QUALIFIED LEGAL COUNSEL REVIEW RECOMMENDED
This international baseline contains jurisdiction-sensitive provisions and interim business defaults. It is not legal advice and should be reviewed by qualified counsel in each launch market, including the governing law, liability limits, retention schedule, subprocessors, transfer mechanisms and contracting flow.
Version: 3.0
Effective date: 7 June 2026
Last updated: 7 June 2026
Provider: Intellilox LLC of Bennett St, Jersey City, NJ 07304, United States ("Intellilox", "we", "us" or "our")
Legal contact: admin@intellilox.com
Privacy contact / Data Protection Officer, if appointed: admin@intellilox.com
Important notice and acceptance
This End User Licence, Acceptable Use and Privacy Agreement (the "Agreement") is a legally binding agreement between Intellilox and the individual who accesses or uses the Services ("User", "you" or "your"). If you use the Services for or through a company, government body, non-profit, educational institution or other organisation (the "Customer"), you confirm that you are authorised by that Customer and that your use is also subject to the Customer's applicable Order and Customer Agreement.
Read this Agreement before using the Services. By selecting an acceptance control, creating or activating an account, accepting an invitation, or accessing or using the Services after being given a reasonable opportunity to review this Agreement, you agree to it. If you do not agree, do not access or use the Services.
Nothing in this Agreement excludes, restricts or modifies a right, remedy, guarantee or liability that applicable law makes non-excludable. If you are a consumer, mandatory consumer protections in your country or state prevail over inconsistent terms. Sections headed in capitals or otherwise dealing with disclaimers, indemnities, suspension, dispute resolution and liability may materially affect your rights.
1. Definitions
In this Agreement:
- Account Data means information used to create, administer, secure or support an account, such as names, work contact details, organisation membership, roles, authentication events and support communications.
- Applicable Data Protection Law means any privacy, data protection, breach-notification or direct-marketing law applicable to the relevant processing, including where applicable the EU GDPR, UK GDPR and Data Protection Act 2018, Australian Privacy Act 1988 and Australian Privacy Principles, California Consumer Privacy Act as amended, Brazil LGPD, South Africa POPIA, Canada PIPEDA and substantially similar provincial laws, New Zealand Privacy Act 2020, Singapore PDPA and Japan APPI.
- Authorised User means a person whom a Customer has authorised to use the Services under its subscription or trial.
- Confidential Information means non-public information disclosed by one party to the other that is marked confidential or should reasonably be understood as confidential given its nature and the circumstances, including Customer Data, credentials, security information, non-public product information, pricing and business plans.
- Customer Agreement means an enterprise services agreement, master subscription agreement or other written agreement between Intellilox and the Customer.
- Customer Data means data, files, records, forms, configurations, content and Personal Data submitted to, stored in, transmitted through or generated from the Services by or for the Customer or its Authorised Users. Customer Data excludes Account Data used by Intellilox as an independent controller, Feedback, and Usage Data that has been Aggregated and De-identified.
- Documentation means the then-current user, security and technical documentation Intellilox makes available for the Services.
- Feedback means suggestions, enhancement requests, recommendations, corrections or other feedback about the Services, but not Customer Data or Customer Confidential Information.
- Intellilox Materials means the Services, Platform, software, APIs, Documentation, designs, workflows, schemas, templates supplied by Intellilox, visual elements, trademarks, know-how and all related intellectual property, updates, modifications and derivative works. Intellilox Materials exclude Customer Data and Customer-owned materials merely hosted through the Services.
- Order means an order form, online checkout, trial registration or other ordering document identifying Services, subscription term, fees, usage limits, region or special terms.
- Personal Data means information relating to an identified or identifiable natural person and includes "personal information", "personal data" and similar terms under Applicable Data Protection Law.
- Platform means the Intellilox Platform Hub and its independently licensable applications, shared services, web and mobile interfaces, APIs and related hosted functionality.
- Sensitive Data means Personal Data subject to heightened protection, including health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade-union membership, sexual-life or orientation, precise location, government identifier, financial-account credential, criminal allegation or child data, as defined by applicable law.
- Services means the Platform, applications, support and related services made available by Intellilox under an Order.
- Usage Data means technical and operational data about use, performance and security of the Services, such as event time, feature interaction, device/browser information, IP-derived security signals, diagnostic records and identifiers. It does not include the content of Customer Data except where strictly necessary to provide support, security, abuse detection or the requested functionality.
2. Contract hierarchy and the parties' relationship
2.1 Hierarchy. If there is a conflict, the documents control in this order unless the higher-ranking document expressly says otherwise: (a) a signed Customer Agreement; (b) the applicable Order; (c) a signed data processing addendum; (d) this Agreement; and (e) Documentation. A Customer Agreement may grant the Customer contractual rights that are not granted to individual Users.
2.2 Organisation-provided accounts. For an account controlled by a Customer:
- the Customer determines who may access its workspace, assigns roles, configures applications and controls Customer Data;
- the Customer may access, export, restrict, correct or delete Customer Data and may suspend or terminate your access;
- your relationship with the Customer, including employment and internal monitoring, is not governed by Intellilox; and
- privacy requests concerning Customer Data should normally be directed to the Customer, which is generally the controller or business for that data. Intellilox will support the Customer as required by law and the applicable Customer Agreement.
2.3 No agency. This Agreement does not create a partnership, joint venture, fiduciary, employment, franchise or agency relationship between you and Intellilox. You may not bind Intellilox.
3. Eligibility, authority and accounts
3.1 You must be at least 18 years old or the age of legal majority where you live, whichever is higher, unless Intellilox and the Customer have expressly authorised a legally compliant educational or workforce deployment for younger users. The Services are not directed to children.
3.2 You represent that: (a) information you provide is accurate and kept current; (b) you have authority to accept this Agreement; (c) you are not barred from using the Services by law; and (d) if you act for a Customer, the Customer has authorised you to use its account and data.
3.3 Accounts are personal to the assigned User. You must not share credentials, use another person's account, create deceptive identities, or permit unauthorised access. You must use reasonable security measures, promptly report suspected compromise, and comply with multi-factor authentication and single sign-on requirements configured for the Customer.
3.4 The Customer's administrators may manage memberships, permissions, applications, records, exports, retention settings and integrations. You are responsible for actions taken through your account except to the extent caused by Intellilox's breach of this Agreement or failure to use reasonable security.
4. Limited licence and permitted use
4.1 Subject to this Agreement, the Customer Agreement and payment of applicable fees, Intellilox grants you a limited, non-exclusive, non-transferable, non-sublicensable and revocable right during the applicable subscription or trial term to access and use the Services and Documentation solely:
- as an Authorised User for the Customer's lawful internal business purposes;
- within the licensed applications, seats, environments, usage limits and regions; and
- in accordance with the Documentation and permissions assigned to you.
