Terms and conditions

for the use of Intellipush

   

Intellipush Business Terms of Service, including Data Processing Addendum

Version 2026.08 · effective 18 August 2026

These terms govern the use of the Intellipush customer portal, APIs and related business messaging functions. Depending on the Customer account and configuration, the Service may include SMS, email, voice delivery, contact and list management, inbound messaging, links and files, reporting, supported callbacks or webhooks and related functions. The Data Processing Addendum in Schedule 1 applies automatically when Intellipush processes personal data on the Customer's behalf. The Acceptable Use Policy is a binding part of the agreement.

1. The agreement

1.1 Parties and business use

The Service is provided by Intellipush AS, Norwegian organisation number 912 302 806, Veumveien 23, 1613 Fredrikstad, Norway (“Intellipush”). The business or organisation that creates or uses the account is the “Customer”. A person accepting the agreement for the Customer confirms that they have authority to bind it. The Service is offered for business use, not as a consumer service.

1.2 Contract documents and priority

The agreement consists of these terms, Schedule 1, the current Acceptable Use Policy, information shown when a purchase is made and any separate written agreement. If documents conflict, a separate written agreement takes priority over these terms. Schedule 1 takes priority on the processing of personal data on the Customer's behalf.

1.3 Acceptance and language

The agreement is formed when the Customer accepts the Terms+DPA and AUP during registration, by another documented action or through a separate agreement. Intellipush may retain proportionate evidence of acceptance, including the account, user, UTC timestamp, language, document version and acceptance action. Marketing consent is separate, voluntary and not a condition of the Service. The Norwegian text governs; this English version is a translation.

2. The Service and dependencies

Intellipush provides business messaging functions for managing contacts, planning and sending communications, and integrating supported channels into the Customer's systems. Depending on the account configuration, the Service may include SMS, email, voice delivery, inbound messaging, links and files, reporting, supported callbacks or webhooks and APIs. The exact functions available depend on the account, country, provider, sender setup, technical documentation and any separate agreement. MMS is not included in the standard Service. Premium-rate, recipient-paid or other specially regulated messaging is not included unless separately agreed in writing where Intellipush supports it.

Messages and related events are transmitted through external providers, communications networks and recipient systems. Intellipush therefore does not guarantee that every message will be delivered, delivered by a particular time, opened, heard or displayed identically on every device or service. Delivery and interaction status is based on information returned by the providers and networks involved. Maintenance and changes may be carried out where needed for operations, security, provider requirements or development. Intellipush seeks to limit unnecessary interruption but provides no general SLA unless separately agreed.

3. Accounts, users and security

The Customer must provide accurate account and billing information, keep contact details current and grant access only to authorised persons. The Customer must protect passwords, API credentials and other access information, remove access when no longer needed, and notify info@intellipush.com of suspected misuse. The Customer is responsible for activity through its accounts and integrations unless it results from a matter for which Intellipush is responsible under the agreement or mandatory law.

4. Credits, prices and payment

The standard model has no fixed monthly platform fee and no lock-in. The Customer purchases SMS credits and pays for actual use. Credits are valid for 24 months from purchase and are non-refundable unless mandatory law or a separate written agreement requires otherwise. Optional services such as keywords, short numbers, dedicated numbers or other rented items may carry recurring charges and separate terms.

Price is affected by destination, message length, character set, number of SMS segments, operator and selected services. Current prices are shown in the portal or agreed in writing. Prices exclude VAT unless stated otherwise. The Customer must pay invoices when due. Intellipush may restrict credit purchases or use following non-payment or a reasonable suspicion of payment abuse.

5. Customer Data, instructions and ownership

The Customer retains its rights in Customer Data and grants Intellipush the limited right needed to provide, secure and support the Service. The Customer is responsible for ensuring that data, instructions, recipients, sender identity and content are lawful, relevant and accurate. The Customer must not enter more personal data than necessary or use a messaging channel for content requiring stronger confidentiality without a documented assessment.

Customer Data may include contact details, list and segment fields, message or voice-delivery content selected by the Customer, files and links, sender information, schedules, delivery and interaction events, inbound communications, callback and integration data, and related operational metadata. The Customer must choose the channel and content according to the confidentiality, legal and operational risk of the intended use.

