This DPA is accepted automatically. By accepting the IntelligenceClaim Terms of Service, your Organization accepts this Data Processing Agreement as in effect from time to time. It is incorporated into the Terms by reference and constitutes a binding written processor contract for the purposes of GDPR Article 28(3). No separate signature is required.
Want a counter signed paper version? Email admin@intelligenceclaim.com and we will send a counter signed PDF within five (5) business days. The signed and the click through versions are legally equivalent.
Parties
This Data Processing Agreement (“DPA”) is entered into between MH Consulting Group AB, a Swedish limited liability company doing business as IntelligenceClaim (the “Processor” or “IntelligenceClaim”), and the Organization that has accepted the IntelligenceClaim Terms of Service (the “Controller” or “Customer”). The DPA is effective on the date Customer accepts the Terms of Service or executes an Order Form referencing IntelligenceClaim.
1. Scope and roles
This DPA applies to Processor's processing of Customer Personal Data on Customer's behalf in connection with the Services. The parties acknowledge that, with respect to Customer Personal Data:
- Customer is the Controller (or, where applicable, the data exporter or processor on behalf of a third party controller);
- IntelligenceClaim is the Processor (or sub processor) acting on Customer's documented instructions.
The subject matter, duration, nature, purpose, types of Personal Data, and categories of data subjects are set out in Annex 1, Processing Details below. Security measures are set out in Annex 2. For Personal Information of residents of California or other US states with enacted consumer privacy laws, the additional service provider terms in Annex 3 apply.
2. Processor's obligations
IntelligenceClaim shall:
- Process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required by Union or Member State law;
- Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement the technical and organizational security measures described in Annex 2, Security Measures, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing;
- Respect the conditions for engaging sub processors set out in Section 5;
- Assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights;
- Assist Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, taking into account the nature of processing and information available to Processor;
- At Customer's choice, delete or return all Personal Data to Customer after the end of the provision of the Services, and delete existing copies unless Union or Member State law requires storage;
- Make available to Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer (subject to the audit procedures in Section 7).
3. Customer's instructions
Customer's use of the Services through the standard product user interface and APIs constitutes Customer's documented instructions to Processor with respect to the processing of Personal Data. The Terms of Service, this DPA, and any subsequent written agreement between the parties constitute the complete instructions. Processor shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR, UK GDPR, or other applicable data protection provisions.
4. Security of processing
Processor shall implement and maintain the technical and organizational measures described in Annex 2, Security Measures. Processor will not materially decrease the overall security of the Services during the term of the DPA without providing prior notice to Customer.
5. Sub processors
Customer authorizes Processor to engage the sub processors listed at /legal/subprocessors. Processor will notify Customer at least thirty (30) days in advance of any new sub processor or replacement sub processor by updating the published list. If Customer objects in writing to a proposed sub processor change within fifteen (15) days of the notification, the parties will work in good faith to resolve the objection. If no resolution can be reached, Customer may terminate the relevant Services without penalty for the unused portion of the subscription term.
Processor will impose data protection terms on each sub processor that provide at least the same level of protection as this DPA. Processor remains fully liable to Customer for the performance of each sub processor's obligations.
6. International data transfers
To the extent Processor processes Personal Data outside the European Economic Area, the United Kingdom, or Switzerland, the parties shall comply with the applicable data transfer mechanism, which shall be:
- The European Commission's Standard Contractual Clauses (Module 2: Controller to Processor) approved by Decision (EU) 2021/914 (the “SCCs”), which are incorporated into this DPA by reference; Customer is the “data exporter” and Processor is the “data importer.” The optional Docking Clause in Clause 7 applies. In Clause 9 (Use of sub processors), Option 2 (General written authorisation) applies. In Clause 11, the optional language is deleted. In Clause 17, the SCCs are governed by the law of Sweden. In Clause 18, disputes shall be resolved before the courts of Sweden;
- For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs, dated 21 March 2022 and issued by the UK Information Commissioner;
- Where applicable, additional safeguards including encryption in transit and at rest, the security measures in Annex 2, and the contractual restrictions on sub processor processing described in Section 5.
