Launching soon — get early access:

Trust Center

Last updated: May 3, 2026

Single-page summary of every regulatory framework, security control, and compliance status that applies to Intelloro.

Privacy

Multi-jurisdiction policy stack: GDPR + UK GDPR + CCPA + 6 US state laws + PIPEDA + Quebec Law 25 + LGPD + PDPO. Children-specific frameworks (UK Children's Code, CA AADC, GDPR Art. 8, Brazil ECA Digital) in progress — will activate when age-detection is deployed.

Platform Regulation

EU Digital Services Act (Art. 15-21 documented; Art. 30 vendor verification in progress), EU AI Act (limited-risk classification + Art. 4 + 50 disclosure), DMCA, CAN-SPAM — documented and live.

Security

TLS encryption in transit (Vercel) + encryption at rest (MongoDB Atlas) + restricted admin access. SOC 2 + ISO 27001 in progress.

Compliance Matrix

FrameworkRegionStatusImplementation
GDPR (Regulation 2016/679)EU/EEACompliantLawful basis mapped, DSAR API, breach 72hr, SCCs+TIA
UK GDPR + DPA 2018United KingdomCompliantSame as GDPR, ICO complaints supported
CCPA / CPRACalifornia, USACompliantDo Not Sell page, CPPA-compliant rights flow
California Delete Act (SB 362)California, USANot ApplicableNot registered as Data Broker (no third-party data sourcing)
Texas TDPSATexas, USACompliantTargeted ad + profiling opt-out, 45-day SLA
Virginia VCDPAVirginia, USACompliantSame as Texas TDPSA framework
Colorado ColoPAColorado, USACompliantGPC signal honored, profiling opt-out
Connecticut CTDPAConnecticut, USACompliantSame framework as ColoPA
Utah UCPAUtah, USACompliantTargeted advertising opt-out
Oregon OCPAOregon, USACompliantSame framework as ColoPA
Quebec Law 25Canada (Quebec)PartialPrivacy Officer named + automated-decision rights documented; PIA framework will be conducted when triggering processing arises
Federal PIPEDACanadaCompliantOPC complaints supported
LGPD (Law 13.709/2018)BrazilCompliantDPO contact, ANPD complaint path
ECA Digital (Law 15.211/2025)Brazil (minors)In ProgressWill apply Privacy-by-Design defaults where minor identified; age-detection not yet deployed
Bangladesh PDPO 2025BangladeshCompliantDPO appointed, lawful basis, cross-border safeguards
COPPA (15 USC §§ 6501-6506)USA (children)CompliantNo knowing collection from under-13
GDPR Art. 8 (children)EU/EEAIn ProgressWill require parental consent where minor identified; age-detection not yet deployed
UK Children's CodeUnited KingdomIn ProgressWill apply ICO Children's Code where minor identified; age-detection not yet deployed
California AADCCalifornia, USAIn ProgressWill apply privacy-by-default where minor identified; age-detection not yet deployed
EU Digital Services Act (DSA)EU/EEAPartialArt. 16 notice form, Art. 17/20/21 process documented, Art. 15 transparency report scheduled. Art. 30 trader-verification flow being implemented
EU AI Act (Reg. 2024/1689)EU/EEAPartialLimited-risk self-classification, Art. 50 disclosure on /ai-disclosure, Art. 4 AI literacy via public methodology. AI-generated content labelling on detail pages being implemented
DMCAUSACompliantDesignated agent, takedown + counter-notice
CAN-SPAM ActUSACompliantSingle-click unsubscribe in every email
ePrivacy Directive (cookies)EU/EEACompliantGranular consent banner, GPC honored
WCAG 2.1 Level AAGlobalIn ProgressSelf-evaluation, see Accessibility Statement
Section 508 (Rehab Act)USA FederalIn ProgressAligned with WCAG 2.1 AA approach
European Accessibility ActEU/EEAIn ProgressPreparing for June 2025 enforcement deadline
TLS encryption (in transit)GlobalCompliantProvided by Vercel edge
Encryption at restGlobalCompliantProvided by MongoDB Atlas
SOC 2 Type IIUSA / GlobalIn ProgressInternal controls aligned with framework; external CPA audit not yet engaged
ISO 27001GlobalIn ProgressInternal controls aligned with framework; certification not yet pursued
GDPR Art. 27 EU RepresentativeEU/EEAIn ProgressAppointment under evaluation; direct contact via info@intelloro.com pending
UK GDPR Art. 27 UK RepresentativeUKIn ProgressAppointment under evaluation

Status Legend

  • Compliant — Framework is fully implemented and documented; user-facing rights are active.
  • In Progress — Implementation is underway; baseline obligations are met but full conformance is being completed.
  • Self-Declared — Internal controls aligned with the framework; no external audit completed yet.
  • Partial — Some elements implemented; gaps identified and prioritized for remediation.
  • Not Applicable — Framework does not apply to Intelloro's current operations.

Quick Links

Need More Detail?

Enterprise customers, security teams, and regulators may request the underlying documents (Transfer Impact Assessment, Privacy Impact Assessments, DPA templates, security questionnaire responses) by emailing info@intelloro.com with the subject “Trust Center Request”.

Response SLA: 5 business days for security questionnaires; 30 days for DSAR / data export.