Core Cognitics
  • Intelinteract
  • Industries
  • Company
  • Blog
ContactBook a demo

Data Processing Addendum

DPA — Core Cognitics / Intelinteract Platform

Effective Date: July 24, 2026

Provider: Core Cognitics ("Core Cognitics", "Company", "Processor", or "We")

Website: https://www.corecognitics.com

Applicable Product: Intelinteract Platform (including Web Widget, AI Voice & Chatbots, Studio, Edge Inference, Outbound Call/SMS Engine, and API Integration Services)

01Overview and Scope

This Data Processing Addendum ("DPA") supplements the Terms of Service or Master Services Agreement ("Agreement") entered into by and between Core Cognitics and the entity agreeing to these terms ("Customer" or "Controller").

This DPA applies to the Processing of Customer Personal Data by Core Cognitics in connection with providing the Intelinteract platform and related services. Intelinteract enables Customer to deploy AI-powered voice and chatbot widgets, handle patient and customer inquiries, automate appointment scheduling, execute outbound marketing campaigns and appointment reminders, and perform live agent transfers.

02Relationship to HIPAA and the Business Associate Agreement (BAA)

This DPA governs Customer Personal Data generally, under the data protection laws listed in Section 3 below. It does not govern Protected Health Information ("PHI") as defined under the U.S. Health Insurance Portability and Accountability Act ("HIPAA").

Where Customer is a covered entity or business associate under HIPAA and Customer Personal Data processed through the Services includes PHI, such PHI is governed exclusively by the Business Associate Agreement ("BAA") separately executed between Customer and Core Cognitics, and not by this DPA. References to "patients," "health scheduling data," or similar categories elsewhere in this DPA (including Annex I) describe the general nature of Customer's business and Data Subjects; they do not expand this DPA's scope to cover PHI. In the event of any conflict between this DPA and the BAA with respect to PHI, the BAA shall control.

03Definitions

"Applicable Data Protection Laws"

means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including (where applicable) the EU General Data Protection Regulation (GDPR), the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and any other data protection law of general application in the jurisdiction where the relevant Data Subjects are located. For the avoidance of doubt, HIPAA is addressed separately under the BAA per Section 2 above and is not an "Applicable Data Protection Law" for purposes of this DPA.

"Customer Personal Data"

means any Personal Data provided by or on behalf of Customer, or collected and processed by Core Cognitics through the Intelinteract platform (including patient details, voice call audio, call transcripts, chat interaction logs, phone numbers, and appointment scheduling data), excluding PHI governed by the BAA.

"Controller"

means the entity that determines the purposes and means of Processing Personal Data (the Customer).

"Processor"

means the entity that Processes Personal Data on behalf of the Controller (Core Cognitics).

"Data Subject"

means the identified or identifiable natural person to whom the Personal Data relates (including patients, website visitors, callers, and end-users).

"Personal Data Breach"

means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Core Cognitics.

"Subprocessor"

means any third-party processor engaged by Core Cognitics to process Customer Personal Data in connection with the Services (e.g., cloud hosting providers, telecom infrastructure partners, STT/TTS voice model providers).

04Roles and Processing Instructions

4.1 Roles of the Parties

The parties acknowledge and agree that with respect to the Processing of Customer Personal Data:

  • Customer acts as the Controller (or a processor acting on behalf of a third-party controller).
  • Core Cognitics acts as the Processor.

4.2 Customer Obligations & Consents

Customer represents and warrants that:

  • It has complied, and will continue to comply, with all Applicable Data Protection Laws in providing Personal Data to Core Cognitics.
  • It has obtained all necessary rights, notices, and explicit consents from Data Subjects (including patients interacting with the Intelinteract widget or receiving outbound calls/SMS) to permit the Processing of Personal Data by Core Cognitics.

4.3 Processing Instructions

Core Cognitics shall Process Customer Personal Data only:

  • In accordance with Customer's documented instructions as set forth in the Agreement, this DPA, and the configuration settings selected within the Intelinteract platform;
  • To provide, maintain, optimize, and secure the Services; and
  • As required by applicable law, provided Core Cognitics informs Customer of such legal requirement prior to processing, unless prohibited by law on important grounds of public interest.