Intellipush does not use identifiable recipient data from customer campaigns for its own marketing. Non-identifying aggregated service statistics may be used for operations, security, capacity management and improvement.

6. Acceptable use

The current Acceptable Use Policy, version 2026.08, is incorporated into the agreement. As a contractual condition of using Intellipush, the Customer must be able to document the recipient's prior consent before sending advertising or marketing through the Service, including SMS, email and automated voice functions where enabled. This Intellipush rule may be stricter than a minimum exception available under local law and does not reduce the Customer's duty to comply with any stricter or additional requirement. The Customer must provide an easy and free opt-out appropriate to the channel, use STOPP or STOP where an SMS reply route supports it, and provide another clear route for one-way senders. Registered opt-outs must be respected in Intellipush and in the Customer's own systems and channels.

Spam, fraud, phishing, harassment, unlawful content, misleading sender identity, malware, unauthorised data collection and circumvention of controls are prohibited. The Service must not be the sole channel for emergency communications or other use where delay or failure may endanger life or health or cause significant damage.

7. Files shared by link

A file shared through a public-link feature is available to anyone who has the link. The link has high entropy, is not listed in a public directory and is configured not to be indexed, but it is not access-controlled. The Customer can revoke or delete the file and must not use the feature for unlawful, secret, sensitive or high-risk content without a separate assessment. Temporary import files are automatically deleted within seven days.

8. Integrations and third-party services

The Customer is responsible for its systems, callbacks, endpoints, integrations and providers. Supported callbacks must use HTTPS. Intellipush is not responsible for third-party services selected by the Customer or for changes, failures and restrictions at operators and other providers outside Intellipush's reasonable control. Documentation may be updated as interfaces or security requirements change.

9. Privacy and confidentiality

Intellipush is the controller for its own purposes, such as accounts, billing, support and security, as explained in the Privacy and Cookie Notice. Where Intellipush processes personal data on the Customer's behalf, Schedule 1 applies automatically. Each party must protect the other party's non-public business information and use it only for the agreement, except information that is public, lawfully received from another source, independently developed or required to be disclosed by law.

10. Intellectual property

Intellipush and its licensors retain rights in the Service, software, documentation, design and trade marks. The agreement grants the Customer a limited, non-exclusive and non-transferable right to use the Service while the agreement remains in force. The Customer must not copy, sell, circumvent, decompile or otherwise exploit the Service beyond what law or the agreement permits. Intellipush may use general feedback without identifying the Customer or disclosing confidential information.

11. Support and changes to the Service

Ordinary support is provided through published contact channels within available capacity. No particular response time applies unless separately agreed. Intellipush may change, improve or discontinue functions where objectively justified. The Customer will be informed through an appropriate channel of a material adverse change to ongoing use where practicable and required.

12. Suspension

Intellipush may restrict or suspend the Service following non-payment, a security risk, legal or operator requirements, complaints, misuse or a material breach. Where circumstances allow, the Customer will have an opportunity to remedy the matter. Urgent action may be taken without prior notice to protect recipients, networks, data or the Service.

13. Termination and Customer Data

The Customer may terminate the standard Service without lock-in. Rented services may have separate notice terms. Intellipush may terminate for material breach, unlawful use, repeated misuse or where the Service can no longer be provided responsibly. Accrued payment obligations continue.

After termination, the Customer normally has 30 days to export Customer Data. Intellipush then erases Customer Data from active systems within 60 days, before remnants expire through the ordinary 14-day backup cycle. Statutory retention, security records, disputes and other lawful exceptions may require limited data to be retained for longer.

14. Service boundaries

The Service is provided with the functionality made available from time to time and without warranties other than those expressly stated in the agreement or mandatory law. The Customer must assess whether the Service suits its purpose, security needs, countries, recipients and industry requirements and must maintain reasonable contingency arrangements for critical workflows.

15. Liability

Neither party is liable for indirect loss, loss of profit, revenue or savings, or loss of data unless mandatory law provides otherwise. Each party's total liability under the agreement is limited to the amount the Customer paid Intellipush in the twelve months before the event giving rise to the claim. The limitation does not apply to wilful misconduct or gross negligence, liability that cannot lawfully be limited, the Customer's payment obligations or infringement of Intellipush's intellectual-property rights.

