Intentflow
Our standard GDPR Article 28 terms, covering personal data you store in a NetBox instance and personal data contained in the network configurations you upload for analysis. View below, or use your browser's print function to save a copy.
Last updated: September 3, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller," "you") and Intentflow, a sole proprietorship based in Poland (NIP 7692052599, REGON 543317392) ("Processor," "Intentflow," "we"), governing Intentflow's processing of personal data on the Controller's behalf in connection with the services at intentflow.co and app.intentflow.co (the "Service") - the hosted NetBox platform, Intentflow Verify, and Intentflow Reconcile, including Reconcile operated against a NetBox instance the Controller hosts itself, as described in our Terms of Service. Terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679) or in the Terms of Service.
Where the Controller is subject to a data protection law other than the GDPR (such as the UK GDPR or Switzerland's FADP) that imposes substantially similar obligations, references to the GDPR in this DPA should be read to include the equivalent provisions of that law.
As between the parties, the Controller is the controller of personal data submitted to the Service (including, where applicable, on behalf of its own end users or third parties), and Intentflow is the processor. Intentflow processes personal data only on the Controller's documented instructions, including as set out in this DPA and the Terms of Service, unless required to do otherwise by EU or Member State law - in which case Intentflow will inform the Controller of that legal requirement first, unless the law prohibits this.
Where the Controller is itself acting as a processor on behalf of one of its own clients (as will typically be the case for an MSP account under Section 3 of the Terms of Service, processing an end client's data on that client's behalf), Intentflow acts as a sub-processor of that end client's data, and references to "Controller" in this DPA are read as the Controller acting in its capacity as a processor. The Controller represents and warrants that it is authorized by its own client to appoint Intentflow as a sub-processor on these terms, and remains solely responsible for its own agreement with that client - Intentflow's relationship remains with the Controller, not with the Controller's end clients, consistent with Section 3 of the Terms of Service.
The subject matter, duration, nature and purpose of processing, and the categories of data subjects and personal data, are set out in Annex I.
Intentflow ensures that any person authorized to process personal data (including employees and contractors) has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
Intentflow implements the technical and organisational measures described in Annex II, designed to ensure a level of security appropriate to the risk, per Article 32 GDPR. These measures reflect what's publicly described on our Security & Infrastructure page as of the date of this DPA; that page may be updated as our posture evolves, and material reductions in security will be reflected here too.
The Controller authorizes Intentflow to engage the sub-processors listed in Annex III to process Controller Personal Data, and any others engaged for that same purpose and published from time to time on our Subprocessors page. Intentflow imposes data protection terms on each sub-processor that are no less protective than this DPA. If Intentflow engages a new sub-processor to process Controller Personal Data, we'll update the Subprocessors page and make reasonable efforts to notify active customers by email in advance. If the Controller objects on reasonable data protection grounds, the parties will work in good faith to address the objection; if unresolved, the Controller's remedy is to terminate the affected Service per the Terms of Service.
Our Subprocessors page also discloses providers Intentflow uses for purposes outside this DPA's scope - for example, payment processing and website operation, where Intentflow itself is the controller (see our Privacy Policy) rather than a processor of Controller Personal Data. Those providers aren't sub-processors under this DPA and aren't listed in Annex III, even though they're disclosed on the same page for full transparency.
Intentflow ensures that transfers of personal data outside the European Economic Area are subject to an appropriate transfer mechanism under Chapter V GDPR, including Standard Contractual Clauses or an applicable adequacy framework. Intentflow's infrastructure sub-processors are located in the United States (see Annex III); the specific mechanism each one relies on - Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework - is identified on our Subprocessors page.
Taking into account the nature of the processing, Intentflow will reasonably assist the Controller, at the Controller's cost for anything beyond routine effort, with: (a) responding to data subject requests to exercise their GDPR rights, to the extent the Controller cannot reasonably do so itself through the Service; (b) the Controller's obligations under Articles 32-36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the information available to Intentflow.
