[{"data":1,"prerenderedAt":829},["ShallowReactive",2],{"services:nav":3,"team:nav":45,"legal-data-processing-agreement":60},[4,15,25,35],{"path":5,"title":6,"description":7,"outcome":8,"icon":9,"image":10},"\u002Fconsulting\u002Fsoftware-development","Software development","Applications and APIs built properly — designed, architected and shipped by someone who has done it at scale.","Something to build, without the team or the expertise to build it.","app-development",{"url":11,"photographer":12,"source":13,"sourceUrl":14},"\u002Fimages\u002Fconsulting\u002Fsoftware-development.jpg","Daria Nepriakhina","Unsplash","https:\u002F\u002Funsplash.com\u002Fphotos\u002FzoCDWPuiRuA?utm_source=intracia&utm_medium=referral",{"path":16,"title":17,"description":18,"outcome":19,"icon":20,"image":21},"\u002Fconsulting\u002Fdata-extraction-and-recovery","Data extraction & recovery","Getting data out of systems that don't want to give it up — undocumented formats, dead platforms, failing media and legacy databases.","Data trapped in a system nobody supports any more.","data",{"url":22,"photographer":23,"source":13,"sourceUrl":24},"\u002Fimages\u002Fconsulting\u002Fdata-extraction-and-recovery.jpg","Patrick Lindenberg","https:\u002F\u002Funsplash.com\u002Fphotos\u002F1iVKwElWrPA?utm_source=intracia&utm_medium=referral",{"path":26,"title":27,"description":28,"outcome":29,"icon":30,"image":31},"\u002Fconsulting\u002Fdeveloper-and-ai-tooling","Developer & AI tooling","Libraries, SDKs, components and internal tooling — plus the MCP servers, agent integrations and evaluation harnesses that make AI features survive production.","A team blocked by something missing from a library they can't change.","libraries",{"url":32,"photographer":33,"source":13,"sourceUrl":34},"\u002Fimages\u002Fconsulting\u002Fdeveloper-and-ai-tooling.jpg","Luca Bravo","https:\u002F\u002Funsplash.com\u002Fphotos\u002FXJXWbfSo2f0?utm_source=intracia&utm_medium=referral",{"path":36,"title":37,"description":38,"outcome":39,"icon":40,"image":41},"\u002Fconsulting\u002Fweb-applications-and-sites","Web applications & sites","Designed and built end to end — customer-facing applications, product interfaces, marketing sites and documentation.","A web app or a site you'll still be proud of in three years.","web",{"url":42,"photographer":43,"source":13,"sourceUrl":44},"\u002Fimages\u002Fconsulting\u002Fweb-applications-and-sites.jpg","Domenico Loia","https:\u002F\u002Funsplash.com\u002Fphotos\u002FhGV2TfOh0ns?utm_source=intracia&utm_medium=referral",[46,53],{"path":47,"name":48,"role":49,"bio":50,"avatar":51,"pronouns":52},"\u002Fteam\u002Fdamien-guard","Damien Guard","Engineering & Operations","Damien has spent four decades writing software, most of it on the tools other developers depend on — .NET at Microsoft, the Atom editor at GitHub, SDKs and developer experience at Auth0, and the official MongoDB provider for Entity Framework Core.","\u002Fteam\u002Fdamien-guard.jpg","he\u002Fhim",{"path":54,"name":55,"role":56,"bio":57,"avatar":58,"pronouns":59},"\u002Fteam\u002Fkerry-guard","Kerry Guard","Marketing & Design","Kerry is CEO of MKG Marketing, the B2B SaaS and tech agency she co-founded in 2011, and leads marketing and web design at Intracia. She spends most of her time on the same problem from two directions: how technical products explain themselves to the people who have to buy them.","\u002Fteam\u002Fkerry-guard.jpg","she\u002Fher",{"id":61,"title":62,"body":63,"covers":817,"description":818,"extension":819,"intro":820,"meta":821,"navigation":822,"path":823,"seo":824,"status":825,"stem":826,"updated":827,"__hash__":828},"legal\u002Flegal\u002Fdata-processing-agreement.md","Data Processing