Skip to content
See a Demo
Legal

Partner DPA

This Data Protection Agreement governs how a Partner processes personal data in connection with services delivered to IntelAgree customers, and forms part of the Partner Agreement between the parties.

This Data Protection Agreement (the “DPA”) is executed as of the Effective Date of the Partner Agreement (the “DPA Effective Date”) between IntelAgree, LLC (“Company”) and Partner Name (“Partner”). Capitalized terms have the meanings provided in the Agreement defined below except as provided here.

WHEREAS, Company and its Customer have executed a Master Software as a Service Agreement or other agreement (“Customer Agreement”) governing Customer’s license of the COMPANY Software and or Services which may include services to be provided by Partner (“Services”); and

WHEREAS, Partner and Company wish to enter this DPA so that Partner can provide services to IntelAgree’s Customer(s), which will supplement certain provisions of the Partner Agreement regarding each party’s respective security and data protection obligations and or is required under the terms of Company’s agreement with its Customer(s) (“Customer Agreement(s)”); and

WHEREAS, this DPA is not a standalone agreement and is only effective if Company and Partner have previously executed a Partner Agreement; and

NOW THEREFORE, the parties agree as follows:

1 Definitions.

  1. “Personal Data Breach” means a breach by Partner of its security obligations in this DPA that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data stored or otherwise processed in Customer’s Company instance as part of the Services that compromises the confidentiality, integrity, or availability of such Personal Data.
  2. “Data Protection Law” means all applicable legislation relating to data protection and privacy together with any national implementing laws in any member state of the European Union or, to the extent applicable, in any other country, state, or province, as amended, repealed, consolidated or replaced from time to time including the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) and the GDPR as transposed into United Kingdom (“UK”) national law by operation of Section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 ("UK GDPR”).
  3. “Personal Data” means any information relating to an identified natural person or a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, in each case that is processed by Partner under the Customer Agreement (each such person a “Data Subject”) where such data are contained within Customer Data.
  4. “Business”, “Service Provider”, “Process”, “Processor”, “Controller” and “Supervisory Authority” will each have the meaning given to them in applicable Data Protection Law.
  5. “Standard Contractual Clauses” means the standard contractual clauses, published by the European Commission, reference 2021/914 or any subsequent final version thereof which shall automatically apply.
  6. “UK Addendum” means UK Information Commissioner’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses Version B1.0 in force 21 March 2022.

