Legal
Data Processing Agreement
How we process the personal data in what your company puts into InteliLang, on your behalf, as Article 28 of the GDPR requires.
Last updated 28 September 2026.
1. Who this agreement is between
The controller is the company that holds an InteliLang account and accepted the Terms of service ("the company", "you").
The processor is Dodera Software SRL, a Romanian limited liability company with its registered office at Str. Banat nr. 1, Satu Mare, Romania, registered with the Trade Register under J30/958/2023, tax identification number (CUI) 49004234, e-mail office@doderasoft.com ("we", "us").
This agreement is part of the Terms of service at https://intelilang.com/terms and takes effect when the company accepts them. Words such as personal data, processing, controller, processor, sub-processor and personal data breach mean what they mean in the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Subject matter and duration
We process personal data contained in what the company and its people put into InteliLang, or connect to it, so that we can provide the service described in the Terms.
The agreement lasts as long as the company has an InteliLang account, and after that for as long as we still hold any of its personal data under section 13.
3. Nature and purpose of the processing
We process the company's personal data only to provide InteliLang to it. That means:
- Storing — content from connected tools, uploads, transcripts and notes, in full, in a database and on a disk in Germany.
- Indexing — splitting content into passages and computing search vectors on our own server, so it can be searched by meaning and by words.
- Reading into memory — sending new content, through the company's own AI account, to be turned into decisions, opinions, action items, open questions and risks, and compiling a short brief of each project.
- Answering — finding the passages a person may see that answer their question, and sending them, with the question, to the company's own AI account for an answer that cites them.
- Transcribing — turning meeting recordings into text with the engine the company chose. The audio is not stored.
- Notifying — sending e-mails, and messages in the company's Slack, that people asked for: sign-in links, invitations, the morning brief, alerts about decisions and to-dos.
- Exporting — preparing a download of the company's data, or one person's, when someone entitled to it asks.
- Deleting — removing content when a person deletes it, when it passes the company's retention period, and when the company is deleted.
We do not use the company's personal data for any other purpose: not to train models, not for advertising, and not to build profiles of anyone.
4. Types of personal data
Whatever personal data the company chooses to put in, which typically includes:
- People who use the app — name, e-mail address, role in the company and on each project, and the accounts they are matched to on Slack, GitHub and Jira.
- Content — messages, threads, meeting transcripts, documents, notes, issues, pull requests, commits and comments, including anything about people written in them.
- What the memory says about people — who decided, proposed, objected to or was given something, with short quotes from the source.
- Details that come with content — authors' names and handles, dates, and links back to where the content came from.
- Usage records — who asked the AI to do what, when, and what it cost.
- The activity log — who changed keys, people, roles, projects, sources, retention or sharing, and when.
InteliLang is not meant for special categories of personal data (health, religion, political opinions, and the others in Article 9 of the GDPR) or for data about criminal convictions. The company should keep them out, and if it puts them in, it is responsible for having a legal basis to do so.
5. Whose data it is
The people the personal data is about are:
- The company's people — employees and contractors who have an account.
- The company's clients — people from client organisations invited into projects.
- People in the content — meeting participants and the authors of messages, documents, issues and code in connected tools.
- People mentioned — anyone named or described in that content.
6. Your instructions
We process the company's personal data only on its documented instructions. Those instructions are this agreement, the Terms, the settings the company's owners and admins choose in the app, and anything else the company asks us in writing. If the law ever requires us to process it otherwise, we tell the company first, unless that law forbids telling it.
If we think an instruction breaks the GDPR or another data protection law, we tell the company straight away and may hold off following it until the company confirms or changes it.
The company is responsible for having a legal basis for what it puts in, for telling the people concerned, including telling everyone in a meeting before recording it, and for the instructions it gives us.
7. Confidentiality
Only the people at Dodera Software who run the service can reach the systems that hold the company's data. Each of them is bound to keep it confidential by contract or by law, and that duty lasts after they stop working with us. They look at the company's content only when that is needed to run the service, to fix a fault or to do what the company asked.
8. Security
We take the technical and organisational measures Article 32 of the GDPR requires, appropriate to the risk. Annex 1 lists the ones in place. Our Security page at https://intelilang.com/security describes them in more detail, and also what we do not have.
We may change these measures as the service changes, but never in a way that lowers the overall level of protection.
9. Sub-processors
The company gives us general authorisation to use sub-processors. Those we use today are in Annex 2.
Before we add or replace a sub-processor that would process the company's personal data, we e-mail the company's owners and admins at least 30 days ahead, saying who it is, where it processes data and what for.
The company may object on reasonable grounds related to data protection by writing to us within that time. We then try to find a solution together. If we cannot, the company may end the contract before the change takes effect.
Each sub-processor is bound by a written contract to data protection obligations at least as strict as ours in this agreement, and we remain responsible to the company for what our sub-processors do.
10. Providers the company chooses itself
Some providers work under the company's own account, not ours: Anthropic, which runs the AI on the company's own key; Soniox, if the company records with it; TypeSafe, if the company turns it on; and the Slack workspace, GitHub organisation and Jira site the company connects. They are not our sub-processors. We send them data only because the company chose them in its settings, and what they may do with it is governed by the company's own agreement with them.
The same goes for the speech service built into a person's browser, when the company leaves that recording engine on, and for any assistant a person connects to InteliLang: what that assistant reads goes to whoever runs it.
11. Helping you meet your obligations
People can ask the company to see, correct, delete, restrict or take away their data. InteliLang lets the company do most of this itself: search and memory to find it, deleting a source, item, note or project, retention settings, and downloading a person's or the whole company's data. Where that is not enough, we help, as far as we reasonably can. If a request reaches us directly, we pass it to the company and do not answer it ourselves unless the company asks us to.