Agreement",{"type":64,"value":65,"toc":792},"minimark",[66,86,92,98,114,117,120,145,148,153,160,171,175,178,189,192,196,199,210,213,217,220,224,231,235,246,253,261,264,268,271,291,295,302,306,317,336,339,343,350,354,357,361,364,366,370,408,412,439,443,449,454,457,620,626,629,632,636,643,650,714,717,732,735,739,749,767,770,774,784],[67,68,69,70,75,76,80,81,85],"p",{},"Our customers agree to these processor terms so they can lawfully store personal data in Intracia\nCMS. It sits alongside our ",[71,72,74],"a",{"href":73},"\u002Fprivacy","Privacy Policy",", ",[71,77,79],{"href":78},"\u002Fterms","Terms of Service"," and\n",[71,82,84],{"href":83},"\u002Facceptable-use","Acceptable Use Policy",".",[87,88,89],"blockquote",{},[67,90,91],{},"This describes what we do today, and we'll tell you before it changes materially. If something\nhere doesn't work for your organisation, tell us. We read these ourselves, and we can discuss\nchanges.",[67,93,94],{},[95,96,97],"strong",{},"Between:",[99,100,101,108],"ul",{},[102,103,104,107],"li",{},[95,105,106],{},"Customer"," (\"Controller\") — the organisation using the Service; and",[102,109,110,113],{},[95,111,112],{},"Intracia Ltd",", Guernsey (\"Processor\", \"we\").",[67,115,116],{},"Together the \"Parties\". This DPA forms part of the agreement under which we provide the Service\n(the \"Agreement\"), and it covers our processing of personal data on the Controller's behalf.",[67,118,119],{},"Up to 4 laws may apply, and where one does, the matching terms below apply with it:",[99,121,122,133,139],{},[102,123,124,125,128,129,132],{},"the ",[95,126,127],{},"EU GDPR"," and the ",[95,130,131],{},"UK GDPR"," — the General Data Protection Regulation in each of those\nregimes;",[102,134,124,135,138],{},[95,136,137],{},"Guernsey DPL"," — the Data Protection (Bailiwick of Guernsey) Law 2017; and",[102,140,124,141,144],{},[95,142,143],{},"CCPA"," — the California Consumer Privacy Act, as amended by the California Privacy Rights\nAct.",[146,147],"hr",{},[149,150,152],"h2",{"id":151},"_1-roles","1. Roles",[67,154,155,156,159],{},"The Controller decides why and how the personal data in its content and configuration is processed\n(\"Customer Personal Data\"). Intracia processes that data only as a ",[95,157,158],{},"processor"," — a \"service\nprovider\" under the CCPA — and only on the Controller's documented instructions.",[67,161,162,163,166,167,170],{},"One thing this DPA doesn't cover: personal data about the Controller's own account holders and\nusers. Intracia processes that as a ",[95,164,165],{},"controller",", and the ",[71,168,74],{"href":169},"\u002Fprivacy#2-the-roles-we-play","\ngoverns it.",[149,172,174],{"id":173},"_2-instructions","2. Instructions",[67,176,177],{},"We process Customer Personal Data in 3 cases only:",[99,179,180,183,186],{},[102,181,182],{},"to provide, maintain and secure the Service under the Agreement;",[102,184,185],{},"as the Controller's own use and configuration of the Service directs; and",[102,187,188],{},"where the law requires it. We'll tell the Controller first, unless the law forbids us to.",[67,190,191],{},"If we think an instruction breaks data-protection law, we'll say so.",[149,193,195],{"id":194},"_3-ccpa-service-provider-terms","3. CCPA \u002F service-provider terms",[67,197,198],{},"The CCPA calls us a \"service provider\" rather than a processor. Under it, we won't:",[99,200,201,204,207],{},[102,202,203],{},"sell or share Customer Personal Data;",[102,205,206],{},"keep, use or disclose it for any purpose other than performing the Service, or outside our\ndirect business relationship with the Controller; or",[102,208,209],{},"combine it with data from other sources, except where the CCPA allows.",[67,211,212],{},"We certify that we understand these restrictions and