IntellicoachIntellicoach
Back to Home

Customer Data Processing Addendum

Last updated: July 10, 2026

This Customer Data Processing Addendum (the “DPA”) forms part of the agreement governing the Customer's use of the Intellicoach services (the “Agreement”) between Intellicoach LLC, a Florida limited liability company at 31434 Spruce Creek Circle, #207, Wesley Chapel, Florida 33543, United States (“Intellicoach”), and the customer identified in the Agreement (“Customer”). This DPA takes effect when Customer accepts the Agreement or this DPA, or when the parties otherwise agree to it.

If Customer accepts this DPA for an organization, the accepting person represents that they are authorized to bind that organization. If there is a conflict concerning the Processing of Customer Personal Data, the following order controls: (1) applicable Standard Contractual Clauses or other mandatory transfer terms; (2) this DPA; and (3) the Agreement.

1. Definitions

Applicable Data Protection Law means privacy, data-protection, data-security, breach-notification, or similar law that applies to Intellicoach's Processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, CCPA, other applicable United States state privacy laws, PIPEDA and similar Canadian provincial laws, Australia's Privacy Act 1988, and Brazil's LGPD.

Customer Personal Data means Personal Data Processed by Intellicoach on Customer's behalf through the Services. It does not include Personal Data for which Intellicoach independently determines the purposes and means of Processing, such as Customer account administration, direct billing, fraud prevention, and Intellicoach's legal compliance; those activities are governed by Intellicoach's Privacy Policy.

Services means the hosted Intellicoach platform and related services described in the Agreement, including authorized channel integrations, conversation management, AI-assisted analysis and response generation, follow-up automation, booking functions, analytics, support, and security operations.

Subprocessor means a third party engaged by Intellicoach to Process Customer Personal Data on Customer's behalf in connection with the Services. A third-party service that Customer independently directs Intellicoach to connect to, and with which Customer has a direct relationship, is not a Subprocessor solely because the Services interoperate with it.

Capitalized terms not defined in this DPA have the meanings given to them in Applicable Data Protection Law or the Agreement, as applicable.

2. Scope and roles

This DPA applies whenever Intellicoach Processes Customer Personal Data on Customer's behalf. Customer is the Controller or Business and Intellicoach is the Processor or Service Provider for that Customer Personal Data. If Customer acts as a Processor or Service Provider for another Controller or Business, Intellicoach acts as Customer's Subprocessor or subcontractor.

Customer is responsible for giving lawful documented instructions; establishing a legal basis for Processing; providing required notices and obtaining required permissions or consents; configuring and using the Services lawfully; responding to Data Subjects except as this DPA requires Intellicoach's assistance; and assessing whether Customer's use requires a data-protection impact assessment, special-category condition, automated-decision safeguard, or regulatory consultation.

Customer's documented instructions include the Agreement, this DPA, Customer's configuration and use of the Services, and other instructions that Intellicoach accepts in writing. Intellicoach will inform Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law, unless prohibited by law.

3. Processing restrictions

Intellicoach will Process Customer Personal Data only to provide, secure, support, and maintain the Services; on Customer's documented instructions; as described in Annex 1; or as required by applicable law, in which case Intellicoach will notify Customer before Processing unless law prohibits notice.

Intellicoach will not Sell or Share Customer Personal Data; retain, use, or disclose it outside the direct business relationship with Customer or for a purpose other than the limited and specified purposes in this DPA and the Agreement; use it for cross-context behavioral or targeted advertising; or attempt to reidentify deidentified information except as permitted by Applicable Data Protection Law.

Intellicoach may generate statistical, aggregated, or deidentified information from Customer Personal Data only if the resulting information cannot reasonably be linked to Customer or any Data Subject and Intellicoach maintains it in deidentified form. Intellicoach may use that information to operate, secure, measure, and improve the Services, subject to Applicable Data Protection Law.

