Core Cognitics
  • Intelinteract
  • Industries
  • Company
  • Blog
ContactGet Started

Data Processing Addendum

Effective Date: July 24, 2026

Provider: Core Cognitics ("Core Cognitics", "Company", "Processor", or "We")

Website: https://www.corecognitics.com/

Applicable Product: Intelinteract Platform (including Web Widget, AI Voice & Chatbots, Studio, Edge Inference, Outbound Call/SMS Engine, and API Integration Services)

01Overview and Scope

This Data Processing Addendum ("DPA") supplements the Terms of Service or Master Services Agreement ("Agreement") entered into by and between Core Cognitics and the entity agreeing to these terms ("Customer" or "Controller").

This DPA applies to the Processing of Customer Personal Data by Core Cognitics in connection with providing the Intelinteract platform and related services. Intelinteract enables Customer to deploy AI-powered voice and chatbot widgets, handle patient and customer inquiries, automate appointment scheduling, execute outbound marketing campaigns and appointment reminders, and perform live agent transfers.

02Relationship to HIPAA and the Business Associate Agreement (BAA)

This DPA governs Customer Personal Data generally, under the data protection laws listed in Section 3 below. It does not govern Protected Health Information ("PHI") as defined under the U.S. Health Insurance Portability and Accountability Act ("HIPAA").

Where Customer is a covered entity or business associate under HIPAA and Customer Personal Data processed through the Services includes PHI, such PHI is governed exclusively by the Business Associate Agreement ("BAA") separately executed between Customer and Core Cognitics, and not by this DPA. References to "patients," "health scheduling data," or similar categories elsewhere in this DPA (including Annex I) describe the general nature of Customer's business and Data Subjects; they do not expand this DPA's scope to cover PHI. In the event of any conflict between this DPA and the BAA with respect to PHI, the BAA shall control.

03Definitions

"Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including (where applicable) the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and applicable state privacy laws. For the avoidance of doubt, HIPAA is addressed separately under the BAA per Section 2 above and is not an "Applicable Data Protection Law" for purposes of this DPA.

"Customer Personal Data" means any Personal Data provided by or on behalf of Customer, or collected and processed by Core Cognitics through the Intelinteract platform (including patient details, voice call audio, call transcripts, chat interaction logs, phone numbers, and appointment scheduling data), excluding PHI governed by the BAA.

"Controller" means the entity that determines the purposes and means of Processing Personal Data (the Customer).

"Processor" means the entity that Processes Personal Data on behalf of the Controller (Core Cognitics).

"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates (including patients, website visitors, callers, and end-users).

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Core Cognitics.

"Subprocessor" means any third-party processor engaged by Core Cognitics to process Customer Personal Data in connection with the Services (e.g., cloud hosting providers, telecom infrastructure partners, STT/TTS voice model providers).

04Roles and Processing Instructions

4.1 Roles of the Parties

The parties acknowledge and agree that with respect to the Processing of Customer Personal Data:

  • Customer acts as the Controller (or a processor acting on behalf of a third-party controller).
  • Core Cognitics acts as the Processor.

4.2 Customer Obligations & Consents

Customer represents and warrants that:

  • It has complied, and will continue to comply, with all Applicable Data Protection Laws in providing Personal Data to Core Cognitics.
  • It has obtained all necessary rights, notices, and explicit consents from Data Subjects (including patients interacting with the Intelinteract widget or receiving outbound calls/SMS) to permit the Processing of Personal Data by Core Cognitics.

4.3 Processing Instructions

Core Cognitics shall Process Customer Personal Data only:

  • In accordance with Customer's documented instructions as set forth in the Agreement, this DPA, and the configuration settings selected within the Intelinteract platform;
  • To provide, maintain, optimize, and secure the Services; and
  • As required by applicable law, provided Core Cognitics informs Customer of such legal requirement prior to processing, unless prohibited by law on important grounds of public interest.

4.4 CCPA/CPRA Specific Terms

Core Cognitics certifies that it understands and will comply with the CCPA/CPRA requirements. Specifically, Core Cognitics shall not:

  • "Sell" or "Share" Customer Personal Data (as those terms are defined under the CCPA);
  • Retain, use, or disclose Customer Personal Data for any purpose other than the specific business purpose of performing the Services under the Agreement;
  • Retain, use, or disclose Customer Personal Data outside of the direct business relationship between Core Cognitics and Customer; or
  • Combine Customer Personal Data with personal data received from or on behalf of another third party, except as permitted under the CCPA.