2 Processing of Personal Data.

  1. Applicability. This DPA will apply only to the extent that the Partner Services are engaged in the processing of Personal Data subject to Data Protection Laws on behalf of IntelAgree’s Customers.
  2. Relationship of the Parties. If applicable Data Protection Law recognizes the roles of Controller/Business and Processor/Service Provider as applied to Personal Data, then as between Company and Partner, Company acts as Controller and Business and Partner acts as a Processor/Service Provider (or Subprocessor, as the case may be) of Personal Data. Company appoints Partner as a Processor to Process Personal Data: (a) for the purposes described in the Customer Agreement, or (b) with Company’s prior written consent (collectively the “Permitted Purpose”), unless Processing is required by applicable Data Protection Law to which Partner is subject, in which case Partner shall, to the extent permitted by applicable law, inform Company of that legal requirement before so Processing that Personal Data. Each party will comply with the obligations that apply to it under Data Protection Law in the Processing of Personal Data. If Partner becomes aware that Processing for the Permitted Purpose infringes Data Protection Law, it will promptly inform Company, provided, however, Partner is not responsible for performing legal research and/or for providing legal advice to Company. The details of the transfer are specified in the attached Exhibit A and incorporated herein by this reference.
  3. Customer’s and/or Company’s Instructions. Any additional or different instructions from Customer or Company pertaining to the Processing of Personal Data require a signed agreement between Company and Partner and and may be subject to additional fees to be mutually agreed by the Parties. For the avoidance of doubt, Customer’s or Company’s instructions for the Processing of Personal Data shall comply with Data Protection Law. Customer or Company shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer or Company acquired Personal Data. If Partner cannot Process Personal Data according to Customer’s or Company’s instructions due to a legal requirement under any applicable Data Protection Law, then Partner will (i) promptly notify Customer or Company of such inability, providing a reasonable level of detail as to the instructions with which it cannot comply and the reasons why it cannot comply, to the greatest extent permitted by applicable law; and (ii) Process (or continue to process) Personal Data to the extent Partner is able to comply with Customer’s or Company’s instructions in order to provide the Services as set forth in the Customer Agreement or applicable agreement between Company and Partner.
  4. Customer Notices and Consents. Customer or Company shall (a) provide all required notices and appropriate disclosures to all Data Subjects regarding Customer’s, and Company’s, Processing of Personal Data and (b) ensure that Customer or Company has obtained (or will obtain) and maintain during the term of the Customer Agreement all rights and consents (if required) which are necessary for Partner to Process Customer Personal Data in accordance with this DPA and the Customer Agreement. If Customer is not required by Data Protection Law to obtain and maintain valid consent from Data Subjects, Customer or Company will otherwise comply with requirements under Data Protection Law to obtain and maintain a valid legal basis to Process Personal Data and for providing such data to Partner for Processing under the Agreement.
  5. Confidentiality of Processing. Partner will treat Personal Data as Customer’s and Company’s Confidential Information. Partner shall implement processes designed to ensure that Personal Data is only made available to those of its personnel, including its Subprocessors, who (i) need to access such Personal Data in order to carry out their roles in the performance of Partner‘s obligations under the Agreement and this DPA and (ii) have committed themselves to protect the confidentiality of such Personal Data or are otherwise under an appropriate statutory obligation of confidentiality.
  6. Cooperation and Data Subjects' Rights. Partner will provide reasonable and timely assistance to Customer or Company (at Partner's expense) to enable Customer or Company to respond to: (a) any request from a Data Subject to exercise any of its rights under Data Protection Law (including its rights of access, correction, objection, erasure and data portability, as applicable); and (b) any other correspondence, enquiry or complaint received from a Data Subject, Supervisory Authority or other third party in connection with the Processing of the Personal Data. If any such request, correspondence, enquiry or complaint is made directly to Partner, then Partner will promptly inform Customer or Company providing full details of the same to the extent Customer is identified as the relevant entity that collected the Data Subject’s Personal Data and to the extent legally permitted. If a Data Subject does not identify an entity that collected its Personal Data, Partner will instruct the Data Subject to identify and contact the relevant entity that collected its Personal Data. Partner shall comply with Customer’s or Company’s instructions regarding the handling of a Data Subject inquiry, subject to the terms of Sections 2a. and 2b.
  7. Personal Data Return and Disposal. Within 30 days after a written request by Customer or Company or the termination or expiration of the Agreement, Partner will: (a) if requested by Customer or Company, provide Customer or Company with a copy of any Personal Data in Partner’s possession that Customer or Company does not already have; and (b) make reasonable efforts to securely destroy all Personal Data in Partner’s possession in a manner that makes such Personal Data non-readable and non-retrievable. Notwithstanding the foregoing, Partner may retain copies of Personal Data: (x) to the extent Parnter has a separate legal right or obligation to retain some or all of the Personal Data; (y) in its capacity as a Controller for Partner’s business operations (such as in email records, customer support or accounting records), and (z) in backup or archive systems until such records have been overwritten or expunged in accordance with Partner’s data retention policy or applicable Data Protection Law if more restrictive.
  8. California Consumer Privacy Act of 2018 (“CCPA”) as amended by California Privacy Rights Act of 2020 (“CPRA”). Partner confirms that it understands the restrictions set forth in 1798.140(ag)(1) of the CPRA and will comply with the same to the extent the Personal Data are subject to the CPRA and no other CPRA exemptions apply.
  9. Special or Sensitive Data. Unless set forth in a statement of work, order, or other document, Personal Data may not include any sensitive or special categories of data that impose specific data security or data protection obligations on Partner in addition to or different from those specified in any documentation or which are not provided as part of the Services. Partner does not require and does not request any sensitive or special categories of data to provide the Services. Company understands and agrees that Paratner does not differentiate between different types of data sensitivity when Processing Personal Data or treat certain types of Personal Data differently from other types and applies the same security measures to all Personal Data as set forth in this DPA.