4.2 The Services are licensed or made available as hosted services, not sold. No source code, ownership interest or implied licence is transferred. Rights not expressly granted are reserved by Intellilox and its licensors.
4.3 A trial, preview, beta, evaluation or free service may be time-limited, feature-limited, support-limited and subject to additional notices. It may be changed or discontinued at any time to the extent permitted by law. Unless an Order states otherwise, trial data may be deleted after the stated trial or export window.
4.4 You may make a reasonable number of internal copies of Documentation solely to support permitted use, retaining all proprietary notices. No right is granted to distribute Documentation publicly.
5. Licence and platform restrictions
Except where applicable law expressly permits conduct that cannot lawfully be restricted, you must not, and must not help or permit anyone else to:
- copy, modify, translate, adapt, create derivative works from, republish, sell, resell, rent, lease, sublicense, distribute, timeshare or commercially exploit the Services or Intellilox Materials;
- reverse engineer, decompile, disassemble, decode, derive or attempt to derive source code, object models, algorithms, non-public APIs, data models, security controls or underlying ideas;
- bypass or interfere with authentication, authorisation, tenant isolation, row-level security, licensing, usage limits, audit logging, rate limits, access restrictions or technical protection measures;
- access the Services to build, train, benchmark or improve a competing product or service, or copy their features, workflows, user interface, look and feel, taxonomy or Documentation;
- publish benchmarks, penetration-test results or security assessments without Intellilox's prior written consent, except for a protected disclosure made under an applicable vulnerability-disclosure policy or law;
- use scraping, crawling, harvesting, data-mining, automated extraction, bots or load tools except through documented APIs and within agreed limits;
- introduce malware, harmful code or data; probe, scan or test vulnerability without written authorisation; disrupt integrity or performance; or access data, systems or accounts you are not authorised to access;
- remove, conceal or alter copyright, trademark, confidentiality, attribution or proprietary notices;
- use the Services to provide a bureau, outsourced or managed service to third parties unless an Order expressly permits it;
- make representations, warranties or commitments about Intellilox or the Services without written authority; or
- use the Services in breach of section 11 (Acceptable Use), sanctions, export controls or other applicable law.
6. Customer configuration and User responsibilities
6.1 You and the Customer are responsible for: (a) the lawfulness, accuracy, quality and integrity of Customer Data; (b) providing required notices and obtaining valid permissions or legal bases; (c) role design and access decisions; (d) configuration, workflows, retention choices and integrations; (e) reviewing outputs before relying on them; and (f) maintaining independent records, controls and business-continuity arrangements appropriate to the Customer's risk.
6.2 Do not submit Customer Data unless the Customer has authorised it and has a lawful basis. Do not submit Sensitive Data unless the relevant application and Order are expressly approved for that category and the Customer has completed any required impact assessment, notices, consents and safeguards.
6.3 Intellilox does not determine whether a Customer's configuration, form, workflow, policy, control, risk rating, incident classification, employment decision, legal position, tax treatment, accounting entry or safety response satisfies the Customer's obligations. The Customer must use qualified personnel and appropriate independent review.
6.4 You must promptly notify the Customer and Intellilox of suspected unauthorised access, data exposure, security weakness or unlawful use. Do not publicly disclose a suspected vulnerability before Intellilox has had a reasonable opportunity to investigate and remediate, subject to protected disclosures under law.
7. Customer Data, intellectual property and data sharing
7.1 Customer ownership. As between Intellilox and the Customer, the Customer retains all right, title and interest in Customer Data and Customer-provided trademarks, forms, policies, taxonomies and other materials. This Agreement does not transfer ownership of Customer Data to Intellilox.
7.2 Operational licence. The Customer, and you to the extent you have rights in submitted material, grant Intellilox and its subprocessors a worldwide, non-exclusive, limited licence during the applicable term to host, copy, transmit, display, transform, index, back up and otherwise process Customer Data only as necessary to:
- provide, secure, maintain, support and improve the contracted Services;
- carry out documented Customer instructions and enabled configurations;
- prevent fraud, abuse and security incidents;
- comply with law and enforce agreements; and
- create Aggregated and De-identified Data in accordance with section 7.7.
This operational licence does not permit Intellilox to sell Customer Data, use it for cross-context behavioural advertising, or disclose it for an unrelated third party's commercial purposes.
7.3 Your content warranty. You represent that you have all rights and permissions required for material you submit and that its collection, use and disclosure through the Services will not infringe intellectual property, privacy, confidentiality, publicity or other rights or violate law. This does not shift responsibility to you for material the Customer independently controls or Intellilox supplies.
7.4 Platform ownership. Intellilox and its licensors own all right, title and interest in the Intellilox Materials, including all intellectual property rights. Customer configuration or use does not create co-ownership of the Platform. General skills, know-how and ideas retained in unaided memory may be used by Intellilox, provided it does not disclose Customer Confidential Information or Customer Data.
7.5 Customer-specific deliverables. Unless an Order expressly transfers ownership, configurations, connectors, templates, reports, implementation materials or other deliverables created by Intellilox are Intellilox Materials. The Customer receives a right to use them with the Services during the term. Customer Data embedded in a deliverable remains Customer Data. An Order may identify genuinely bespoke materials assigned to the Customer, subject to Intellilox retaining its pre-existing materials, generic components, tools and know-how.
7.6 Feedback. Feedback is voluntary. You grant Intellilox a perpetual, irrevocable, worldwide, royalty-free, transferable and sublicensable right to use, reproduce, modify, commercialise and otherwise exploit Feedback without restriction or payment. Intellilox will not identify you or the Customer publicly as the source without permission. Do not include Customer Confidential Information or Customer Data in Feedback.
7.7 Aggregated and De-identified Data. Intellilox may create and use data derived from use of the Services only after taking reasonable measures designed to prevent it from identifying, relating to, describing or being reasonably capable of being linked to an individual or Customer. Intellilox will not attempt to re-identify that data, will contractually restrict recipients from re-identification where required, and will not publish statistics that reasonably expose a Customer. It may use such data for security, reliability, capacity planning, service improvement, research and lawful business analysis.
7.8 No training on identifiable Customer Data by default. Intellilox will not use identifiable Customer Data to train a general-purpose machine-learning model for use across customers unless the Customer gives specific written opt-in authorisation in an Order or separate agreement. Product features that process Customer Data to produce a result for that Customer remain subject to the Customer's instructions and the applicable data processing terms.
