Legal
Data Processing Agreement
Version 2026-06-21 · Last updated June 21, 2026
This agreement is incorporated when a customer accepts the DPA in the intentLM dashboard setup wizard. For countersigned PDFs or enterprise amendments, contact contact.intentlm@gmail.com.
1. Parties and roles
Customer ("Controller") is the entity that registers for intentLM and deploys the SDK in its application.
intentLM ("Processor") provides real-time behavioural intent classification services via API and dashboard.
Where the Customer processes personal data of end users through the Service, the Customer is the data controller and intentLM acts as a data processor under GDPR Article 28 and as a service provider under the California Consumer Privacy Act (CCPA), as applicable.
2. Subject matter and duration
Processor will process personal data on behalf of Controller for the duration of the Customer's subscription or trial, and until deletion obligations in section 9 are fulfilled.
3. Nature and purpose of processing
Processor processes data solely to:
- Classify behavioural intent from tokenised session sequences in real time
- Return intent labels, confidence scores, and related metadata to Controller
- Deliver webhooks and dashboard analytics configured by Controller
- Maintain, secure, and improve the Service as described in section 4
4. Categories of data and data subjects
Personal data (as pseudonymous or personal data depending on Controller context and applicable law) may include:
- Integer token IDs representing navigation and product events (global taxonomy)
- Inter-event timing (
time_deltas_ms) - Ephemeral
session_id - Optional opaque identifiers supplied by Controller:
user_id,account_id(must not contain email or direct identifiers unless Controller has lawful basis) - Optional
visitor_id(random UUID in first-party cookie_ilm_vid) when Controller enables cross-session persistence
Processor does not intentionally receive raw URLs, DOM text, form values, or email addresses from the SDK. Controller is responsible for SDK configuration and for not passing PII in optional identifier fields.
Data subjects are end users of Controller's application who interact with pages instrumented by the SDK.
4.1 Model training and service improvement
Processor may use pseudonymised tokenised event sequences to train and improve intent classification models that benefit Controller and other customers. Such processing:
- Constitutes service improvement under this DPA
- Does not constitute a "sale" or "sharing" of personal information under applicable US privacy law when Processor acts as a service provider
- Does not expose or make recoverable individual Controller session sequences to other customers
Aggregated or anonymised statistics derived from processing may be used for product benchmarks only where permitted by Controller plan and applicable law.
5. Controller obligations
- Ensure a valid legal basis (consent, legitimate interests, or contract as applicable) for processing and for any UI personalisation or nudges triggered by intent classifications
- Maintain an accurate privacy policy naming intentLM as a processor and linking to intentlm.ai/privacy
- Configure consent hooks (
consentCheck) appropriately - Issue lawful instructions to Processor within the scope of the Service
6. Processor obligations
- Process personal data only on documented instructions from Controller
- Ensure personnel with access are bound by confidentiality obligations
- Implement appropriate technical and organisational measures (encryption in transit, access controls, logical tenant isolation by customer API key)
- Not retain, use, disclose, or sell personal data for any purpose other than providing the Service except as permitted by this DPA and applicable law
- Assist Controller with data subject requests and DPIAs where reasonably required
- Notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data
7. Subprocessors
Controller authorises Processor to engage subprocessors necessary to operate the Service, including cloud infrastructure (e.g. Google Cloud Platform), database hosting (e.g. Supabase), and caching providers. Processor maintains a subprocessor list available on request at contact.intentlm@gmail.com. Processor will impose data protection obligations on subprocessors equivalent to those in this DPA.
8. International transfers
Where personal data is transferred from the EEA, UK, or Switzerland to the United States or other countries without an adequacy decision, the parties agree that the European Commission Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference and apply to such transfers. Controller may request the current SCC annex via contact.intentlm@gmail.com.
9. Retention and deletion
Tokenised session sequences are retained for 90 days by default unless Controller configures a shorter window. Longitudinal visitor profiles (if enabled) use a Controller-configurable window of 30–365 days (default 90).
Controller may delete session or account data via the config API (DELETE /v1/customers/{id}/sessions/{session_id}, account erasure endpoints). Processor will complete deletion within 72 hours and maintain an audit log of erasure requests.
Upon termination of the Service, Processor will delete or return personal data at Controller's choice within 30 days, except where retention is required by law.
10. Audit and compliance
Upon reasonable written notice, Processor will make available information necessary to demonstrate compliance with this DPA and allow audits conducted by Controller or an independent auditor, subject to confidentiality and no more than once per year unless required by a supervisory authority.
11. Liability
Each party's liability under this DPA is subject to the limitation of liability in the main service terms between the parties. Nothing in this DPA limits either party's liability where limitation is prohibited by applicable law.
12. Acceptance
Controller accepts this DPA by clicking "I accept" in the intentLM dashboard setup wizard or by executing a separate order form referencing version 2026-06-21. Processor records acceptance timestamp and IP address for audit purposes.
Download. Use your browser's Print → Save as PDF to save this document. Countersigned copies: contact.intentlm@gmail.com
Related: Privacy Policy