1. Who We Are
Legal entity: IntelWork4ce is a trading name operated by Bachir Farah Badar, registered in France as an Entrepreneur Individuel.
| Detail | Information |
|---|---|
| Trade name | IntelWork4ce |
| Legal name | Farah Badar Bachir |
| Legal form | Entrepreneur Individuel |
| SIREN | 106 101 470 |
| SIRET | 106 101 470 00016 |
| APE / NAF code | 62.02A: IT systems and software consulting |
| Registered address | Paris, Ile-de-France, France |
| VAT status | Not VAT-registered: micro-entrepreneur regime (art. 293B CGI) |
IntelWork4ce operates two complementary activities:
IntelWork4ce Consulting: a senior AI transformation consulting practice serving clients across EMEA and North America: assessments, custom AI agent development, and embedded AI leadership.
IntelWork4ce App: an invitation-only showroom platform (app.intelwork4ce.com) providing access to 17 specialized AI agents for prospective consulting clients, and a consulting practice delivering custom AI agent systems deployed to client cloud infrastructure.
This Privacy Policy covers both activities.
Data controller: Bachir Farah Badar, trading as IntelWork4ce, Paris, Ile-de-France, France.
Privacy contact: privacy@intelwork4ce.com: Response within 72 hours.
For B2B customers: IntelWork4ce acts as a data processor under GDPR Article 28 when processing personal data on your behalf (for example, contact data from your CRM, or team member data in a consulting engagement). Your organization remains the data controller for that data. A Data Processing Agreement (DPA) is available at intelwork4ce.com/dpa.
2. Data We Collect
2.1 Account and Identity Data
Collected at registration and maintained during your showroom access or consulting engagement:
- Full name and professional email address
- Company name and country (for business customers)
- Authentication credentials: managed via Clerk, passwords are hashed and never stored in plaintext
- Billing information: processed by Stripe, IntelWork4ce never stores card numbers
2.2 Platform Usage Data
Generated as you use the IntelWork4ce App:
- Agent task types executed, and task completion status
- Slack workspace ID, channel IDs, and user IDs of workspace members interacting with agents
- Message content directed to IntelWork4ce agents in designated channels (required to execute tasks)
- Approval actions (accepted/rejected) and timestamps
- Session logs and navigation data within the customer portal
2.3 Consulting Engagement Data
For consulting clients:
- Contact details of client team members (name, email, role)
- Engagement metadata: project phase, milestone dates, status
- Deliverable references: titles, versions, links to shared files
- Client-facing KPIs and progress data
- Payment schedule data (amounts, due dates, status): read-only reference
This data is processed solely to deliver and report on the consulting engagement. It is not used for platform training or shared with other clients.
2.4 Third-Party Connector Data
When you authorize a connector via OAuth 2.0, we access only the scopes you explicitly grant:
| Connector type | Data accessed (per your authorization) |
|---|---|
| Google Workspace | Emails, calendar events, Drive documents you request agents to process |
| CRM (HubSpot, Salesforce, Pipedrive) | Contacts, deals, activities: for sales agent task execution |
| LinkedIn (via Marc agent) | Profile and connection metadata: for prospecting tasks |
| Social platforms (Buffer, X, LinkedIn) | Post metadata and account identifiers: for publishing tasks |
| Accounting tools (Xero, QuickBooks) | Invoice and expense data: for Hugo (finance) agent tasks |
| Analytics (PostHog, Google Analytics) | Aggregated usage metrics: for Leo (data) agent tasks |
| Any other connector | Only the specific OAuth scopes you authorize at connection |
OAuth credentials are stored encrypted at rest using AES-256-GCM, isolated per workspace. Tokens are never logged or shared beyond the intended connected service.
