Wednesday, May 20, 2026
S&P 500 · NDX · NVDA · Gold · BTC
  Data Processing Addendum · INTELAR Privacy →
DPA · v2026.1 · Effective 23 May 2026

Data Processing Addendum.

This DPA forms part of the agreement between INTELAR Intelligence Group AG (i.G.) ("Controller") and any reader, subscriber, or enterprise customer ("Data Subject" / "Customer") whose personal data INTELAR processes. It complements the privacy policy and the Terms of Service.

1. Parties and roles

INTELAR Intelligence Group AG (i.G.), Zürich, Switzerland, acting as Controller under Swiss nDSG and EU GDPR. Sub-processors listed in §3 are Processors acting on documented INTELAR instructions.

2. Scope and subject-matter

This DPA governs the processing of personal data described in §2 of the privacy policy for the purposes listed in §4 there. Categories of data subjects: readers, subscribers, contributors, contacts. Special categories of personal data (GDPR Art. 9): not processed.

3. Sub-processors

Current sub-processors (mirrors the privacy policy §6 in tabular form). Notice of new sub-processors is given via this page with at least 30 days' lead time for objection.

SP-01
Anthropic, PBC
San Francisco, USA · Service: AI inference (Claude family) · Safeguard: SCCs 2021 Modules 2&3 + DPF + zero-retention training opt-out. Onboarded 2026-02-01.
SP-02
OpenAI, LLC
San Francisco, USA · Service: AI inference (GPT-5 family) · Safeguard: SCCs 2021 + DPF + zero-retention. Onboarded 2026-02-01.
SP-03
Google Ireland Ltd.
Dublin, Ireland (Vertex AI) · Service: AI inference (Gemini) · Safeguard: EU-resident processing where possible; SCCs + DPF for US fallback. Onboarded 2026-02-01.
SP-04
Mistral AI SAS
Paris, France · Service: AI inference (Mistral Large 3) · Safeguard: EU-resident; no extra-EEA transfer. Onboarded 2026-02-01.
SP-05
Stripe Payments Europe Ltd.
Dublin, Ireland · Service: payment processing · Safeguard: EU-resident; SCCs + DPF for US sub-processing within Stripe. Onboarded 2026-02-01.
SP-06
Railway Corp.
San Francisco, USA · Service: application hosting · Safeguard: SCCs 2021 + edge caching to minimise EU/CH egress. Onboarded 2026-02-01.
SP-07
Cloudflare, Inc.
San Francisco, USA (with EU/CH POPs) · Service: edge delivery, DDoS, DNS · Safeguard: SCCs + Data Localization Suite where used. Onboarded 2026-02-01.
SP-08
CH-resident GPU partners (federated)
Zürich, Bern, Lausanne · Service: editorial pipeline batch compute and INTELAR foundation-model training · Safeguard: Swiss-resident processing under nDSG; named partners disclosed on request under NDA. Onboarded 2026-03-01.

4. Processor obligations and Controller instructions

Every sub-processor is bound by a written contract that mirrors GDPR Art. 28 obligations: processing only on documented instructions, confidentiality, security per Art. 32, assistance with data-subject rights (Arts. 15–22), notification of breaches without undue delay, deletion/return of personal data on termination, audit cooperation.

5. Security measures

TLS 1.3 in transit, AES-256 at rest, hardware-key MFA for production access, least-privilege IAM, network isolation between editorial and reader-facing components. Annual penetration test. Logging and monitoring with 14-day retention for security logs.

6. Personal data breach notification

In the event of a personal data breach, INTELAR will notify the competent supervisory authority within 72 hours per GDPR Art. 33 / nDSG Art. 24. Where Art. 34 applies, affected data subjects will be notified directly. The incident log is summarised in the annual transparency report.

7. International data transfers

All transfers from CH/EU to third countries are covered by SCCs 2021 (Modules as appropriate), the EU-US and Swiss-US Data Privacy Framework certifications where applicable, plus a Transfer Impact Assessment on file. Customers can request the TIA under NDA.

8. Termination and data return

On termination of an enterprise relationship or data-subject relationship, personal data is deleted or returned per the data-subject's choice, subject to the retention exceptions in privacy policy §5 (accounting, legal hold).

9. Contact

DPA queries, audit requests, sub-processor objections: /contact. Direct to DPO: dpo[at]intelar.news.

Privacy policy → Legal framework →