This DPA is entered into between you ("Controller") and IntelWork4ce, trading name of Bachir Farah Badar, Entrepreneur Individuel, SIREN 106 101 470, Paris, Ile-de-France, France ("Processor"). It supplements and forms part of the Terms & Conditions. By using the IntelWork4ce platform, you agree to this DPA.
1. Definitions
- "Controller" means the Customer who determines the purposes and means of processing Personal Data via the Service.
- "Processor" means IntelWork4ce (Bachir Farah Badar, Entrepreneur Individuel, SIREN 106 101 470), which processes Personal Data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" has the meaning given in Article 4(2) of the GDPR.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "GDPR" means EU Regulation 2016/679 of 27 April 2016.
2. Scope and Duration
This DPA applies to all processing of Personal Data by IntelWork4ce on behalf of the Customer in connection with the use of the IntelWork4ce platform and any consulting engagement.
This DPA remains in effect for the duration of the Customer's subscription or engagement and until all Personal Data has been deleted or returned in accordance with Section 12.
3. Data Processing Details
3.1 Categories of Data Subjects
- Customer's employees and team members
- Customer's clients and prospects (CRM data accessed via connectors)
- End users of Customer's services
- Client team members involved in IntelWork4ce Consulting engagements
3.2 Types of Personal Data
- Contact information (name, email, phone)
- Professional information (job title, company, LinkedIn profile data)
- CRM records and sales pipeline data
- Communication content (Slack messages processed by agents)
- Usage analytics and behavioral data during showroom evaluation (aggregated)
- Consulting engagement data: team contact details, project metadata, KPIs, deliverable references
3.3 Purpose of Processing
Personal Data is processed solely to provide the IntelWork4ce services described in the Terms, including: orchestrating AI agents, generating reports and digests, executing marketing, sales, finance, and operations tasks, providing analytics, and delivering consulting engagements.
| Category | Legal basis | Retention |
|---|---|---|
| Account data | Contract performance | Duration of showroom access or consulting engagement + 30 days |
| CRM and pipeline data | Legitimate interest of Controller | Duration of showroom access or engagement |
| Slack messages processed by agents | Legitimate interest of Controller | 72 hours after task completion |
| Usage analytics | Legitimate interest | 26 months |
| Billing and accounting records | Legal obligation | 10 years (art. L123-22 Code de commerce) |
| Commercial contracts and correspondence | Legal obligation | 5 years (art. L110-4 Code de commerce) |
| Consulting engagement data | Contract performance | Duration of engagement + 5 years |
4. Controller Obligations
The Controller shall:
- Ensure that Personal Data is collected and transferred to the Processor in compliance with applicable data protection laws
- Provide clear and lawful instructions for processing
- Inform data subjects about the use of IntelWork4ce as a processor where required
- Respond to data subject requests, with assistance from the Processor as described in Section 10
- Ensure that any special categories of personal data (health, biometric, political, religious) are not processed through the Platform without prior written agreement with IntelWork4ce
5. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorized to process Personal Data are bound by appropriate confidentiality obligations
- Implement the technical and organizational measures described in Section 8
- Not engage another processor without prior specific or general written authorization of the Controller
- Assist the Controller in fulfilling its obligations regarding data subject rights, DPIAs, and breach notifications
- Delete or return all Personal Data upon termination, as described in Section 12
- Make available all information necessary to demonstrate compliance with this DPA and allow for audits
6. Sub-processors
The Controller provides general authorization for the Processor to engage sub-processors. The Processor shall inform the Controller of any intended changes at least 30 days in advance, giving the Controller the opportunity to object.
6.1 Current Sub-processors
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Google Cloud Platform | Infrastructure hosting (Cloud Run), AI inference (Gemini 2.5 Pro), Secret Manager | EU (europe-west1, Belgium) | EEA (no transfer) |
| Supabase Inc. | Database hosting and authentication | EU (Frankfurt) | EEA (no transfer) |
| Nango | OAuth credential management | EU | EEA (no transfer) |
| Clerk Inc. | User authentication and sessions | EU | EEA (no transfer) |
| Anthropic PBC | AI language model processing (Claude API) | US | SCCs (Decision 2021/914) |
| Stripe Inc. | Payment processing | EU / US | SCCs + DPF |
| Slack Technologies (Salesforce) | Messaging platform integration | US | SCCs + DPF |
| PostHog Inc. | Product analytics | EU (Frankfurt) | EEA (no transfer) |
7. International Transfers
Where Personal Data is transferred outside the EEA, the Processor ensures appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): European Commission Decision 2021/914 (controller-to-processor module where applicable)
- EU-US Data Privacy Framework (DPF): for US sub-processors certified under the DPF (Stripe, Slack)
- Supplementary measures: as recommended by the EDPB where required
Anthropic PBC transfers are covered by SCCs. Anthropic does not currently participate in the DPF; supplementary measures including data minimization and purpose limitation are applied.
8. Security Measures
The Processor implements the following technical and organizational measures:
- AES-256-GCM encryption for all credentials and tokens at rest
- TLS 1.3 for all data in transit
- Per-workspace data isolation enforced at the database layer via Supabase Row-Level Security (RLS)
- Role-based access controls with principle of least privilege
- OAuth tokens stored in Google Cloud Secret Manager, not in application code or logs
- Regular security vulnerability assessments
- Automated backup and disaster recovery
- Logging and monitoring of all data access events
- Employee and contractor confidentiality obligations
9. Data Breach Notification
In the event of a Data Breach, the Processor shall:
- Notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach
- Provide all information necessary for the Controller to comply with its notification obligations under Articles 33 and 34 of the GDPR
- Take immediate steps to contain the breach and prevent further unauthorized access
- Maintain a breach register and make it available to the Controller upon request
The Controller is responsible for notifying the relevant supervisory authority (CNIL or equivalent) within 72 hours where required under Art. 33 GDPR.
10. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests under GDPR Chapter III, including rights of access, rectification, erasure, restriction, portability, and objection.
Self-service tools for data export and account deletion are available in the platform at: Settings > Your Data.
Manual requests: privacy@intelwork4ce.com. Response within 30 days.
11. Audits
The Processor shall make available all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller.
Audit requests must be made with at least 30 days' written notice and shall be conducted during normal business hours, no more than once per year unless required by a supervisory authority.
12. Data Deletion and Return
Upon termination of the subscription or engagement:
- The Controller may export their data using the self-service export tool within 30 days
- After 30 days, the Processor shall delete all Personal Data unless retention is required by applicable law (see retention schedule in Section 3.3)
- The Processor shall provide written certification of deletion upon request from the Controller
13. Liability
Each party's liability under this DPA is subject to the limitations set forth in the Terms & Conditions. Nothing in this DPA limits either party's liability for breaches of applicable data protection law to the extent that such limitation is not permitted by law.
14. Governing Law
This DPA is governed by French law. Any disputes shall be submitted to the exclusive jurisdiction of the courts of Paris, France.
15. Contact
Data Protection Contact
IntelWork4ce: Bachir Farah Badar, Entrepreneur Individuel
SIREN: 106 101 470
Email: privacy@intelwork4ce.com
CNIL registration: Pending
intelwork4ce.com/dpa