3 International Transfers.

  1. Partner will not transfer Personal Data outside the European Economic Area (“EEA”) unless it takes such measures as are necessary to provide adequate protection for such Personal Data consistent with the requirements of Data Protection Law. To the extent Partner Processes (or causes to be Processed) any Personal Data originating from the EEA in a country that has not been designated by the European Commission or other relevant authority as providing an adequate level of protection for Personal Data, Comapny and Partner agree that the transfer will be subject to the Standard Contractual Clauses and UK Addendum, as applicable, where Exhibit A provides the necessary information for the Appendix of the Standard Contractual Clauses and UK Addendum, or if the Standard Contractual Clauses or UK Addendum are no longer available or valid, another mechanism compliant with Data Protection Law.
  2. Company shall be deemed to have signed the Standard Contractual Clauses in its capacity of “data exporter” and Partner in its capacity as “data importer.” Module Two or Module Three of the Standard Contractual Clauses shall apply to the transfer depending on whether Customer or Company is Controller of the Personal Data (for Module Two) or a if Company is a Processor of the Personal Data on behalf of its Customer (for Module Three). If Module Three applies, Company hereby notifies Partner that it is a Processor and the instructions shall be as set forth in Section 2a. of this DPA. For purposes of Clauses 17 and 18 of the Standard Contractual Clauses, the Parties select Portugal. Additional provisions applicable to Personal Data transferred pursuant to Standard Contractual Clauses are set forth in Exhibit B.

4 Subprocessing.

  1. Company authorizes Partner to engage Partner affiliates and third party suppliers and vendors to process Personal Data for the Permitted Purpose (“Subprocessors”) provided that: (a) Partner will maintain an up-to-date list of Subprocessors located at a website provided to Company or as attached as Appendix A to the Partner Agreement, which it will update with details of any change in Subprocessors; and (b) Partner will enter into a binding written agreement with the Subprocessor that imposes on the Subprocessor the same level of restrictions that apply to Partner under this DPA to the extent applicable to the nature of the services provided by such Subprocessor. For the avoidance of doubt, the above authorization constitutes Customer’s and Company’s prior written consent to the subprocessing of Personal Data for purposes of Clause 9, Option 2 of the Standard Contractual Clauses.
  2. Customer or Company may object to Partner's appointment or replacement of a Subprocessor prior to its appointment or replacement, provided such objection is based on reasonable and objective grounds that the Subprocessor does not or cannot comply with applicable Data Protection Law. Company has thrity (30) days after Partner notifies Company of such new Subprocessor to notify Partner in writing of its objection supported by documentary evidence. Upon receipt of Company’s written objection, Company and Partner will work together without unreasonable delay to find a mutually acceptable resolution to address the objection, including but not limited to reviewing additional documentation supporting the Subprocessor's ability to comply with Data Protection Law. To the extent Company and Partner do not reach a mutually acceptable resolution within a reasonable timeframe, COMPANY will use reasonable endeavors to make available to Company a change in the Services or will recommend a commercially reasonable change to the Services to prevent the applicable Subprocessor from processing Personal Data. If Partner is unable to make available such a change within a reasonable period of time, which shall not exceed thirty (30) days, Company may, suspend or terminate the Partner Agreement and any relevant order forms, SOWs or similar documents referencing the Partner Agreement, in accordance with the termination provisions in the Partner Agreement without liability to Company.
  3. Where any of its Subprocessors fails to fulfil its data protection obligations in relation to the Services provided to Company, such that Partner would be found to have violated its obligations to Company under this DPA, then Partner will be responsible to Company for the performance of its Subprocessor’s obligations.