4. Confidentiality and personnel

Intellicoach will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations, receive access only when necessary for their responsibilities, receive appropriate privacy and security instructions, and Process Customer Personal Data only as permitted by this DPA. Intellicoach remains responsible for its personnel's compliance with this DPA.

5. Security

Intellicoach will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures described in Annex 2 apply as of the effective date and may be updated as technology and risks change, provided an update does not materially reduce the overall protection of Customer Personal Data.

Customer is responsible for securely configuring its account and integrations, protecting credentials, limiting authorized users, maintaining lawful channel access, and promptly notifying Intellicoach of suspected unauthorized access.

6. Subprocessors

Customer grants Intellicoach general written authorization to engage the Subprocessors listed in Annex 3 and to replace or add Subprocessors in accordance with this section. Intellicoach will conduct risk-based diligence, impose written data-protection obligations appropriate to the service, limit a Subprocessor's Processing to what is necessary to provide the Services, and remain responsible for the Subprocessor's data-protection obligations to the extent required by Applicable Data Protection Law.

Intellicoach will maintain its current Subprocessor list in Annex 3 and give Customer at least 30 days' notice before a new Subprocessor begins Processing Customer Personal Data, except when an urgent change is reasonably necessary to protect the Services or Customer Personal Data. Notice may be sent to the email address associated with Customer's account or provided in the Services.

Customer may object to a new Subprocessor within 15 days after notice by explaining reasonable data-protection grounds. The parties will work in good faith toward a commercially reasonable solution. If Intellicoach cannot provide a reasonable alternative, Customer may terminate the affected Services before the new Subprocessor begins Processing, with a refund of prepaid fees for the terminated period. This is Customer's sole remedy for an unresolved Subprocessor objection except where Applicable Data Protection Law requires otherwise.

7. Data Subject requests

Taking into account the nature of the Processing, Intellicoach will provide reasonable technical and organizational assistance to help Customer respond to valid requests to access, correct, delete, restrict, object to, or port Customer Personal Data.

If Intellicoach receives a request directly from a Data Subject concerning Customer Personal Data, it will, where reasonably identifiable, notify Customer without undue delay, direct the requester to Customer, and not substantively respond except on Customer's documented instruction or as required by law. Intellicoach may charge reasonable fees for unusually burdensome assistance not included in the Services, after advance notice, unless the request results from Intellicoach's breach of this DPA.

8. Personal Data Breaches

Intellicoach will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent known and reasonably available, the notice will describe the nature of the breach; the categories and approximate numbers of affected Data Subjects and records; likely consequences; measures taken or proposed to contain, investigate, mitigate, and remediate the incident; and a contact for follow-up.

Intellicoach may provide information in phases as its investigation progresses. Intellicoach will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably assist Customer with legally required notifications. Customer is responsible for deciding whether to notify regulators, Data Subjects, or others unless law directly requires Intellicoach to notify them. Notice is not an admission of fault or liability.

9. Assessments and regulatory assistance

Taking into account the nature of the Processing and information available to Intellicoach, Intellicoach will reasonably assist Customer with data-protection impact assessments, risk assessments, prior consultations, and regulator inquiries relating specifically to Intellicoach's Processing of Customer Personal Data. Intellicoach may provide standardized security and compliance documentation to satisfy this obligation.

10. Information and audits

Intellicoach will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, subject to appropriate confidentiality restrictions. Customer will first use current third-party assessments, certifications, security questionnaires, and other documentation Intellicoach makes available.

If that documentation is reasonably insufficient, Customer may conduct one audit in a 12-month period, unless a Personal Data Breach or regulator request reasonably requires another audit. An audit must be limited to relevant systems and records, occur on at least 30 days' notice during normal business hours, avoid access to other customers' information and unreasonable disruption, be performed by Customer or a non-competitor independent auditor bound by confidentiality, and comply with Intellicoach's reasonable security requirements. Customer bears its audit costs and reimburses Intellicoach's reasonable costs for non-routine assistance unless the audit identifies a material breach by Intellicoach.

