DPA

1. Definitions

For the purposes of this DPA:


2. Subject Matter and Duration

The Processor will process Lead Personal Data solely to provide the services described in the Terms of Service, following the Controller's documented instructions. This DPA is coextensive in duration with the Terms of Service. Termination of the Terms implies termination of this DPA.


3. Description of Processing

Element Description
Categories of personal data Business trade name, contact person name, phone, contact email, physical address, URL and public visual data from the business website
Categories of data subjects Representatives, contact persons and owners of B2B businesses
Purposes of processing Extraction, enrichment, structured storage and facilitation of B2B commercial communication sending, under the Controller's explicit instruction
Duration of processing Term of the Controller's active subscription + 30 additional days for export
Nature of processing Collection, storage, enrichment, organization, display and facilitation of sending

4. Processor Obligations (LeadGen-Agent)

4.1 Following Instructions

The Processor will process Lead Personal Data only in accordance with the Controller's documented instructions, unless a legal obligation imposes different processing. In that case, the Processor will inform the Controller before proceeding, unless prohibited by law for reasons of public interest.

4.2 Personnel Confidentiality

The Processor will ensure that personnel with access to Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory.

4.3 Security Measures — Article 32 GDPR

The Processor will implement and maintain technical and organizational measures appropriate to the level of risk, including:

4.4 Sub-processors

The Processor will not engage new sub-processors without prior authorization from the Controller. General authorization for the sub-processors listed in Article 5 of this DPA is granted by the Controller upon accepting the Terms of Service.

The Processor will impose data protection obligations equivalent to those of this DPA on each sub-processor. If a sub-processor fails to meet its obligations, the Processor remains liable to the Controller to the same extent as if the Processor itself had failed to perform.

4.5 Assisting the Controller

The Processor will reasonably assist the Controller in:

4.6 Breach Notification

The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Security Breach affecting Lead Personal Data. The notification will include, to the extent available:

If not all information is available within 72 hours, the Processor will provide it in subsequent notifications.

4.7 Deletion or Return of Data

Upon termination of the Service (by cancellation, termination or expiry), the Processor will, at the Controller's choice expressed within the 30-day period following termination, either:

unless applicable law requires retention for an additional period.

4.8 Cooperation in Audits

The Processor will provide the Controller with all information reasonably necessary to demonstrate compliance with the obligations of this DPA. Upon at least 30 days' advance notice, the Processor will facilitate audits conducted by the Controller or a third-party auditor designated by the Controller, under reasonable conditions of confidentiality and without disrupting service operations for other clients.


5. Authorized Sub-processors

The Controller authorizes the Processor to use the following sub-processors for Service delivery:

Sub-processor Processing Country Function Protection Guarantee
Google LLC United States Google Maps/Places API for lead extraction; Gmail OAuth API for email sending Standard Contractual Clauses (SCCs) — Decision 2021/914/EU
Paddle BV Netherlands (EU) Payment processing and tax management Native GDPR (EEA)
AI Providers (per active configuration) United States AI generation of presentations and proposals SCCs or specific DPA
VPS Infrastructure Provider (per configuration) Per server region Hosting, PostgreSQL database, network and storage Data processing contract + equivalent technical measures

If the Processor wishes to add or replace sub-processors, it will notify the Controller 30 days in advance by email. The Controller may reasonably object to the new sub-processor within that period. If the Controller does not object, authorization is deemed granted. If the Controller objects and the Processor cannot provide the Service without the new sub-processor, the Controller may terminate the Service without penalty.


6. International Transfers

Transfers of Personal Data from the EEA/UK to countries without a European Commission adequacy decision are carried out using the Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914/EU), which are incorporated into this DPA by reference. Applicable Modules are Module 2 (controller to processor) and Module 3 (processor to processor), as applicable.


7. Controller Obligations (User)

The Controller acknowledges, accepts and warrants:


8. Liability between the Parties

The parties agree that each party is liable to data subjects to the extent that it is responsible for the specific damage or infringement alleged by those data subjects. If one party pays compensation for damages that are wholly or partly attributable to the other party, the former will have the right to claim the corresponding portion from the latter, pursuant to Article 82 GDPR.


9. Amendments

This DPA may be amended to reflect changes in the GDPR, European Commission decisions or other applicable regulations. The Processor will notify the Controller at least 30 days in advance of material changes. Continued use of the Service implies acceptance.


10. Governing Law

This DPA is governed by the laws of the Republic of Colombia. For matters specifically covered by the GDPR, Regulation (EU) 2016/679 applies as special law of superior rank.


11. DPA Contact

For matters related to this Agreement or data processing as a processor:

privacy@leadgen-agent.com LeadGen-Agent — Sergio Jauregui Bogotá D.C., Colombia