Sales & support · intravo.comintravo.com→
Trust & Compliance

Data Processing Addendum

Terms for Intravo's processing of personal data on behalf of a customer.

Version 2.0 — September 24, 2026
Contract status. This DPA applies only when it is incorporated into, or executed with, an agreement or order between Intravo Corp and the identified customer. Posting it on this site does not by itself create a contract.

1. Parties, scope, and definitions

This DPA forms part of the applicable services agreement or order (the “Agreement”) between Intravo Corp (“Intravo”) and the customer identified there (“Customer”). It governs Intravo's processing of personal data on Customer's behalf. Customer is the controller and Intravo is the processor; if Customer is itself a processor, Intravo is its subprocessor.

“Data Protection Laws” means privacy and data-protection laws applicable to the processing, including GDPR, UK GDPR, applicable US state privacy laws, and successor legislation. Other defined terms have the meanings in the Agreement or applicable law.

2. Instructions and compliance

Intravo will process personal data only on Customer's documented instructions, including the Agreement, this DPA, authorized service configuration, and written directions, unless law requires otherwise. Intravo will inform Customer before legally required processing unless prohibited by law. Intravo will promptly inform Customer if an instruction appears to violate applicable Data Protection Laws.

Customer is responsible for lawful instructions, notices, legal bases, and the accuracy and proportionality of data submitted to the services.

3. Confidentiality and security

Intravo will ensure that personnel authorized to process personal data are subject to confidentiality obligations and receive security and privacy guidance appropriate to their work. Intravo will maintain technical and organizational measures designed for the nature, scope, context, and risk of the processing, including the measures summarized in Annex 2 and our Security Overview.

4. Subprocessors

Customer authorizes Intravo to use the providers on the current Subprocessors page. Intravo will impose data-protection obligations appropriate to the services and remains responsible for each subprocessor's performance to the extent required by law and the Agreement.

Intravo will provide notice of a material new customer-data subprocessor through the notice method agreed with Customer or the update process described on that page. Customer may raise a reasonable, documented data-protection objection within the stated notice period. The parties will work in good faith on a practical solution; if none is available, the applicable Agreement governs the affected service.

5. Individual rights and regulatory assistance

Taking into account the nature of processing, Intravo will provide reasonable assistance through appropriate technical and organizational measures for Customer to respond to individual-rights requests. If Intravo receives a request relating solely to Customer data, it will refer the requester to Customer unless law permits or requires a different response.

Intravo will provide reasonable information and assistance for Customer's security, breach-notification, data-protection impact assessment, and regulator-consultation obligations, taking into account the processing and information available to Intravo.

6. Personal-data breaches

After confirming a personal-data breach affecting Customer data, Intravo will notify Customer without undue delay. As information becomes available, the notice will describe the nature of the incident, affected data and individuals where known, likely consequences, mitigation taken or proposed, and a contact for follow-up. Intravo's notice is not an admission of fault or liability. Customer remains responsible for determining whether and when it must notify authorities or individuals.

7. Return and deletion

At the end of services, Intravo will return or delete Customer personal data as provided by the Agreement or Customer's documented instruction, unless law requires retention. Residual copies may remain in protected backups until overwritten under normal cycles and remain subject to this DPA while retained.

8. Audit information

Intravo will make available information reasonably necessary to demonstrate compliance with this DPA. Subject to confidentiality, security, proportionality, and non-disruption safeguards, Customer may request relevant questionnaires, summaries, policies, vendor assurance materials, or a reasonable audit where legally required and other evidence is insufficient. The parties will agree scope, timing, and allocation of reasonable costs in advance.

9. International transfers

Regional processing follows the Agreement and our Data Residency summary. When Customer personal data subject to EEA restrictions is transferred to a country without an adequacy decision, the 2021 European Commission Standard Contractual Clauses are incorporated as applicable: Module 2 for controller-to-processor transfers or Module 3 for processor-to-processor transfers. The docking clause applies; optional Clause 11 does not; Clause 9 uses general written authorization; and the competent authority and governing law are determined under the applicable SCCs and Customer establishment.

For UK restricted transfers, the UK International Data Transfer Addendum modifies the SCCs as required. For Swiss transfers, references are adapted to the Swiss Federal Act on Data Protection. The Agreement and Annex 1 supply the party and processing details needed by those mechanisms.

10. US state privacy laws

Where Intravo processes personal information as a service provider, contractor, or processor under applicable US state law, Intravo will process it for the limited business purposes in the Agreement; will not sell or share it for cross-context behavioral advertising; will not retain, use, or disclose it outside the direct business relationship except as permitted by law; and will provide required assistance and contractual protections.

11. Order of precedence and changes

If this DPA conflicts with the Agreement on personal-data processing, this DPA controls; applicable SCCs control over both where required. Changes must be agreed in writing, except updates necessary to reflect mandatory law or approved subprocessor changes under this DPA.

Annex 1 — Processing details

Annex 2 — Technical and organizational measures

Contact

Questions or execution requests: privacy@intravo.com.