05Confidentiality and Personnel

Core Cognitics shall ensure that any employee, contractor, or agent authorized to process Customer Personal Data:

  • Is subject to strict contractual or statutory duties of confidentiality;
  • Is trained on data privacy, security standards, and handling of sensitive interaction logs; and
  • Accesses Customer Personal Data solely on a strict need-to-know basis necessary to fulfill Core Cognitics' duties under the Agreement.

06Security of Processing

6.1 Technical and Organizational Measures

Core Cognitics shall implement and maintain appropriate technical and organizational security measures designed to protect Customer Personal Data against Personal Data Breaches, as detailed in Annex II of this DPA.

6.2 Security Governance

These measures include, but are not limited to:

  • Encryption in Transit & at Rest: Standard TLS 1.3 encryption for web/voice traffic and AES-256 for resting database entries and call recordings.
  • Role-Based Access Control (RBAC): Scoped user permissions and multi-factor authentication for platform administration.
  • Carrier-Grade Edge Execution: Support for edge inference deployment to ensure voice telemetry and patient data can remain strictly localized when required by enterprise governance.

07Subprocessors

7.1 Authorized Subprocessors

Customer provides general written authorization for Core Cognitics to engage Subprocessors to assist in delivering the Services (including telephony providers, cloud infrastructure hosts, and neural voice synthesis providers).

7.2 Subprocessor Obligations

Core Cognitics shall:

  • Enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA; and
  • Remain fully liable to Customer for the performance of Subprocessors' obligations.

7.3 Notification of Subprocessor Changes

Core Cognitics shall provide Customer with notification of any intended addition or replacement of Subprocessors (via email or platform update). Customer may object to a new Subprocessor on reasonable data protection grounds within thirty (30) days of receiving notice. If Customer objects, the parties will work in good faith to resolve the concern. If no resolution is reached, Customer may terminate the affected Services without penalty.

08Data Subject Rights and Assistance

8.1 Data Subject Requests

Core Cognitics shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject seeking to exercise rights of access, rectification, erasure, restriction, data portability, or objection under Applicable Data Protection Laws.

8.2 Processor Assistance

Taking into account the nature of the Processing, Core Cognitics shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests. Customer shall be responsible for any reasonable costs arising from non-standard assistance requested.

09Personal Data Breach Management

9.1 Breach Notification

In the event of a confirmed Personal Data Breach impacting Customer Personal Data, Core Cognitics shall:

  • Notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach);
  • Provide details regarding the nature of the breach, affected data categories, estimated number of affected Data Subjects, and potential impacts;
  • Describe the remedial actions taken or planned to mitigate the risk and contain the breach.

9.2 Investigation & Remediation

Core Cognitics shall take immediate steps to investigate, mitigate, and remediate any Personal Data Breach at its own expense, keeping Customer informed of progress.

10Data Protection Impact Assessments (DPIA)

Core Cognitics shall provide reasonable assistance to Customer with any data protection impact assessments (DPIAs) and prior consultations with supervisory authorities required under Applicable Data Protection Laws, taking into account the nature of Processing and information available to Core Cognitics.

11Deletion or Return of Personal Data

11.1 Post-Termination Handover

Upon termination or expiration of the Agreement, Core Cognitics shall, at Customer's written election, enable Customer to export or download all Customer Personal Data (including interaction logs, patient appointment records, and call recordings) for up to ninety (90) days following termination.

11.2 Data Deletion

Within one hundred eighty (180) days following the expiration of the retention window or upon Customer's explicit request, Core Cognitics shall securely delete and purge all copies of Customer Personal Data from its production systems and backups, except to the extent that Applicable Data Protection Laws require continued retention.

12Audit and Compliance Rights

12.1 Compliance Documentation

Core Cognitics shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA.

12.2 Audits

Customer or an independent third-party auditor designated by Customer may conduct an audit of Core Cognitics' data processing controls once per calendar year, upon thirty (30) days' advance written notice. Audits shall be conducted during normal business hours without disrupting business operations. Customer shall bear all costs associated with such audits unless the audit reveals a material failure by Core Cognitics to comply with this DPA.

