IntraQ, Inc. — Privacy Policy
Version: 1.0 Effective date: August 26, 2026 Last updated: August 26, 2026
This policy describes how IntraQ, Inc. handles information in IntraQ. It is written to describe what the product actually does. Two things are worth knowing before you read further. Your content is transmitted to third-party AI providers to produce answers and documents, and it is not masked or anonymized first — Section 12 explains exactly what is sent. And we do not delete most data on a fixed schedule — Sections 18 and 19 explain what that means and how to ask us to delete something.
1. Who we are and what this covers
IntraQ, Inc. provides IntraQ, a compliance and policy platform for HR teams. This policy covers the IntraQ application, our public website, and the email we send in connection with the Service. It applies alongside our Terms & Conditions and, for business customers, our Data Processing Addendum. It does not cover the practices of a service you connect to IntraQ, or of a third-party site we link to; those are governed by their own policies.
2. Our role: business/controller and service provider/processor
Most information in IntraQ belongs to a customer organization, not to us. When your employer uses IntraQ, your employer decides what is collected and why, and we handle that information on their instructions. For that workspace content, employee records, and documents, we act as a service provider (under the California Consumer Privacy Act) and a processor (under other U.S. state privacy laws). Our processing in that role is governed by the Data Processing Addendum.
We act as a business/controller for a smaller set of information: account registration details, billing information, support requests, and information submitted through our public website.
If you are an employee or other individual and you want to see, correct, or remove information your employer holds in IntraQ, start with your employer. We will support them, but we will not change their records without their instruction.
3. Account and organization information
When an account is created we collect and store:
- name, email address, and, where provided, job title and profile photo;
- a password, which we store only as a one-way hash — we cannot read or recover it;
- if you sign in with Google or Microsoft, the identifier that provider gives us for you;
- if multi-factor authentication is enabled, the secret and recovery/backup codes that support it, which are encrypted before storage;
- organization details: company name, workspace configuration, roles and permissions, approval settings, and the configuration of any service you connect.
4. Workforce information
IntraQ keeps a lightweight employee roster so that policies, acknowledgments, and compliance obligations can be tied to real people. For each person on the roster we hold name, work email address, job title, department, hire and termination dates, the state and country whose employment law governs the role, employment type, exemption classification, directory visibility, and status. Workforce records may be entered manually or imported by read-only connection from an HR system you connect.
For workforce records and compliance evidence, IntraQ applies a structural data-minimization control that rejects fields whose names indicate categories such as government identifiers, date of birth, salary or compensation, financial-account numbers, and home address. This control operates on field names, not on the values inside free-form content, so it reduces — but does not eliminate — the chance that such information is stored; content you place in documents, policies, evidence, questions, or conversations may still contain it. IntraQ also supports HRIS-backed I-9 compliance controls.
5. Documents and content
We store the documents you upload or generate — handbooks, policies, compliance documents, job descriptions, employment agreements, and files retrieved from a service you connect — together with text extracted from those documents and a numeric index (embeddings) of that text, which is what makes search and retrieval work. We also store the compliance state derived from that content: control evaluations, evidence records, findings, gaps, coverage, and posture.
6. Questions you ask and answers we generate
We store the questions you ask, the searches you run, and the answers IntraQ produces, together with the documents cited in them. Conversations are kept so you can return to them and so an answer can be traced back to its sources. We also record structured metadata about how an AI request was executed, in order to diagnose failures.
7. Policy acknowledgment and signature records
Some records exist specifically to be evidence. When someone acknowledges or signs a policy through IntraQ, we record who acknowledged and when, their typed name or signature, their IP address and browser user agent, a snapshot of the policy text as it stood at that moment, and a cryptographic fingerprint of that text, so the record cannot be quietly altered afterwards.
8. Technical and diagnostic information
We record sign-in activity, IP address, and browser user agent for authentication and abuse prevention, and diagnostic logs when something fails. Diagnostic logs can contain incidental personal information — an error message may quote the value that caused it. We do not operate a product-analytics platform, a session recorder, an error-monitoring vendor, or a behavioral-tracking pipeline in the product or on our website.