The Customer will indemnify Intellipush against documented third-party claims resulting directly from the Customer's unlawful recipient evidence, content, sender identity or instruction, to the extent Intellipush did not contribute to the claim.

16. Matters beyond reasonable control

Neither party is liable for failure caused by a matter beyond its reasonable control, including widespread network or operator failure, power failure, natural events, war, government action, industrial disputes or serious cyberattacks. The affected party must seek to limit the impact and inform the other where reasonably practicable.

17. Changes to the agreement

Intellipush may update the agreement for legal, security, operational or commercial reasons. A new version will have a version number and effective date. Existing customers will be informed through the portal, email or another suitable channel where a change is material. No fixed minimum notice period is promised. Changes driven by law, authorities, operators or security may take effect quickly. Continued use after the effective date constitutes acceptance where lawful; otherwise, the Customer may terminate before the change takes effect.

18. General provisions, governing law and disputes

The Customer may not assign the agreement without written consent. Intellipush may assign it as part of a reorganisation or business transfer if the Customer's rights are not materially reduced. Invalidity of one provision does not affect the remainder. A failure to enforce is not a waiver. Notices may be given through the portal, email or published contact channels.

The agreement is governed by Norwegian law. The parties must first seek to resolve disagreements through dialogue. If no solution is reached, proceedings may be brought before the ordinary Norwegian courts with venue where Intellipush has its registered office, unless mandatory law provides otherwise.


Schedule 1 – Data Processing Addendum

This DPA forms part of the service terms and applies automatically where Intellipush processes personal data on the Customer's behalf. It is to be interpreted in accordance with Article 28 GDPR and applicable Norwegian data-protection law.

1. Roles and scope

The Customer is the controller and Intellipush the processor for Customer Data processed on the Customer's behalf, unless the parties have documented another lawful allocation. Intellipush is an independent controller for its own purposes, including account administration, billing, support, security, abuse prevention and legally required records.

2. Documented instructions

Intellipush processes Customer Data to provide, secure, support and terminate the Service under the agreement, the Customer's use and other documented instructions. If Intellipush considers an instruction to infringe data-protection law, it will inform the Customer where legally permitted. Processing required by law may be carried out after notice unless notification is prohibited.

3. Customer obligations

The Customer must ensure a valid legal basis, transparency, data quality, data minimisation, data-subject rights and lawful instructions. It must configure users, opt-out and integrations responsibly and must not send or upload data that is unnecessary or unsuitable for the selected messaging channel. The Customer is responsible for assessing whether the Service and controls are appropriate to the risk of the intended processing.

4. Confidentiality and personnel

Intellipush will limit access to persons who need it for their duties and ensure that they are bound by confidentiality under contract or law. Access will be removed when the need ends.

5. Security

Intellipush will maintain risk-based technical and organisational measures. High-level measures are set out in Annex B and on the security page. Measures may evolve provided the overall level of protection is not materially reduced. No control provides an absolute guarantee against incidents.

6. Subprocessors

The Customer gives general authorisation for Intellipush to use the subprocessors listed in the exact, versioned subprocessor schedule. The schedule is commercially confidential and is made available to verified customers and prospects before contracting and subsequently on request. Intellipush will impose relevant privacy, confidentiality and security obligations on each subprocessor and remains responsible for its obligations under this Schedule 1. Intellipush will notify the Customer through the portal, email or another suitable channel a reasonable time before a planned material new or replacement subprocessor begins processing Customer Data, allowing the Customer to object on documented, reasonable data-protection grounds. The parties will seek a reasonable solution; if none is available, the affected function or agreement may be terminated. Public provider categories and contact information are available under GDPR and data processing.

7. International transfers

Core infrastructure and backups are with AWS in Ireland, but message routes, recipient countries, mobile networks and supporting functions may involve processing outside the EEA. Intellipush will use a valid transfer basis and necessary safeguards where required for a transfer for which it is responsible. The Customer remains responsible for its instructions, recipient countries and integrations.

8. Assistance and rights

Taking account of the nature of processing and information available, Intellipush will assist the Customer with data-subject rights, security assessments, impact assessments and engagement with supervisory authorities to the extent required by GDPR. The Customer must first use available functions and provide necessary, limited information. Particularly extensive assistance may be charged at an agreed or reasonable rate where the need was not caused by Intellipush's breach.

