Terms & policies
Data processing addendum
Last updated: 22 August 2026.
The processor agreement between your company and ours, with security measures, subprocessors and retention periods.
1. Purpose and parties
This addendum governs the processing of personal data that Intake carries out on behalf of the Customer when providing the service, and forms part of the terms of service.
The Customer acts as controller and Adrià Castany Carranza, tax ID 48219934C, as processor, within the meaning of Regulation (EU) 2016/679.
Where this addendum conflicts with the terms of service, this addendum prevails on data protection matters.
2. Subject matter, duration and nature of processing
The processing serves to provide the AI support service: receiving, classifying and answering conversations from the Customer end users, and running the actions the Customer has enabled.
Processing lasts for the term of the subscription, plus the retention period set out in this addendum.
3. Categories of data and data subjects
The Customer decides what data it puts into the service. Generally, processing covers:
- Identification and contact data of end users: name, email address, phone number where a messaging channel is used.
- Support conversation content, including attachments the end user sends.
- Account data the Customer exposes through its API: plan, permissions, usage limits, billing status.
- Technical data associated with the conversation, such as session identifier, language and timestamp.
4. Intake obligations as processor
Process the data only on documented instructions from the Customer, including as regards international transfers, unless required otherwise by law, in which case we will inform the Customer before processing unless the law prohibits it.
Not use the data for our own purposes, not disclose it to third parties other than authorised subprocessors, and not train third-party models with it.
Ensure that persons authorised to process the data have committed themselves to confidentiality.
Apply the technical and organisational measures described in section 6.
Assist the Customer, so far as reasonable, in responding to data subject rights and in any impact assessments it must carry out.
Make available to the Customer the information needed to demonstrate compliance with these obligations and allow audits, on reasonable notice and without affecting the security of other customers.
5. Subprocessors
The Customer gives general authorisation for the use of subprocessors. The current list, with purpose and location, is the one in section 11 of this addendum.
We will give at least thirty days notice of any addition or replacement of a subprocessor. If the Customer objects on reasonable data protection grounds, it may terminate the subscription without penalty before the change takes effect.
We require each subprocessor to accept data protection obligations equivalent to those in this addendum, and we remain liable to the Customer for their performance.
6. Security measures
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS and encryption at rest in storage and backups.
- Role-based access control, on a least-privilege basis, with strong authentication for administrative access.
- Logical separation of each customer organisation data within the platform.
- Activity logging and error monitoring, with bounded retention of those logs.
- Regular backups and a tested restore procedure.
- Review of the measures when the architecture changes or a new risk appears.
7. Personal data breaches
If we become aware of a security breach affecting personal data processed on the Customer behalf, we will notify the Customer without undue delay and in any case within forty-eight hours of becoming aware.
The notification will include the nature of the incident, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed.
It is for the Customer, as controller, to assess notification to the supervisory authority and to data subjects.
8. Data location and international transfers
Data is hosted and processed in data centres located in the European Union.
The artificial intelligence models the service uses run in European Union regions through Amazon Bedrock.
If a transfer outside the European Economic Area becomes necessary in future, we will rely on an adequacy decision or on the European Commission standard contractual clauses, and we will reflect it in this addendum and in the subprocessors list before carrying it out.
9. Data subject rights
Where an end user exercises a right of access, rectification, erasure, restriction, portability or objection with us, we will redirect them to the Customer and inform the Customer without delay.
The service lets the Customer locate, export and delete the conversations and data associated with a specific person, so that it can handle those rights.
10. Return and deletion
On termination of the subscription, the Customer has thirty days to export its data.
After that period we will delete the personal data processed on its behalf, including copies, unless a legal obligation requires retention, in which case it will be kept only for as long and for the purpose that obligation imposes.
11. Subprocessors: current list
All the providers below operate under contract with data protection obligations equivalent to those in this addendum, and all of them process data in the European Union.
Infrastructure: Amazon Web Services (Ireland) for hosting, file storage and backups; Amazon Bedrock (European Union) for running the models; MongoDB Atlas (European Union) as the primary database; Redis (European Union) for the task queue and cache.
Running the service: Stripe Payments Europe (Ireland) for subscription billing, which processes the Customer billing data and not their end users data; Sentry (European Union) for error logging; and a transactional email provider (European Union) for alerts and notifications.
Messaging channels, only where the Customer connects that channel: Meta Platforms Ireland for WhatsApp Business Platform, where Intake is registered as an independent tech provider and the account belongs to the Customer; and Slack Technologies for sending alerts to their workspace.