When this agreement applies
This agreement forms part of the service agreement where a customer is a controller and we process personal data on that customer's behalf. Where the customer is itself a processor, it confirms it has the authority needed to appoint us. Actual decision-making determines each party's role, not the label applied to it.
Account administration and other processing we carry out for our own purposes fall outside this agreement and are covered by our Privacy Policy.
What is processed
- Subject matter: the research, enrichment, storage, export and outreach functions selected in the customer's order.
- Duration: the service period, plus any agreed return or deletion window and any retention the law requires.
- Data: the business contact, source, verification, pipeline and message fields needed for those functions. Special category data, criminal offence data and children's data are excluded from authorised use.
- Individuals: business contacts, prospects and the customer's authorised users.
- Customer rights: to give lawful instructions, obtain assistance, authorise suppliers, and require return or deletion.
Limits on processing
We process covered data only on the customer's documented lawful instructions, including about transfers, unless the law requires otherwise. Where we are permitted to, we will tell the customer before processing on that basis. If an instruction appears to conflict with data protection law, we will say so and pause it while it is resolved.
We do not reuse covered data for our own marketing, sell it, or use it for general AI model training under this appointment.
Confidentiality and security
Access is limited to authorised people under confidentiality obligations. We implement technical and organisational measures appropriate to the risk, taking account of the nature of the data and the processing.
Those measures cover access control, protection in transit and at rest, availability and recovery, incident handling, deletion and periodic testing. No platform can promise absolute security, and we do not.
Sub-processors and transfers
Appointing a sub-processor requires the customer's authorisation. Under a general authorisation, we give advance notice of additions or replacements and a meaningful opportunity to object on data protection grounds before that processing starts.
Each sub-processor is bound by equivalent obligations, and we remain responsible to the customer for their performance. Where an objection cannot be resolved, we will offer an alternative or stop the affected processing.
Transfers between countries use an appropriate legal mechanism, with any additional safeguards the circumstances require.
Requests, incidents and assessments
Taking account of the processing and the information available to us, we assist the customer with individual rights requests, security obligations, breach assessment and notification, impact assessments and regulatory consultation. Requests that reach us directly are referred to the customer promptly unless the law requires us to respond.
We notify the customer without undue delay after becoming aware of a personal data breach affecting covered data. We do not wait for a complete investigation before making initial contact, and we supplement the information as it becomes available.
Evidence and audits
We make available the information needed to demonstrate compliance with this agreement, and allow and contribute to audits by the customer or an auditor it appoints. Reasonable arrangements may protect confidentiality and other customers, but will not be used to defeat an audit right.
Where reasonable costs of assistance are shared, that is agreed in advance and is not used to withhold cooperation the law requires.
Return, deletion and retained copies
At the end of the relevant processing we return or delete covered data at the customer's choice, and delete existing copies unless the law requires us to keep them. Exports, deletion from active systems and backup expiry follow the agreed schedule, and anything retained stays protected and limited to the reason it was kept.
Statutory rights and regulatory powers are not affected by what the parties agree between themselves.
Sign Up