Privacy and security
GDPR and data processing
This page explains how roles and the Data Processing Addendum work when Intellipush is used for enabled SMS, email, voice and related messaging functions. The DPA applies automatically as Schedule 1 to the service terms; it does not require a separate order or signature.
The customer's and Intellipush's roles
The customer is normally the controller when it determines why recipient data is used and the essential parameters of the campaign. Intellipush is normally the processor when we process that data on the customer's documented instructions. Intellipush is also the controller for its own purposes, such as accounts, billing, support and security. Both parties retain their independent legal duties.
The Data Processing Addendum is included
Schedule 1 to the Intellipush Business Terms of Service is the DPA between the customer and Intellipush. It applies automatically whenever Intellipush processes personal data on the customer's behalf. It covers instructions, confidentiality, security, subprocessors, transfers, assistance, breaches, audit and what happens when the service ends.
The customer's independent responsibility
The customer must have a valid legal basis, provide required information, minimise data, keep contact data current, and handle rights and opt-outs. Under the Acceptable Use Policy, advertising and marketing through enabled channels requires documented prior consent. Standard messaging channels are not necessarily end-to-end encrypted, and sensitive or high-risk content requires a separate assessment. Intellipush features do not replace the customer's assessment of lawfulness.
Export, termination and erasure
After termination, the customer normally has 30 days to export customer data. Customer data is then erased from active systems within 60 days and expires through the ordinary 14-day backup cycle. Statutory retention, security records, disputes and other lawful exceptions may require limited data to be retained for longer.
Rights and assistance
A recipient should normally contact the organisation that determined the purpose of the campaign. Intellipush assists the customer with relevant requests, assessments, breaches and regulatory engagement to the extent required by the DPA and law. The customer must not send more personal data than is necessary for the assistance.
Provider categories and data processing
Core infrastructure and backups are with AWS in Ireland. Depending on the enabled functions and selected message route, Intellipush may also use messaging-routing and delivery providers, national and international mobile and communications networks, and optional communications and support services. The exact, versioned subprocessor schedule is commercially confidential and is made available to verified customers and prospects before contracting and subsequently on request. Not every communications network, customer-selected destination or recipient acts as a subprocessor. Its role is assessed according to the actual processing and message route concerned.
International transfers
Message routes, recipient countries, mobile networks and some supporting services may involve processing outside the EEA. Where international-transfer rules apply, Intellipush and the customer must meet their respective duties and use a valid basis and necessary safeguards for the transfer concerned.
Security in practice
Intellipush uses risk-based organisational and technical measures. Verified high-level controls are described on the security page. The customer remains responsible for its own users, passwords, integration credentials, content and recipients. Security is an ongoing discipline, not an absolute guarantee against errors or incidents.
Last fact-checked: · Responsible function: Intellipush Management