11. Return and deletion

During the subscription term, Customer may export or delete Customer Personal Data using available Service functionality or by submitting a verified request to Intellicoach.

Following termination, Intellicoach retains and deletes Customer Personal Data in accordance with Customer's documented instructions, Intellicoach's documented retention schedule, this DPA, and applicable law. Customer may request return, export, or earlier deletion, subject to limited legal exceptions.

Customer Personal Data in backups will remain protected and will be deleted through Intellicoach's documented backup-expiration cycle. If a backup is restored, Intellicoach will reapply an applicable deletion request. Intellicoach may retain limited information necessary to establish, exercise, or defend legal claims; comply with law; maintain fraud or suppression records; or document compliance, provided it limits Processing to those purposes and protects the retained information.

12. Restricted Transfers

Each party will comply with Applicable Data Protection Law governing Restricted Transfers. The parties may rely on an applicable adequacy decision, an approved certification framework in which the relevant data importer actively participates, the Standard Contractual Clauses described in Annex 4, or another lawful transfer mechanism. If a selected mechanism becomes invalid or unavailable, the parties will cooperate in good faith to implement a lawful replacement. Intellicoach may suspend an affected Restricted Transfer if no lawful mechanism is reasonably available.

13. Sensitive and regulated data

Customer acknowledges that free-form conversations may contain health, financial, relationship, or other sensitive information. Customer is responsible for establishing any required legal basis and condition for Processing it and for limiting collection to what is necessary.

The Services are not offered as a HIPAA-compliant service. Intellicoach does not agree to Process protected health information on behalf of a HIPAA covered entity or business associate unless the parties execute a separate Business Associate Agreement and Intellicoach confirms that the relevant Services and Subprocessors are authorized for that use.

Customer will not intentionally use the Services to Process Social Security numbers, government identification documents, payment-card authentication data, genetic data, biometric identifiers used for unique identification, precise geolocation, criminal-offense data, or children's data unless Intellicoach expressly agrees in writing and the parties implement required safeguards.

14. Customer instructions and liability

Customer represents that it has all rights and permissions necessary to provide Customer Personal Data to Intellicoach and to instruct Intellicoach to Process it under this DPA. Each party's liability arising from this DPA is subject to the exclusions and limitations in the Agreement, except to the extent Applicable Data Protection Law prohibits the limitation. Nothing in this DPA limits a Data Subject's rights or either party's direct obligations under Applicable Data Protection Law.

15. General

This DPA continues while Intellicoach Processes Customer Personal Data. Intellicoach may update this DPA to reflect changes in law, the Services, or Processing, provided it gives notice of material changes and does not materially reduce the overall protection of Customer Personal Data. If a material update is required and Customer reasonably objects on data-protection grounds, the parties will work in good faith toward a solution.

Notices concerning this DPA may be sent to Customer's account contact and to Intellicoach at support@intellicoach.ai. This DPA may be accepted electronically and in counterparts. Electronic acceptance, electronic signature, or use of the Services after presentation of this DPA constitutes a signature to the extent permitted by law.

Annex 1 — Processing Details

A. Parties

Data importer / Processor: Intellicoach LLC, 31434 Spruce Creek Circle, #207, Wesley Chapel, Florida 33543, United States. Privacy contact: support@intellicoach.ai.

Data exporter / Controller or Processor: Customer and its permitted affiliates identified in the Agreement, order form, account record, or signature block. Customer's data-protection contact is the account owner unless Customer designates another contact.

B. Subject matter, purpose, and nature of Processing

Intellicoach Processes Customer Personal Data to provide, secure, support, and maintain the Services, including connecting Customer-authorized messaging and booking accounts; receiving, storing, displaying, organizing, and transmitting conversations and attachments; analyzing context and generating suggested or automated replies; qualifying and categorizing leads; scheduling follow-ups and supporting appointment booking; producing Customer-facing analytics, exports, notifications, and operational records; detecting abuse; authenticating users; troubleshooting; and carrying out Customer's documented instructions.

