Data processing terms
The terms on which we process personal data in an engagement — and when we act as your processor rather than as an independent controller, which is not the same for a lead list as for work inside your CRM.
Which role we hold, and when
Which obligations apply depends on whose personal data it is. We sell two kinds of service and the roles differ between them.
| Service | Our role | The customer's role |
|---|---|---|
| Lead lists | Independent controller | Independent controller from delivery onwards |
| CRM integration and enrichment of the customer's own data | Processor | Controller |
For a lead list we determined the purposes and means of collection ourselves, before the customer was involved. We are therefore not the customer's processor for that data, and a processor agreement covering it would describe a relationship that does not exist. On delivery the customer becomes controller of their copy; section 2 sets out what that involves.
Where we work in the customer's CRM, or on a list the customer supplied, the data is the customer's and we process it solely on the customer's instructions. Sections 3 onwards then apply, and they are our data processing terms.
Lead lists: two independent controllers
Where the data comes from, why we process it and for how long is set out in section 4 of the privacy policy. In short: professional details from licensed B2B sources and companies' own public websites, on a legitimate interest basis.
As recipient of the list, the customer is responsible for their own copy. That means informing the data subjects under Article 14 no later than at first contact, having their own legal basis for their outreach, respecting objections and erasure requests, and setting and applying their own retention period.
We delete the data produced for an order from our own systems no later than 60 days after delivery. After that we retain only a suppression list of people who have objected, so that they can be kept out of future lists.
If either of us receives a request concerning the other's processing, we forward it without undue delay.
Subject matter and duration of the processing
The following applies where we act as the customer's processor.
- Subject matter
- Completing, qualifying and structuring personal data in the customer's CRM or in a list the customer has supplied.
- Duration
- For as long as the engagement lasts, and thereafter until the data has been deleted or returned.
- Types of data
- Name, job title, employer, work email address, work phone number, town and public professional profile.
- Data subjects
- Contacts and decision-makers at the customer's existing or prospective customers.
- Special categories
- Not processed. The customer must not supply such data to us.
Instructions and confidentiality
We process the data only on the customer's documented instructions, being the order, these terms and any later written addition. If we consider an instruction to infringe data protection law, we inform the customer. We never process the customer's data for our own purposes and never add it to our own lead lists.
Everyone at our end who is given access to the data is bound by confidentiality and has received training appropriate to the task. Access is granted only to those who need it to perform the engagement.
Security measures
- Encryption in transit (TLS) and at rest.
- Role-based access control with two-factor authentication on all accounts.
- Logging of access to personal data, and separation between customers' data.
- Backups with restore capability, and regular restore testing.
- A procedure for detecting, handling and reporting personal data breaches.
Sub-processors
The customer gives us general authorisation to engage sub-processors. We enter into agreements with each of them imposing at least the same obligations as we carry, and we remain liable for their processing as for our own. The following are engaged today.
| Supplier | What they do | Where |
|---|---|---|
| Supabase | Database and application platform | EU |
| Vercel | Website and API hosting | EU/US |
| OpenAI | Assessing whether a company matches the stated criteria | US |
| Firecrawl | Automated reading of companies' public websites | US |
| Google (Workspace) | Email and delivery of lists | EU/US |
| Stripe | Payments and invoicing | EU/US |
| Slack | Internal operational notifications | EU/US |
We notify the customer before a sub-processor is added or replaced, at least 30 days in advance. Where the customer raises reasoned objections we discuss them, and if no agreement is reached the customer may terminate the affected service at no cost.
Assistance to the customer
We assist the customer with appropriate technical and organisational measures so that the customer can respond to requests from data subjects. If we receive such a request directly, we do not answer it ourselves but refer the data subject to the customer and inform the customer without undue delay.
We also assist the customer with security, breach notification, impact assessments and prior consultation under Articles 32–36, to the extent the customer needs it and taking into account the information available to us.
In the event of a personal data breach affecting the customer's data, we inform the customer without undue delay and within 24 hours of becoming aware of it at the latest, with the information the customer needs for their own notification.
Deletion and audit
When the engagement ends we delete or return the data at the customer's choice and delete existing copies, unless the law requires them to be retained. We confirm deletion in writing on request.
We make available the information needed to demonstrate compliance with the obligations in Article 28 and allow for audits conducted by the customer or an auditor appointed by the customer. Audits are announced at least 30 days in advance, take place during normal working hours and must not unreasonably disrupt operations.
Need a signed agreement?
These terms apply as the data processing agreement between us and the customer. If your organisation needs a separately signed copy, or wants to use your own template, send it to us and we will execute it.
General
These terms apply alongside our general terms and supplement them in respect of personal data. Swedish law applies. The counterparty is Ready Check Group AB, reg. no. 559546-8140, Södra Stapeltorgsgatan 28, 802 53 Gävle.