5 COMPANY Security Measures

  1. Security in COMPANY-Managed Deployments. In deployments where Partner manages the Services, Partner shall implement procedural, technical, and administrative safeguards designed to protect Personal Data from a Personal Data Breach when cached in the Services or in transit between Company’s or Partner’s databases and the Services. Partner may update its security practices from time to time but will not materially decrease the overall security of the Services during the term of this DPA or the Partner Agreement.
  2. Personnel Background Checks. Prior to engaging any employee or contractor who may receive access to Personal Data Partner will conduct a background check subject to local laws.
  3. Company Responsibilities. Company is responsible for security relating to its environment and databases and security relating its configuration of the Software. This includes implementing and managing procedural, technical, and administrative safeguards on its software and networks sufficient to: (a) ensure the confidentiality, security, integrity, and privacy of Customer or Company Data in transit, at rest, and in storage; (b) protect against any anticipated threats or hazards to the security and integrity of Customer or Company Data; and (c) protect against any unauthorized processing, loss, use, disclosure or acquisition of or access to Customer or Company Data.

6 Information and Assistance.

  1. Data Protection Impact Assessment. Partner will provide reasonable cooperation to Company (at Company's expense) in connection with any data protection impact assessment that Company or its Customer may be required to perform under Data Protection Law.
  2. Audit. If a Data Protection Law permits Company to audit COMPANY’s compliance with such law, then Partner will assist Company in satisfying the audit as follows. On Company’s request and subject to the confidentiality obligations set forth in the Agreement or an appropriate NDA, Partner will make available to Company a summary of its most recent SOC 2 audit report, as available, not more than once per year.
  3. Questionnaires. If Company requires additional information, then Partner will respond to a reasonable and written Company security questionnaire no more than once per year and meet by teleconference to address any additional questions.
  4. Audit. If Company requires additional information and reasonably believes Partner is not in compliance with this DPA or if required by a Supervisory Authority, then Company may contact Partner in accordance with the “Notices” Section of the Partner Agreement, if applicable or on ten (10) days’ notice if not applicable, to request an on-site audit, not more than once per year (unless required by a Supervisory Authority), of its procedures relevant to the protection of Personal Data.
  5. Audit Procedure. At least two weeks before the commencement of any such on-site audit, Company will provide to Partner a draft written audit plan, after which Company and Partner shall discuss in good faith and finalize the audit plan and the parties shall mutually agree upon the scope, timing, and duration of the audit and the reimbursement rate for any travel or other expenses Partner incurs in the course of such audit. Audits may be conducted only during regular business hours, in accordance with the finalized audit plan and Partner's security and other policies, and may not unreasonably interfere with Partner's regular business activities. Company shall promptly notify Partner with information regarding any non-compliance discovered during the course of an audit. Any third party engaged by Company to conduct an audit must be pre-approved by Partner (such approval not to be unreasonably withheld).
  6. Audit Results. Information obtained or results produced in connection with an audit are Partner Confidential Information under the Partner Agreement and may only be used by Company to confirm compliance with this DPA, including by providing such results to Company’s Customer, and for complying with its requirements under Data Protection Law.

7 Company Security Measures.

  1. Appropriate Permissioning. Company and its Customer are solely responsible for provisioning Authorized Users on the Software, including: (a) methods of authenticating Authorized Users (such as industry-standard secure username/password policies, two-factor authentication or SAML-supported SSO iDP); (b) restricting access by Authorized User or group, and from the database level down to the row or column level; (c) managing administrator privileges; (d) deauthorizing personnel who no longer need access to the Services; (e) securely configuring any APIs; and (e) regularly auditing any public access links Authorized Users create and restricting the permission to create public links, as necessary.
  2. COMPANY Permission to Access Company or Custoemr Databases. In order to use the Services, Company must authorize the Services to access Company’s or Customer’s databases. When granting authorization, Company must follow the principle of least privilege to Company database information, especially by granting Partner no more than read-only access to database data. Partner will not be responsible for any Personal Data Breach, security incident, or other loss to the extent Company provides the Services with write or administrator access to Company’s or Customer’s databases or other Personal Data.

