The processor terms, for customers who need one on file. Template — review before signing. · Last updated 2026-09-28
This Addendum forms part of the Terms of Service between [LEGAL ENTITY NAME] ("Processor") and the customer ("Controller"). It applies where the Processor processes personal data on the Controller's behalf under UK GDPR, EU GDPR, or both.
The Controller determines the purposes and means of processing prospect data. The Processor processes it only on the Controller's documented instructions, which for these purposes are the Terms of Service, this Addendum, and the configuration the Controller sets in the Service.
The Controller gives general authorisation for the sub-processors listed on this page. The Processor will give at least 30 days' notice before adding or replacing one, and the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate without penalty. The Processor remains liable for its sub-processors' acts and omissions.
Where personal data is transferred outside the UK/EEA, the parties incorporate the EU Standard Contractual Clauses (Module Two, controller to processor) and, for UK transfers, the UK International Data Transfer Addendum, in each case with the docking clause enabled and the Processor as data importer.
The Controller can export all workspace data as CSV at any time from within the Service. On termination or on request, data is deleted within 30 days, and from backups within a further 60 days as they age out.
The Processor will respond to reasonable written information requests within 30 days. On-site audits may be requested once in any 12-month period, on 30 days' notice, during business hours, and subject to confidentiality — or satisfied by an independent report where one is available.
Liability under this Addendum is subject to the limitations in the Terms of Service, except where applicable data protection law does not permit that.
We may update this document. Material changes are announced in the product and by email to workspace owners at least 14 days before they take effect. The date at the top is the version in force.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Questions about this document: [legal@yourdomain].
Everyone we send customer data to, and why. Changes are announced 30 days in advance.
| Provider | Purpose | Location | Data |
|---|---|---|---|
| Cloudflare | Application hosting, database (D1), object storage, CDN, DDoS protection | Global (edge) | All service data |
| Unipile | LinkedIn account connection, invitations, messages, inbox sync | EU (France) | LinkedIn account credentials/session, message content, contact identifiers |
| Apify | Public LinkedIn profile and post data collection | EU (Czechia) / US | Public profile URLs and the profile data returned |
| ScrapeCreators | Public LinkedIn post metadata and profile enrichment | US | Public profile and post URLs and the data returned |
| Google (Vertex AI / Gemini) | Scoring prospects, drafting messages, reading company websites | US / EU | Prospect profile text, your company profile, post text |
| Resend | Transactional and notification email | US / EU | Account email addresses and message content |
| PostHog | Website and product analytics, session replay, error reports | US | Pages viewed, clicks, referrer and campaign parameters, device and approximate location, account and workspace identifiers; replays with form inputs and workspace data masked |