9. Website visitors and assessments
You can run the compliance assessment on our public website. If you ask for your results, we store the name, work email, company, and role you give us, your answers and dimension scores, the marketing preference you select, and the campaign parameters in the link you arrived from. These assessment-lead records are automatically deleted 24 months (730 days) after they are created.
10. Payment and billing information
Payments are handled by Stripe. Card details are entered directly with Stripe and never reach IntraQ. We store the plan, billing cycle, subscription status, seat counts, and the identifiers Stripe gives us so we can show you your subscription and invoices.
11. How we use information, and what we do not do
We use information to: run the Service (sign you in, apply permissions, keep workspaces separate); generate policies and answers, search your content, and evaluate compliance obligations; send transactional email (invitations, password resets, agreements, trial and billing notices, and compliance notifications you or your administrator turn on); protect the Service against unauthorized access and abuse; investigate problems and fix defects; and meet legal obligations and respond to lawful requests.
What we do not do:
- We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising or with advertisers.
- We do not use your content to train any AI model. IntraQ, Inc. operates no model training of any kind.
- We do not run advertising, ad targeting, or third-party tracking technology in the product or on our website.
- The email IntraQ sends from the product is transactional. If we introduce marketing email, it will carry a way to opt out.
12. Artificial intelligence: what leaves IntraQ
IntraQ transmits content to third-party AI providers to generate policies, answer questions, and produce recommendations. We use Anthropic and OpenAI. We choose the provider and model automatically for each request based on the task and on availability; you do not select one, and the same request may be routed to a different provider on a retry.
Depending on the feature and request, what is sent to a provider can include:
- the text of your question or instruction, as entered;
- portions of your documents and policies (retrieved passages), together with document titles;
- your organization’s name;
- recent conversation context; and
- therefore any personal or other information contained in those materials, including names and email addresses that appear in your documents, policies, questions, or conversations.
In addition, OpenAI receives document content during ingestion and search text from queries in order to generate the embeddings that make retrieval work.
We do not mask, tokenize, anonymize, or de-identify this information before sending it. We would rather tell you that plainly than let you assume otherwise.
IntraQ, Inc. does not use your content to train any model. A provider processes your content in order to return a response. We engage Anthropic and OpenAI under their commercial/API agreements, which include the providers’ data processing terms; under those agreements Anthropic does not train its models on content submitted through the API and is subject to confidentiality obligations, and OpenAI does not use content submitted through the API to develop or improve its services unless the customer expressly agrees. We do not otherwise control a provider’s internal practices, and we do not represent that any provider operates on a zero-data-retention basis. If a provider’s retention practices are material to your organization, contact us and we will share the relevant terms.
Not everything in IntraQ is AI. Compliance scoring, control evaluation, applicability, coverage, and posture are computed by our own deterministic logic. Where an AI model drafts an answer, figures that do not appear in the underlying evidence are rejected rather than published. IntraQ IQ is automated software; it drafts and analyzes, and a person decides whether a consequential action happens.
13. Services you connect
You can connect IntraQ to HR systems (such as BambooHR, Dayforce, UKG, and Deel), to document sources (Google Drive, Microsoft SharePoint and OneDrive), and to communication tools (Slack and Microsoft Teams). We access only the locations you authorize, and we retrieve content in order to index and search it. IntraQ reads connected content; it does not create, modify, or delete anything in a connected service. Disconnecting a service stops future retrieval and clears the stored connection credentials. Disconnecting does not by itself delete content or workforce records already retrieved; those remain in your workspace, and may be marked as no longer current, until they are deleted in accordance with Sections 18 and 19.
14. Service providers who process data for us
These providers handle data on our behalf as subprocessors:
- Anthropic and OpenAI — AI generation; OpenAI additionally for search indexing (embeddings), as described in Section 12.
- Amazon Web Services — storage for uploaded and generated files and profile photos.