7.9 Legal requests. Intellilox may disclose Customer Data when legally required. Unless prohibited, it will use reasonable efforts to notify the Customer before disclosure, direct the requester to the Customer where appropriate, challenge facially invalid or overbroad demands, and disclose only what is legally required. Nothing requires Intellilox to violate law or jeopardise a person or investigation.
7.10 IP and data allocation summary. Schedule 3 provides a plain-language allocation matrix. It does not expand any licence beyond this section.
8. Confidentiality
8.1 The receiving party will: (a) protect the disclosing party's Confidential Information using at least reasonable care and no less care than it uses for its own similar information; (b) use it only to perform or exercise rights under the applicable agreements; and (c) disclose it only to personnel, professional advisers and contractors who need to know it and are bound by confidentiality obligations at least as protective.
8.2 Confidential Information excludes information the receiving party can document: (a) is public without breach; (b) was lawfully known without restriction; (c) was independently developed without use of the Confidential Information; or (d) was lawfully received from a third party without duty of confidentiality.
8.3 A legally compelled recipient may disclose Confidential Information as required, subject to advance notice where lawful and reasonable assistance, at the discloser's cost, if the discloser seeks protection.
8.4 Unauthorised disclosure may cause irreparable harm for which damages are inadequate. A party may seek injunctive or equitable relief in addition to other remedies, without limiting mandatory procedural protections.
9. Privacy roles and commitments
9.1 Privacy Notice. Sections 9 and 10 and Schedule 1 describe how Intellilox handles Personal Data when acting as an independent controller/business. They form the Intellilox Privacy Notice.
9.2 Customer Data role. For Personal Data in Customer Data, the Customer generally determines purposes and means and acts as controller/business; Intellilox generally acts as processor, service provider, contractor or data intermediary. Schedule 2 supplies baseline processing terms for this relationship only where incorporated into a Customer Agreement or Order. It is not an instruction from an individual User to override the Customer's lawful decisions.
9.3 Independent-controller role. Intellilox acts as an independent controller/business for Account Data, contracting, billing, service security, fraud prevention, legal compliance, direct business communications, public website submissions and privacy-request administration. The Customer may separately be a controller of copies of Account Data it receives.
9.4 No sale or targeted-advertising sharing. Intellilox does not sell Personal Data for money and does not share Personal Data for cross-context behavioural advertising as those terms are defined by California law. If practices change, Intellilox will first update notices and provide any legally required opt-out mechanism. A disclosure to a contracted service provider for specified business purposes is not a sale merely because the provider is paid, subject to applicable law.
9.5 Customer notice obligation. The Customer must give its workforce, contractors, customers, incident reporters and other data subjects an accurate notice covering the Customer's use of the Services. Intellilox's Privacy Notice does not replace the Customer's notice.
10. Intellilox Privacy Notice
10.1 Personal Data collected
Depending on the relationship and features used, Intellilox may collect:
- identity and account data: name, work email, phone, organisation, job information, user identifier, memberships, role and preferences;
- authentication and security data: password hash (not readable passwords), MFA and SSO events, session identifiers, IP address, device/browser data, sign-in history, access-control decisions and suspected-abuse signals;
- commercial and transaction data: Order, plan, licensed applications, seats, billing contact, invoices, payment status and tax/transaction records. Payment-card data should be processed by the identified payment provider and not stored by Intellilox except for tokenised references and limited transaction details;
- communications: support requests, sales enquiries, trial requests, survey responses, newsletter preferences and correspondence;
- public website data: page path, first-party session identifier, device type, referrer host, campaign parameters, clicks, scroll depth and section-view duration. Current website analytics are designed not to use cookies, capture form values, retain raw IP addresses or retain full query strings, and are disabled when recognised Global Privacy Control or Do Not Track signals are enabled;
- Usage Data: feature events, timestamps, diagnostics, performance information, API activity, audit events and error reports;
- Customer Data: any Personal Data a Customer chooses to submit, which may include incident, safety, risk, compliance, policy, issue, expense, timesheet, sales/customer, evidence and attachment data; and
- inferences: limited risk, fraud or service-health indicators derived from the above. Intellilox will not use solely automated processing to make a decision producing legal or similarly significant effects about an individual unless disclosed and permitted by law.
Do not submit payment-card authentication data, passwords, national-security classified data, unlawful surveillance data or other prohibited material. Sensitive Data may be processed only where the relevant Customer has lawfully configured and authorised the feature.
10.2 Sources
Personal Data comes from you; the Customer and its administrators; other Authorised Users; enabled identity providers and integrations; your device and use of the Services; public website forms; support and sales interactions; service providers; and public or business sources where law permits.
10.3 Purposes and legal bases
Intellilox processes Personal Data for the following purposes and, where EU/UK-style legal bases apply, on the following bases:
| Purpose | Typical data | Legal basis where required |
|---|---|---|
| Provide, authenticate, administer and support the Services | Identity, account, authentication, Customer Data, communications, Usage Data | Contract; steps requested before contract; Customer's documented instructions |
| Secure the Services; prevent fraud, abuse and unauthorised access; investigate incidents | Authentication, network, device, audit and diagnostic data | Legitimate interests in security; legal obligation; substantial public interest where applicable |
| Operate Customer workspaces, roles, licensing, audit, files, notifications and enabled applications | Account Data and Customer Data | Contract; Customer instructions |
| Bill, account, audit and manage the commercial relationship | Commercial, transaction and contact data | Contract; legal obligation; legitimate interests in business administration |
| Respond to sales, trial, support and privacy requests | Contact, request and correspondence data | Steps before contract; contract; consent where required; legal obligation; legitimate interests |
| Improve reliability, usability and capacity | Usage Data, diagnostics, Feedback, Aggregated and De-identified Data | Legitimate interests, balanced against individual rights; consent where legally required |
| Send product, service and marketing communications | Work contact and preference data | Consent where required; legitimate interests for permitted business marketing; always subject to opt-out rights |
| Comply with law and establish, exercise or defend legal claims | Relevant records and communications | Legal obligation; legitimate interests; legal claims |
Where consent is the basis, it may be withdrawn at any time without affecting earlier lawful processing. Where legitimate interests are used, Intellilox considers necessity, proportionality and individual impact and provides an objection right where required.
10.4 Disclosures
Intellilox may disclose Personal Data only as reasonably necessary to:
- the Customer and its authorised administrators and Users;
- contracted hosting, cloud infrastructure, content delivery, communications, support, identity, security, monitoring, payment and professional-service providers listed in the current subprocessor register, available on request from admin@intellilox.com;
- integrations and third-party services the Customer or User deliberately enables;
- Intellilox affiliates that are bound by appropriate confidentiality and data protection obligations;
- professional advisers, auditors, insurers and financing parties under confidentiality duties;
- a purchaser, successor or participant in a genuine financing, reorganisation, merger or sale, subject to appropriate confidentiality and use limitations; and
- public authorities or other persons where required by law or reasonably necessary to protect rights, security and safety.
