Legal

Privacy Policy

Last updated 2026-06-21

This Enterprise Privacy Policy (this “Privacy Policy”) describes how Intello Legal (“Intello Legal,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects Personal Data in connection with the Intello Legal AI-powered contract review and legal intelligence platform (the “Services”). It is incorporated by reference into, and should be read together with, the Enterprise Terms and Conditions of Service (the “Terms”). Capitalized terms not defined here have the meanings given in the Terms. This Privacy Policy is designed to satisfy the requirements of multiple data protection frameworks, including the Digital Personal Data Protection Act, 2023 of India (“DPDP Act”), the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018 (“UK GDPR”), and, where applicable, the California Consumer Privacy Act as amended (“CCPA”). With respect to Customer Data, Intello Legal acts as a processor or Data Processor on Customer's instructions; with respect to Account Data, Usage Data, and Website and Marketing Data, Intello Legal acts as a controller or Data Fiduciary.

1. Scope and Key Definitions

  • “Account Data” means information relating to Customer's Organization Account and Authorized Users provided directly to Intello Legal for account administration, including names, business email addresses, job titles, employer name, billing contact details, and authentication credentials.
  • “Data Principal” means an identifiable individual to whom Personal Data relates, as defined under the DPDP Act; “Data Subject” under the GDPR and UK GDPR carries the equivalent meaning.
  • “Data Fiduciary” means a person who, alone or with others, determines the purpose and means of processing of Personal Data, as defined under the DPDP Act; “controller” under the GDPR and UK GDPR carries the equivalent meaning.
  • “Data Processor” means a person who processes Personal Data on behalf of a Data Fiduciary; “processor” under the GDPR and UK GDPR carries the equivalent meaning.
  • “Personal Data” means any data about an individual who is identifiable by or in relation to such data, as further defined under the DPDP Act, GDPR, UK GDPR, or CCPA, as applicable.
  • “Sensitive Personal Data” means categories of Personal Data subject to heightened protection under applicable law, including financial information, health data, biometric data, genetic data, data revealing racial or ethnic origin, religious or philosophical beliefs, trade union membership, sexual orientation, criminal history, and government-issued identification numbers, to the extent recognized as sensitive or special category data under applicable law.

Other capitalized terms used here, including “Customer Data,” “Usage Data,” “AI Output,” “Authorized User,” and “Third-Party Services,” have the meanings given in the Terms.

2. Information We Collect

2.1 Customer Data

2.1.1 Customer Data consists of the documents, contracts, correspondence, and other content that Customer and its Authorized Users upload to or generate within the Services, together with any Personal Data contained therein, such as the names, titles, employers, signatures, and contact details of contracting parties, negotiators, and other individuals referenced in uploaded documents.

2.1.2 Customer is the Data Fiduciary or controller with respect to Customer Data, and is responsible for ensuring it has an appropriate legal basis to collect and disclose to Intello Legal any Personal Data contained within Customer Data, in accordance with Section 8.

2.2 Account Data

2.2.1 When Customer establishes an Organization Account and when Authorized Users are provisioned, Intello Legal collects Account Data, including names, business email addresses, job titles, and employer details of Administrators and Authorized Users, billing and procurement contact details, and authentication credentials such as hashed passwords or single sign-on identifiers.

2.3 Usage Data

2.3.1 Intello Legal automatically collects Usage Data when Customer and its Authorized Users interact with the Services, including log data (IP address, browser type, operating system, access timestamps), feature interaction data, performance and diagnostic data, and configuration data relating to Organization Account settings.

2.4 Device Data

2.4.1 Where Customer or its Authorized Users access the Services via a desktop or mobile application, Intello Legal may collect device identifiers, device type and operating system, application version, and network connection information, for purposes of providing, securing, and supporting the Services.

2.5 Cookies and Similar Technologies

2.5.1 Intello Legal uses cookies and similar tracking technologies on its web application and marketing website, as described in greater detail in the separate Cookies Policy, which is incorporated into this Privacy Policy by reference.