7. Audit rights
Processor shall make available to Customer, upon Customer's written request and no more than once per calendar year (or more frequently where required by a competent supervisory authority), the following information to demonstrate compliance with this DPA:
- The most recent third party security audit report, penetration test summary, or equivalent assurance documentation;
- Written responses to a reasonable security questionnaire (e.g., CAIQ, SIG Lite);
- Such other documentation as is reasonably necessary to demonstrate compliance.
If Customer reasonably believes that the documentation referenced above is insufficient, Customer may, at its own expense and upon at least thirty (30) days' written notice, conduct an on site or remote audit of Processor's processing of Customer Personal Data. The audit shall be subject to a confidentiality agreement, shall be limited to information strictly necessary to demonstrate compliance with this DPA, and shall not disrupt the Services for other customers. Audits initiated other than at the request of a competent supervisory authority are subject to a reasonable cost recovery payable by Customer.
8. Data subject requests
Processor shall, to the extent legally permitted, promptly notify Customer if Processor receives a request from a data subject seeking to exercise rights under applicable data protection law. Processor shall not respond to such requests except on documented instructions from Customer or where required by applicable law. Processor will assist Customer in fulfilling its obligations to respond to such requests through appropriate technical and organizational measures.
9. Personal data breach
Processor shall notify Customer without undue delay, and in any event within seventy two (72) hours, after becoming aware of a Personal Data breach affecting Customer Personal Data. The notification shall include the information required by Article 33(3) GDPR to the extent then known to Processor, and Processor shall provide further information as it becomes available. Processor shall cooperate with Customer in investigating, mitigating, and remediating the breach.
10. Data protection impact assessments
Processor shall, on Customer's reasonable request and at Customer's cost (where significant cost is incurred), provide Customer with information reasonably necessary to conduct data protection impact assessments and prior consultations with supervisory authorities pursuant to Articles 35 and 36 GDPR.
11. Term and return / deletion of personal data
This DPA shall remain in effect for as long as Processor processes Customer Personal Data under the Services. Upon termination of the Services, Processor shall, at Customer's choice, delete or return all Customer Personal Data within the periods described in the Privacy Policy (currently: documents and media within 90 days of termination; structured claim data deleted after the legally required retention period). Processor shall provide written confirmation of deletion upon request.
12. Liability and indemnity
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits liability that cannot be limited under applicable data protection law.
13. General
This DPA is governed by the law of Sweden, without prejudice to mandatory provisions of applicable data protection law. The dispute resolution provisions of the Terms of Service apply to disputes under this DPA. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall remain in effect to the maximum extent permitted.
Annex 1, Processing details
Subject matter of processing: Provision of the IntelligenceClaim AI powered restoration claim analysis platform and related services.
Duration of processing: The term of Customer's subscription to the Services plus the data retention periods set out in the Privacy Policy.
Nature and purpose of processing: Hosting, storage, AI powered analysis, retrieval, and presentation of Customer Personal Data to enable Customer to identify potentially billable items, prepare rebuttal documentation, and operate its restoration business.
Categories of Personal Data:
- Identification and contact data (names, email addresses, job titles, business addresses);
- Authentication data (hashed credentials, session tokens);
- Property and claim data (addresses, claim numbers, carrier names, adjuster names, project manager assignments);
- Document content uploaded by Customer (PDFs, photographs, field notes, which may incidentally contain Personal Data of third parties);
- Technical and usage data (IP addresses, device identifiers, log data, analytics events);
- Communications data (support requests, in product messages).
Categories of data subjects: Customer's personnel and Authorized Users; Customer's clients and property owners whose data appears in uploaded documents; insurance carrier personnel, adjusters, and contractor personnel referenced in uploaded documents; any other natural person whose data is included in Customer uploaded content.
Sensitive categories: The Customer shall not upload special categories of Personal Data under GDPR Article 9 (including health data, racial / ethnic origin, biometric data for unique identification) or PHI under HIPAA without entering a separate written addendum with Processor. Standard restoration claim photographs and notes are not expected to contain such categories.