will comply with them.",[149,214,216],{"id":215},"_4-confidentiality","4. Confidentiality",[67,218,219],{},"Everyone we authorise to process Customer Personal Data is under a duty of confidentiality, and\nreaches it only where the job in front of them needs it.",[149,221,223],{"id":222},"_5-security","5. Security",[67,225,226,227,230],{},"We keep the safeguards set out in ",[95,228,229],{},"Annex 2",". They include encryption in transit and at rest for\nsecrets, tenant isolation through Row Level Security, least-privilege access, signed webhooks,\nrate limiting, and audit logging. Together these are what the GDPR calls \"technical and\norganisational measures\". We may change them, so long as the protection doesn't materially drop.",[149,232,234],{"id":233},"_6-sub-processors","6. Sub-processors",[67,236,237,238,241,242,245],{},"The Controller gives ",[95,239,240],{},"general authorisation"," for us to engage the sub-processors listed in\n",[95,243,244],{},"Annex 3"," to provide the Service. A sub-processor is a supplier we bring in who handles\nCustomer Personal Data on our behalf. We hold each of them to data-protection terms at least as\nstrict as this DPA, and we remain liable for what they do.",[67,247,248,249,252],{},"We'll give the Controller ",[95,250,251],{},"at least 7 days' advance notice"," of any new or replacement\nsub-processor, by email. The Controller may object on reasonable data-protection grounds; if we\ncan't resolve the objection, the Controller may terminate the affected part of the Service.",[67,254,255,256,260],{},"The ",[71,257,259],{"href":258},"\u002Fprivacy#9-who-else-sees-it","published sub-processor list"," (Privacy Policy, section 9) is the authoritative\nregister — Annex 3 refers to it rather than duplicating it, so they can't drift apart. That\n7-day figure is stated in the public policy too; change one and you must change the other.",[67,262,263],{},"7 days is the notice period during early access. We intend to lengthen it to 30 days at general\navailability, and this clause will be updated when we do.",[149,265,267],{"id":266},"_7-assistance-to-the-controller","7. Assistance to the Controller",[67,269,270],{},"So far as the nature of the processing allows, we'll help the Controller to:",[99,272,273,279,285],{},[102,274,275,278],{},[95,276,277],{},"Answer requests from data subjects"," — the people the data is about. We forward any request\nthat comes to us directly, and we provide the tools and exports needed to find, correct, delete\nor export Customer Personal Data.",[102,280,281,284],{},[95,282,283],{},"Keep the data secure, and report a breach in time"," — the duties in Articles 32 to 34 of the\nGDPR.",[102,286,287,290],{},[95,288,289],{},"Carry out a data protection impact assessment, and consult a regulator where one is needed"," —\nArticles 35 and 36. An impact assessment is the written risk assessment the GDPR requires before\nprocessing that's likely to be high risk.",[149,292,294],{"id":293},"_8-personal-data-breaches","8. Personal-data breaches",[67,296,297,298,301],{},"We'll notify the Controller ",[95,299,300],{},"without undue delay"," after becoming aware of a breach\naffecting Customer Personal Data, with the information the Controller reasonably needs to meet\nits own notification duties. We don't notify supervisory authorities or data subjects on the\nController's behalf unless separately agreed.",[149,303,305],{"id":304},"_9-international-transfers","9. International transfers",[67,307,308,309,312,313,316],{},"Intracia is established in ",[95,310,311],{},"Guernsey",", which both the EU and the UK recognise as offering an\n",[95,314,315],{},"adequate"," level of protection. That is the highest status a country outside the EEA can