Legal
Privacy Policy
This Privacy Policy explains how Intentrax, Inc. ("Intentrax," "we," "us," or "our") collects, uses, discloses, and protects personal data when you visit our website, create an account, or use the Intentrax execution-assurance platform (collectively, the "Service").
1. Who We Are
Intentrax, Inc. is a Delaware corporation and is the entity responsible for the Service. Registered address: [registered address — to be completed]. If Intentrax is required to designate an EU/UK representative or Data Protection Officer under applicable law, that contact will be listed here: [EU representative / Data Protection Officer, if applicable — to be completed]. Until that designation is added, use the contact details in Section 15 for all privacy inquiries.
2. Scope of this Policy
This Policy applies to personal data processed through the Intentrax marketing website, the console, our APIs and SDKs, the public verifier, and related account, support, and billing interactions. Where your organization submits personal data to us as part of Execution Evidence (Section 3), our role and your organization's role are described in Section 6.
3. Personal Data We Collect
- Account and contact data: name, work email, organization, role, and authentication identifiers (OpenID Connect subject identifiers for sign-in providers such as Google, or salted password hashes — we never store plaintext passwords).
- Execution payloads and evidence: intent definitions, execution metadata, proofs, receipts, and verification records that you or your organization submit to or generate through the Service. This category may incidentally contain personal data that your organization chooses to include in an execution; we do not control what your organization submits.
- Usage and billing data: Verified Execution Event (VEE) counts, plan and subscription state, invoices, and payment status. We do not store full payment card numbers ourselves (see Section 7 on subprocessors).
- Technical and log data: IP addresses, browser/device information, request logs, session identifiers, and error/audit logs used for security, debugging, and service operation.
- Communications: messages you send us, such as support requests, sales inquiries, or content submitted through a contact form.
We describe only the categories of data and technology that the Service plausibly and currently uses; we do not deploy third-party advertising trackers, and this Policy will be updated if that changes (see Section 12).
4. How and Why We Use Data
- Providing and securing the Service, including authentication, tenant isolation, and audit trails.
- Metering usage and, where billing is enabled for your account, processing billing (VEE counting, invoicing, payment processing through our merchant of record).
- Service communications such as verification links, usage alerts, security notices, and billing notices.
- Responding to support, sales, and general inquiries.
- Improving the reliability, security, and usability of the Service.
- Legal compliance, fraud prevention, and enforcement of our Terms of Service.
We do not sell your personal data, and we do not use Execution Evidence submitted by customers to train models outside the scope of providing the Service to that customer.
5. Legal Bases for Processing (GDPR)
Where the EU/UK GDPR applies, we rely on the following legal bases under Article 6: performance of a contract (providing the Service you signed up for); legitimate interests (securing the Service, preventing fraud and abuse, and improving our product, balanced against your rights); legal obligation (tax, accounting, and regulatory recordkeeping); and consent where we specifically ask for it (for example, for optional communications), which you may withdraw at any time.
6. Controller and Processor Roles
For account, contact, and billing data collected directly from you, Intentrax acts as a data controller. For personal data contained within Execution Evidence that your organization submits to the Service, Intentrax acts as a data processor (or "service provider" under the CCPA), processing that data only on your organization's documented instructions and for the purpose of providing the Service, subject to a data processing addendum where applicable. If you are an individual whose personal data was submitted by an Intentrax customer organization rather than by you directly, please direct data-subject requests to that organization in the first instance; we will support that organization in responding.
7. Sharing and Subprocessors
We do not sell personal data. We share personal data only with service providers (subprocessors) who need it to help us run the Service, under contractual confidentiality and data-protection obligations:
- Cloud hosting infrastructure (Amazon Web Services (AWS)) — compute, storage, and managed database infrastructure underlying the Service.
- A payments merchant of record — once paid billing is enabled for your account, payment processing, invoicing, and tax collection will be handled by a third-party merchant of record (currently anticipated to be Paddle.com Market Limited and its affiliates, "Paddle"); it receives billing contact and payment details, and Intentrax does not store full card numbers.
- Sign-in / identity providers — if you choose to authenticate using a third-party OpenID Connect identity provider (which may include Google), that provider processes the sign-in on your behalf and shares limited profile data (such as name and email) with us to create your account.
We may also disclose personal data where required to comply with law, respond to lawful legal process, protect the rights, property, or safety of Intentrax, our users, or others, or in connection with a merger, acquisition, financing, or sale of assets (subject to confidentiality commitments). We intend to maintain an up-to-date subprocessor list and to give notice before adding a new subprocessor that will process personal data, consistent with any data processing addendum in place with you.
8. International Data Transfers
Intentrax and its subprocessors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we intend to rely on appropriate safeguards recognized under applicable law, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent mechanism, together with supplementary measures as needed.
9. Data Retention
We retain account data for as long as your account is active, plus a reasonable wind-down period after closure to allow for export and account recovery. Execution Evidence is retained according to your plan terms and your organization's configuration. Immutable audit and billing records are retained for as long as required for legal, tax, and accounting purposes, and are then deleted or irreversibly anonymized. We retain other personal data only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
10. Security Practices
We apply security practices designed to protect personal data, including: per-tenant logical isolation enforced with row-level security controls; encryption of data in transit; hashed (not plaintext) authentication credentials and session tokens; role-based access control for administrative actions; and immutable audit logging of administrative and billing actions. These are practices and ongoing commitments, not certifications — Intentrax does not currently hold, and does not claim, SOC 2, ISO 27001, HIPAA, or other third-party compliance certifications. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your Rights
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; obtain a portable copy of your data; restrict or object to certain processing; and withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal. You also generally have the right to lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, use, and disclose; to delete personal information we hold about you (subject to exceptions); to correct inaccurate personal information; to obtain a portable copy of your data; and to opt out of "sale" or "sharing" of personal information and of certain profiling. Intentrax does not sell or share your personal data, as those terms are defined under the CCPA/CPRA, and we will not discriminate against you for exercising any privacy right.
To exercise any of these rights, contact us using the details in Section 15. Where Intentrax processes data as a processor on behalf of a customer organization (Section 6), we will direct or support your request through that organization as appropriate. We may need to verify your identity before completing a request.
13. Children's Privacy
The Service is a business product intended for organizations and professionals, and it is not directed to, and we do not knowingly collect personal data from, children under 16 years of age (or the higher age threshold required by applicable local law, such as 18 for certain jurisdictions). If we learn that we have collected personal data from a child in violation of this Policy, we will take steps to delete it.
14. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated Policy on this page with a revised effective date, and for material changes we will provide additional notice, such as an in-product notice or an email to the contact address on file for your organization, before the change takes effect.
15. How to Contact Us / Exercise Your Rights
For general privacy questions or to exercise the rights described in Section 11, email hello@intentrax.com or use Contact Intentrax. We intend to stand up a dedicated privacy mailbox, privacy@intentrax.com [placeholder — not yet a live mailbox], for privacy-specific requests; until it is live, use the address above.