Intellilox does not disclose Customer Data to another Customer. Administrators and Users within the same Customer may see data according to the Customer's permissions and configuration.
10.5 International transfers and data location
Customer business data is intended to reside in the data-plane region selected for the Customer and is not silently moved to another operating region. Identity and directory data is held in the Platform's designated control-plane home region. Static web assets may be delivered globally. Support, security, email, content delivery, subprocessors, legal compliance and Customer-enabled integrations may involve processing outside the selected data region. The final published notice and Order must identify the actual regions and subprocessors.
For restricted transfers, Intellilox will use a lawful mechanism applicable to the transfer, which may include an adequacy decision, the European Commission's 2021 Standard Contractual Clauses with the appropriate module and supplementary measures, the UK International Data Transfer Addendum or IDTA, or another recognised mechanism. Intellilox will use contractual and technical measures appropriate to the transfer and will provide relevant mechanism information on request where required.
10.6 Retention and deletion
Intellilox retains Personal Data only for as long as reasonably necessary for the disclosed purpose, the Customer's documented instructions, contractual commitments, security, dispute resolution and legal requirements. The following baseline periods apply unless an Order, Customer Agreement or applicable law requires a different period:
| Record | Baseline retention rule |
|---|---|
| Active Account Data | Subscription term plus 24 months, unless earlier deletion is required or longer retention is legally necessary |
| Customer Data after termination | Customer export window of 30 days, then deletion or de-identification, subject to backups and law |
| Production backups | Rolling retention of up to 30 days under normal backup rotation |
| Security and application logs | 12 months, unless a longer period is reasonably required for an active security investigation or by law |
| Append-only business audit records | 7 years after the relevant event; identifiers may be anonymised where deletion is required and audit continuity must be preserved |
| Trial request and trial workspace data | 90 days after the request is closed or the trial expires |
| Sales enquiries | 24 months after the last meaningful contact |
| Newsletter records | Until unsubscribe, plus a minimal suppression record for 5 years |
| Privacy and legal requests | 7 years to demonstrate compliance and resolve disputes |
Deletion from active systems may not immediately remove encrypted backup copies. Backup data remains protected, is not restored except for continuity or recovery, and is deleted through normal rotation unless law requires longer preservation. Intellilox may retain Aggregated and De-identified Data that cannot reasonably identify an individual or Customer.
10.7 Security
Intellilox uses administrative, technical and organisational measures designed to protect Personal Data, including tenant-scoped access controls, encryption in transit and at rest, role-based access, audit logging, restricted infrastructure access, secure development practices, vulnerability management, backups and incident response. No system is completely secure. Security descriptions are not a guarantee that incidents will never occur and must not state certifications that have not actually been obtained.
If Intellilox confirms a Personal Data Breach, it will investigate, mitigate, preserve appropriate evidence, and notify affected Customers and regulators or individuals as required by applicable law and the data processing terms. Users must report suspected incidents to admin@intellilox.com without unreasonable delay.
10.8 Individual privacy rights
Depending on where you live and the relevant context, you may have rights to:
- know or be informed about processing and categories, sources, purposes and recipients;
- access or obtain a copy of Personal Data;
- correct inaccurate Personal Data;
- delete or erase Personal Data, subject to exceptions;
- restrict or object to certain processing, including direct marketing;
- receive portable data where applicable;
- withdraw consent;
- opt out of sale, targeted-advertising sharing or certain profiling (Intellilox states in section 9.4 that it does not currently conduct the first two activities);
- limit certain use or disclosure of Sensitive Personal Information;
- not receive discriminatory treatment for exercising applicable rights;
- request human review of certain solely automated significant decisions; and
- complain to a competent privacy or data protection regulator.
Submit a request to admin@intellilox.com. Intellilox may reasonably verify identity and authority, and an authorised agent may need to provide proof. Intellilox will respond within the legally required period. Rights are not absolute and may be limited to protect others, security, legal privilege, intellectual property and compliance duties.
For Customer Data, Intellilox will normally refer the request to the Customer and assist it. Contact your Customer administrator first where practical. Intellilox will not disclose Customer Data directly if doing so would conflict with the Customer's lawful control, unless legally required.
10.9 Marketing and communications
You may opt out of marketing emails using the unsubscribe control or by contacting admin@intellilox.com. Intellilox may still send non-marketing messages necessary for the Services, such as security, account, legal, billing and operational notices. The Customer controls notifications it configures within its workspace.
10.10 Children
The Services are not knowingly offered directly to children. Intellilox does not knowingly collect child Personal Data through public website trial, sales or newsletter forms. If you believe a child has provided Personal Data without lawful authorisation, contact admin@intellilox.com. A Customer that uses the Services with minors must first obtain Intellilox's written agreement and meet all consent, notice, safeguarding and education/employment-law requirements.
10.11 Complaints
Contact admin@intellilox.com first so Intellilox can investigate. You may also complain to the competent regulator where you live or work or where an alleged infringement occurred. Intellilox will not retaliate against a person for making a good-faith privacy complaint.
11. Acceptable Use Policy
You must not use the Services to create, upload, process, transmit, facilitate or promote:
- unlawful conduct, fraud, corruption, money laundering, sanctions evasion or infringement of another person's rights;
- threats, harassment, stalking, hateful abuse, exploitation, non-consensual intimate material, trafficking or material that sexualises or exploits a child;
- malware, credential theft, phishing, spam, denial of service, unauthorised surveillance, intrusion or evasion of security controls;
- intellectual-property infringement, trade-secret theft, impersonation or deceptive misrepresentation;
- discriminatory decisions prohibited by law, or solely automated high-impact employment, credit, housing, insurance, healthcare, education or legal decisions without required review and safeguards;
- content or instructions that create an unreasonable risk of death, bodily harm, environmental harm or damage to critical infrastructure;
- regulated, classified or export-controlled data unless the Order expressly authorises it and all safeguards are in place;
- excessive load or activity that unreasonably degrades the Services or another customer's use; or
- any attempt to discover, access or correlate data belonging to another Customer.
Intellilox may investigate suspected misuse, preserve relevant evidence and cooperate with lawful authorities. It may remove or restrict content or suspend access when reasonably necessary to prevent material harm, protect the Services or comply with law, subject to section 15.