hold, and\nthe only one that removes the transfer restriction rather than papering over it. Sending Customer\nPersonal Data from the EEA or the UK to us therefore needs no further safeguard, and no Standard\nContractual Clauses.",[67,318,319,320,323,324,327,328,331,332,335],{},"Providing the Service then means moving it on to sub-processors outside the EEA, the UK and\nGuernsey — the database in the United States above all. ",[95,321,322],{},"We are the exporter on those transfers,\nnot the Controller."," We make each one under the ",[95,325,326],{},"EU Standard Contractual Clauses"," and the\n",[95,329,330],{},"UK International Data Transfer Addendum"," we have entered into with that provider, or under its\n",[95,333,334],{},"Data Privacy Framework"," certification where it holds one. Annex 3 names every provider and links\nits terms.",[67,337,338],{},"We apply technical measures on top of whichever safeguard applies.",[149,340,342],{"id":341},"_10-deletion-or-return","10. Deletion or return",[67,344,345,346,349],{},"When the Service ends we'll delete or return Customer Personal Data within ",[95,347,348],{},"30 days",",\nwhichever the Controller chooses, and delete any copies we still hold. The one exception is\nanything the law requires us to keep. Backups clear on their own cycle: we take them daily and\nkeep them for 7 days.",[149,351,353],{"id":352},"_11-audits","11. Audits",[67,355,356],{},"We'll give the Controller what it needs to check that we're keeping to this DPA, and we allow\naudits. This document and Annex 2 answer most of it, and we'll answer a written question directly.\nThe Controller can arrange an on-site audit on reasonable notice and at its own cost, subject to\nconfidentiality and without compromising other customers.",[149,358,360],{"id":359},"_12-liability-and-precedence","12. Liability and precedence",[67,362,363],{},"Liability is subject to the limitations in the Agreement. If this DPA conflicts with the\nAgreement on data protection, this DPA prevails.",[146,365],{},[149,367,369],{"id":368},"annex-1-details-of-processing","Annex 1 — Details of processing",[99,371,372,378,384,390,396,402],{},[102,373,374,377],{},[95,375,376],{},"Subject-matter:"," provision of Intracia.",[102,379,380,383],{},[95,381,382],{},"Duration:"," the term of the Agreement, plus deletion or return under Clause 10.",[102,385,386,389],{},[95,387,388],{},"Nature and purpose:"," hosting, storing, editing, versioning, syncing (Git), publishing, and\nserving Controller content and media, plus optional AI-assisted authoring; and handling the\nsupport correspondence that arises from the Service, which may itself contain Customer Personal\nData the Controller chooses to send us.",[102,391,392,395],{},[95,393,394],{},"Types of personal data:"," any personal data the Controller chooses to include in its\ncontent, media, metadata, and configuration — potentially names, contact details, images,\nand other identifiers of the Controller's staff, authors, or the subjects\u002Freaders of its\nsites.",[102,397,398,401],{},[95,399,400],{},"Categories of data subjects:"," as determined by the Controller (for example its staff, authors,\ncustomers, website audience).",[102,403,404,407],{},[95,405,406],{},"Special categories:"," not intended; the Controller must not submit special-category data\nunless separately agreed and safeguarded.",[149,409,411],{"id":410},"annex-2-technical-and-organisational-measures","Annex 2 — Technical and organisational measures",[99,413,414,417,424,427,430,433,436],{},[102,415,416],{},"Encryption of secrets\u002Fcredentials at rest; TLS in transit.",[102,418,419,420,85],{},"Tenant isolation via Postgres Row Level Security keyed on ",[421,422,423],"code",{},"site_id",[102,425,426],{},"Role-based