The nature of Processing may include collection, recording, organization, structuring, hosting, storage, retrieval, consultation, analysis, inference, generation, adaptation, transmission, display, alignment, combination, restriction, export, deletion, and destruction.

C. Duration and frequency

Processing is continuous or event-driven during the Agreement. After termination, Processing may continue only as described in Section 11 and Intellicoach's documented retention schedule. Restricted Transfers may occur when Customer or an authorized integration submits Customer Personal Data to the Services or Intellicoach uses an authorized Subprocessor.

D. Data Subjects and Personal Data

Data Subjects may include Customer's account owners, authorized users, personnel and support contacts; prospective, current, and former customers or clients; leads, followers, commenters, direct-message participants, and other people who interact with Customer through an authorized channel; appointment attendees; and people whose information is included in conversation content.

Customer Personal Data may include identifiers and contact information; conversation content, prompts, replies, attachments, audio, images, transcripts, and metadata; profile, preference, interest, and relationship information volunteered in conversations; fitness, wellness, health-goal, financial, availability, motivation, objection, qualification, and readiness information volunteered in conversations; AI-generated or inferred conversation state, summaries, classifications, lead-stage data, sentiment or intent indicators, memories, and response suggestions; channel, device, browser, IP, access, diagnostic, security, and audit data; and account configuration, scripts, personas, resources, calendars, automation rules, and integration metadata.

Free-form conversations may incidentally include special-category or sensitive data, particularly health or wellness information. Safeguards include access limitations, encryption in transit, managed-provider encryption at rest where configured, confidentiality obligations, data-minimization instructions, incident response, and deletion controls described in Annex 2.

Annex 2 — Technical and Organizational Measures

Intellicoach maintains technical and organizational measures designed to provide a level of security appropriate to the risk, taking account of the Services and the nature of Customer Personal Data. These measures include:

  • Governance and personnel: assigned responsibility for privacy and security; confidentiality obligations; role- and business-need-based access; and risk-based review of material system and Subprocessor changes.
  • Access controls: authenticated access to the hosted application; authorization controls designed to scope Customer records to the relevant workspace or coach; controls for administrative access; and processes to revoke access when it is no longer required.
  • Encryption and secrets: HTTPS/TLS for production web and API traffic; encryption at rest provided by managed services where configured; application-layer encryption for supported third-party OAuth credentials and session material; and environment-managed secrets.
  • Application and tenant security: Customer-data access scoped through authenticated workspace or coach identifiers; authentication or signature-verification controls for supported webhooks and queue callbacks; input validation; and software-development practices designed to address dependency and application-security risks.
  • Availability and recovery: managed hosting, database, object-storage, cache, and queue services; provider-supported backup and recovery capabilities; and retry, idempotency, or deduplication controls for selected message and job-processing paths.
  • Logging and incident response: application and provider logs used to investigate errors, authentication activity, webhooks, queues, and security events; procedures designed to identify, contain, investigate, mitigate, and notify Customers of Personal Data Breaches; and controls designed to limit unnecessary sensitive values in logs.
  • Data lifecycle: controls and procedures designed to authenticate deletion requests, restrict access to data that is no longer needed for ordinary Service use, and delete Customer Personal Data in accordance with documented retention and backup-expiration schedules.
  • Assurance: code review and focused automated testing for material application changes, together with security testing proportionate to the system and risk.

Annex 3 — Subprocessors

The following Subprocessors are authorized to Process Customer Personal Data on Intellicoach's behalf in connection with the Services.