12. Third-party services, integrations and open-source components
12.1 The Services may interoperate with third-party products selected by the Customer. Those products are governed by their own terms and privacy practices. Intellilox is not responsible for third-party products it does not control, but remains responsible for its subprocessors to the extent required by the applicable data processing terms.
12.2 Enabling an integration instructs the Services to exchange the data described by that integration with the third party. The Customer is responsible for authorisation, configuration, lawful transfer and disabling access when no longer required.
12.3 Open-source and third-party software included in the Services may be governed by applicable notices and licences. Those licences apply only to the relevant components and do not grant rights to proprietary Intellilox Materials. If a mandatory third-party licence conflicts with this Agreement for a component, that licence controls for that component only.
13. Service operation, changes and support
13.1 Intellilox may maintain, update, enhance or modify the Services. It will not materially reduce core paid functionality during a current committed subscription term without reasonable notice, except where necessary for security, law, third-party dependency, preview functionality or to prevent harm. Contracted service levels, support and maintenance windows are governed by the Customer Agreement or Order.
13.2 The Services may occasionally be unavailable due to maintenance, faults, internet or third-party failures, force majeure or security response. Intellilox will use commercially reasonable efforts to operate the paid Services in accordance with applicable service commitments.
13.3 Preview or beta features may be incomplete, changed, unsupported or discontinued and may have additional data restrictions. Do not use them for production-critical decisions unless expressly approved in the Order.
14. Fees and taxes
Fees, payment dates, renewal, seat and usage limits, price changes, taxes and refund rights are governed by the Order or Customer Agreement. Individual Users are not personally responsible for Customer subscription fees unless they are the named purchaser. Statutory cancellation, refund and cooling-off rights remain unaffected.
15. Suspension
15.1 Intellilox may suspend affected access immediately and proportionately if it reasonably believes: (a) there is a material security threat or unauthorised access; (b) use materially violates sections 5 or 11; (c) suspension is required by law; (d) continued use risks material harm to Intellilox, a Customer, a person or the Services; or (e) undisputed fees are materially overdue under the Customer Agreement.
15.2 Where lawful and practicable, Intellilox will notify the Customer of the reason and scope and allow a reasonable opportunity to cure before suspension. Immediate action may be taken for urgent security, legal or harm-prevention needs. Access will be restored promptly after the issue is resolved. Intellilox will avoid suspending unaffected services where reasonably possible.
15.3 A Customer administrator may suspend an Authorised User according to the Customer's policies. Disputes about a Customer's decision should be raised with the Customer.
16. Term, termination, export and effect
16.1 This Agreement begins on acceptance and continues while you access the Services. Your licence ends automatically when the Customer's subscription or your authorisation ends.
16.2 You may terminate this Agreement by ceasing use and, for a direct account, following the account-closure process. Account closure does not terminate a Customer Agreement or require deletion contrary to the Customer's instructions or law.
16.3 Intellilox may terminate your rights for material breach that is not cured within a reasonable notice period, or immediately where breach is incapable of cure, creates material harm, involves unlawful access or where continued provision is prohibited by law. Customer subscription termination is governed by the Customer Agreement.
16.4 On termination, you must stop using the Services and Intellilox Materials. The Customer may export Customer Data during the contractual export window using available tools or agreed assistance. After that window, Intellilox may delete or de-identify Customer Data subject to law, backups, legal holds and Schedule 2.
16.5 Sections intended by nature to survive do survive, including ownership, confidentiality, accrued payment, disclaimers, liability, indemnity, dispute terms and general provisions.
17. Warranties
17.1 Each party warrants that it has authority to enter this Agreement. Intellilox warrants that paid Services will perform materially in accordance with the applicable Documentation under normal authorised use. The exclusive contractual remedy for breach of this warranty is for Intellilox to use commercially reasonable efforts to correct the material non-conformity and, if it cannot do so within a reasonable period, for the Customer to terminate the affected Service and receive any refund expressly provided by the Customer Agreement.
17.2 The warranty does not cover issues caused by Customer Data, unauthorised use or changes, unsupported integrations, Customer systems, misuse, force majeure, or trial, preview, beta or free Services.
18. Important disclaimers
18.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, EXCEPT FOR THE EXPRESS WARRANTY IN SECTION 17, THE SERVICES AND INTELLILOX MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE". INTELLILOX DISCLAIMS ALL IMPLIED OR STATUTORY WARRANTIES, CONDITIONS AND REPRESENTATIONS, INCLUDING MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, UNINTERRUPTED AVAILABILITY AND ERROR-FREE OPERATION.
18.2 Intellilox does not warrant that the Services alone make the Customer compliant with any law, standard, framework, contract, policy, safety duty, tax rule, accounting rule or regulatory obligation. Templates, dashboards, risk scores, alerts, recommendations, analytics and automated outputs are tools for qualified human review, not legal, medical, safety, accounting, tax, insurance or other professional advice.
18.3 The Services are not designed as an emergency dispatch system, life-support system, medical device, autonomous safety controller or sole system for preventing death, injury, environmental damage or critical-infrastructure failure. Users must follow emergency procedures and maintain appropriate independent controls.
18.4 Nothing in this section excludes a non-excludable consumer guarantee or liability for fraudulent misrepresentation.
19. Limitation of liability
19.1 Excluded losses. To the maximum extent permitted by law, neither party is liable under or in connection with this Agreement for indirect, incidental, special, exemplary, punitive or consequential loss, or loss of profit, revenue, goodwill, anticipated savings or business opportunity, even if advised of the possibility. This exclusion does not apply to amounts payable to a third party under an indemnity to the extent the indemnity applies.
19.2 General cap. To the maximum extent permitted by law, each party's aggregate liability arising out of or relating to this Agreement and the Services will not exceed the fees paid or payable by the Customer for the affected Services during the 12 months immediately before the event giving rise to the claim. For a free or trial Service where no fees were paid, Intellilox's aggregate liability will not exceed USD 100.
19.3 Enhanced cap. Subject to non-excludable law, aggregate liability for breach of confidentiality, breach of Schedule 2, or an indemnified third-party intellectual-property claim will not exceed two times the general cap. Security and privacy claims are subject to this enhanced cap unless the Customer Agreement expressly states a different cyber-insurance-aligned cap.
19.4 Uncapped and mandatory liabilities. Nothing limits liability to the extent it cannot lawfully be limited, including where applicable liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, wilful misconduct, or a party's obligation to pay undisputed fees. Whether other liabilities can be capped varies by jurisdiction and must be confirmed by counsel.
19.5 Allocation and claims. The limitations apply regardless of legal theory and reflect the allocation of risk and pricing. Multiple claims do not multiply a cap. A party must take reasonable steps to mitigate loss. No limitation gives Intellilox a right to process Personal Data contrary to Applicable Data Protection Law.