2.6 Website and Marketing Data

2.6.1 Where an individual visits Intello Legal's public marketing website, requests a demonstration, registers for a webinar, or otherwise provides contact information for marketing purposes, Intello Legal collects the Personal Data submitted through such forms, including name, business email, employer, and stated areas of interest, for the purposes described in Section 3.5.

2.7 Information from Third Parties

2.7.1 Intello Legal may receive Personal Data about Customer's Authorized Users from identity providers in connection with single sign-on integrations, from Customer's designated procurement or billing systems, and from Third-Party Services that Customer elects to connect to the Services, in each case limited to the information necessary to provide the relevant integration or functionality.

3. Purposes of Processing

3.1 Providing and Maintaining the Services

3.1.1 Intello Legal processes Customer Data and Account Data to provide, operate, and maintain the Services, including authenticating Authorized Users, processing uploaded documents, generating AI Output, and enabling collaboration features within an Organization Account.

3.2 AI Features

3.2.1 Intello Legal processes Customer Data through the AI Features to generate contract analysis, risk identification, redlining suggestions, summaries, and other AI Output requested by Customer and its Authorized Users, as further described in Section 5.

3.3 Security and Fraud Prevention

3.3.1 Intello Legal processes Usage Data, Account Data, and, where necessary, Customer Data to detect, investigate, and prevent security incidents, fraud, unauthorized access, and violations of the Acceptable Use Policy, and to maintain the integrity and availability of the Services.

3.4 Support and Communications

3.4.1 Intello Legal processes Account Data to respond to support requests, provide service notifications, communicate about changes to the Services or this Privacy Policy, and administer the Organization Account.

3.5 Marketing Communications

3.5.1 Where an individual has provided Personal Data through the marketing website or otherwise consented to receive marketing communications, Intello Legal may use such Personal Data to send product updates, invitations to events, and promotional communications. Recipients may opt out at any time using the unsubscribe mechanism provided in each communication or by contacting Intello Legal using the details in Section 15.

3.6 Product Improvement and Analytics

3.6.1 Intello Legal processes Usage Data, and, subject to Section 5, aggregated or de-identified Customer Data, to analyze usage trends, improve the performance and reliability of the Services, develop new features, and generate benchmarking and analytics insights.

3.7 Legal and Compliance Purposes

3.7.1 Intello Legal processes Personal Data as necessary to comply with applicable law, respond to lawful requests from public or regulatory authorities, establish, exercise, or defend legal claims, and enforce the Terms and this Privacy Policy.

4. Legal Bases for Processing

4.1 Where the GDPR or UK GDPR applies, Intello Legal relies on the following legal bases, as applicable: performance of a contract (to provide the Services); legitimate interests (for security, fraud prevention, product improvement, and analytics, where not overridden by the interests or fundamental rights of the individual); consent (for marketing where required, for non-essential cookies, and for any use of Customer Data to train generally available or third-party AI models as described in Section 5.2); and compliance with legal obligation.

4.2 Where the DPDP Act applies, Intello Legal, acting as Data Fiduciary with respect to Account Data, Usage Data, and Website and Marketing Data, processes Personal Data on the basis of: (a) the consent of the Data Principal, obtained through clear affirmative action; or (b) “legitimate uses” recognized under Section 7 of the DPDP Act. Where Intello Legal acts as Data Processor with respect to Customer Data on Customer's instructions, Customer, as Data Fiduciary, is responsible for establishing the applicable legal basis, including any required notice and consent.

4.3 Where the CCPA applies, Intello Legal processes Personal Data for the business purposes described in Section 3, and does not sell or share Personal Data for cross-context behavioral advertising, as further described in Section 14.

5. AI Processing

5.1 The AI Features process Customer Data submitted by Customer and its Authorized Users to generate AI Output, including contract analysis, clause identification, risk flagging, redlining suggestions, and summaries. This processing is carried out using machine learning models operated by Intello Legal and, in certain cases, by Third-Party Services engaged by Intello Legal as described in Section 10.

