal Data are collected by design; any incidental service data is Intelligena Controller Data | C (to the extent any student data is ever Processed) |
| Upstratus (upstratus.com) | Collecting sensor and audio data, training embedded ML models, generating firmware | Processor | D, E, F |
| Intelligena (intelligena.com) | Company site, partner and alpha portal | Independent Controller | — |
| QuorumLock (Helixseal) | Post-quantum secrets management, installed and operated by Customer | Not a Processor of Customer Content; Processor only of support data | G |
| Unforgetabl, Mandelta, and any other Service | — | As stated in the order form; otherwise Processor | H |
Part B — Health information (HIPAA and state health-data laws)
B.1 Protected Health Information (“PHI”) may be submitted only to Practiceful, and only after the parties have executed Intelligena’s Business Associate Agreement (“BAA”). For every other Service, and for Practiceful before a BAA is executed, PHI is Prohibited Data.
B.2 Once executed, the BAA governs PHI and controls over this DPA as to PHI, under §3.2. The BAA’s breach-notice period, access/amendment/accounting periods and cost allocation apply in place of the corresponding terms of this DPA.
B.3 Intelligena physically maintains every electronic health record it holds for Customer, and every backup, cache and copy of it, within the United States, including at subcontracted facilities. This commitment is made for Texas Health and Safety Code §183, as amended by Texas SB 1188, and similar laws.
B.4 HIPAA compliance is a status Customer holds as a covered entity. The Services support it but cannot hold it on Customer’s behalf.
Part C — Children’s and student data
C.1 Scope. “Student Data” means Personal Data about a student or a child under eighteen (18) that Customer, a school, a teacher, a parent or guardian, or a student submits to the Services in an educational context. This includes education records within the meaning of FERPA.
C.2 Authority and consent. Learners under eighteen (18) may use the Services only through a school, educational agency, teacher, parent or guardian. That person warrants that they hold every authority and consent the law requires. Children under thirteen (13) may use an education Service only where:
- (a) an educational institution has authorised it for the use and benefit of the school, and for no other commercial purpose, as permitted by the COPPA Rule (16 C.F.R. §312.5(c)); or
- (b) verifiable parental consent has been obtained.
Customer is responsible for obtaining that consent or authorisation and for giving parents any notice the law requires. Intelligena will provide the information about its practices that Customer reasonably needs to do so.
C.3 FERPA. Where Customer is an educational agency or institution, Intelligena acts as a “school official” with a “legitimate educational interest” under 34 C.F.R. §99.31(a)(1). It is under Customer’s direct control with respect to education records, and will not re-disclose education records except as FERPA permits and Customer directs.
C.4 Prohibited uses. Intelligena will not:
- use Student Data for targeted advertising;
- build a profile of a student for any purpose other than providing the Services;
- sell Student Data; or
- disclose Student Data except as this DPA permits.
These commitments are given for the purposes of California Business and Professions Code §22584 (SOPIPA) and equivalent state laws. Intelligena may use Student Data for adaptive or personalised learning within the Services, and may use de-identified Student Data under §2.5.
C.5 Retention. Intelligena keeps Student Data only as long as reasonably necessary to provide the Services, under a written retention policy. It deletes Student Data under §13, or earlier on Customer’s written request, unless a parent or eligible student has chosen to keep content in an account they control.
C.6 Security program. Intelligena maintains a written information security program for children’s personal information, as the amended COPPA Rule requires. That program is consistent with Annex II.
C.7 Parent and student requests. Requests to review, correct or delete Student Data go to the school or Customer, which Intelligena will assist under §9.
C.8 State student-data agreements. Where state law requires a specific agreement, Customer and Intelligena will execute it on request. Examples are New York Education Law §2-d (with its Parents’ Bill of Rights and supplemental information), Illinois SOPPA, and the Student Data Privacy Consortium’s National Data Privacy Agreement. Once executed, that agreement controls over this DPA under §3.2.
Part D — Artificial intelligence features
D.1 Processing on request. Customer Content is submitted to a machine-learning model only when an Authorised User invokes a feature that requires it, and only to the extent required. Inference runs on infrastructure Intelligena operates, or with a model-provider Subprocessor listed in Annex III.
D.2 No training. Intelligena will not use Customer Content to train, fine-tune or improve any third-party general-purpose or foundation model. Its contracts with model providers prohibit them from doing so.
Intelligena may train or improve models that it operates exclusively to provide the Services only in either of these cases:
- using Aggregated Data; or
- where Customer has expressly opted in for the relevant feature (for example, Upstratus training a model on Customer’s own sensor data for Customer’s own use). A model trained that way for Customer is Customer Content.
D.3 Outputs. AI outputs may be inaccurate, incomplete or biased. They are recommendations for a human to review, and Customer is responsible for that review and for any decision based on them (§10.3). The Agreement’s disclaimers apply to outputs.
D.4 EU AI Act. For any AI system made available through the Services, Intelligena acts as provider of the system as Intelligena supplies it. Customer acts as deployer for its own use. Customer will not use any feature for a purpose the EU AI Act classifies as prohibited, and will not use a feature for a high-risk purpose without Intelligena’s prior written agreement. Where Customer does so, Customer is responsible for the obligations that attach to that use.
Part E — Biometric data
E.1 Unless a Service is expressly designed to Process biometric data and Customer has accepted this Part E for it, Customer will not submit biometric identifiers or biometric information. This includes face geometry, voiceprints and fingerprints, and their templates or embeddings.