access control (admin\u002Feditor), authenticated and authorised API routes.",[102,428,429],{},"Server-only elevated credentials; no service keys or DB connection strings exposed to\nbrowsers.",[102,431,432],{},"Inbound webhooks signed and verified, so we can tell a genuine one from a forgery; rate\nlimiting on API, AI, preview, and outbound paths.",[102,434,435],{},"Audit trails: activity logs, sign-in\u002Fsecurity logs, push\u002Fpull job records.",[102,437,438],{},"Least-privilege sub-processor access and documented retention\u002Fdeletion.",[149,440,442],{"id":441},"annex-3-approved-sub-processors","Annex 3 — Approved sub-processors",[67,444,445,446,448],{},"The authoritative register, with purposes, data categories and regions, is published in the\n",[71,447,74],{"href":258},", section 9. It's public, so the Controller doesn't have to request\nit, and this Annex points at it rather than duplicating it so that they can't drift apart.",[450,451,453],"h3",{"id":452},"engaged-by-us","Engaged by us",[67,455,456],{},"These process Personal Data on our instruction in every deployment of the Service. Each is engaged\nunder data-protection terms no less protective than this DPA:",[458,459,460,479],"table",{},[461,462,463],"thead",{},[464,465,466,470,473,476],"tr",{},[467,468,469],"th",{},"Sub-processor",[467,471,472],{},"Function",[467,474,475],{},"Region",[467,477,478],{},"Their DPA",[480,481,482,505,522,539,555,571,587,603],"tbody",{},[464,483,484,488,491,498],{},[485,486,487],"td",{},"Supabase",[485,489,490],{},"Authentication and primary database",[485,492,493,494,497],{},"United States (",[421,495,496],{},"us-east-2",")",[485,499,500],{},[71,501,502],{"href":502,"rel":503},"https:\u002F\u002Fsupabase.com\u002Flegal\u002Fdpa",[504],"nofollow",[464,506,507,510,513,516],{},[485,508,509],{},"Cloudflare",[485,511,512],{},"Application hosting, edge, KV cache, AI Gateway",[485,514,515],{},"Global network",[485,517,518],{},[71,519,520],{"href":520,"rel":521},"https:\u002F\u002Fwww.cloudflare.com\u002Fcloudflare-customer-dpa\u002F",[504],[464,523,524,527,530,533],{},[485,525,526],{},"PostHog",[485,528,529],{},"Product analytics, session replay, error tracking",[485,531,532],{},"United States",[485,534,535],{},[71,536,537],{"href":537,"rel":538},"https:\u002F\u002Fposthog.com\u002Fdpa",[504],[464,540,541,544,547,549],{},[485,542,543],{},"Resend",[485,545,546],{},"Transactional email delivery",[485,548,532],{},[485,550,551],{},[71,552,553],{"href":553,"rel":554},"https:\u002F\u002Fresend.com\u002Flegal\u002Fdpa",[504],[464,556,557,560,563,565],{},[485,558,559],{},"GitHub",[485,561,562],{},"Git integration — OAuth, GitHub App, webhooks",[485,564,532],{},[485,566,567],{},[71,568,569],{"href":569,"rel":570},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy",[504],[464,572,573,576,579,581],{},[485,574,575],{},"IPGeolocation.io",[485,577,578],{},"Approximate location for sign-in addresses",[485,580,532],{},[485,582,583],{},[71,584,585],{"href":585,"rel":586},"https:\u002F\u002Fipgeolocation.io\u002Fgdpr.html",[504],[464,588,589,592,595,597],{},[485,590,591],{},"OpenRouter (via Cloudflare AI Gateway)",[485,593,594],{},"Schema and template assistance, and alt-text suggestions",[485,596,532],{},[485,598,599],{},[71,600,601],{"href":601,"rel":602},"https:\u002F\u002Fopenrouter.ai\u002Fterms",[504],[464,604,605,608,611,614],{},[485,606,607],{},"Microsoft (Microsoft 365)",[485,609,610],{},"Our mailboxes and working documents — support and account correspondence",[485,612,613],{},"European Union",[485,615,616],{},[71,617,618],{"href":618,"rel":619},"https:\u002F\u002Faka.ms\u002Fdpa",[504],[67,621,622,625],{},[95,623,624],{},"Microsoft is in this table for a narrower reason than the