DPA — Core Cognitics / Intelinteract Platform
Effective Date: July 24, 2026
Provider: Core Cognitics ("Core Cognitics", "Company", "Processor", or "We")
Website: https://www.corecognitics.com
Applicable Product: Intelinteract Platform (including Web Widget, AI Voice & Chatbots, Studio, Edge Inference, Outbound Call/SMS Engine, and API Integration Services)
This Data Processing Addendum ("DPA") supplements the Terms of Service or Master Services Agreement ("Agreement") entered into by and between Core Cognitics and the entity agreeing to these terms ("Customer" or "Controller").
This DPA applies to the Processing of Customer Personal Data by Core Cognitics in connection with providing the Intelinteract platform and related services. Intelinteract enables Customer to deploy AI-powered voice and chatbot widgets, handle patient and customer inquiries, automate appointment scheduling, execute outbound marketing campaigns and appointment reminders, and perform live agent transfers.
This DPA governs Customer Personal Data generally, under the data protection laws listed in Section 3 below. It does not govern Protected Health Information ("PHI") as defined under the U.S. Health Insurance Portability and Accountability Act ("HIPAA").
Where Customer is a covered entity or business associate under HIPAA and Customer Personal Data processed through the Services includes PHI, such PHI is governed exclusively by the Business Associate Agreement ("BAA") separately executed between Customer and Core Cognitics, and not by this DPA. References to "patients," "health scheduling data," or similar categories elsewhere in this DPA (including Annex I) describe the general nature of Customer's business and Data Subjects; they do not expand this DPA's scope to cover PHI. In the event of any conflict between this DPA and the BAA with respect to PHI, the BAA shall control.
"Applicable Data Protection Laws"
means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including (where applicable) the EU General Data Protection Regulation (GDPR), the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and any other data protection law of general application in the jurisdiction where the relevant Data Subjects are located. For the avoidance of doubt, HIPAA is addressed separately under the BAA per Section 2 above and is not an "Applicable Data Protection Law" for purposes of this DPA.
"Customer Personal Data"
means any Personal Data provided by or on behalf of Customer, or collected and processed by Core Cognitics through the Intelinteract platform (including patient details, voice call audio, call transcripts, chat interaction logs, phone numbers, and appointment scheduling data), excluding PHI governed by the BAA.
"Controller"
means the entity that determines the purposes and means of Processing Personal Data (the Customer).
"Processor"
means the entity that Processes Personal Data on behalf of the Controller (Core Cognitics).
"Data Subject"
means the identified or identifiable natural person to whom the Personal Data relates (including patients, website visitors, callers, and end-users).
"Personal Data Breach"
means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Core Cognitics.
"Subprocessor"
means any third-party processor engaged by Core Cognitics to process Customer Personal Data in connection with the Services (e.g., cloud hosting providers, telecom infrastructure partners, STT/TTS voice model providers).
The parties acknowledge and agree that with respect to the Processing of Customer Personal Data:
Customer represents and warrants that:
Core Cognitics shall Process Customer Personal Data only:
Core Cognitics shall not:
Core Cognitics shall ensure that any employee, contractor, or agent authorized to process Customer Personal Data:
Core Cognitics shall implement and maintain appropriate technical and organizational security measures designed to protect Customer Personal Data against Personal Data Breaches, as detailed in Annex II of this DPA.
These measures include, but are not limited to:
Customer provides general written authorization for Core Cognitics to engage Subprocessors to assist in delivering the Services (including telephony providers and cloud infrastructure hosts).
Core Cognitics shall:
Core Cognitics shall provide Customer with notification of any intended addition or replacement of Subprocessors (via email or platform update). Customer may object to a new Subprocessor on reasonable data protection grounds within thirty (30) days of receiving notice. If Customer objects, the parties will work in good faith to resolve the concern. If no resolution is reached, Customer may terminate the affected Services without penalty.
Core Cognitics shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject seeking to exercise rights of access, rectification, erasure, restriction, data portability, or objection under Applicable Data Protection Laws.
Taking into account the nature of the Processing, Core Cognitics shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests. Customer shall be responsible for any reasonable costs arising from non-standard assistance requested.
In the event of a confirmed Personal Data Breach impacting Customer Personal Data, Core Cognitics shall:
Core Cognitics shall take immediate steps to investigate, mitigate, and remediate any Personal Data Breach at its own expense, keeping Customer informed of progress.
Core Cognitics shall provide reasonable assistance to Customer with any data protection impact assessments (DPIAs) and prior consultations with supervisory authorities required under Applicable Data Protection Laws, taking into account the nature of Processing and information available to Core Cognitics.
Upon termination or expiration of the Agreement, Core Cognitics shall, at Customer's written election, enable Customer to export or download all Customer Personal Data (including interaction logs, patient appointment records, and call recordings) for up to ninety (90) days following termination.
Within one hundred eighty (180) days following the expiration of the retention window or upon Customer's explicit request, Core Cognitics shall securely delete and purge all copies of Customer Personal Data from its production systems and backups, except to the extent that Applicable Data Protection Laws require continued retention.
Core Cognitics shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA.
Customer or an independent third-party auditor designated by Customer may conduct an audit of Core Cognitics' data processing controls once per calendar year, upon thirty (30) days' advance written notice. Audits shall be conducted during normal business hours without disrupting business operations. Customer shall bear all costs associated with such audits unless the audit reveals a material failure by Core Cognitics to comply with this DPA.
Where Customer Personal Data is transferred outside the European Economic Area (EEA), United Kingdom (UK), or Switzerland to a country not recognized as providing an adequate level of data protection, such transfers shall be governed by:
| Field | Detail |
|---|---|
| Data Exporter | Customer (subscribing business, clinic, healthcare provider, or enterprise). |
| Data Importer | Core Cognitics (provider of the Intelinteract AI platform). |
| Categories of Data Subjects | Patients, prospective clients, callers, website visitors, and employees of Customer. |
| Categories of Personal Data | Contact Info: Name, phone number, email address, physical address. Interaction Data: AI chatbot transcripts, voice call audio recordings, caller speech-to-text transcripts, intent metadata, appointment dates, preferred doctors/departments. System Data: IP address, browser type, widget telemetry, session IDs. |
| Special Categories of Data | Patient inquiry details and health scheduling contexts provided voluntarily by Data Subjects during calls/chats, to the extent such details do not constitute PHI (see Section 2). Processed strictly under Customer's directive and subject to enhanced security protocols. |
| Frequency & Duration | Continuous during the active subscription term of the Agreement. |
Access Control & Identity Management
Multi-factor authentication (MFA), role-based access control (RBAC), strict password governance, automated session timeouts.
Data Transmission Security
Mandatory TLS 1.3 encryption for web widgets and APIs; secure SIP/SRTP telephony transport for voice interactions.
Data Storage Security
AES-256 bit encryption for databases, call recording archives, and transcript logs.
Network & Infrastructure Security
Web Application Firewalls (WAF), Distributed Denial of Service (DDoS) protection, continuous vulnerability scanning, and isolated container execution.
System Resiliency & Backup
Automated daily backups with geo-redundant storage, disaster recovery protocols, and carrier-grade uptime SLA monitoring.
Data Separation
Strict logical and database segregation of Customer tenant data across cloud environments.
For inquiries regarding this Data Processing Addendum or Data Protection compliance, please contact:
| Field | Detail |
|---|---|
| Team | Core Cognitics Privacy Team |
| [email protected] | |
| Website | https://www.corecognitics.com |
© 2026 Core Cognitics. All Rights Reserved.