Effective Date: July 24, 2026
Provider: Core Cognitics ("Core Cognitics", "Company", "Processor", or "We")
Website: https://www.corecognitics.com/
Applicable Product: Intelinteract Platform (including Web Widget, AI Voice & Chatbots, Studio, Edge Inference, Outbound Call/SMS Engine, and API Integration Services)
This Data Processing Addendum ("DPA") supplements the Terms of Service or Master Services Agreement ("Agreement") entered into by and between Core Cognitics and the entity agreeing to these terms ("Customer" or "Controller").
This DPA applies to the Processing of Customer Personal Data by Core Cognitics in connection with providing the Intelinteract platform and related services. Intelinteract enables Customer to deploy AI-powered voice and chatbot widgets, handle patient and customer inquiries, automate appointment scheduling, execute outbound marketing campaigns and appointment reminders, and perform live agent transfers.
This DPA governs Customer Personal Data generally, under the data protection laws listed in Section 3 below. It does not govern Protected Health Information ("PHI") as defined under the U.S. Health Insurance Portability and Accountability Act ("HIPAA").
Where Customer is a covered entity or business associate under HIPAA and Customer Personal Data processed through the Services includes PHI, such PHI is governed exclusively by the Business Associate Agreement ("BAA") separately executed between Customer and Core Cognitics, and not by this DPA. References to "patients," "health scheduling data," or similar categories elsewhere in this DPA (including Annex I) describe the general nature of Customer's business and Data Subjects; they do not expand this DPA's scope to cover PHI. In the event of any conflict between this DPA and the BAA with respect to PHI, the BAA shall control.
"Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including (where applicable) the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and applicable state privacy laws. For the avoidance of doubt, HIPAA is addressed separately under the BAA per Section 2 above and is not an "Applicable Data Protection Law" for purposes of this DPA.
"Customer Personal Data" means any Personal Data provided by or on behalf of Customer, or collected and processed by Core Cognitics through the Intelinteract platform (including patient details, voice call audio, call transcripts, chat interaction logs, phone numbers, and appointment scheduling data), excluding PHI governed by the BAA.
"Controller" means the entity that determines the purposes and means of Processing Personal Data (the Customer).
"Processor" means the entity that Processes Personal Data on behalf of the Controller (Core Cognitics).
"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates (including patients, website visitors, callers, and end-users).
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Core Cognitics.
"Subprocessor" means any third-party processor engaged by Core Cognitics to process Customer Personal Data in connection with the Services (e.g., cloud hosting providers, telecom infrastructure partners, STT/TTS voice model providers).
The parties acknowledge and agree that with respect to the Processing of Customer Personal Data:
Customer represents and warrants that:
Core Cognitics shall Process Customer Personal Data only:
Core Cognitics certifies that it understands and will comply with the CCPA/CPRA requirements. Specifically, Core Cognitics shall not:
Core Cognitics shall ensure that any employee, contractor, or agent authorized to process Customer Personal Data:
Core Cognitics shall implement and maintain appropriate technical and organizational security measures designed to protect Customer Personal Data against Personal Data Breaches, as detailed in Annex II of this DPA.
These measures include, but are not limited to:
Customer provides general written authorization for Core Cognitics to engage Subprocessors to assist in delivering the Services (including telephony providers, cloud infrastructure hosts, and neural voice synthesis providers).
Core Cognitics shall:
Core Cognitics shall provide Customer with notification of any intended addition or replacement of Subprocessors (via email or platform update). Customer may object to a new Subprocessor on reasonable data protection grounds within thirty (30) days of receiving notice. If Customer objects, the parties will work in good faith to resolve the concern. If no resolution is reached, Customer may terminate the affected Services without penalty.
Core Cognitics shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject seeking to exercise rights of access, rectification, erasure, restriction, data portability, or objection under Applicable Data Protection Laws.
Taking into account the nature of the Processing, Core Cognitics shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests. Customer shall be responsible for any reasonable costs arising from non-standard assistance requested.
In the event of a confirmed Personal Data Breach impacting Customer Personal Data, Core Cognitics shall:
Core Cognitics shall take immediate steps to investigate, mitigate, and remediate any Personal Data Breach at its own expense, keeping Customer informed of progress.
Core Cognitics shall provide reasonable assistance to Customer with any data protection impact assessments (DPIAs) and prior consultations with supervisory authorities required under Applicable Data Protection Laws, taking into account the nature of Processing and information available to Core Cognitics.
Upon termination or expiration of the Agreement, Core Cognitics shall, at Customer's written election, enable Customer to export or download all Customer Personal Data (including interaction logs, patient appointment records, and call recordings) for up to ninety (90) days following termination.
Within one hundred eighty (180) days following the expiration of the retention window or upon Customer's explicit request, Core Cognitics shall securely delete and purge all copies of Customer Personal Data from its production systems and backups, except to the extent that Applicable Data Protection Laws require continued retention.
Core Cognitics shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA.
Customer or an independent third-party auditor designated by Customer may conduct an audit of Core Cognitics' data processing controls once per calendar year, upon thirty (30) days' advance written notice. Audits shall be conducted during normal business hours without disrupting business operations. Customer shall bear all costs associated with such audits unless the audit reveals a material failure by Core Cognitics to comply with this DPA.
Where Customer Personal Data is transferred outside the European Economic Area (EEA), United Kingdom (UK), or Switzerland to a country not recognized as providing an adequate level of data protection, such transfers shall be governed by:
Data Exporter: Customer (subscribing business, clinic, healthcare provider, or enterprise).
Data Importer: Core Cognitics (provider of the Intelinteract AI platform).
Categories of Data Subjects: Patients, prospective clients, callers, website visitors, and employees of Customer.
Frequency & Duration: Continuous during the active subscription term of the Agreement.
Categories of Personal Data:
For inquiries regarding this Data Processing Addendum or Data Protection compliance, please contact:
| Field | Detail |
|---|---|
| Team | Core Cognitics Privacy Team |
| [email protected] | |
| Website | https://www.corecognitics.com/ |