5.2 No Training of Third-Party or Generally Available Models Without Consent

5.2.1 Intello Legal does not use Customer Data to train, fine-tune, or otherwise improve any third-party foundation model or any AI model made generally available to parties other than Intello Legal, without Customer's prior, explicit, opt-in consent. This commitment applies regardless of whether the underlying AI infrastructure is operated by Intello Legal or by a Third-Party Service provider, and is reflected in Intello Legal's contractual arrangements with such providers as described in Section 10.2.

5.3 Use of Customer Data to Improve Intello Legal's Own Models

5.3.1 Subject to Customer's right to opt out, Intello Legal may use Customer Data, on an aggregated or de-identified basis wherever feasible, to evaluate, improve, and enhance the accuracy and performance of Intello Legal's own proprietary AI models, solely for the benefit of Intello Legal's customer base generally.

5.3.2 Customer may opt out of such model improvement processing through the Organization Account settings, where available, or by written notice to Intello Legal using the contact details in Section 15. Where Customer opts out, Intello Legal will exclude Customer Data from such processes on a going-forward basis within a commercially reasonable period.

5.4 Automated Decision-Making

5.4.1 The AI Features do not make autonomous legal, contractual, or business decisions on Customer's behalf. AI Output is a decision-support tool intended to inform, and not replace, the professional judgment of Customer's Authorized Users.

5.4.2 To the extent any processing through the AI Features would constitute “solely automated decision-making” producing legal or similarly significant effects within the meaning of Article 22 of the GDPR or UK GDPR, Intello Legal does not engage in such processing as the Services are currently designed, because they are intended to require human review before any AI Output is acted upon. Where Customer configures the Services in a manner that results in automated decision-making with legal or similarly significant effects, Customer is responsible, as Data Fiduciary or controller, for ensuring an appropriate legal basis, safeguards, and rights of human review.

6. Data Retention

6.1 Intello Legal retains Customer Data for the duration of the applicable Subscription Term and, following expiration or termination, for the Retrieval Period described in the Terms, after which Customer Data is deleted or de-identified in accordance with Section 6.3, except as required by applicable law or for legitimate backup, archival, audit, or legal compliance purposes.

6.2 Intello Legal retains Account Data for as long as the Organization Account remains active, and for a reasonable period thereafter to comply with legal, accounting, tax, or regulatory obligations, to resolve disputes, and to enforce agreements.

6.3 Upon expiration of the applicable retention period, Intello Legal will delete or irreversibly de-identify the relevant Personal Data using commercially reasonable methods, except where retained data is subject to a legal hold or ongoing legitimate business purpose disclosed in this Privacy Policy.

6.4 Backup copies of Customer Data may persist in encrypted backup systems for a limited period following deletion from production systems, and will be overwritten or deleted in the ordinary course of Intello Legal's backup rotation cycle.

7. Security Measures

7.1 Intello Legal implements administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, including:

  • Encryption of Customer Data in transit using industry-standard protocols (such as TLS 1.2 or higher) and at rest using industry-standard encryption algorithms;
  • Role-based access controls and the principle of least privilege for personnel access to Personal Data;
  • Logging and monitoring of access to systems that process Personal Data;
  • Network segmentation and logical segregation of Customer Data between customer environments;
  • Regular security testing, including vulnerability scanning and periodic penetration testing; and
  • A documented incident response process, as described in Section 13.

7.2 Further detail regarding Intello Legal's security program, including its compliance roadmap toward certifications such as SOC 2 Type II, ISO/IEC 27001, and ISO/IEC 27701, is available in the Trust Center documentation.

8. Customer's Responsibilities as Data Fiduciary

8.1 Where Customer uploads Customer Data containing Personal Data of its own clients, counterparties, employees, or other third parties, Customer acts as the Data Fiduciary or controller and is responsible for: (a) providing any notice and obtaining any consent required under applicable law prior to disclosing such Personal Data to Intello Legal; (b) ensuring it has a valid legal basis for such processing; and (c) responding to and fulfilling data subject or data principal rights requests relating to such Personal Data, with Intello Legal's reasonable assistance as described in Section 11.

