Data Processing Agreement
Last updated: August 16, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer,” the “Controller”) and AgencyLeads (“Processor”) governing the provision of the AgencyLeads platform (the “Service”). It applies whenever the Service involves processing of personal data subject to the EU/UK GDPR.
1. Definitions
Terms used here have the meaning given in the GDPR. Where a term is not defined here or in the GDPR, our Terms of Service apply.
2. Roles
The Customer is the Controller of personal data uploaded to, generated within, or routed through the Service for outbound campaigns, list management, and pipeline tracking. AgencyLeads is the Processor and processes such personal data only on the Customer's documented instructions, except where required by applicable law.
3. Scope of Processing
Subject matter: provision of the AgencyLeads Service.
Duration: for the term of the Customer's account. If a subscription lapses without the account being deleted, Customer Data remains stored and exportable until the Customer deletes the account; deletion is immediate and self-serve (see Section 9).
Nature & purpose: sourcing, enriching, verifying, sending to, and tracking outbound communications with business contacts identified by the Customer.
Categories of personal data: business contact information (name, work email, job title, employer, LinkedIn URL, work location), behavioural data (email opens, clicks, replies), and reply content authored by recipients.
Categories of data subjects: business decision-makers, employees, and other professional contacts targeted by Customer's outbound activity.
4. Controller Responsibilities
The Customer is responsible for:
- Having a valid legal basis to upload, source, and process the relevant personal data;
- Issuing instructions to the Processor that comply with applicable law;
- Responding to data-subject requests addressed to the Customer;
- Honouring opt-outs and suppression lists generated by recipients of outbound campaigns;
- Notifying the Processor without undue delay if the Customer's instructions change.
5. Processor Obligations
AgencyLeads will:
- Process personal data only on the Customer's documented instructions;
- Ensure persons authorised to process personal data are bound by confidentiality;
- Implement appropriate technical and organisational measures (TLS in transit; encrypted storage in Supabase; role-based access; audit logs; least-privilege keys for third-party providers);
- Assist the Customer with data-subject requests insofar as feasible;
- Make available the information necessary to demonstrate compliance and allow reasonable audits, subject to a confidentiality agreement and reasonable notice;
- Notify the Customer without undue delay (and in any event within 72 hours) of becoming aware of a personal-data breach affecting the Customer's data.
6. Sub-Processors
The Customer authorises AgencyLeads to engage the following sub-processors to provide the Service:
- Vercel, Inc. — hosting and edge compute (US/EU regions).
- Supabase, Inc. — managed PostgreSQL database and file storage (EU region selected by default).
- Upstash, Inc. — background job queue and rate limiting. Queue messages reference records being processed.
- CoreSignal — B2B employee and company data sourcing (Lithuania/EU).
- AI Ark — B2B people and company data sourcing, and email finding (engaged on Customer instruction).
- Blitz — B2B people and company data sourcing, and email finding (engaged on Customer instruction).
- QuickEnrich — email-finder and contact-enrichment provider (engaged on Customer instruction).
- Findymail / MillionVerifier — email-finder and verification providers (engaged on Customer instruction).
- Scraper.tech / Open Web Ninja — Google Maps business-listing data, including publicly listed owner and contact names (engaged on Customer instruction).
- Serper — Google search results, used to research a company from public sources.
- Smartlead.ai — outbound email infrastructure and reply ingestion.
- Anthropic, PBC — Claude API for personalization, company research and reply classification. Anthropic does not train models on data sent via the API.
- OpenAI, L.L.C. — secondary AI processing for the same purposes. OpenAI does not train models on data sent via the API.
- Resend, Inc. — transactional email to the Customer, including reply previews.
- Google LLC — OAuth identity provider and (when connected by Customer) Gmail mailbox access via Smartlead.
- Whop / Stripe — subscription billing and payment processing.
- Slack Technologies (Salesforce) — internal operations messaging. Reply notifications for the AgencyLeads team include the lead's name, email address, company, and an excerpt of the reply text.
- Clearbit (HubSpot) — company logo images fetched by domain; Clearbit receives the company domain being displayed, no personal data.
Providers marked “engaged on Customer instruction” receive data only when the Customer runs the corresponding feature. A Customer who never uses a given provider's feature sends it no data.
AgencyLeads will notify the Customer of any intended addition or replacement of a sub-processor at least 14 days in advance. The Customer may object on reasonable, documented data-protection grounds; if the parties cannot resolve the objection in good faith, the Customer may terminate the affected portion of the Service.
7. International Transfers
Where personal data is transferred outside the EEA/UK, the parties rely on the European Commission's 2021 Standard Contractual Clauses (Module Two: Controller to Processor) and on the UK International Data Transfer Addendum, both incorporated by reference into this DPA. Copies are available on request.
8. Security Measures
AgencyLeads implements at minimum the following technical and organisational measures:
- TLS 1.2+ for all data in transit;
- AES-256 encryption at rest for the database;
- Encrypted storage for OAuth tokens and third-party API keys;
- Role-based access controls on the Supabase admin layer;
- Row-level security policies enabled on all tenant tables;
- Audit logging of authentication and privileged actions;
- Regular dependency-vulnerability scans and timely patching;
- Background checks on personnel with production access;
- Documented incident-response runbook.
9. Deletion & Return of Data
The Customer may export Customer Data (CSV export per list) at any time while the account exists, including after a subscription lapses. Export before deleting: deleting the account or a workspace is self-serve (Settings → Danger Zone) and removes the workspace's Customer Data — lists, campaigns, replies, pipeline records, and credit history — from active systems immediately and irreversibly; there is no post-deletion export window. Backup copies are purged automatically on a rolling window of no more than 7 days.
Contact records in AgencyLeads' shared contact catalogue (business profiles sourced under AgencyLeads' own agreements with the data providers listed in Section 6, which AgencyLeads processes as an independent controller) are not deleted by account deletion. Where a record was created by the Customer's own import, or on the Customer's documented instruction naming specific records, AgencyLeads will delete or suppress those records within 30 days, unless retention is required by applicable law.
10. Liability
Each party's liability arising out of or related to this DPA is subject to the limitation of liability set out in the Terms of Service.
11. Conflict
In the event of a conflict between this DPA and the Terms of Service with respect to processing of personal data, this DPA prevails.
12. Contact
Data protection: privacy@agencyleads.com
Security incidents: security@agencyleads.com