Data Processing Addendum (DPA)
Between: [Company Name], operating [Product Name] ("Processor") and the Customer identified in the applicable order/invoice ("Controller").
This DPA supplements the Terms of Service and applies when Customer submits personal data of its own contacts (e.g., an imported lead list containing names/emails Customer already controls) for processing through the Service. Provide this document to enterprise/EU/UK customers who request one for their own GDPR compliance file.
1. Roles
For personal data that Customer uploads or imports about its own known contacts, Customer is the Controller and [Product Name] is the Processor, processing that data only on Customer's documented instructions (i.e., to run the requested scans/enrichment and return results).
For personal data that [Product Name]'s scanner independently extracts from a publicly available third-party website at Customer's request (Contact Finder results), [Product Name] acts as an independent controller for the initial collection, as described in the Privacy Policy; once Customer downloads and uses that data for its own outreach, Customer separately becomes a controller for its own subsequent use. [This split-controller structure is a reasonable starting position but is genuinely fact-specific — confirm the framing with a data-protection lawyer, since some regulators/customers may expect a joint-controller or full-controller characterization instead.]
2. Subject matter and duration
Subject matter: provision of the [Product Name] sales-intelligence Service. Duration: for as long as Customer maintains an active account, plus any retention period described in the Privacy Policy.
3. Nature and purpose of processing
Scanning submitted URLs/lists, matching/enriching contact information, scoring leads, generating briefs and pitch drafts, and returning results to Customer via dashboard, export, API, or MCP connector.
4. Categories of data subjects and data
Data subjects: individuals whose business contact information appears in Customer's imported lists or on scanned third-party websites. Data: name, business email, business phone, job title/role (where published), social-media profile URL, and company affiliation. No special-category data is intentionally processed.
5. Processor obligations
Processor will: (a) process personal data only on Controller's documented instructions, unless required otherwise by law; (b) ensure personnel with access are bound by confidentiality; (c) implement appropriate technical and organizational security measures; (d) assist Controller, at Controller's reasonable request, with data subject rights requests and with Controller's own obligations regarding security, breach notification, and data protection impact assessments, to the extent relevant to Processor's processing; (e) notify Controller without undue delay after becoming aware of a personal data breach affecting Controller's data; (f) delete or return personal data at the end of the Service relationship, except as required to be retained by law; and (g) make available information reasonably necessary to demonstrate compliance with this DPA.
6. Sub-processors
Controller authorizes Processor's use of the sub-processors listed in the Privacy Policy (Section 4) and any updated list made available on request. Processor will notify Controller of a new sub-processor, and Controller may object on reasonable data-protection grounds within 14 days.
7. International transfers
Where Controller's personal data is transferred from the UK/EEA to the United States or another country without an adequacy decision, the parties agree that such transfer is made under the EU Standard Contractual Clauses (Controller-to-Processor module) and, for UK transfers, the UK International Data Transfer Addendum, incorporated by reference. [Confirm actual execution of SCCs/IDTA with counsel — referencing them here is not the same as having them properly executed and annexed.]
8. Audit rights
On reasonable prior notice and no more than once per year (absent a security incident), Controller may request written information demonstrating Processor's compliance with this DPA in lieu of an on-site audit, given Processor's size; a full on-site audit may be discussed for Flagship/Fleet/Custom contracts.
9. Liability
Liability under this DPA is subject to the limitation of liability in the Terms of Service, except where applicable data-protection law prohibits limiting liability for that specific type of claim.
10. Term
This DPA remains in effect for as long as Processor processes personal data on Controller's behalf under the Terms of Service.
Template only, styled on common GDPR Article 28 processor-clause structure. Before offering this to enterprise customers, have a data-protection lawyer confirm: (1) the controller/processor role split in Section 1 fits your actual product design, (2) SCCs/IDTA referenced in Section 7 are properly executed with each relevant sub-processor, and (3) whether you need to appoint an EU and/or UK representative under GDPR/UK GDPR Article 27 given the volume and nature of your scanning activity.