19.6 Mandatory consumer remedy. Where a guarantee cannot be excluded but the remedy may lawfully be limited, Intellilox's liability is limited, at its option, to resupplying the services or paying the reasonable cost of resupply. This sentence applies only where legally valid and does not limit any mandatory remedy that must remain available.
20. Indemnities
20.1 Customer/User indemnity. To the extent permitted by law, the Customer under its Customer Agreement—and an individual User only for that User's own intentional or unlawful conduct—will defend and indemnify Intellilox and its affiliates from a third-party claim arising from: (a) Customer Data infringing that third party's intellectual-property, privacy or confidentiality rights; (b) unlawful collection or instruction by the Customer; or (c) use in material breach of sections 5 or 11. An employee or consumer User is not required to indemnify Intellilox for the Customer's conduct merely because the person used a Customer-provided account.
20.2 Intellilox IP indemnity. If included in the Customer Agreement, Intellilox will defend the Customer against a third-party claim that authorised use of the paid proprietary Services infringes that third party's patent, copyright or trademark, and pay finally awarded damages or approved settlements. This does not cover claims caused by Customer Data, combinations not supplied by Intellilox, unauthorised modification or use, continued use after notice, or compliance with Customer specifications.
20.3 If an infringement claim is likely, Intellilox may procure continued use, modify or replace the affected Service with materially equivalent functionality, or terminate it and provide the refund required by the Customer Agreement. This states the Customer's exclusive contractual remedy for covered IP infringement, without limiting mandatory law.
20.4 The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation at the indemnifying party's cost, and allow control of defence and settlement. No settlement may admit fault by or impose non-monetary obligations on the indemnified party without written consent, not unreasonably withheld. Delay in notice relieves obligations only to the extent materially prejudicial.
21. Compliance with laws, export controls and sanctions
21.1 Each party must comply with laws applicable to its performance. You must not access, export, re-export, transfer or use the Services in violation of trade sanctions or export-control laws, or for prohibited weapons, military end uses or sanctioned persons where prohibited.
21.2 You represent that you are not located in, ordinarily resident in, organised under the laws of, or owned or controlled by a sanctioned territory or person to the extent dealings are prohibited. Intellilox may conduct proportionate screening and suspend access required to comply with law.
21.3 Government Users receive only the rights expressly granted under this Agreement and the applicable procurement contract. Any mandatory public-sector term must be recorded in the Order or Customer Agreement.
22. Disputes, governing law and mandatory local rights
22.1 This Agreement is governed by the laws of the State of New Jersey, United States, without regard to conflict-of-laws rules. State and federal courts located in Hudson County, New Jersey have exclusive jurisdiction, except that either party may seek urgent injunctive relief in any competent court and an individual may use a regulator or small-claims forum where permitted.
22.2 Before filing a contractual claim, the parties will attempt in good faith for 30 days to resolve it through written notice to admin@intellilox.com and Intellilox LLC, Bennett St, Jersey City, NJ 07304, United States. This does not delay urgent relief, a limitation deadline that cannot be suspended, a privacy complaint, regulator contact or a non-waivable consumer remedy.
22.3 If you are a consumer, section 22.1 does not deprive you of mandatory protections or access to courts in your habitual residence. No class-action waiver, mandatory arbitration clause or jury waiver is included in this baseline; counsel may add a jurisdiction-specific mechanism only after assessing enforceability, fairness, cost and required opt-out procedures.
22.4 The United Nations Convention on Contracts for the International Sale of Goods does not apply.
23. Changes to this Agreement
23.1 Intellilox may update this Agreement for legal, security, operational or product reasons. It will post the updated text with a new date and provide reasonable advance notice of a material adverse change through the Services or account contact, unless an urgent legal or security change requires faster effect.
23.2 Material changes will apply prospectively. If law requires renewed consent, Intellilox will request it. A Customer on a committed term may retain the prior commercial terms until renewal if its Customer Agreement so provides. Continued use after the effective date constitutes acceptance only where lawful and after adequate notice.
24. Notices
Legal notices to Intellilox must be sent to admin@intellilox.com and Intellilox LLC, Bennett St, Jersey City, NJ 07304, United States. Intellilox may send notices to the email associated with your account, the Customer's contractual contact, or through a prominent in-Service notice. Notices sent by email are deemed received when transmitted if the sender receives no delivery-failure notice; notices sent by tracked courier or registered or certified mail are deemed received on documented delivery. Routine support messages are not legal notices.
25. General
25.1 Assignment. You may not assign this Agreement without Intellilox's written consent. Intellilox may assign it to an affiliate or in connection with a merger, reorganisation, financing or sale of substantially all relevant assets, provided the assignee assumes applicable obligations and the assignment does not reduce mandatory privacy rights. Any other assignment requires reasonable consent. Mandatory consumer rights prevail.
25.2 Force majeure. Neither party is liable for delay or failure caused by events beyond reasonable control, excluding payment obligations already due. The affected party must use reasonable efforts to mitigate and resume performance. If a material force majeure continues for 60 days, termination rights follow the Customer Agreement.
25.3 Severability and interpretation. An unenforceable provision will be enforced to the maximum lawful extent and otherwise severed without affecting the remainder. "Including" means "including without limitation". Headings are for convenience. No rule construing ambiguity against the drafter applies where law allows and the terms were negotiated; it does not displace consumer interpretation rules.
25.4 Waiver. A waiver must be in writing and applies only to the stated instance. Delay is not waiver.
25.5 No third-party beneficiaries. Except for indemnified persons and as required by privacy transfer clauses, no person other than the parties has enforcement rights under this Agreement.
25.6 Entire agreement. This Agreement and the documents identified in section 2 are the entire agreement about its subject and supersede prior discussions. Neither party relies on a statement not included in them, except that nothing excludes fraud or mandatory pre-contract disclosure liability.
25.7 Electronic contracting. Electronic acceptance and records have the same effect as paper signatures to the extent permitted by law. Intellilox should retain evidence of the version shown, acceptance action, timestamp, User/account, locale and notice history.
25.8 Language. The English version controls only to the extent permitted by law. Where a legally required local-language version conflicts, the version required to protect the User under local law controls.
Schedule 1 — Regional Privacy Disclosures
This Schedule supplements section 10. It applies only where the stated law applies and does not concede that a particular law applies to every User or processing activity.