- MongoDB — the database where your records are stored.
- Upstash — queue job references and session state that support request handling.
- Resend — delivery of the email we send, which means recipient addresses and message contents pass through it.
- Stripe — payment processing and billing.
- Railway and Vercel — application compute and edge delivery of the Service; request traffic passes through them.
Google and Microsoft provide sign-in when you choose them, and Google, Microsoft, and the HR and communication systems above are engaged when you connect them; those are services you direct rather than subprocessors we engage to process data on our behalf. A current list of subprocessors, and the mechanism for changes, is maintained in the Subprocessor Schedule to our Data Processing Addendum. We also retrieve public legislative and regulatory data from third-party sources; those requests carry state codes, subject areas, and date ranges, and no customer content is sent to them.
15. Access by IntraQ personnel
A small number of IntraQ, Inc. personnel hold a platform-administrator role used to operate the Service. That access can reach customer records across workspaces and is used to operate the platform, investigate reported problems, and respond to support requests. It is restricted to that purpose, gated by role and a platform multi-factor-authentication requirement, and IntraQ does not operate any log in as customer impersonation mechanism. Actions taken through governed surfaces are recorded in a tamper-evident audit log.
16. Where data is stored, and transfers
IntraQ, Inc. operates from the United States, and the production Service, its primary database, and its file storage are configured to United States regions. Certain subprocessors may process data in other locations in the course of providing their services, and the AI providers are accessed at their default global endpoints. Because some infrastructure providers’ backup, replication, and object-version retention configurations are managed by those providers, we do not represent that every backup or historical copy of data resides exclusively in the United States. IntraQ does not currently offer data-residency selection or region-specific routing.
IntraQ’s Service and this policy are directed to organizations in the United States. If your organization is located in, or has data subjects in, the European Economic Area, the United Kingdom, or Switzerland, contact us before you subscribe; we will tell you what is possible, and additional transfer terms would need to be agreed.
17. How we protect information
We describe these as behaviors rather than mechanisms.
- Stored document files are encrypted at rest in our object storage.
- Credentials for connected services are encrypted before storage using authenticated encryption (AES-256-GCM) with a key-derivation function that fails closed if its key is not configured. Credentials stored under an earlier encryption format are migrated to this format when they are next written.
- Access is governed by roles, and permission checks fail closed — when authority cannot be established, the action is refused.
- Each customer workspace is scoped separately in our application logic.
- Multi-factor authentication is available to every user and required for IntraQ, Inc. platform administrators. SAML 2.0 single sign-on is available on plans that include it.
- Compliance-relevant activity is written to a tamper-evident, hash-chained record, so a later alteration is detectable.
- Sign-in attempts are rate limited.
- Connections to source systems are read-only; mutating operations are structurally excluded.
IntraQ, Inc. does not hold a SOC 2 report and does not hold any third-party security certification, attestation, or audit opinion. We will say so when we have completed an audit, and you should treat any claim to the contrary as an error we want to hear about.
No system is completely secure. You are responsible for keeping your credentials confidential, managing who has access inside your organization, and telling us promptly if you suspect a problem.
18. How long we keep information
We retain information for as long as necessary for the purposes described in this policy: to provide and secure the Service, to meet legal and regulatory obligations, to maintain the auditability of compliance records, to resolve disputes, and to enforce our agreements. Retention varies by category rather than following a single fixed period.
- Website assessment-lead records are automatically deleted 24 months (730 days) after creation.
- Compliance audit-log entries are retained on a long-term basis (currently seven years) and are hash-chained so they cannot be quietly altered.
- Compliance evidence is retained for the period your organization configures; when that period ends, personal data in the record is redacted while an audit shell is preserved.
- Conversations do not automatically expire; they are retained until you delete them or until your workspace’s data is deleted on request.
- Policy acknowledgment and signature records are retained on a long-term basis because their purpose is to be evidence later.
- Records evidencing acceptance of the Terms and this policy, and prior versions of those documents, are retained for their evidentiary purpose.