2.5 Technical and Diagnostic Data
- IP addresses (30-day retention for security)
- Browser type and OS (portal usage only)
- API request logs (90-day retention for debugging)
- Error logs and crash reports (aggregated, anonymized)
3. Legal Basis for Processing (GDPR Art. 6)
| Legal basis | Processing activities covered |
|---|---|
| Contract performance (Art. 6(1)(b)) | Account management, agent task execution, credit billing, connector operations, Slack integration, consulting engagement delivery |
| Legitimate interests (Art. 6(1)(f)) | Platform security, fraud prevention, aggregated analytics, error diagnostics |
| Legal obligation (Art. 6(1)(c)) | Tax and accounting records under French law (art. L123-22 Code de commerce, art. 293B CGI), CNIL compliance |
| Consent (Art. 6(1)(a)) | Marketing communications (explicit opt-in only); non-essential analytics cookies |
4. How We Use Your Data
- Executing AI agent tasks: instructions processed via Gemini 2.5 Pro (Google Cloud europe-west1, Belgium)
- Operating the Slack integration: routing messages, managing approval workflows, delivering agent outputs
- Running connector operations: reading and writing data to authorized third-party services on your behalf
- Managing subscriptions: credit tracking, Stripe billing, plan management, usage reporting
- Delivering consulting engagements: project tracking, milestone management, deliverable access, KPI reporting, payment scheduling
- Security and fraud prevention: anomaly detection, unauthorized access monitoring
- Customer support: diagnosing issues and responding to enquiries
- Platform improvement: anonymized, aggregated usage pattern analysis: no task content or client data is used
5. Sub-processors
All sub-processors are bound by GDPR Article 28-compliant data processing agreements. Full list: intelwork4ce.com/subprocessors
| Sub-processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Google Cloud (GCP) | Hosting (Cloud Run), AI inference (Gemini 2.5 Pro) | europe-west1 (Belgium) | EEA (no transfer) |
| Supabase | Database, authentication, file storage | EU (Frankfurt) | EEA (no transfer) |
| Nango | OAuth credential management | EU | EEA (no transfer) |
| Clerk | Portal authentication and sessions | EU | EEA (no transfer) |
| Stripe | Payment processing and billing | EU / US | SCCs + DPF |
| Google Secret Manager | API key and token vault | europe-west1 | EEA (no transfer) |
| Slack Technologies | Messaging platform integration | US | SCCs + DPF |
| Anthropic PBC | AI language model processing (Claude API) | US | SCCs |
| PostHog | Product analytics | EU (Frankfurt) | EEA (no transfer) |
6. Data Retention
| Data category | Retention period | Legal reference |
|---|---|---|
| Accounting and billing records | 10 years | Art. L123-22 Code de commerce |
| Commercial contracts and correspondence | 5 years | Art. L110-4 Code de commerce |
| Slack message content processed by agents | Deleted within 72 hours of task completion | Minimum necessary principle |
| Agent task logs (metadata only, no content) | 12 months | Service operation |
| Consulting engagement metadata | Duration of engagement + 5 years | Art. L110-4 Code de commerce |
| OAuth connector tokens | Until connector is disconnected or account deleted | Contractual necessity |
| IP addresses and access logs | 30 days | Security |
| API request logs | 90 days | Debugging |
| Credit usage records | 3 years | Billing audit trail |
7. International Data Transfers
IntelWork4ce primarily processes data within the EEA. For transfers outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
- The EU-US Data Privacy Framework (DPF, July 2023) for certified US entities (Stripe, Slack)
All AI inference via Google Cloud runs on EU infrastructure (europe-west1, Belgium). Anthropic transfers are covered by SCCs. We verify transfer safeguards before engaging any new sub-processor.
8. Your Rights (GDPR)
Write to privacy@intelwork4ce.com. We respond within 30 days.
| Right | Description |
|---|---|
| Access (Art. 15) | Obtain a copy of all personal data we hold about you |
| Rectification (Art. 16) | Correct inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your personal data |
| Portability (Art. 20) | Receive your data in machine-readable format (JSON / CSV) |
| Restriction (Art. 18) | Restrict processing in defined circumstances |
| Objection (Art. 21) | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw consent at any time without affecting prior lawful processing |
You have the right to lodge a complaint with the CNIL: www.cnil.fr
9. Data Deletion on Account Termination
Upon subscription cancellation or account deletion:
- Agent task content and Slack message data: deleted within 72 hours
- OAuth credentials and connector tokens: revoked and deleted immediately
- Consulting engagement metadata: retained for 5 years (art. L110-4 Code de commerce)
- Accounting and billing records: retained for 10 years (art. L123-22 Code de commerce)
To request full data deletion: email privacy@intelwork4ce.com, subject: “Data Deletion Request: [Workspace / Client Name]”. Confirmed within 10 business days.
10. Security
- Data in transit: TLS 1.2+ encryption
- Data at rest: AES-256-GCM encryption
- Per-workspace isolation: no data leakage between customer environments
- OAuth tokens: stored in Google Cloud Secret Manager, never in application logs or code
- Breach notification: supervisory authority within 72 hours; affected customers without undue delay (GDPR Art. 33)
11. Changes to This Policy
Material changes will be communicated by email and in-app notification at least 14 days before they take effect. Continued use of IntelWork4ce after the effective date constitutes acceptance.
12. Contact
privacy@intelwork4ce.com | support@intelwork4ce.com
IntelWork4ce: Bachir Farah Badar, Entrepreneur Individuel
SIREN 106 101 470 | Paris, Ile-de-France, France
intelwork4ce.com/privacy