8 Data Breach Notification and Resolution.

  1. Breach Notice. If it becomes aware of a confirmed Personal Data Breach, Partner shall inform Company via email without undue delay and in any event withing forty-eight (48) hours or less from Partner’s discovery of the Personal Data Breach. Partner shall further take any such reasonably necessary measures and actions to address or mitigate the effects of the Personal Data Breach and will keep Company informed of all material developments in connection with the Personal Data Breach. Company’s contact point for additional details regarding a Personal Data Breach is security@intelagree.com. Except as required by applicable Data Protection Legislation, the obligations set out in this Section shall not apply to Personal Data Breaches caused by Company or Customer.
  2. Cooperation. Company is solely responsible for complying with data incident notification requirements applicable to Company and fulfilling any third-party notification obligations related to any Personal Data Breach. Partner will provide reasonable information and cooperation to Company so that Company, and if applicable its Customer, can fulfill any Personal Data Breach reporting obligations it or they may have under (and in accordance with the timescales required by) Data Protection Law. Partner’s prior written approval shall be required for any statements containing specific information regarding Partner’s systems, security practices, or the nature of the Personal Data Breach or references to Partner by name.

9 Miscellaneous.

  1. Construction; Interpretation. This DPA is part of the Partner Agreement and is governed by its terms and conditions (including limitations of liability. This DPA and the Partner Agreement are the complete and exclusive statement of the mutual understanding of the parties and supersede and cancel all previous written and oral agreements and communications relating to the subject matter hereof. Headings contained in this DPA are for convenience of reference only and do not form part of this DPA. To the extent of any conflict between this DPA and the Partner Agreement related to Personal Data, the DPA shall control. To the extent of any conflict between the Standard Contractual Clauses and the DPA, the Standard Contractual Clauses shall control.
  2. Severability. If any provision of this DPA is adjudicated invalid or unenforceable, this DPA will be amended to the minimum extent necessary to achieve, to the maximum extent possible, the same legal and commercial effect originally intended by the parties. To the extent permitted by applicable law, the parties waive any provision of law that would render any clause of this DPA prohibited or unenforceable in any respect.
  3. Amendment; Enforcement of Rights. No modification of or amendment to this DPA, nor any waiver of any rights under this DPA, will be effective unless in writing signed by the parties to this DPA. The failure by either party to enforce any rights under this DPA will not be construed as a waiver of any rights of such party. In the event Data Protection Laws change subsequent to the signing of this DPA or the Partner Agreement, the Parties shall negotiate in good faith to reach agreement on reasonable next steps, including, where applicable, changes that may be necessary and operationally, technically and commercially feasible to the Agreement, the DPA and/or the Services (including, without limitation, the fees payable by Company to COMPANY for the Services) in order to enable Partner to continue providing the Services in compliance with such revised Data Protection Laws.

EXHIBIT A

APPENDIX TO THE STANDARD CONTRACTUAL CLAUSES

ANNEX I

A. LIST OF PARTIES

Data exporter

Name: The data exporter is the entity identified as “Company” in the DPA
Address: As set forth in the Partner Agreement or relevant agreement that references the Partner Agreement (collectively referred to in this Annex I as “Partner Agreement”)
Contact person: General Counsel/Legal
100 E Madison St Suite 300, Tampa, FL 33602
legal@intelagree.com
Activities relevant to the data transferred under these Clauses: As set forth in the Partner Agreement
Signature and date: Refer to DPA
Role: Controller, except when processing data on behalf of another entity, in which case data exporter is a processor

Data importer

Name: The data importer is the entity identified as “Partner” in the DPA
Address: As set forth in the Partner Agreement
Contact person: As set forth in the Notices provision in the Partner Agreement
Activities relevant to the data transferred under these Clauses: As set forth in the Partner Agreement
Signature and date: Refer to DPA
Role: Processor, or sub-processor if data exporter is a processor

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred: “Authorized Users” as defined in the Partner Agreement or applicable agreement between Company and its Customer(s)
Categories of personal data transferred: Name
Email address
Cookie Information
Device Identifiers,
IP-address and other online identifiers
Account log-in details and passwords
Telephone/mobile number
Location Data
Sensitive categories of data (if appropriate): As determined and controlled by Customer in its sole discretion, and if provided to data importer, data exporter shall comply with Section 2.9 of the DPA
The frequency of the transfer: As set forth in the Partner Agreement
Nature of the processing: As set forth in Sections 2 of the DPA, and in the Partner Agreement
Purposes of the data transfer and further processing: As set forth in Sections 2 and 4 of the DPA, and in the Partner Agreement
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be processed for the duration of the Partner Agreement, subject to Section 2.7 of the DPA
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: As set forth in Sections 2 and 4 of the DPA, and in the Partner Agreement

