Launching soon — get early access:

Trust Center

Last updated: August 28, 2026

Single-page summary of every regulatory framework, security control, and compliance status that applies to Intelloro.

Privacy

Multi-jurisdiction policy stack: GDPR + UK GDPR + CCPA + 6 US state laws + PIPEDA + Quebec Law 25 + LGPD + PDPO. Children-specific frameworks (UK Children's Code, CA AADC, GDPR Art. 8, Brazil ECA Digital) in progress — will activate when age-detection is deployed.

Platform Regulation

EU Digital Services Act (Art. 15-21 documented; Art. 30 vendor verification in progress), EU AI Act (limited-risk classification + Art. 4 + 50 disclosure), DMCA, CAN-SPAM — documented and live.

Security

TLS encryption in transit (Vercel) + encryption at rest (MongoDB Atlas) + restricted admin access. SOC 2 + ISO 27001 in progress.

Compliance Matrix

FrameworkRegionStatusImplementation
GDPR (Regulation 2016/679)EU/EEAPartialLawful basis mapped, DSAR API, breach 72hr, SCCs+TIA; Art. 27 EU Representative appointment pending
UK GDPR + DPA 2018United KingdomPartialSame as GDPR, ICO complaints supported; Art. 27 UK Representative appointment pending
CCPA / CPRACalifornia, USASelf-DeclaredDo Not Sell page, CPPA-aligned rights flow
California Delete Act (SB 362)California, USANot ApplicableNot registered as Data Broker (no third-party data sourcing)
Texas TDPSATexas, USASelf-DeclaredTargeted ad + profiling opt-out, 45-day SLA
Virginia VCDPAVirginia, USASelf-DeclaredSame as Texas TDPSA framework
Colorado ColoPAColorado, USASelf-DeclaredGPC signal honored, profiling opt-out
Connecticut CTDPAConnecticut, USASelf-DeclaredSame framework as ColoPA
Utah UCPAUtah, USASelf-DeclaredTargeted advertising opt-out
Oregon OCPAOregon, USASelf-DeclaredSame framework as ColoPA
Quebec Law 25Canada (Quebec)PartialPrivacy Officer named + automated-decision rights documented; PIA framework will be conducted when triggering processing arises
Federal PIPEDACanadaSelf-DeclaredOPC complaints supported
LGPD (Law 13.709/2018)BrazilSelf-DeclaredDPO contact, ANPD complaint path
ECA Digital (Law 15.211/2025)Brazil (minors)In ProgressWill apply Privacy-by-Design defaults where minor identified; age-detection not yet deployed
Bangladesh PDPO 2025BangladeshSelf-DeclaredDPO appointed, lawful basis, cross-border safeguards
COPPA (15 USC §§ 6501-6506)USA (children)Self-DeclaredNo knowing collection from under-13
GDPR Art. 8 (children)EU/EEAIn ProgressWill require parental consent where minor identified; age-detection not yet deployed
UK Children's CodeUnited KingdomIn ProgressWill apply ICO Children's Code where minor identified; age-detection not yet deployed
California AADCCalifornia, USAIn ProgressWill apply privacy-by-default where minor identified; age-detection not yet deployed
EU Digital Services Act (DSA)EU/EEAPartialArt. 16 notice form, Art. 17/20/21 process documented, Art. 15 transparency report scheduled. Art. 30 trader-verification flow being implemented
EU AI Act (Reg. 2024/1689)EU/EEAPartialLimited-risk self-classification, Art. 50 disclosure on /ai-disclosure, Art. 4 AI literacy via public methodology. AI-generated content labelling on detail pages being implemented
DMCAUSASelf-DeclaredDesignated agent, takedown + counter-notice
CAN-SPAM ActUSASelf-DeclaredSingle-click unsubscribe in every email
ePrivacy Directive (cookies)EU/EEASelf-DeclaredGranular consent banner, GPC honored
WCAG 2.1 Level AAGlobalIn ProgressSelf-evaluation, see Accessibility Statement
Section 508 (Rehab Act)USA FederalIn ProgressAligned with WCAG 2.1 AA approach
European Accessibility ActEU/EEAIn ProgressPreparing for June 2025 enforcement deadline
TLS encryption (in transit)GlobalCompliantProvided by Vercel edge
Encryption at restGlobalCompliantProvided by MongoDB Atlas
SOC 2 Type IIUSA / GlobalIn ProgressInternal controls aligned with framework; external CPA audit not yet engaged
ISO 27001GlobalIn ProgressInternal controls aligned with framework; certification not yet pursued
GDPR Art. 27 EU RepresentativeEU/EEAIn ProgressAppointment under evaluation; direct contact via info@intelloro.com pending
UK GDPR Art. 27 UK RepresentativeUKIn ProgressAppointment under evaluation

Status Legend

  • Compliant — Framework is fully implemented and documented; user-facing rights are active.
  • In Progress — Implementation is underway; baseline obligations are met but full conformance is being completed.
  • Self-Declared — Internal controls aligned with the framework; no external audit completed yet.
  • Partial — Some elements implemented; gaps identified and prioritized for remediation.
  • Not Applicable — Framework does not apply to Intelloro's current operations.

These statuses reflect Intelloro's own self-assessment, not a government certification. Data-protection regulations such as GDPR, CCPA, LGPD and PDPO have no official certification scheme — a “Self-Declared” row means we have implemented the framework's requirements ourselves and have not undergone an independent third-party audit. Rows naming a specific external certification (SOC 2, ISO 27001) show their true audit status, and encryption rows describe a factual technical control provided by our infrastructure vendors.

Quick Links

Need More Detail?

Enterprise customers, security teams, and regulators may request the underlying documents (Transfer Impact Assessment, Privacy Impact Assessments, DPA templates, security questionnaire responses) by emailing info@intelloro.com with the subject “Trust Center Request”.

Response SLA: 5 business days for security questionnaires; 30 days for DSAR / data export.