E.2 Where a Service detects or compares faces in images Customer submits:
- (a) Customer will obtain, before the image is submitted, every written notice, written release and consent that the Illinois Biometric Information Privacy Act (740 ILCS 14), Texas Business and Commerce Code §503.001, Washington RCW 19.375, and any similar law requires from each individual depicted;
- (b) Intelligena will use any biometric data only to provide the requested feature, will not sell, lease, trade or otherwise profit from it, and will not disclose it except to Subprocessors under §8;
- (c) Intelligena will not keep any face template or embedding longer than needed to complete the request, and in any event will permanently destroy it no later than the end of the Customer’s subscription, or within three (3) years of the individual’s last interaction, whichever is earlier; and
- (d) Customer’s indemnity in §4.5 extends to any claim arising from a failure to obtain the notices, releases and consents in (a).
Part F — Payments and Stripe Connect
F.1 Where a Service enables Customer to accept payments from its own clients, students or purchasers, the payment processor processes the payment data. This is the case, for example, with Practiceful client billing and Yoshuko course sales.
F.2 Where Customer holds its own connected account with that processor, the processor acts under its own agreement with Customer and is a Third-Party Service under §2.6, not Intelligena’s Subprocessor. Intelligena receives only the transaction metadata needed to reflect the payment in the Service.
Part G — Customer-hosted software (QuorumLock / Helixseal)
G.1 QuorumLock is installed, hosted and operated by Customer. Secrets and other content stored in it are encrypted under keys that Customer controls, and Intelligena has no access to them. Intelligena does not Process that content.
G.2 This DPA applies only to Personal Data Intelligena receives:
- (a) in licensing and account administration (which is Intelligena Controller Data); and
- (b) in support, troubleshooting or professional services, where Customer chooses to share logs, diagnostics or a supervised remote session.
Customer will redact secrets and Personal Data from material it shares, to the extent practicable. Any remote session is initiated and controlled by Customer, and may be ended by Customer at any time.
G.3 Intelligena has no responsibility for the security of Customer’s deployment, its hardware, key custody, backups or configuration. Those remain Customer’s responsibility.
Part H — Other and future Services
For any Service not named in Part A, Intelligena acts as Processor of Customer Content under the body of this DPA. Annex I describes the Processing, as supplemented by the order form or product documentation for that Service. Intelligena will add a specific row to Part A before the Service is made generally available.
Annex V — Transfer mechanisms
V.1 EU SCCs (Modules Two and Three)
- Clause 7 (docking clause): included.
- Clause 9(a) (subprocessors): Option 2, general written authorisation, with the time period in §8.4 of this DPA (thirty (30) days).
- Clause 11(a) (redress): the optional language is not included.
- Clause 13 (supervision): as stated in Annex I.C.
- Clause 17 (governing law): Option 1, the law of Ireland.
- Clause 18(b) (forum): the courts of Ireland.
- Annex I: Annex I of this DPA.
- Annex II: Annex II of this DPA.
- Annex III: Annex III of this DPA.
- Clause 8.1 (instructions): §4.1 of this DPA states Customer’s instructions.
- Clauses 8.5 and 16(d) (deletion): satisfied by §13. Certification of deletion is provided on request.
- Clause 8.9 (audits): carried out as §11 provides, which the parties agree is how that clause is to be performed.
- Clause 12 (liability): as between the parties, and to the extent permitted, subject to §16 of this DPA. §16 does not limit liability to Data Subjects.
V.2 UK Addendum
The EU SCCs, as completed in V.1, apply to Restricted Transfers from the UK, as amended by the UK Addendum, which is incorporated by reference. In the UK Addendum:
- Table 1: the parties’ details and contacts are as in Annex I.A.
- Table 2: the selected modules and clauses are as in V.1.
- Table 3: the appendix information is in Annexes I, II and III.
- Table 4: either party may end the UK Addendum as permitted by its Section 19.
Where the UK Addendum conflicts with the EU SCCs for a UK transfer, the UK Addendum controls.
V.3 Switzerland
For transfers subject to the FADP, the EU SCCs apply as completed in V.1, with these modifications:
- (a) references to the GDPR are read as references to the FADP;
- (b) the competent supervisory authority under Clause 13 is the Federal Data Protection and Information Commissioner;
- (c) the term “Member State” does not exclude Data Subjects habitually resident in Switzerland from bringing claims in their place of habitual residence under Clause 18(c); and
- (d) the governing law and forum remain those in V.1, except where the FADP requires otherwise.
Before you sign. This DPA takes effect as the preamble states, whether or not the block below is signed. It is not self-executing as a separate signed instrument unless both parties sign it. A countersigned copy is available on request. To request a signed copy or an executed version, write to legal@intelligena.com.
Signatures
Use the signature block below only where the DPA is executed separately rather than accepted with the Agreement.
| Intelligena LLC | Customer | |
|---|---|---|
| Signature | ||
| Name | ||
| Title | ||
| Date | ||
| Notices | legal@intelligena.com · Republic Registered Agent Inc., 3400 Cottage Way Ste G2, Sacramento CA 95825, United States of America |
Version dpa-2026-10-01. Copyright © 2026
Intelligena LLC. All rights reserved.
How to reach us
- General and legal
- legal@intelligena.com
- Privacy requests
- privacy@intelligena.com
- Copyright / DMCA
- dmca@intelligena.com
- Abuse reports
- abusereport@intelligena.com
- Support
- support@intelligena.com
Notices in writing
Any notice this agreement requires to be given in writing may be sent to:
Intelligena LLCRepublic Registered Agent Inc.
3400 Cottage Way Ste G2
Sacramento CA 95825
United States of America