rest, and the difference matters.","\nEvery other sub-processor above touches the Service: the Controller's content passes\nthrough it as a matter of course. Microsoft doesn't. Nothing in Intracia reads from or writes to\nMicrosoft 365, and no Customer Personal Data is routed there by the Service.",[67,627,628],{},"It's listed because a Controller who emails us about a fault may include Customer Personal Data in\nthat email: a draft, an export, a screenshot, a name in a stack trace. That correspondence then sits\nin our mailbox. Where it does, Microsoft is processing Customer Personal Data on our behalf, and\nClause 6 applies to it the same as to anything else.",[67,630,631],{},"No payment processor is engaged: the Service takes no payments. One will be added here, with the\nnotice required by Clause 6, before it handles anything.",[450,633,635],{"id":634},"connected-by-the-controller-not-our-sub-processors","Connected by the Controller — not our sub-processors",[67,637,638,639,642],{},"Where the Controller connects ",[95,640,641],{},"their own"," repository, storage bucket or deployment target, the\nService reads from and writes to it on the Controller's instruction and under the Controller's own\naccount. Uploaded media is written to the storage source the Controller configures — Cloudflare R2,\nAmazon S3, Azure Blob Storage, or an S3-compatible endpoint.",[67,644,645,646,649],{},"Those providers are therefore the ",[95,647,648],{},"Controller's"," processors, not our sub-processors. We don't\ncontract with them, can't impose terms on them, and aren't liable for them. The Controller is\nresponsible for its own agreement with each, including:",[458,651,652,662],{},[461,653,654],{},[464,655,656,659],{},[467,657,658],{},"Commonly connected",[467,660,661],{},"Their terms",[480,663,664,675,683,694,704],{},[464,665,666,669],{},[485,667,668],{},"Amazon Web Services (S3)",[485,670,671],{},[71,672,673],{"href":673,"rel":674},"https:\u002F\u002Faws.amazon.com\u002Fcompliance\u002Fgdpr-center\u002F",[504],[464,676,677,680],{},[485,678,679],{},"Other providers (S3-compatible storage — MinIO, Backblaze B2, DigitalOcean Spaces, Wasabi and the like)",[485,681,682],{},"Whatever that provider publishes",[464,684,685,688],{},[485,686,687],{},"Microsoft Azure",[485,689,690],{},[71,691,692],{"href":692,"rel":693},"https:\u002F\u002Fazure.microsoft.com\u002Fen-us\u002Fexplore\u002Ftrusted-cloud\u002Fprivacy",[504],[464,695,696,699],{},[485,697,698],{},"Cloudflare (the Controller's own R2 account)",[485,700,701],{},[71,702,520],{"href":520,"rel":703},[504],[464,705,706,709],{},[485,707,708],{},"GitHub (the Controller's own repositories)",[485,710,711],{},[71,712,569],{"href":569,"rel":713},[504],[67,715,716],{},"The distinction matters for liability and for the Controller's own record of processing: a bucket the\nController owns is within the Controller's control, and this DPA doesn't extend to it.",[67,718,719,722,723,726,727,731],{},[95,720,721],{},"Some of these names appear elsewhere in a different role, so here is the untangling."," GitHub and\nMicrosoft are also sign-in providers — an account holder may authenticate with GitHub, Microsoft,\nLinkedIn, Facebook or Google. In that role they are independent controllers of the sign-in itself rather than\nsub-processors of ours: they tell us who you're, they don't process Customer Personal Data on our\ninstruction. Authentication concerns account data, not the content this DPA governs. The\n",[71,724,74],{"href":725},"\u002Fprivacy#52-signing-in"," describes it in section 5.2, and\n",[71,728,730],{"href":729},"\u002Fprivacy#sign-in-providers","section 9"," tabulates each provider and what it hands us.",[67,733,734],{},"Both also appear in the first table