A. EEA, Switzerland and United Kingdom
Intellilox will identify its controller, representative and DPO where legally required. Individuals may exercise the rights listed in section 10.8 and complain to their local supervisory authority. Restricted transfers will use an applicable adequacy decision or appropriate safeguard. Where the 2021 EU Standard Contractual Clauses apply, the parties will select the factually correct module, complete the annexes, conduct required transfer assessments and use supplementary measures. UK transfers will use the UK Addendum, IDTA or other valid mechanism as appropriate. Swiss adaptations will be made where required.
Intellilox's lawful bases are described in section 10.3. A final record of processing must confirm each purpose and basis; "legitimate interests" must not be used as a catch-all. Users may object to direct marketing at any time and to other legitimate-interest processing on grounds relating to their situation.
B. Australia
Where the Privacy Act 1988 applies, Intellilox will handle Personal Information in accordance with applicable Australian Privacy Principles, including transparency, collection notice, use and disclosure limits, security, access, correction and cross-border disclosure requirements. Overseas disclosures and likely countries must be accurately identified before publication. Eligible data breaches will be assessed and notified under the Notifiable Data Breaches scheme where required. Complaints may be made to the Office of the Australian Information Commissioner after giving Intellilox a reasonable opportunity to respond.
Nothing in this Agreement excludes consumer guarantees under the Australian Consumer Law. "Intellilox" must identify whether it is an APP entity and confirm its Australian link with counsel.
C. California and other United States privacy states
Where the CCPA applies, section 10 identifies the categories of Personal Information collected, sources, purposes and categories of recipients. Intellilox states that it does not sell Personal Information or share it for cross-context behavioural advertising and does not knowingly sell or share Personal Information of persons under 16. California residents may have rights to know, access, correct, delete, portability, limit use of Sensitive Personal Information, opt out of sale/sharing and receive non-discriminatory treatment, subject to exceptions.
Intellilox will honour legally required opt-out preference signals for activities to which they apply. Because current public analytics are first-party, cookie-free and disabled when recognised Global Privacy Control or Do Not Track signals are present, publication must not imply broader advertising tracking. The production data inventory must determine whether any website vendor changes this conclusion.
For Customer Data, Intellilox acts as a service provider/contractor where those definitions apply, processes Personal Information only for specified business purposes under the Customer's instructions, does not sell or share it, does not retain/use/disclose it outside the direct business relationship except as permitted, and will provide the level of privacy protection required by applicable law. The Customer may take reasonable steps to verify and remediate use as required by law.
Other US state rights will be honoured where applicable. The final notice should include any state-specific appeal process and regulator contact required by the Customer's launch footprint.
D. Canada
Where PIPEDA or substantially similar provincial law applies, Intellilox will apply accountability, identified purposes, meaningful consent where required, collection limitation, appropriate use/disclosure/retention, accuracy, safeguards, openness, individual access and complaint handling. The privacy contact in the heading will be accountable for enquiries. Cross-border processing will be described transparently and protected contractually.
E. Brazil
Where the LGPD applies, references to controller, processor, data subject, Personal Data, Sensitive Personal Data and processing have their LGPD meanings. Intellilox will identify the applicable legal bases, provide data-subject rights, use appropriate international-transfer mechanisms, maintain security and incident processes, and identify its data-protection contact or encarregado where required. Requests may be made to admin@intellilox.com and complaints to the ANPD.
F. South Africa
Where POPIA applies, Intellilox will process Personal Information in accordance with the conditions for lawful processing, including accountability, processing limitation, purpose specification, further-processing compatibility, information quality, openness, security safeguards and data-subject participation. Cross-border transfers must satisfy section 72 or another applicable condition. The final notice must identify the responsible party, Information Officer and Information Regulator complaint details where required.
G. New Zealand
Where the Privacy Act 2020 applies, Intellilox will comply with applicable Information Privacy Principles, including Principle 12 for overseas disclosure, and notify notifiable privacy breaches where required. Individuals may contact the Office of the Privacy Commissioner after raising concerns with Intellilox.
H. Singapore
Where the PDPA applies, Intellilox will comply with applicable accountability, notification, consent, purpose limitation, accuracy, protection, retention limitation, transfer limitation, access/correction and breach-notification obligations. It will identify its Data Protection Officer contact where required and provide comparable protection for overseas transfers as required by law.
I. Japan
Where APPI applies, Intellilox will specify purposes of use, handle retained Personal Data and third-party provision as required, implement security controls, respond to applicable disclosure/correction/cessation requests and satisfy requirements for provision to a third party in a foreign country.
J. Other jurisdictions
Intellilox will apply mandatory local law. This international baseline does not eliminate the need for local notices, consent language, registrations, representatives, data-residency terms, employment consultation or regulator filings.
Schedule 2 — Baseline Data Processing Addendum
This Schedule applies between Intellilox and the Customer only when incorporated into their Customer Agreement or Order. Individual acceptance of the EULA does not create a separate or conflicting controller instruction.
1. Scope and roles
The Customer appoints Intellilox to process Customer Personal Data to provide, secure and support the Services for the term. The Customer is the controller/business/responsible party/organisation and Intellilox is the processor/service provider/operator/data intermediary, except where law assigns a different role for a specific activity. Each party will comply with Applicable Data Protection Law applicable to its role.
The Customer warrants that its instructions are lawful; it has provided required notices and established required legal bases; and it will not instruct Intellilox to violate law. If Intellilox believes an instruction infringes Applicable Data Protection Law, it will inform the Customer unless prohibited and may suspend the affected processing while the parties resolve it.
2. Instructions
The Customer Agreement, Order, this Schedule, Customer configuration and documented support requests are the Customer's complete instructions. Additional instructions outside the Services are subject to feasibility, law and reasonable fees. Intellilox will not process Customer Personal Data for its own advertising or unrelated purposes.
3. Confidentiality and personnel
Intellilox will ensure persons authorised to process Customer Personal Data are bound by confidentiality and receive appropriate privacy and security training. Access will be limited according to role and need.
4. Security measures
Intellilox will maintain measures appropriate to risk, taking account of state of the art, implementation cost, scope, context and purposes, including as applicable:
- logical tenant isolation and row-level access enforcement;
- least-privilege, role-based and multi-factor administrative access;
- encryption in transit and at rest with managed keys;
- secure credential storage and secrets management;
- audit and security logging protected from unauthorised modification;
- vulnerability, patch, dependency and malware-management processes;
- secure development, code review and deployment controls;
- network segmentation, private data stores, rate limiting and edge protection;
- backup, recovery, business-continuity and incident-response processes;
- personnel security and access revocation; and
- regular testing and evaluation proportionate to risk.
Detailed security documentation may be provided under confidentiality. Intellilox may update measures without materially reducing overall protection.