SubprocessorService and purposeCustomer Personal DataProcessing location
Vercel Inc.Application hosting, serverless execution, asset and voice storage, and performance telemetry.Prospect conversation/contact and Customer account/configuration data.Primarily United States; Vercel and its Subprocessors may process globally.
Neon Inc.Production PostgreSQL database.Prospect conversation/contact and Customer account/configuration data.AWS us-east-1, Northern Virginia, for the Intellicoach production database.
Upstash, Inc.Redis caching, rate limiting, scheduling, and QStash background jobs.Prospect conversation/contact and Customer account/configuration data; queued payloads may contain identifiers rather than full records.Account- and region-dependent.
Google LLCGemini API for AI analysis and prospect-response generation.Prospect conversation/contact and Customer account/configuration data.Global standard API endpoint; no Intellicoach-specific regional endpoint is selected.
OpenAI, L.L.C.AI classifications, embeddings, and fallback response generation.Prospect conversation/contact and Customer account/configuration data.Standard API processing; locations are described in OpenAI's current subprocessor materials.
Anthropic, PBCAI safety fallback when primary AI providers are unavailable.Prospect conversation/contact and Customer account/configuration data.United States, Europe, Asia, and Australia, as described in Anthropic's current materials.
Sendinblue SAS, trading as BrevoTransactional emails, OTPs, and operational notifications.Prospect conversation/contact and Customer account/configuration data, including limited notification context.Primarily EU infrastructure, including France, Germany, and Belgium.
ElevenLabs Inc.Voice-note generation, voice samples, and voice cloning where enabled.Prospect conversation/contact and Customer account/configuration data when the voice feature is used.United States for the standard service; isolated regional deployments may be available separately.
Slack Technologies, LLCInternal cancellation and operational notifications.Customer account data.United States by default, subject to Intellicoach's workspace plan and data-residency settings.
MicrolinkFallback link-preview extraction when direct unfurling does not produce a sufficient preview.URLs in prospect conversations, which may contain personal information or tokens.Processing locations are governed by Microlink's applicable service and subprocessor terms.

Stripe, Microsoft Clarity, and Tolt are not included in this Subprocessor list for ordinary Service Processing: Stripe processes billing data under its own terms and may act as an independent controller; Microsoft describes Clarity as a controller for its analytics service; and Tolt's role is subject to its own terms and contractual protections. Their use is described in the Privacy Policy where applicable.

Annex 4 — International Transfer Terms

1. EU Standard Contractual Clauses

For a Restricted Transfer governed by the EU GDPR that is not covered by an adequacy decision or another valid transfer mechanism, the parties incorporate the European Commission's standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) by reference. Module Two applies when Customer is a Controller and Intellicoach is a Processor. Module Three applies when Customer is a Processor and Intellicoach is a Subprocessor.

For the EU SCCs, Clause 7 (docking) is included; Clause 9(a), Option 2 (general written authorization) applies with the notice period in Section 6; the optional language in Clause 11(a) is not included; the governing law under Clause 17 is Ireland; and disputes under Clause 18 are resolved by the courts of Ireland. Annex I.A is completed by Annex 1.A and the Agreement or account record; Annex I.B by Annex 1.B through Annex 1.D; Annex I.C is determined under Clause 13 of the EU SCCs; Annex II by Annex 2; and Annex III by Annex 3. If this DPA conflicts with the EU SCCs, the EU SCCs control.

2. United Kingdom

For a Restricted Transfer governed by UK Data Protection Law, the parties incorporate the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (the “UK Addendum”). The tables in the UK Addendum are completed using the parties and Processing information in the Agreement and Annexes 1 through 3, and the selected EU SCC modules and options are those described above.

3. Switzerland

For a Restricted Transfer governed by Swiss Data Protection Law, the EU SCCs apply with references to the EU GDPR understood to include the Swiss Federal Act on Data Protection where appropriate; the competent authority is the Swiss Federal Data Protection and Information Commissioner for matters governed exclusively by Swiss law; and “Member State” is interpreted to include Switzerland where necessary to preserve Data Subject rights.

4. Transfer cooperation

On reasonable request, each party will provide information necessary for the other to conduct a transfer risk assessment. Intellicoach will implement supplementary safeguards reasonably necessary for the relevant transfer, taking into account the nature of the data, destination, and available technical and organizational measures.

Related Information

We use cookies to measure ad performance and improve your experience. Privacy Policy