8.2 Customer shall not upload Sensitive Personal Data to the Services unless it has determined that doing so is appropriate given the nature of the data and has implemented any additional safeguards required under applicable law.

8.3 Where required under applicable law, including Section 8(6) of the DPDP Act, Customer, as Data Fiduciary, remains responsible for compliance with applicable obligations notwithstanding that certain processing is carried out on its behalf by Intello Legal as Data Processor, and Intello Legal's processing of Customer Data is governed by the Terms and any applicable data processing addendum.

9. International Data Transfers

9.1 Intello Legal may process and store Personal Data in data centers that may be located outside the jurisdiction in which Customer or the relevant Data Principal is located.

9.2 Transfers from the European Economic Area and United Kingdom. Where Personal Data subject to the GDPR or UK GDPR is transferred to a country not recognized as providing an adequate level of data protection, Intello Legal relies on appropriate safeguards recognized under applicable law, including the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.

9.3 Transfers under the DPDP Act. Intello Legal's cross-border transfer of Personal Data subject to the DPDP Act is carried out in accordance with Section 16 of the DPDP Act and any rules, notifications, or restricted-country lists issued by the Government of India from time to time.

9.4 Customer may request additional information regarding the specific safeguards applicable to a cross-border transfer of its Customer Data by contacting Intello Legal using the details in Section 15.

10. Third-Party Processors

10.1 Intello Legal engages Third-Party Service providers to assist in providing the Services, including cloud infrastructure and hosting providers; large language model and AI infrastructure providers used to deliver the AI Features; customer support and communication tools; analytics providers; and payment processors.

10.2 Each Third-Party Service provider engaged to process Customer Data is bound by a written agreement containing data protection terms consistent with this Privacy Policy, including confidentiality obligations and, where such provider processes Customer Data to deliver AI Features, a contractual prohibition on using Customer Data to train models for the benefit of any party other than Intello Legal, except where Customer has provided explicit consent as described in Section 5.2.

10.3 A current list of categories of Third-Party Service subprocessors that may process Customer Data is available upon request by contacting Intello Legal using the details in Section 15. Intello Legal will provide reasonable advance notice of the addition of a new material subprocessor, and Customer may object on reasonable data protection grounds in accordance with any applicable data processing addendum.

11. Your Rights

11.1 Subject to applicable law and the exceptions and limitations described therein, individuals may have the following rights with respect to their Personal Data:

  • Right of Access: to obtain confirmation of whether Intello Legal processes Personal Data about the individual and to obtain a copy of such Personal Data and related information;
  • Right to Rectification: to request correction of inaccurate or incomplete Personal Data;
  • Right to Erasure: to request deletion of Personal Data, subject to applicable retention obligations and legitimate business purposes;
  • Right to Data Portability: to receive Personal Data in a structured, commonly used, machine-readable format, and to request its transmission to another data fiduciary or controller, where technically feasible;
  • Right to Object: to object to processing based on legitimate interests or for direct marketing purposes;
  • Right to Restrict Processing: to request that Intello Legal limit processing under certain circumstances;
  • Right to Withdraw Consent: where processing is based on consent, to withdraw such consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal;
  • Right to Nominate: under the DPDP Act, to nominate another individual to exercise their rights in the event of death or incapacity; and
  • Right to Grievance Redressal: to file a complaint with Intello Legal's Grievance Officer (Section 15) and, where applicable, with the relevant supervisory authority.

11.2 Exercising Your Rights

11.2.1 Individuals may exercise the rights described in Section 11.1 by submitting a request using the contact details in Section 15. Intello Legal will verify the identity of the requester before acting, using reasonable and proportionate verification methods.

11.2.2 Requests Relating to Customer Data. Where a request relates to Personal Data contained within Customer Data, and Customer is the relevant Data Fiduciary or controller, Intello Legal will direct the individual to submit the request to Customer and will provide Customer with reasonable assistance to enable Customer to respond, consistent with Intello Legal's role as Data Processor.