C. COMPETENT SUPERVISORY AUTHORITY

If Customer is established in an EU Member state, the competent supervisory authority shall be the supervisory authority applicable to the establishment location of Company’s Customer. If Company’s Customer is not established in an EU Member state, the competent supervisory authority shall be the supervisory authority located where Company’s Customer has appointed its EU Representative. If Company or its Customer is not established in an EU Member state and is not required to appoint an EU Representative, the competent supervisory authority shall be the supervisory authority applicable to the location of the Data Subject whose data is at issue.

ANNEX II

Technical and organizational measures, including technical and organizational measures, to ensure the security of the data:

1.1 Access Control of Processing Areas

Processes to prevent unauthorized persons from gaining access to Vendor data processing equipment (namely telephones, database and application servers and related hardware) where the Customer Data are processed or used. All Customer Data stored and processed within IntelAgree is managed and maintained in accordance with applicable compliance for each customer. The IntelAgree data management policy and security controls provide appropriate administrative, technical, and physical safeguards for the protection of customer confidential information.

1.2 Access Control to Data Processing Systems

Processes to prevent Vendor data processing systems from being used by unauthorized persons. Only access for implementation activities will be required during the implementation phase and the appropriate support required access based upon Customer’s specific implementation. IntelAgree utilizes least privilege and role-based access. Only authorized employees have access to the appropriate environment based upon their role and their required activities (implementation, development, and support).

1.3 Access Control to Use Specific Areas of Data Processing Systems

Measures to ensure that persons entitled to use Vendor data processing systems are only able to access the data within the scope and to the extent covered by their respective access permission (authorization) and that Customer Data cannot be read, copied or modified or removed without authorization. Only access for implementation activities will be required during the implementation phase and the appropriate support required access based upon Customer’s specific implementation. IntelAgree utilizes least privilege and role-based access. Only authorized employees have access to the appropriate environment based upon their role and their required activities (implementation, development, and support).

1.4 Transmission Control

Procedures to prevent Customer Data from being read, copied, altered or deleted by unauthorized parties during the transmission thereof or during the transport of the data media and to ensure that it is possible to check and establish to which bodies the transfer of Customer Data by means of data transmission facilities is envisaged. In addition to the access controls Customer’s subscription, the applicable data is further protected by additional protections provided such as:

  • A Separate SQL Azure database provided per subscriber.
  • A firewall that allows restriction of access by IP address.
  • Microsoft key vault cryptographic access keys for access to Customer’s subscription
  • Continuous system monitoring and auditing for access and QA support including tracking of all logins and system actions.

1.5 Input Control

Measures to ensure that it is possible to check and establish whether and by whom Customer Data has been input into data processing systems or removed. Access is only granted to the appropriate personnel and limited by role, job function and industry best practices. All administrative access utilizes multi-factor authentication and advanced access controls. IntelAgree is a SaaS platform hosted by Microsoft Azure, and IntelAgree utilizes Azure sentinel for SIEM which has an embedded IDS & IPS. Additionally, IntelAgree has an active threat monitoring management program utilizing real-time environment QA scanning and monitoring via Qualys.

1.6 Availability Control

Measures to ensure that Customer Data is protected from accidental destruction or loss. IntelAgree is a SaaS platform hosted by Microsoft Azure, and IntelAgree utilizes Active Geo-replication between the Microsoft Azure US East and the Microsoft Azure US west data center.

1.7 Segregation of Processing

Procedures to ensure that data collected for different purposes can be processed separately. All Data stored in the IntelAgree platform is stored in the hosting data center environment which is Microsoft US East data Center. Customer Data will only be extracted or accessed by Customer’s team for Customer’s specific subscription. In addition to the access controls, Customer’s subscription and the applicable data is further protected by additional protections provided such as:

  • A Separate SQL Azure database provided per subscriber.
  • A firewall that allows restriction of access by IP address.
  • Microsoft key vault cryptographic access keys for access to Customer’s subscription.