above, for reasons that have nothing to do with sign-in. GitHub\nis there because the Git integration genuinely is a sub-processing arrangement. Microsoft is there\nbecause our mailboxes are, as set out under that table. So each name carries up to 3 separate\nroles, and which one applies depends on what the data is rather than on whose logo is on it.",[450,736,738],{"id":737},"where-we-host-the-controllers-repository-or-bucket","Where we host the Controller's repository or bucket",[67,740,741,742,745,746,748],{},"For Controllers whose sites we built and whose infrastructure we run as part of that engagement, the\nstorage bucket may sit in ",[95,743,744],{},"our"," Cloudflare account and the repository in ",[95,747,744],{}," GitHub\norganisation. Where that's the case — and it's set out in the Controller's agreement with us —\nthe position reverses:",[99,750,751,758,761],{},[102,752,753,754,757],{},"Cloudflare and GitHub are ",[95,755,756],{},"our sub-processors"," for that content, as in the first table above, and\nwe're liable for their performance in respect of it.",[102,759,760],{},"The content is Personal Data we process on the Controller's instruction, with the full weight of\nthis DPA behind it, including deletion at the end of the engagement.",[102,762,763,766],{},[95,764,765],{},"On request, and at the end of the engagement, we transfer it out",": the repository to an\norganisation the Controller nominates, and the objects to a bucket in the Controller's own account.\nThe Controller isn't required to give a reason, and this doesn't depend on the engagement ending\namicably.",[67,768,769],{},"A Controller in this position should record it in their own record of processing. It's the one\ncase where content they might assume sits in their own infrastructure doesn't.",[149,771,773],{"id":772},"annex-4-transfer-mechanism","Annex 4 — Transfer mechanism",[67,775,776,779,780,783],{},[95,777,778],{},"The Controller doesn't need to sign Standard Contractual Clauses with us."," Sending data to us is\ncovered by Guernsey's adequacy, and the onward transfers are covered by clauses we hold with each\nsub-processor — ",[71,781,730],{"href":782},"#9-international-transfers"," sets out both.",[67,785,786,787,791],{},"If a compliance review needs the detail, write to\n",[71,788,790],{"href":789},"mailto:privacy@intracia.com","privacy@intracia.com"," and we'll tell you which clauses cover which\nprovider. These published terms bind us whether or not anything separate has been signed.",{"title":793,"searchDepth":794,"depth":794,"links":795},"",2,[796,797,798,799,800,801,802,803,804,805,806,807,808,809,810,816],{"id":151,"depth":794,"text":152},{"id":173,"depth":794,"text":174},{"id":194,"depth":794,"text":195},{"id":215,"depth":794,"text":216},{"id":222,"depth":794,"text":223},{"id":233,"depth":794,"text":234},{"id":266,"depth":794,"text":267},{"id":293,"depth":794,"text":294},{"id":304,"depth":794,"text":305},{"id":341,"depth":794,"text":342},{"id":352,"depth":794,"text":353},{"id":359,"depth":794,"text":360},{"id":368,"depth":794,"text":369},{"id":410,"depth":794,"text":411},{"id":441,"depth":794,"text":442,"children":811},[812,814,815],{"id":452,"depth":813,"text":453},3,{"id":634,"depth":813,"text":635},{"id":737,"depth":813,"text":738},{"id":772,"depth":794,"text":773},null,"The Data Processing Agreement for Intracia — our obligations as processor of the personal data our customers store in their sites.","md","The processor terms under which we handle the personal data inside your content.",{},true,"\u002Flegal\u002Fdata-processing-agreement",{"title":62,"description":818},"published","legal\u002Fdata-processing-agreement","18 August 2026","4YFJU-70LHuUiZ2jibhKU4CVqiOJJ3O8R0sjn64iJm8",1788372939056]