1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between IngrIntel Ltd ("Processor") and the Customer ("Controller"). It applies where IngrIntel processes personal data contained in Customer Data (for example names and emails of team members, or supplier contact details) on the Customer's behalf.
2. Details of processing
| Subject matter | Provision of the IngrIntel platform |
|---|---|
| Duration | The term of the agreement plus the deletion period below |
| Nature & purpose | Hosting, storage, retrieval, analysis and display of Customer Data to provide the Service |
| Data subjects | Customer's authorised users; supplier and business contacts |
| Personal data | Names, business contact details, account and usage data |
| Special category data | None — Customer must not upload special category data |
3. Processor obligations
IngrIntel will:
- process personal data only on the Controller's documented instructions (including these Terms), unless required by law;
- ensure personnel authorised to process data are bound by confidentiality;
- implement appropriate technical and organisational measures (Art. 32), including encryption in transit, hashed credentials, access controls, logging and regular testing;
- only engage sub-processors under written terms imposing equivalent obligations, give at least 30 days' notice of new sub-processors, and allow the Controller to object on reasonable grounds;
- assist the Controller with data subject requests, security, breach notification, DPIAs and prior consultation (Arts. 32–36);
- notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach;
- at the Controller's choice, delete or return personal data at the end of the Service (within 30 days, with backups expiring within 90 days), unless retention is required by law;
- make available information necessary to demonstrate compliance, and allow for reasonable audits on 30 days' notice, no more than once per year.
4. International transfers
Any transfer of personal data outside the UK or EEA will be made under an adequacy decision/regulation, the ICO International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses (as applicable), supplemented by a transfer risk assessment.
5. Controller obligations
The Controller warrants it has a lawful basis and has provided all necessary notices for the personal data it submits, and that its instructions comply with data protection law.
6. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms. In case of conflict between this DPA and the Terms regarding personal data, this DPA prevails. Enterprise customers may request a countersigned copy from legal@ingrintel.co.uk.