11.2.3 Intello Legal will respond to verified requests within the time periods required under applicable law. Intello Legal may decline or limit a request to the extent permitted or required by applicable law, including where the request is manifestly unfounded, excessive, or would adversely affect the rights of other individuals.

11.3 No Fee Generally Required

11.3.1 Intello Legal will not charge a fee to process a valid rights request, unless permitted under applicable law for requests that are manifestly unfounded, excessive, or repetitive, in which case Intello Legal may charge a reasonable administrative fee or decline to act.

12. Children's Privacy

12.1 The Services are intended for use by businesses and professionals and are not directed to, and should not be used by, individuals under the age of eighteen (18). Intello Legal does not knowingly collect Personal Data from individuals under eighteen (18) years of age.

12.2 If Intello Legal becomes aware that it has inadvertently collected Personal Data from an individual under eighteen (18) years of age, including in connection with the DPDP Act's requirements regarding the processing of children's data with verifiable parental consent, Intello Legal will take reasonable steps to delete such Personal Data promptly. Parents or guardians may contact Intello Legal using the details in Section 15.

13. Incident Response and Breach Notification

13.1 Intello Legal maintains a documented incident response process designed to detect, investigate, contain, and remediate security incidents affecting Personal Data.

13.2 Where a Security Incident affects Personal Data for which Customer is the Data Fiduciary or controller, Intello Legal will notify Customer without undue delay, generally within seventy-two (72) hours of confirming the Security Incident, and will provide reasonably available information to support Customer's own breach notification obligations under applicable law, including the DPDP Act, GDPR, and UK GDPR.

13.3 Where a Security Incident affects Personal Data for which Intello Legal is the Data Fiduciary or controller, such as Account Data, Intello Legal will notify affected individuals and, where required, the relevant supervisory or regulatory authority (including the Data Protection Board of India under the DPDP Act, or the competent supervisory authority under the GDPR or UK GDPR), within the timeframes required under applicable law.

14. CCPA-Specific Disclosures

14.1 To the extent the CCPA applies to Intello Legal's processing of Personal Data of California residents, the following disclosures apply in addition to the rights described in Section 11:

  • Categories of Personal Data Collected: identifiers (such as name and email address), professional and employment-related information, internet or electronic network activity information (Usage Data), and, within Customer Data, such categories as may be contained in uploaded documents;
  • Sources of Personal Data: directly from Customer and its Authorized Users, automatically through use of the Services, and from Third-Party Services as described in Section 2.7;
  • Business or Commercial Purpose for Collection: the purposes described in Section 3;
  • Categories of Third Parties to Whom Personal Data Is Disclosed: Third-Party Service providers described in Section 10, and, where required, regulators or governmental authorities;
  • Sale or Sharing of Personal Data: Intello Legal does not sell Personal Data, and does not share Personal Data for cross-context behavioral advertising, as those terms are defined under the CCPA; and
  • Right to Non-Discrimination: Intello Legal will not discriminate against an individual for exercising any right under the CCPA.

14.2 California residents may exercise their CCPA rights using the contact details in Section 15 and may designate an authorized agent to make a request on their behalf, subject to Intello Legal's verification procedures.

15. Contact Details

For questions about this Privacy Policy or to exercise the rights described in Section 11, please contact Intello Legal's Data Protection / Privacy Team and Grievance Officer (DPDP Act, India) at intellolegal@gmail.com.

16. Changes to This Privacy Policy

16.1 Intello Legal may update this Privacy Policy from time to time to reflect changes in its data practices, the Services, or applicable law. Intello Legal will post the updated Privacy Policy with a revised “Last updated” date and, for material changes, will provide notice through in-product notification or email to the Administrator.

16.2 Where required by applicable law, Intello Legal will obtain renewed consent or provide an opportunity to object before a material change takes effect with respect to a particular individual's Personal Data.