9. Personal-data breaches

Intellipush will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data. The notice will contain available relevant information about the incident, likely consequences and measures and may be provided in stages. The Customer is responsible for notifications to data subjects and authorities in its role as controller.

10. Information and audit

Intellipush will make available information needed to demonstrate compliance with this Schedule 1. The Customer may request reasonable documentation and, where that is insufficient, conduct or commission a relevant audit on reasonable notice, during normal working hours and without compromising other customers' confidentiality or security. The parties will agree scope and costs. Intellipush bears the cost of an audit that establishes its material breach.

11. Export, return and erasure

On termination, the Customer normally has 30 days to export Customer Data. Intellipush then erases Customer Data from active systems within 60 days. Remnants in production backups expire through the normal 14-day cycle. Intellipush may retain limited data where required by law or for security, disputes or legal claims and will then restrict further processing. Backups will not be restored for ordinary use; if restoration is necessary, deleted data will be handled through normal re-deletion so far as reasonably practicable.

12. Duration and liability

Schedule 1 applies for as long as Intellipush processes Customer Data on the Customer's behalf. The agreement's limitations of liability also apply to this Schedule 1 to the extent permitted by law. Duties concerning confidentiality, erasure and lawful further retention continue after termination where their nature requires it.

Annex A – Processing details

  • Subject matter and purpose: provide, secure, support and terminate the customer portal, SMS, email and voice-delivery functions where enabled, APIs, contact and list management, imports, inbound messaging, opt-out and suppression, files and links, reporting, supported callbacks or webhooks and agreed related functions.
  • Operations: receipt, recording, organisation, structuring, storage, validation, retrieval, display, transmission, routing, delivery, reporting, suppression, support, export, restriction and erasure according to the Customer's use and documented instructions.
  • Data subjects: the Customer's contacts and recipients, its users, and other persons the Customer chooses to process in the Service.
  • Personal data: telephone numbers, email addresses, names and contact fields selected by the Customer, list and segment data, SMS, email and voice-delivery content or configuration, sender information, timestamps, status and interaction events, opt-outs, inbound messages, files and links, import data, callback and integration data, and related operational and security metadata.
  • Special-category and high-risk data: not intended for standard use. The Customer must avoid special-category, criminal-offence, credential, secret, child-targeted, emergency or other high-risk data unless a separate documented assessment, lawful instruction and appropriate controls have been agreed.
  • Duration: the agreement term plus the export, active-system erasure, backup expiry, legal-hold and lawful-exception periods stated in the agreement and Schedule 1.

Annex B – High-level security measures

  • Privileged administrative access is protected by MFA; remote production administration takes place through a VPN.
  • Access is limited according to need, and production and staging environments are separated for customer content.
  • HTTPS is used for the portal, supported REST v2 API endpoints and supported callbacks. The supported REST v2 authentication flow uses OAuth 2.0. Messaging-channel transport and downstream provider controls vary by channel and route; this does not mean that SMS, standard email or voice delivery is end-to-end encrypted.
  • Core portal infrastructure and backups are hosted with AWS in Ireland. Other AWS services, messaging routes, provider support, recipient countries and onward communications networks may involve other locations, as described in the public category information and confidential subprocessor schedule. No statement is made that all processing occurs in the EEA. Production backups follow a 14-day expiry cycle.
  • Temporary import files are automatically deleted within seven days.
  • Blacklists, opt-out suppression and campaign limits help prevent misuse.
  • An external penetration test was performed in April 2026 following security hardening.
  • Potential incidents are assessed and handled according to severity, affected data and applicable notification duties.

Annex C – Confidential subprocessor schedule and change notices

Intellipush maintains an exact, versioned and commercially confidential schedule of subprocessors that may process Customer Data on Intellipush's behalf. It identifies the legal entity, role, purpose, relevant countries and transfer basis where applicable. It is made available to verified customers and prospects before contracting and subsequently on request through the Intellipush contact channel. Intellipush records the schedule version associated with contractual acceptance when portal acceptance logging is activated. Downstream mobile and communications networks, customer-selected destinations and independent-controller recipients may have roles that differ from a conventional subprocessor. Payment, accounting and website-security providers used mainly for Intellipush's own controller purposes are described in the Privacy and Cookie Notice and are not automatically subprocessors for Customer Data.

x
x
x
x