We also help the company, with the information we have, with security, with breach notifications, with data protection impact assessments and with prior consultation of a supervisory authority, under Articles 32 to 36 of the GDPR.
12. Personal data breaches
If we become aware of a breach affecting the company's personal data, we tell the company's owners and admins without undue delay, so the company can meet its own 72-hour deadline. We tell them as much of the following as we know, and the rest as we learn it:
- What happened — the kind of breach, and roughly which data and how many people and records it concerns.
- Who to talk to — a person at Dodera Software who can answer questions about it.
- Likely consequences — what the breach is likely to mean for the people concerned.
- What is being done — what we have done or propose to do about it, including to limit the harm.
We record every breach, with its facts, effects and what was done. Telling the company is not an admission of fault.
13. When the contract ends
Before an account ends, the company's owners and admins can download all of its data from Settings → Data and deletion. We help if the company needs it in another form.
When the company is deleted, its personal data is deleted from the database and the disk straight away; if the account ends another way, we delete it within 30 days. If a copy exists anywhere else we control, it is deleted within the same 30 days and not used in the meantime.
We keep something only where Romanian or EU law requires us to, such as invoices, and only for as long as it requires. We confirm the deletion in writing if the company asks.
14. Showing that we comply
We make available to the company the information it needs to show that we meet this agreement and Article 28 of the GDPR, and we answer its reasonable written questions.
If that is not enough, the company, or an independent auditor it chooses who is bound to confidentiality and is not our competitor, may audit us, including by inspection. The company gives us at least 30 days' notice, audits at most once a year unless a breach or a supervisory authority requires more, pays its own costs, and takes care not to disturb the service or reach other companies' data.
15. Transfers outside the EU
We process the company's personal data inside the European Economic Area, and our sub-processors in Annex 2 do too. We do not transfer it outside the EEA unless the company instructs us to, or unless we have told the company under section 9 and the transfer is covered by an adequacy decision, such as the EU-US Data Privacy Framework for a certified company, or by the European Commission's Standard Contractual Clauses.
Data that reaches the providers in section 10 leaves the EEA when those providers are outside it, as Anthropic, Soniox and TypeSafe are, in the United States. The company chose them, under its own accounts; the safeguards for those transfers are in the company's own agreements with them.
16. Liability and precedence
Each party's liability under this agreement is governed by the liability section of the Terms, except where the GDPR does not allow it to be limited.
If this agreement and the Terms say different things about personal data, this agreement prevails. Romanian law governs it, and the courts named in the Terms decide disputes about it.
Annex 1. Security measures
These are in place in the code and the way it is run today:
- Separation between companies — every table that holds customer data has a row-level security policy in Postgres, and the application reads it as a database role those policies apply to, set for one company and one person on every request. A query that forgets its filter returns nothing. Tests against a real database check this on every change.
- Who sees what inside a company — every piece of content is visible to the client, the team or only to leadership, and the database applies that to every query. Chats are private to the person who wrote them.
- Encrypted keys and tokens — AI keys and connector tokens are encrypted with XChaCha20-Poly1305 under a key kept outside the database, and are never sent to the browser.
- Credentials out of the application's reach — sessions, password hashes, two-step secrets, personal-key hashes and sign-in links are in tables the application's database role cannot read.
- Passwords — stored only as scrypt hashes. People can sign in with a one-time e-mail link instead.
- Two-step sign-in — codes from an authenticator app, with backup codes, available to everyone and required for our own staff's administration area.
- Sessions — an http-only, secure, same-site cookie, checked against the database on every request, ending after seven days or on sign-out. Sign-in links work once, for fifteen minutes.
- Rate limits and input checks — requests are rate limited per client, sign-in attempts more tightly, every input is checked against a schema, and uploads have a size limit.
- Encryption in transit — HTTPS for everything, with HSTS. The database is reachable only on the host's private network.
- Browser protections — a nonce-based content security policy, framing limited to our own site, no referrer sent, and the camera and location turned off.
- Recordings — audio is never stored by the application; only the transcript is saved.
- Assistant connections — an assistant connected by a person reads only what that person may read. Personal keys are stored as hashes, limited in rate and revocable; an assistant's access is checked against the person's consent on every call.
- Activity log — every change to keys, people, roles, projects, sources, retention, sharing and billing is recorded, without secrets or content, and shown to the company's owners and admins.
- Retention — content, chats and usage records are deleted every night once they pass the periods the company set.
- Our people — only the people who run the service can reach the server, they are bound to confidentiality, and they look at content only to fix a fault or do what the company asked.
- Location — the server and the database run at Hetzner in Nuremberg, Germany.
Annex 2. Sub-processors
We use these sub-processors for the company's personal data:
- Hetzner Online GmbH, Germany — hosting: the server the application runs on and the database and disk that hold the data, in Nuremberg, Germany.
- Hostinger International Ltd., Cyprus — e-mail, from its data centres in the EU: sign-in links, invitations, the morning brief and alerts, which carry project content, and the messages the company writes to us.
Stripe (billing), Google ("Continue with Google") and PostHog (product analytics) do not process the company's content. Stripe and Google act as controllers of what they receive, and PostHog processes usage data that we collect for our own purposes, as the Privacy page explains. The providers the company chooses itself are in section 10.
Signatures
Accepting the Terms is enough for this agreement to apply. Sign below only if you want a signed copy.
For the controller (the company)
Name
Role
Date
Signature
For the processor, Dodera Software SRL
Name
Role
Date
Signature
A signed copy
This agreement applies as soon as your company accepts the Terms. If you need it signed, print it, sign it and send it to us; we countersign it and send it back.
office@doderasoft.com