- Billing records are retained by Stripe under its terms; we retain the subscription information described in Section 10.
Aside from the categories with a stated schedule above, IntraQ does not delete customer content on a fixed schedule. If your organization requires a specific retention period for a category of data, raise it with us and we will tell you what we can support.
19. Deleting data
You can delete an individual document in IntraQ. When you do, IntraQ deletes the stored file object, the document’s text chunks, the extracted content, and the vector embeddings derived from it, and clears the document’s original file name; if any part of that erasure fails, we report the failure rather than reporting success. Vector representations are stored together with the document’s records and are removed when those records are erased; there is no separate external vector store.
Because our infrastructure providers maintain their own backup, replication, and — for stored files — object-version retention, a copy of deleted content may persist in those provider-managed systems for a limited period until it is overwritten or expires under the provider’s retention, and we may retain data where required for legal, regulatory, security, audit, or contractual purposes. We do not represent that deletion instantly destroys every historical backup or object version.
Deleting a whole workspace, or all of one person’s data, is handled as a request. Removing someone’s access removes their ability to sign in; it does not by itself erase their records. To have data deleted, email privacy@intraqai.com. We will handle the request subject to applicable legal, regulatory, security, audit, contractual, and technical retention requirements, and we will tell you what we removed, what we retained, and why.
20. Your rights, and how to exercise them
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to receive a copy of it, to opt out of the sale or sharing of personal information, to limit the use and disclosure of sensitive personal information, and — where processing relies on consent — to withdraw consent. You also have the right not to receive discriminatory or retaliatory treatment for exercising these rights, including as a job applicant, employee, or independent contractor.
- We do not sell personal information and we do not share it for cross-context behavioral advertising.
- We do not use sensitive personal information for purposes other than providing the Service and the related purposes permitted by law; where we act as a service provider, we handle any such information only on our customer’s instructions.
- We handle rights requests through our team rather than an automated self-service portal. Some information you can change yourself in the product; some is managed by your organization’s administrator; and some — including your account email address — currently requires you to contact us so we can make the change. If your employer put the information into IntraQ, start with them.
To exercise a right, email privacy@intraqai.com. We will verify your identity before acting and respond within the period the applicable law requires.
21. Cookies and browser storage
Cookies. IntraQ sets only cookies necessary for the product to function — keeping you signed in, carrying you through a multi-factor challenge, protecting the sign-in exchange with an external identity provider, and maintaining your session. We set no analytics, advertising, or third-party tracking cookies.
Local storage. We use your browser’s local storage to remember interface preferences and where you left off in setup. That information stays on your device.
Session storage. On our public website, when you arrive through a link that contains campaign parameters, we temporarily store those parameters in your browser’s session storage, under the key intraq.campaign, in same-origin, tab-scoped storage. The first such link in a tab’s visit is kept and is not overwritten during that visit, and the value is discarded when the browser tab closes. This exists so that campaign attribution survives your navigation from the landing page to the assessment. Session storage is not a cookie; it is not transmitted automatically with your requests. These parameters are sent to us only if you submit an assessment, at which point they are associated with your assessment-lead record and retained as described in Section 9. This mechanism does not use cookies, advertising pixels, device fingerprinting, session recording, cross-site behavioral tracking, or a behavioral or product-analytics platform.
22. Children
IntraQ is a business tool and is not intended for anyone under 18. We do not ask for a date of birth. If we learn we hold information from a child, we will delete it.
23. Changes to this policy, and how to reach us
Each version of this policy has a version number and an effective date, and we retain prior versions. When we make a change that materially affects how we handle your information — such as new categories of data, new purposes, or new recipients — we will give you advance notice by email or in the product before the change takes effect. Where a change would use information we already collected in a way you did not previously authorize, we will obtain your consent before applying the change to that information. Immaterial changes take effect when we post the updated version and update the Last updated date.
When the product and this page disagree, the page is the thing that is wrong, and we want to know. Contact us at privacy@intraqai.com.