IntelAgree has an efficient risk management program and has an annual SOC 2 Type Audit and a HIPAA Type 1 audit performed by a trusted 3rd party provider. IntelAgree utilizes encryption for data in transit via TLS 1.2 and IntelAgree utilizes TDE (Transparent Data Encryption) for data at rest. Each customer is provided with a separate Azure Blob storage instance for their specific subscription.

ANNEX III

Data importer’s current list of Subprocessors: to be provided by Partner in the Partner Agreement

EXHIBIT B – ADDITIONAL SCC PROVISIONS

BASED ON EUROPEAN DATA PROTECTION BOARD RECOMMENDATIONS 01/2020

  1. Partner shall promptly notify Company of any request for the disclosure of Personal Data by a governmental or regulatory body or law enforcement authority (including any Supervisory Authority) (“Disclosure Request”) unless otherwise prohibited by law or a legally binding order of such body or agency and without responding to such request, unless otherwise required by applicable law (including to provide acknowledgement of receipt of the request). Partner will review applicable law to evaluate any Disclosure Request, for example the ability of the requesting authority to make the Disclosure Request, and to challenge the Disclosure Request if, after a careful assessment, it concludes that there are grounds under applicable law to do so. When challenging a Disclosure Request, Partner shall seek interim measures to suspend the effects of the Disclosure Request until an applicable court or other authority has decided on the merits. Partner shall not disclose Personal Data requested until required to do so under applicable law. Partner shall only provide the minimum amount of Personal Data permissible when responding to the Disclosure Request, based on a reasonable interpretation of the Disclosure Request. If the Disclosure Request is incompatible with the SCCs or other data transfer mechanism utilized in accordance with Section 3 in this DPA, Partner will so notify the requesting authority and, if permitted by applicable law, notify the competent EEA government authority with jurisdiction over the Personal Data subject to the Disclosure Request. Partner will maintain a record of Disclosure Requests and its evaluation, response, and handling of the requests. Partner will provide Company with such records relevant to Personal Data except as prohibited by applicable law or legal process or in the interest in protecting Partner’s legal rights in connection with threatened, pending, or current litigation.
  2. Partner will utilize industry standard encryption while Personal Data are being Processed by Partner.
  3. Partner has not purposefully created “back doors” or similar programming in its systems that provide Services that could be used to access the systems and/or Personal Data, nor has Partner purposefully created or changed its business processes in a manner that facilitates access to Personal Data or its systems that provide the Services. To the best of Partner’s knowledge, United States Data Protection Law does not require Partner to create or maintain “back doors” or to facilitate access to Personal Data or systems that provide Services or for Partner to possess or provide the encryption key in connection with a United States Disclosure Request.
  4. Partner shall use reasonable efforts to assist Company and its Data Subjects, as instructed by Company (in accordance with Section 2 of the DPA), regarding Disclosure Requests, unless prohibited by applicable law, for example to provide information to Company in connection with the Data Subject’s efforts to exercise its rights and obtain legally available redress, provided Partner shall not be required to provide Company or Data Subjects with legal advice.
  5. Company may request to audit Partner access logs regarding access to Personal Data, subject to the terms of Section 6 of the DPA.
  6. Partner has established an internal policy and procedure regarding handling of Disclosure Requests and applicable transfers of Personal Data of customers. Partner Legal and Audit personnel are provided information regarding applicable transfers of Personal Data prior to the transferring of any such data, where such information may include an explanation of the necessity of the transfer and any data protection safeguards in scope.
  7. In the event Partner receives a request to voluntarily disclose unencrypted Personal Data to a government authority, Partner will use reasonable efforts to first obtain Company’s consent, either on its behalf or on behalf of the relevant Data Subject.

See IntelAgree put AI to work on your contracts.

Get a personalized walkthrough of the AI-native CLM platform.

  • AI review, redlining, and risk scoring built into every contract.
  • Native connections to the systems your team already uses.
  • A searchable, obligation-aware repository for every executed agreement.

Request a demo