Intentflow will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably available to help the Controller meet its own breach-notification obligations under Articles 33-34 GDPR.
On reasonable prior written notice, and no more than once per 12 months (except following a personal data breach, or where required by a supervisory authority), Intentflow will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable confidentiality protections and without unreasonably disrupting Intentflow's operations or other customers.
On termination of the Service, Intentflow will delete Controller personal data on the schedules set out in Section 7 of the Terms of Service, unless EU or Member State law requires continued storage. Those schedules differ by artifact and run independently of termination: a hosted instance keeps full read/write access for 7 days after cancellation and is then deleted, while uploaded configurations and the reports derived from them expire on their own fixed clocks (Annex I, Duration) whether or not the subscription is still running. The Controller is responsible for exporting any data it wants to retain before that window closes. Production data is deleted at the end of this period; residual copies contained in encrypted backups (see Annex II for retention periods) are deleted automatically as those backups expire on their normal retention schedule, and are not restored except where necessary for disaster recovery.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA is intended to expand either party's liability beyond what the Terms of Service provide.
This DPA is governed by the laws of Poland, consistent with Section 14 of the Terms of Service.
| Subject matter | Intentflow's provision to the Controller of (a) hosted NetBox infrastructure, storage, and support; (b) automated analysis of network device configurations the Controller uploads (Intentflow Verify); and (c) comparison of those configurations against a NetBox instance, and writing of Controller-confirmed changes into it (Intentflow Reconcile), whether that instance is hosted by Intentflow or by the Controller. |
|---|---|
| Duration | For the term of the Controller's subscription, or for a one-time purchase until the resulting report is deleted. Individual artifacts are held for their own fixed periods, which run independently of the subscription: uploaded configurations 7 days (Verify) or 30 days (Reconcile); Verify reports 7 days (one-time) or 30 days (subscription); reconciliation data 30 days; a hosted instance 7 days after cancellation. See Section 10 and Annex II. |
| Nature of processing | Hosting, storage, backup, and technical support of data the Controller stores in its NetBox instance; and automated, deterministic analysis of the network configurations the Controller uploads, in order to produce the verification or reconciliation report the Controller has requested, together with the writing of Controller-confirmed changes into a NetBox instance. Intentflow performs no profiling, no automated decision-making producing legal or similarly significant effects concerning a data subject, and no use of Controller data for any purpose other than providing the Service. Controller data is not used to train any model and is not transmitted to any artificial intelligence or large language model service. |
| Purpose | Providing the Service the Controller has subscribed to. |
| Categories of data subjects | Determined by the Controller - typically the Controller's own employees, contractors, and business contacts recorded in NetBox (e.g. site or device contact records), or identifiable in the device configurations the Controller uploads (e.g. named local accounts or contact fields). Where the Controller is a managed service provider or consultant, these may be the personnel of the Controller's own end client. |
| Categories of personal data | Determined by the Controller. Typically names, work contact details, and any other fields the Controller chooses to record in NetBox's contact, device, or custom-field data; and, within uploaded device configurations, whatever the Controller has placed there - commonly local account usernames, authentication and SNMP identifiers, and free-text description or contact fields. Also the Controller's own account email address and, for standalone Reconcile, the address and API credential of the NetBox instance it operates. Intentflow does not require or request special category (Article 9) data and asks Controllers not to submit it; the Controller is responsible for removing anything it does not wish to submit before uploading. |
Summarized from our Security & Infrastructure page, which remains the authoritative, current version:
Sub-processors engaged to process Controller Personal Data specifically (see Annex I) - not the full list of Intentflow's vendors, which our Subprocessors page discloses in full and keeps current. As of the date of this DPA:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, and backups for the Controller's NetBox instance; encrypted object storage of uploaded configurations and derived reports; and the compute on which analysis runs | USA (us-east-1) |
Questions about this DPA: support@intentflow.co.