1. Parties, scope, and definitions
This DPA forms part of the applicable services agreement or order (the “Agreement”) between Intravo Corp (“Intravo”) and the customer identified there (“Customer”). It governs Intravo's processing of personal data on Customer's behalf. Customer is the controller and Intravo is the processor; if Customer is itself a processor, Intravo is its subprocessor.
“Data Protection Laws” means privacy and data-protection laws applicable to the processing, including GDPR, UK GDPR, applicable US state privacy laws, and successor legislation. Other defined terms have the meanings in the Agreement or applicable law.
2. Instructions and compliance
Intravo will process personal data only on Customer's documented instructions, including the Agreement, this DPA, authorized service configuration, and written directions, unless law requires otherwise. Intravo will inform Customer before legally required processing unless prohibited by law. Intravo will promptly inform Customer if an instruction appears to violate applicable Data Protection Laws.
Customer is responsible for lawful instructions, notices, legal bases, and the accuracy and proportionality of data submitted to the services.
3. Confidentiality and security
Intravo will ensure that personnel authorized to process personal data are subject to confidentiality obligations and receive security and privacy guidance appropriate to their work. Intravo will maintain technical and organizational measures designed for the nature, scope, context, and risk of the processing, including the measures summarized in Annex 2 and our Security Overview.
4. Subprocessors
Customer authorizes Intravo to use the providers on the current Subprocessors page. Intravo will impose data-protection obligations appropriate to the services and remains responsible for each subprocessor's performance to the extent required by law and the Agreement.
Intravo will provide notice of a material new customer-data subprocessor through the notice method agreed with Customer or the update process described on that page. Customer may raise a reasonable, documented data-protection objection within the stated notice period. The parties will work in good faith on a practical solution; if none is available, the applicable Agreement governs the affected service.
5. Individual rights and regulatory assistance
Taking into account the nature of processing, Intravo will provide reasonable assistance through appropriate technical and organizational measures for Customer to respond to individual-rights requests. If Intravo receives a request relating solely to Customer data, it will refer the requester to Customer unless law permits or requires a different response.
Intravo will provide reasonable information and assistance for Customer's security, breach-notification, data-protection impact assessment, and regulator-consultation obligations, taking into account the processing and information available to Intravo.
6. Personal-data breaches
After confirming a personal-data breach affecting Customer data, Intravo will notify Customer without undue delay. As information becomes available, the notice will describe the nature of the incident, affected data and individuals where known, likely consequences, mitigation taken or proposed, and a contact for follow-up. Intravo's notice is not an admission of fault or liability. Customer remains responsible for determining whether and when it must notify authorities or individuals.
7. Return and deletion
At the end of services, Intravo will return or delete Customer personal data as provided by the Agreement or Customer's documented instruction, unless law requires retention. Residual copies may remain in protected backups until overwritten under normal cycles and remain subject to this DPA while retained.
8. Audit information
Intravo will make available information reasonably necessary to demonstrate compliance with this DPA. Subject to confidentiality, security, proportionality, and non-disruption safeguards, Customer may request relevant questionnaires, summaries, policies, vendor assurance materials, or a reasonable audit where legally required and other evidence is insufficient. The parties will agree scope, timing, and allocation of reasonable costs in advance.
9. International transfers
Regional processing follows the Agreement and our Data Residency summary. When Customer personal data subject to EEA restrictions is transferred to a country without an adequacy decision, the 2021 European Commission Standard Contractual Clauses are incorporated as applicable: Module 2 for controller-to-processor transfers or Module 3 for processor-to-processor transfers. The docking clause applies; optional Clause 11 does not; Clause 9 uses general written authorization; and the competent authority and governing law are determined under the applicable SCCs and Customer establishment.
For UK restricted transfers, the UK International Data Transfer Addendum modifies the SCCs as required. For Swiss transfers, references are adapted to the Swiss Federal Act on Data Protection. The Agreement and Annex 1 supply the party and processing details needed by those mechanisms.
10. US state privacy laws
Where Intravo processes personal information as a service provider, contractor, or processor under applicable US state law, Intravo will process it for the limited business purposes in the Agreement; will not sell or share it for cross-context behavioral advertising; will not retain, use, or disclose it outside the direct business relationship except as permitted by law; and will provide required assistance and contractual protections.
11. Order of precedence and changes
If this DPA conflicts with the Agreement on personal-data processing, this DPA controls; applicable SCCs control over both where required. Changes must be agreed in writing, except updates necessary to reflect mandatory law or approved subprocessor changes under this DPA.
Annex 1 — Processing details
- Subject matter and purpose: provide, secure, support, maintain, and improve the contracted services under Customer's instructions.
- Duration: the Agreement term plus the limited retention period described above.
- Data subjects: Customer users, personnel, event participants, invitees, presenters, interpreters, support contacts, and other people whose data Customer submits.
- Data: account and contact details; authentication and usage records; event, meeting, support, and uploaded content; and audio, transcripts, translations, or messages when the contracted feature uses them.
- Special data: not intentionally required unless the applicable service and Agreement expressly support it and Customer provides lawful instructions.
- Frequency: continuous or on demand as Customer uses the service.
Annex 2 — Technical and organizational measures
- Documented security and privacy governance, risk assessment, training, confidentiality, and incident-response processes.
- Role-based and least-privilege access, centrally managed identity controls, multifactor authentication where required, and access removal processes.
- Encryption in transit and platform-supported encryption at rest; controlled secret and key handling.
- Risk-based secure development, change control, vulnerability management, logging, monitoring, backup, recovery, and continuity practices.
- Vendor due diligence, contractual safeguards, regional-processing review, and periodic reassessment based on risk.
- Data minimization, classification, retention, secure disposal, and customer-controlled configuration appropriate to the service.
Contact
Questions or execution requests: privacy@intravo.com.