4.4 Restrictions on Use of Personal Data

Core Cognitics shall not:

  • Sell, rent, or trade Customer Personal Data to any third party;
  • Retain, use, or disclose Customer Personal Data for any purpose other than the specific business purpose of performing the Services under the Agreement;
  • Retain, use, or disclose Customer Personal Data outside of the direct business relationship between Core Cognitics and Customer; or
  • Combine Customer Personal Data with personal data received from or on behalf of another third party, except as permitted under this DPA or Applicable Data Protection Laws.

05Confidentiality and Personnel

Core Cognitics shall ensure that any employee, contractor, or agent authorized to process Customer Personal Data:

  • Is subject to strict contractual or statutory duties of confidentiality;
  • Is trained on data privacy, security standards, and handling of sensitive interaction logs; and
  • Accesses Customer Personal Data solely on a strict need-to-know basis necessary to fulfill Core Cognitics' duties under the Agreement.

06Security of Processing

6.1 Technical and Organizational Measures

Core Cognitics shall implement and maintain appropriate technical and organizational security measures designed to protect Customer Personal Data against Personal Data Breaches, as detailed in Annex II of this DPA.

6.2 Security Governance

These measures include, but are not limited to:

  • Encryption in Transit & at Rest: Standard TLS 1.3 encryption for web/voice traffic and AES-256 for resting database entries and call recordings.
  • Role-Based Access Control (RBAC): Scoped user permissions and multi-factor authentication for platform administration.
  • Carrier-Grade Edge Execution: Support for edge inference deployment to ensure voice telemetry and patient data can remain strictly localized when required by enterprise governance.

07Subprocessors

7.1 Authorized Subprocessors

Customer provides general written authorization for Core Cognitics to engage Subprocessors to assist in delivering the Services (including telephony providers and cloud infrastructure hosts).

7.2 Subprocessor Obligations

Core Cognitics shall:

  • Enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA; and
  • Remain fully liable to Customer for the performance of Subprocessors' obligations.

7.3 Notification of Subprocessor Changes

Core Cognitics shall provide Customer with notification of any intended addition or replacement of Subprocessors (via email or platform update). Customer may object to a new Subprocessor on reasonable data protection grounds within thirty (30) days of receiving notice. If Customer objects, the parties will work in good faith to resolve the concern. If no resolution is reached, Customer may terminate the affected Services without penalty.

08Data Subject Rights and Assistance

8.1 Data Subject Requests

Core Cognitics shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject seeking to exercise rights of access, rectification, erasure, restriction, data portability, or objection under Applicable Data Protection Laws.

8.2 Processor Assistance

Taking into account the nature of the Processing, Core Cognitics shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests. Customer shall be responsible for any reasonable costs arising from non-standard assistance requested.

09Personal Data Breach Management

9.1 Breach Notification

In the event of a confirmed Personal Data Breach impacting Customer Personal Data, Core Cognitics shall:

  • Notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach);
  • Provide details regarding the nature of the breach, affected data categories, estimated number of affected Data Subjects, and potential impacts;
  • Describe the remedial actions taken or planned to mitigate the risk and contain the breach.

9.2 Investigation & Remediation

Core Cognitics shall take immediate steps to investigate, mitigate, and remediate any Personal Data Breach at its own expense, keeping Customer informed of progress.

10Data Protection Impact Assessments (DPIA)

Core Cognitics shall provide reasonable assistance to Customer with any data protection impact assessments (DPIAs) and prior consultations with supervisory authorities required under Applicable Data Protection Laws, taking into account the nature of Processing and information available to Core Cognitics.

11Deletion or Return of Personal Data

11.1 Post-Termination Handover

Upon termination or expiration of the Agreement, Core Cognitics shall, at Customer's written election, enable Customer to export or download all Customer Personal Data (including interaction logs, patient appointment records, and call recordings) for up to ninety (90) days following termination.

11.2 Data Deletion

Within one hundred eighty (180) days following the expiration of the retention window or upon Customer's explicit request, Core Cognitics shall securely delete and purge all copies of Customer Personal Data from its production systems and backups, except to the extent that Applicable Data Protection Laws require continued retention.

12Audit and Compliance Rights

12.1 Compliance Documentation

Core Cognitics shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA.