5. Personal Data Breach
Intellilox will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available about nature, affected data and people, likely consequences, measures taken or proposed, and a contact point. Information may be supplied in phases. Intellilox will take reasonable measures to contain, investigate, mitigate and remediate and will reasonably assist the Customer's notification duties.
The Customer is responsible for notices to individuals and regulators as controller, unless law requires Intellilox to notify directly. Intellilox's notice is not an admission of fault. The final Customer Agreement should set a contractual outer notification target only if operations can meet it; do not promise a fixed number merely for marketing.
6. Subprocessors
The Customer gives general written authorisation for subprocessors on the current register, available on request from admin@intellilox.com. Intellilox will:
- conduct proportionate diligence;
- impose written data protection and security obligations no less protective in material effect for the relevant processing;
- remain responsible for subprocessor performance to the extent required by law and contract; and
- give at least 30 days' prior notice of a new subprocessor where required.
The Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a reasonable alternative. If none is available, the Customer may terminate the materially affected Service according to the Customer Agreement. Objection does not permit use of the Service without an essential subprocessor.
7. Data-subject requests
Taking account of the nature of processing, Intellilox will provide reasonable technical and organisational assistance for the Customer to respond to applicable requests. If Intellilox receives a request concerning Customer Personal Data, it will not respond substantively except on Customer instruction or legal requirement and will forward it where lawful.
8. Impact assessments and regulator consultation
Intellilox will provide information reasonably necessary for the Customer's data protection impact assessment and prior consultation concerning the Services, taking account of processing and information available. Customer-specific consulting beyond standard documentation may be subject to reasonable fees.
9. Demonstrating compliance and audits
Intellilox will make available information reasonably necessary to demonstrate compliance, normally through current independent reports, certifications, questionnaires and security documentation when available. If that is insufficient for a specific legal requirement, the Customer may conduct one audit per year on reasonable notice, during business hours, under confidentiality, without accessing another customer's data or compromising security. Additional audits may occur after a material breach or regulator request. The Customer bears audit cost unless the audit identifies a material Intellilox breach. Intellilox may require use of an independent qualified auditor and reasonable scope controls.
No audit right permits source-code disclosure, credential access, unsafe testing, production disruption or disclosure of another customer's information.
10. Return and deletion
On termination or written instruction, Intellilox will return or make available Customer Personal Data using standard export features and then delete it according to section 10.6, unless law requires retention. Legal-hold data will be isolated and used only for that requirement. Backup copies will be protected and deleted through normal rotation.
11. International transfers
The parties will use the transfer mechanism required by law. Where EU SCCs apply, the appropriate 2021 module is incorporated by reference, completed using Annex A below and the current subprocessor/security documentation; optional provisions and governing details must be completed in the Customer Agreement. Where UK rules apply, the current UK Addendum or IDTA is incorporated as completed by the Customer Agreement. Conflicting SCC/IDTA terms prevail for the restricted transfer only. The parties will cooperate on transfer assessments and supplementary measures.
12. CCPA/US service-provider terms
Where applicable, Intellilox will process Customer Personal Information only for the limited and specified purposes in this Schedule; comply with applicable obligations and provide the same level of privacy protection required of the Customer; notify the Customer if it can no longer comply; permit reasonable monitoring and remediation; not sell or share the Personal Information; and not retain, use or disclose it outside the direct business relationship or combine it with Personal Information from other sources except as legally permitted for a service provider/contractor.
Annex A — Processing details
| Item | Description |
|---|---|
| Subject matter | Hosted multi-tenant Platform Hub and licensed applications, authentication, storage, workflows, audit, support, notifications and Customer-enabled integrations |
| Duration | Subscription term plus export, deletion, backup and legally required retention periods |
| Nature and purpose | Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, transmission, support, security, backup, deletion and other operations needed to provide the Services on Customer instructions |
| Data subjects | Customer workforce, contractors, users, administrators, customers, suppliers, contacts, incident reporters, witnesses, claimants and other people whose data the Customer submits |
| Personal Data | Identity/contact, account, organisation, role, activity/audit, communications, forms, workflow records, incidents, risks, issues/actions, policies, compliance evidence, expenses, timesheets, sales/customer records, attachments and custom fields configured by Customer |
| Sensitive Data | Only categories the Customer lawfully chooses and is authorised to process; may include health/safety, injury, disability, allegation, criminal, union, demographic or financial data depending on configuration |
| Frequency | Continuous or as initiated by Customer and Authorised Users |
| Customer instructions | Customer Agreement, Order, enabled configuration, documented API actions and authorised support requests |
| Approved regions | Control-plane home region: East US 1; Customer data-plane region: East US 1 unless a different region is stated in the Order; exceptions and subprocessors in register |
| Deletion | Section 10.6 and Schedule 2 section 10, subject to completed production retention schedule |
Schedule 3 — Intellectual Property and Sharing Matrix
| Asset or information | Owner / controller as between the parties | Intellilox permitted use | Sharing rule |
|---|---|---|---|
| Customer business records, uploaded files and form submissions | Customer or its licensors | Provide, secure, support and lawfully operate the Services | Customer-authorised recipients, contracted subprocessors, enabled integrations and legally required disclosures only |
| Personal Data within Customer Data | Relevant individual has statutory rights; Customer generally controls processing | Processor/service-provider role on Customer instructions | As above and subject to Applicable Data Protection Law |
| Customer trademarks and pre-existing policies/templates | Customer or its licensors | Display and process for the Customer | No unrelated public or commercial use without permission |
| Platform source/object code, architecture, UI, APIs and generic data models | Intellilox or its licensors | Full ownership and operation | No transfer; access only under the limited licence |
| Intellilox-supplied generic forms, frameworks and templates | Intellilox or identified licensor unless Order says otherwise | Provide and improve across customers | Customer may use with licensed Services; no standalone resale or public redistribution |
| Bespoke deliverable | As expressly stated in Order; otherwise Intellilox, excluding Customer Data | Reuse generic tools, components and know-how without exposing Customer Confidential Information | Assignment only if expressly written; background IP always reserved |
| Feedback | Intellilox receives broad licence under section 7.6 | Any lawful product or commercial use | Source not publicly identified without permission |
| Usage Data in identifiable Customer/User form | Intellilox controller for security/operations, subject to law; not ownership of underlying Customer Data | Security, support, billing, reliability and improvement | Limited providers, advisers, legal recipients and Customer as described in notice |
| Aggregated and De-identified Data | Intellilox | Security, capacity, improvement, research and analysis | May be shared if reasonable measures prevent identification and re-identification is prohibited |
| Third-party/open-source components | Relevant licensor | As permitted by licence | Notices and mandatory licence terms apply to component only |