Annex 2, Security measures
Processor implements the following technical and organizational security measures, which it may update from time to time provided the overall level of security is not materially reduced:
Access control and authentication.
- Role based access control with least privilege provisioning for all systems processing Customer Personal Data;
- Multi factor authentication enforced for administrative and engineering access;
- Time limited, audit logged administrator impersonation for support purposes only;
- Automatic session timeout and re authentication for active sessions;
- Credential rotation, secrets management via dedicated secret storage systems, no plaintext credentials in code or logs.
Encryption.
- Encryption in transit using current industry standard protocols (TLS 1.2 or higher) for all browser to server and server to server communication;
- Encryption at rest for all primary databases, object storage, and backups using industry standard algorithms;
- End to end encryption of credential material in dedicated key management systems.
Tenant isolation.
- Database layer row level security policies enforce per Organization data isolation; cross tenant queries are technically blocked at the database layer;
- Automated security monitoring scans for anomalous cross tenant access patterns;
- Storage paths and signed URLs are scoped per Organization.
Logging, monitoring, and incident response.
- Tamper resistant audit logging of all user actions, data modifications, and administrative events;
- Automated anomaly detection and security alerting routines;
- Documented incident response procedure with on call rotation;
- Security event log retention of three (3) years.
Development and change management.
- Mandatory peer review of all code changes deployed to production;
- Automated lint, type checks, and test suites in continuous integration pipelines;
- Separate staging and production environments with distinct secrets;
- Vulnerability scanning of dependencies and container images.
Personnel.
- Background checks for personnel with administrative access where permitted by applicable law;
- Confidentiality agreements with all personnel and contractors;
- Security awareness training for personnel with access to Customer Personal Data.
Vendor and sub processor management.
- Due diligence review prior to engaging a sub processor with access to Customer Personal Data;
- Contractual data protection terms with each sub processor at least as protective as this DPA;
- Published, up to date sub processor list at /legal/subprocessors.
Annex 3, US service provider terms (CCPA + other state privacy laws)
This Annex applies whenever IntelligenceClaim processes Personal Information of California consumers, or of residents of other US states with enacted consumer privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and any successor or equivalent statute), on the Organization's behalf. The Organization is the “business” (or equivalent role), and IntelligenceClaim is the “service provider” (or equivalent role) with respect to such Personal Information.
IntelligenceClaim shall:
- Process Personal Information only for the limited and specified business purposes set out in the Terms of Service and this DPA, and not for any commercial purpose other than performing the Services;
- Not sell or share Personal Information, as those terms are defined under the CCPA / CPRA and equivalent state laws;
- Not retain, use, or disclose Personal Information outside the direct business relationship between the Organization and IntelligenceClaim, or for any purpose other than the specific purpose of performing the Services;
- Not combine Personal Information received from the Organization with Personal Information received from or on behalf of any other person, except where permitted by applicable state privacy law for a business purpose of IntelligenceClaim;
- Comply with applicable obligations under the CCPA, CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, and equivalent or successor state privacy laws, and provide the same level of privacy protection as required of the Organization under those laws;
- Notify the Organization promptly if IntelligenceClaim determines it can no longer meet its obligations under the CCPA, CPRA, or other applicable state privacy law, and cooperate with the Organization to take reasonable and appropriate steps to stop and remediate any unauthorized use;
- Permit the Organization, on reasonable notice, to take reasonable and appropriate steps to ensure that IntelligenceClaim uses Personal Information in a manner consistent with the Organization's obligations under applicable state privacy law (the audit procedure in Section 7 of this DPA satisfies this requirement);
- Assist the Organization in responding to verifiable consumer requests to exercise rights under applicable state privacy law (right to know, delete, correct, opt out, limit, etc.) within the timelines required by such law.
The Organization certifies that it understands these restrictions and will not direct IntelligenceClaim to perform any processing that would cause IntelligenceClaim to violate its obligations under applicable state privacy law.
IntelligenceClaim, a service of MH Consulting Group AB
admin@intelligenceclaim.com
© 2026 MH Consulting Group AB. All Rights Reserved.