12.2 Audits

Customer or an independent third-party auditor designated by Customer may conduct an audit of Core Cognitics' data processing controls once per calendar year, upon thirty (30) days' advance written notice. Audits shall be conducted during normal business hours without disrupting business operations. Customer shall bear all costs associated with such audits unless the audit reveals a material failure by Core Cognitics to comply with this DPA.

13International Data Transfers

Where Customer Personal Data is transferred outside the European Economic Area (EEA), United Kingdom (UK), or Switzerland to a country not recognized as providing an adequate level of data protection, such transfers shall be governed by:

  • The EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor or Module 3: Processor-to-Processor);
  • The UK International Data Transfer Addendum (UK Addendum); or
  • An equivalent legally valid transfer mechanism under Applicable Data Protection Laws.

Annex I: Details of Processing

FieldDetail
Data ExporterCustomer (subscribing business, clinic, healthcare provider, or enterprise).
Data ImporterCore Cognitics (provider of the Intelinteract AI platform).
Categories of Data SubjectsPatients, prospective clients, callers, website visitors, and employees of Customer.
Categories of Personal DataContact Info: Name, phone number, email address, physical address. Interaction Data: AI chatbot transcripts, voice call audio recordings, caller speech-to-text transcripts, intent metadata, appointment dates, preferred doctors/departments. System Data: IP address, browser type, widget telemetry, session IDs.
Special Categories of DataPatient inquiry details and health scheduling contexts provided voluntarily by Data Subjects during calls/chats, to the extent such details do not constitute PHI (see Section 2). Processed strictly under Customer's directive and subject to enhanced security protocols.
Frequency & DurationContinuous during the active subscription term of the Agreement.

Annex II: Technical and Organizational Security Measures

Access Control & Identity Management

Multi-factor authentication (MFA), role-based access control (RBAC), strict password governance, automated session timeouts.

Data Transmission Security

Mandatory TLS 1.3 encryption for web widgets and APIs; secure SIP/SRTP telephony transport for voice interactions.

Data Storage Security

AES-256 bit encryption for databases, call recording archives, and transcript logs.

Network & Infrastructure Security

Web Application Firewalls (WAF), Distributed Denial of Service (DDoS) protection, continuous vulnerability scanning, and isolated container execution.

System Resiliency & Backup

Automated daily backups with geo-redundant storage, disaster recovery protocols, and carrier-grade uptime SLA monitoring.

Data Separation

Strict logical and database segregation of Customer tenant data across cloud environments.

Contact

For inquiries regarding this Data Processing Addendum or Data Protection compliance, please contact:

FieldDetail
TeamCore Cognitics Privacy Team
Email[email protected]
Websitehttps://www.corecognitics.com

© 2026 Core Cognitics. All Rights Reserved.

AI where it helps.
People where it matters.

Connect with us
WhatsApp
Scan to chat with Core Cognitics on WhatsApp

Scan to chat

Intelinteract

  • Platform
  • Studio
  • Edge

Industries

  • Healthcare
  • Telecom
  • Education
  • Agriculture
  • Retail
  • EPCM

Company

  • Home
  • About
  • Blog
  • Careers
  • Trust & Security
  • Contact

Legals

  • Copyright & IP Policy
  • Privacy Notice
  • Communication Compliance
  • User & Acceptable Use Policy

Office Locations

Parkside, London Rd, Ipswich, Suffolk, IP2 0SS, United Kingdom

Special Economic Zone, Kerala Govt. Cyberpark, India

Ras Al Khor Industrial Second, Dubai, UAE

CLOUDWISE TECHNOLOGIES QFZ LLC Building 1, Street 504, Zone 49, Ras Bufontas Free Zone Doha, Qatar

Headquarters

Parkside, London Rd, Ipswich,
Suffolk, IP2 0SS, United Kingdom

Contact

[email protected]

🇬🇧+44 20 3886 3934

Certifications & Compliance

ISO 27001
ISO 27001
ISO 9001
ISO 9001
GDPR
GDPR
HIPAA
HIPAA
Cyber Essentials
Cyber Essentials
CPAASAA
CPAASAA
Core Cognitics

Follow Us

LinkedInFacebookInstagramYouTube
Privacy Policy|T & C|Cookie Policy|DPA

© 2026 Core Cognitics. All rights reserved.