13International Data Transfers

Where Customer Personal Data is transferred outside the European Economic Area (EEA), United Kingdom (UK), or Switzerland to a country not recognized as providing an adequate level of data protection, such transfers shall be governed by:

  • The EU Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor or Module 3: Processor-to-Processor);
  • The UK International Data Transfer Addendum (UK Addendum); or
  • An equivalent legally valid transfer mechanism under Applicable Data Protection Laws.

Annex IDetails of Processing

Data Exporter: Customer (subscribing business, clinic, healthcare provider, or enterprise).

Data Importer: Core Cognitics (provider of the Intelinteract AI platform).

Categories of Data Subjects: Patients, prospective clients, callers, website visitors, and employees of Customer.

Frequency & Duration: Continuous during the active subscription term of the Agreement.

Categories of Personal Data:

  • Contact Info: Name, phone number, email address, physical address.
  • Interaction Data: AI chatbot transcripts, voice call audio recordings, caller speech-to-text transcripts, intent metadata, appointment dates, preferred doctors/departments.
  • System Data: IP address, browser type, widget telemetry, session IDs.
  • Special Categories (Sensitive Data): Patient inquiry details and health scheduling contexts provided voluntarily by Data Subjects during calls/chats, to the extent such details do not constitute PHI (see Section 2). Processed strictly under Customer's directive and subject to enhanced security protocols.

Annex IITechnical and Organizational Security Measures

  • Access Control & Identity Management: Multi-factor authentication (MFA), role-based access control (RBAC), strict password governance, automated session timeouts.
  • Data Transmission Security: Mandatory TLS 1.3 encryption for web widgets and APIs; secure SIP/SRTP telephony transport for voice interactions.
  • Data Storage Security: AES-256 bit encryption for databases, call recording archives, and transcript logs.
  • Network & Infrastructure Security: Web Application Firewalls (WAF), Distributed Denial of Service (DDoS) protection, continuous vulnerability scanning, and isolated container execution.
  • System Resiliency & Backup: Automated daily backups with geo-redundant storage, disaster recovery protocols, and carrier-grade uptime SLA monitoring.
  • Data Separation: Strict logical and database segregation of Customer tenant data across cloud environments.

ContactInquiries

For inquiries regarding this Data Processing Addendum or Data Protection compliance, please contact:

FieldDetail
TeamCore Cognitics Privacy Team
Email[email protected]
Websitehttps://www.corecognitics.com/

AI where it helps.
People where it matters.

Connect with us
WhatsApp
Scan to chat with Core Cognitics on WhatsApp

Scan to chat

Intelinteract

  • Platform
  • Studio
  • Edge

Industries

  • Healthcare
  • Telecom
  • Education
  • Agriculture
  • Retail
  • EPCM

Company

  • Home
  • About
  • Blog
  • Careers
  • Trust & Security
  • Contact

Legals

  • Cookie Policy
  • Copyright & Intellectual Property
  • Data Processing Addendum
  • Privacy Notice
  • Privacy Policy
  • TCPA & Telecommunications
  • Terms of Service
  • User & Acceptable Use Policy

Office Locations

Parkside, London Rd, Ipswich, Suffolk, IP2 0SS, United Kingdom

Special Economic Zone, Kerala Govt. Cyberpark, India

Ras Al Khor Industrial Second, Dubai, UAE

CLOUDWISE TECHNOLOGIES QFZ LLC Building 1, Street 504, Zone 49, Ras Bufontas Free Zone Doha, Qatar

Headquarters

Parkside, London Rd, Ipswich,
Suffolk, IP2 0SS, United Kingdom

Contact

[email protected]

🇬🇧+44 20 3886 3934

Certifications & Compliance

ISO 27001
ISO 27001
ISO 9001
ISO 9001
GDPR
GDPR
HIPAA
HIPAA
Cyber Essentials
Cyber Essentials
CPAASAA
CPAASAA
Core Cognitics

Follow Us

LinkedInFacebookInstagramYouTube
Privacy Policy|T & C|Cookie Policy

© 2026 Core Cognitics. All rights reserved.