Data Processing Agreement
Last updated: March 2, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between LeadScoutr ("Processor") and the customer ("Controller") for the provision of the LeadScoutr platform (the "Service"), in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction, as defined in Article 4(2) of the GDPR.
- "Controller" means the customer who determines the purposes and means of the Processing of Personal Data.
- "Processor" means LeadScoutr, which processes Personal Data on behalf of the Controller.
- "Sub-Processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
2. Scope of Processing
The Processor shall process Personal Data only to the extent necessary to provide the Service to the Controller, including:
- Account and user management (names, email addresses, authentication credentials)
- Lead and contact data storage and enrichment
- AI-powered search and scoring features
- Analytics and usage reporting
- Email communications (transactional and notification emails)
The categories of data subjects include the Controller's employees, team members, and the business contacts stored within the Service.
3. Controller Obligations
The Controller shall:
- Ensure that it has a lawful basis for processing Personal Data and for instructing the Processor to process such data
- Provide clear and documented instructions to the Processor regarding the processing of Personal Data
- Comply with all applicable data protection laws, including the GDPR
- Ensure that data subjects have been informed about the processing and their rights
- Respond to data subject requests and involve the Processor where necessary
4. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law
- Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR
- Assist the Controller in responding to data subject requests under Articles 15 to 22 of the GDPR
- Assist the Controller in ensuring compliance with obligations under Articles 32 to 36 of the GDPR, taking into account the nature of processing and information available to the Processor
- At the choice of the Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless retention is required by applicable law
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR
5. Sub-Processors
The Controller provides general authorization for the Processor to engage Sub-Processors. The Processor shall:
- Maintain an up-to-date list of Sub-Processors on its Sub-Processors page
- Notify the Controller at least 30 days in advance of any intended changes to Sub-Processors, giving the Controller the opportunity to object
- Ensure that each Sub-Processor is bound by data protection obligations no less protective than those set out in this DPA
- Remain fully liable to the Controller for the performance of each Sub-Processor's obligations
Current Sub-Processors include: MongoDB Atlas (database hosting), Anthropic (AI processing), DeepSeek (AI processing), People Data Labs (data enrichment), Serper (search infrastructure), Resend (email delivery), Cloudflare R2 (file storage), Upstash (rate limiting), PostHog (analytics), and Vercel (hosting and deployment).
6. Security Measures
The Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data, including but not limited to:
- Encryption: TLS 1.3 for data in transit, AES-256 encryption at rest
- Access control: Role-based access control with least-privilege principles
- Data isolation: Multi-tenant architecture with company-scoped data segregation
- Authentication: Secure session management with configurable authentication methods
- Monitoring: Continuous monitoring, logging, and alerting for security events
- Backups: Regular automated backups with tested recovery procedures
- Vulnerability management: Regular security assessments and timely patching
7. Data Breach Notification
In the event of a Data Breach, the Processor shall:
- Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach
- Provide the Controller with sufficient information to enable the Controller to meet its obligations under Articles 33 and 34 of the GDPR, including:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
- Cooperate with the Controller in investigating and remediating the breach
- Document all Data Breaches, including the facts, effects, and remedial actions taken
8. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under this DPA and Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
- Audits shall be conducted with reasonable prior notice (at least 30 days)
- Audits shall be limited to once per year, unless a Data Breach or regulatory investigation requires additional review
- The Controller shall bear the costs of any audit
- Audit activities shall not unreasonably disrupt the Processor's business operations
- The Controller and its auditors shall be bound by confidentiality obligations regarding any information accessed during the audit
9. Data Deletion and Return
Upon termination of the Service agreement, the Processor shall, at the Controller's choice:
- Return: Provide the Controller with all Personal Data in a structured, commonly used, and machine-readable format
- Delete: Securely delete all Personal Data and existing copies, unless applicable law requires retention
The Controller must communicate its choice within 30 days of termination. If no instruction is received, the Processor shall delete all Personal Data within 90 days of termination. The Processor shall certify the deletion in writing upon request.
10. International Data Transfers
Where the processing of Personal Data involves a transfer outside the European Economic Area (EEA), the Processor shall ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- Transfers to countries with an adequacy decision under Article 45 of the GDPR
- Supplementary technical and organizational measures where necessary to ensure an equivalent level of protection
Details of Sub-Processor locations and applicable transfer mechanisms are available on our Sub-Processors page.
11. Liability
Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set out in the main Service agreement between the parties. Nothing in this DPA shall limit either party's liability for breaches of its obligations under the GDPR to the extent that such liability cannot be limited under applicable law.
12. Contact and Execution
To execute this Data Processing Agreement or to discuss its terms, please contact us:
Email: [email protected]
Subject line: DPA Execution Request
We will provide a countersigned copy of this DPA within 10 business days of receiving your signed version.
Related documents: