IntraQ, Inc. — Data Processing Addendum
Version: 1.0 Effective date: August 26, 2026
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Terms & Conditions or other written agreement (the “Agreement”) between IntraQ, Inc. (“IntraQ”) and the customer identified in the Agreement (“Customer”). It governs IntraQ’s processing of Personal Information contained in Customer Content on Customer’s behalf. If there is a conflict between this DPA and the Agreement regarding processing of Personal Information, this DPA controls. This DPA is scoped to United States privacy law; Section 15 addresses international transfers.
1. Definitions
- “Applicable Privacy Law” means U.S. state privacy and consumer-protection laws applicable to the processing of Personal Information under the Agreement, including the California Consumer Privacy Act as amended (the “CCPA”), the Texas Data Privacy and Security Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, and the Connecticut Data Privacy Act, in each case as and to the extent applicable.
- “Business,” “Controller,” “Service Provider,” “Processor,” “Sell,” “Share,” “Consumer,” “Sensitive Personal Information,” and “Personal Information” have the meanings given under Applicable Privacy Law. Where a term is defined differently across statutes, the definition of the statute applicable to the relevant processing applies.
- “Customer Content” has the meaning given in the Agreement.
- “Subprocessor” means a third party engaged by IntraQ to process Personal Information contained in Customer Content on IntraQ’s behalf in providing the Service.
- “Data Subject Request” means a request from a Consumer to exercise rights under Applicable Privacy Law.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Information contained in Customer Content processed by IntraQ.
2. Roles of the parties
With respect to Personal Information contained in Customer Content, Customer is the Business/Controller and IntraQ is the Service Provider/Processor. IntraQ processes such Personal Information only on Customer’s documented instructions and only for the limited and specified business purposes set out in Section 3. Customer is responsible for the accuracy, quality, and legality of Customer Content and for having provided all notices and obtained all rights, consents, and legal bases necessary for IntraQ to process it as described. This DPA does not apply to information for which IntraQ is itself the Business/Controller (account, billing, support, and website information), which is governed by the Privacy Policy. Whether a party acts as a Controller or Processor for a given processing activity is a fact-based determination; IntraQ remains a Processor/Service Provider so long as it adheres to Customer’s instructions.
3. Scope, purpose, and nature of processing
- Subject matter and nature. Hosting, storage, indexing (including text extraction and vector embeddings), retrieval, generation, analysis, transmission to Subprocessors, and related processing necessary to provide, secure, support, and improve the Service.
- Purpose. The specific business purposes of providing the Service to Customer as described in the Agreement and Documentation: determining which compliance obligations apply, evaluating whether supporting evidence exists, surfacing gaps, drafting policy documents for human approval, answering questions about Customer’s own material, and operating and securing the Service. These purposes are specific and are not described by generic reference to the Agreement as a whole.
- Duration. For the term of the Agreement and thereafter as set out in Section 11.
- Categories of Data Subjects. Customer’s personnel and authorized users; Customer’s employees, workers, and other individuals whose information Customer places into the Service.
- Categories of Personal Information. Identifiers (such as name and work email); professional and employment information (such as job title, department, work location, employment type, exemption status, and hire/termination dates); account and authentication data; content of documents, policies, questions, and conversations that Customer submits; and any other Personal Information Customer chooses to include in Customer Content. IntraQ does not solicit special categories of information through structured fields, and applies a structural control that rejects certain sensitive field names in workforce and evidence records; however, Customer controls what it submits, and Customer Content may contain Sensitive Personal Information within free-form documents, policies, evidence, questions, or conversations (see Section 12).
4. Customer instructions
IntraQ will process Personal Information contained in Customer Content only on Customer’s documented instructions, including as set out in this DPA, the Agreement, and the Documentation, and as configured by Customer through the Service, unless required to do otherwise by law (in which case Section 10 applies). IntraQ will inform Customer if, in its opinion, an instruction infringes Applicable Privacy Law, unless legally prohibited from doing so.
5. Service Provider / Processor restrictions
IntraQ will not:
- Sell or Share Personal Information contained in Customer Content;
- retain, use, or disclose such Personal Information for any purpose other than the business purposes specified in Section 3, or as otherwise permitted by Applicable Privacy Law, including for any commercial purpose other than those business purposes;
- retain, use, or disclose such Personal Information outside the direct business relationship between IntraQ and Customer; or
- combine such Personal Information with Personal Information that IntraQ receives from, or on behalf of, another person, or collects from its own interaction with the Consumer, except as permitted by Applicable Privacy Law to perform a business purpose.
IntraQ certifies that it understands the restrictions in this Section and Section 6 and will comply with them. IntraQ does not use Customer Content to train, fine-tune, or develop AI models.
6. Same level of protection; assistance
IntraQ will provide at least the level of privacy protection required of a Service Provider/Processor by Applicable Privacy Law. Taking into account the nature of the processing and the information available to IntraQ, IntraQ will reasonably assist Customer in:
- responding to Data Subject Requests (Section 8);
- meeting Customer’s obligations regarding security of processing and Security Incident notification (Section 9);
- conducting data protection assessments where required; and
- complying with Applicable Privacy Law with respect to the Personal Information IntraQ processes.
7. Confidentiality and personnel
IntraQ will ensure that personnel authorized to process Personal Information contained in Customer Content are subject to a duty of confidentiality and are limited to those who need access to provide, secure, or support the Service. IntraQ personnel access across workspaces is limited to platform operation, investigation of reported problems, and support, is gated by role and a platform multi-factor-authentication requirement, and is subject to audit logging; IntraQ operates no customer-impersonation mechanism.
