Data Processing Agreement
Last updated: May 25, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer,” the “Controller”) and AgencyLeads (“Processor”) governing the provision of the AgencyLeads platform (the “Service”). It applies whenever the Service involves processing of personal data subject to the EU/UK GDPR.
1. Definitions
Terms used here have the meaning given in the GDPR. Where a term is not defined here or in the GDPR, our Terms of Service apply.
2. Roles
The Customer is the Controller of personal data uploaded to, generated within, or routed through the Service for outbound campaigns, list management, and pipeline tracking. AgencyLeads is the Processor and processes such personal data only on the Customer's documented instructions, except where required by applicable law.
3. Scope of Processing
Subject matter: provision of the AgencyLeads Service.
Duration: for the term of the Customer's account, plus a 90-day grace window after termination during which Customer Data may be exported.
Nature & purpose: sourcing, enriching, verifying, sending to, and tracking outbound communications with business contacts identified by the Customer.
Categories of personal data: business contact information (name, work email, job title, employer, LinkedIn URL, work location), behavioural data (email opens, clicks, replies), and reply content authored by recipients.
Categories of data subjects: business decision-makers, employees, and other professional contacts targeted by Customer's outbound activity.
4. Controller Responsibilities
The Customer is responsible for:
- Having a valid legal basis to upload, source, and process the relevant personal data;
- Issuing instructions to the Processor that comply with applicable law;
- Responding to data-subject requests addressed to the Customer;
- Honouring opt-outs and suppression lists generated by recipients of outbound campaigns;
- Notifying the Processor without undue delay if the Customer's instructions change.
5. Processor Obligations
AgencyLeads will:
- Process personal data only on the Customer's documented instructions;
- Ensure persons authorised to process personal data are bound by confidentiality;
- Implement appropriate technical and organisational measures (TLS in transit; encrypted storage in Supabase; role-based access; audit logs; least-privilege keys for third-party providers);
- Assist the Customer with data-subject requests insofar as feasible;
- Make available the information necessary to demonstrate compliance and allow reasonable audits, subject to a confidentiality agreement and reasonable notice;
- Notify the Customer without undue delay (and in any event within 72 hours) of becoming aware of a personal-data breach affecting the Customer's data.
6. Sub-Processors
The Customer authorises AgencyLeads to engage the following sub-processors to provide the Service:
- Vercel, Inc. — hosting and edge compute (US/EU regions).
- Supabase, Inc. — managed PostgreSQL database (EU region selected by default).
- CoreSignal — B2B employee and company data sourcing (Lithuania/EU).
- Findymail / Better Contact / MillionVerifier — email-finder and verification providers (engaged on Customer instruction).
- Smartlead.ai — outbound email infrastructure and reply ingestion.
- Anthropic, PBC — Claude API for personalization and reply classification. Anthropic does not train models on data sent via the API.
- Google LLC — OAuth identity provider and (when connected by Customer) Gmail mailbox access via Smartlead.
- Whop — subscription billing.
AgencyLeads will notify the Customer of any intended addition or replacement of a sub-processor at least 14 days in advance. The Customer may object on reasonable, documented data-protection grounds; if the parties cannot resolve the objection in good faith, the Customer may terminate the affected portion of the Service.
7. International Transfers
Where personal data is transferred outside the EEA/UK, the parties rely on the European Commission's 2021 Standard Contractual Clauses (Module Two: Controller to Processor) and on the UK International Data Transfer Addendum, both incorporated by reference into this DPA. Copies are available on request.
8. Security Measures
AgencyLeads implements at minimum the following technical and organisational measures:
- TLS 1.2+ for all data in transit;
- AES-256 encryption at rest for the database;
- Encrypted storage for OAuth tokens and third-party API keys;
- Role-based access controls on the Supabase admin layer;
- Row-level security policies enabled on all tenant tables;
- Audit logging of authentication and privileged actions;
- Regular dependency-vulnerability scans and timely patching;
- Background checks on personnel with production access;
- Documented incident-response runbook.
9. Deletion & Return of Data
On termination, the Customer may export Customer Data within 90 days. After that window, AgencyLeads will delete Customer Data from active systems within 30 days and from backups within 90 days, unless retention is required by applicable law.
10. Liability
Each party's liability arising out of or related to this DPA is subject to the limitation of liability set out in the Terms of Service.
11. Conflict
In the event of a conflict between this DPA and the Terms of Service with respect to processing of personal data, this DPA prevails.
12. Contact
Data protection: privacy@agencyleads.com
Security incidents: security@agencyleads.com