8. Data Subject Requests
IntraQ will, taking into account the nature of the processing, provide Customer with the ability, or reasonable assistance, to fulfill Data Subject Requests, including requests to access, correct, delete, obtain a copy of, opt out of Sale/Sharing of, or limit the use and disclosure of Sensitive Personal Information. IntraQ fulfills these requests through operator-supported processes on Customer’s instruction rather than through an automated self-service interface. If IntraQ receives a Data Subject Request directed to Customer’s Customer Content, IntraQ will, unless legally prohibited, promptly inform the Consumer to direct the request to Customer or forward it to Customer, and will not respond except on Customer’s instruction or as legally required.
9. Security and Security Incidents
Security. IntraQ will implement and maintain reasonable administrative, technical, and organizational measures designed to protect Personal Information contained in Customer Content, appropriate to its nature. IntraQ’s current measures include those described in Section 17 of the Privacy Policy. IntraQ does not hold a SOC 2 report or other third-party security certification and does not represent otherwise.
Security Incidents. IntraQ will notify Customer without undue delay, and in any event within seventy-two (72) hours, after IntraQ confirms a Security Incident affecting Customer’s Personal Information, and will provide the information reasonably available to it about the nature of the incident and the data affected, and will take reasonable steps to mitigate and remediate. IntraQ’s notification is not an acknowledgment of fault.
10. Legally required disclosures
If IntraQ is compelled by law to disclose Personal Information contained in Customer Content, IntraQ will, unless legally prohibited, give Customer prior notice so that Customer may seek a protective order or other remedy, and will disclose only what is legally required.
11. Deletion and return
On expiration or termination of the Agreement, or on Customer’s earlier written request, IntraQ will, at Customer’s direction, delete or return Personal Information contained in Customer Content, and delete existing copies, except to the extent retention is required by law or permitted by Applicable Privacy Law for a limited, specified purpose (such as compliance audit records and acceptance/evidence records described in the Privacy Policy). IntraQ’s deletion removes the stored file object, document text chunks, extracted content, and vector embeddings, and reports a failure state rather than reporting success if erasure does not complete. Because IntraQ’s infrastructure providers maintain their own backup, replication, and object-version retention, a copy of deleted content may persist in those provider-managed systems for a limited period until it is overwritten or expires under the provider’s retention. IntraQ will, on request, confirm what it has deleted and what it has retained and why.
12. Sensitive Personal Information
IntraQ does not solicit Sensitive Personal Information through structured fields and applies a structural control that rejects certain sensitive field names in workforce and evidence records. IntraQ will not use or disclose any Sensitive Personal Information contained in Customer Content except to perform the services specified in Section 3, as directed by Customer, and as permitted by Applicable Privacy Law. Where Customer directs IntraQ to limit the use or disclosure of Sensitive Personal Information, IntraQ will comply and will convey that instruction to relevant Subprocessors. Customer is responsible for determining whether to place Sensitive Personal Information into Customer Content and for any resulting notice, consent, or limitation obligations.
13. Subprocessors
Customer authorizes IntraQ to engage Subprocessors to process Personal Information contained in Customer Content in providing the Service. IntraQ:
- will engage each Subprocessor under a written contract requiring it to observe obligations no less protective than those in this DPA, including the restrictions in Section 5 and, as applicable, a prohibition on training AI models on Customer Content;
- remains responsible for each Subprocessor’s performance of those obligations;
- maintains a current list of Subprocessors in the Subprocessor Schedule to this DPA; and
- will provide notice of a new Subprocessor before it begins processing Personal Information contained in Customer Content, and a mechanism for Customer to object, as set out in the Subprocessor Schedule.
The AI providers (Anthropic and OpenAI) are Subprocessors. Services that Customer independently connects and directs (such as customer HR systems, document sources, communication tools, and identity providers) are not IntraQ Subprocessors; Customer’s use of them is governed by those providers’ own terms.
14. Audits and assessments
IntraQ will make available to Customer information reasonably necessary to demonstrate IntraQ’s compliance with this DPA, and will allow and cooperate with reasonable assessments by Customer or Customer’s designated assessor, no more than once every 12 months absent a Security Incident or legal requirement, subject to reasonable confidentiality and security conditions. IntraQ may satisfy this obligation by providing a then-current independent assessment or report covering the relevant controls, where available.
15. International data transfers
The Service is operated from the United States and is offered to U.S. organizations. IntraQ does not currently offer data-residency selection, and the AI providers are accessed at their default global endpoints. This DPA does not incorporate the EU or UK Standard Contractual Clauses or the obligations of the EU or UK General Data Protection Regulation. Before onboarding data subjects in the European Economic Area, the United Kingdom, or Switzerland, the parties would need to agree additional terms, including processor terms meeting Article 28 of the EU/UK General Data Protection Regulation, a lawful cross-border transfer mechanism (such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum), and supporting operational measures. IntraQ does not represent compliance with those regimes under this DPA.
16. General
This DPA is governed by the law and the dispute-resolution and liability provisions of the Agreement. IntraQ’s total liability arising out of or related to this DPA is subject to the limitation of liability in the Agreement, including its carve-outs. This DPA supersedes any prior data processing terms between the parties for the processing it covers. IntraQ may update this DPA to reflect changes in Applicable Privacy Law or its Subprocessors, consistent with the change-notice provisions of the Agreement and the Subprocessor Schedule; no update will materially diminish the protections in this DPA for the Personal Information it covers.
