Legal

Data processing terms

The terms on which we process personal data in an engagement — and when we act as your processor rather than as an independent controller, which is not the same for a lead list as for work inside your CRM.

Last updated 7 September 2026

Which role we hold, and when

Which obligations apply depends on whose personal data it is. We sell two kinds of service and the roles differ between them.

ServiceOur roleThe customer's role
Lead listsIndependent controllerIndependent controller from delivery onwards
CRM integration and enrichment of the customer's own dataProcessorController

For a lead list we determined the purposes and means of collection ourselves, before the customer was involved. We are therefore not the customer's processor for that data, and a processor agreement covering it would describe a relationship that does not exist. On delivery the customer becomes controller of their copy; section 2 sets out what that involves.

Where we work in the customer's CRM, or on a list the customer supplied, the data is the customer's and we process it solely on the customer's instructions. Sections 3 onwards then apply, and they are our data processing terms.

Lead lists: two independent controllers

Where the data comes from, why we process it and for how long is set out in section 4 of the privacy policy. In short: professional details from licensed B2B sources and companies' own public websites, on a legitimate interest basis.

As recipient of the list, the customer is responsible for their own copy. That means informing the data subjects under Article 14 no later than at first contact, having their own legal basis for their outreach, respecting objections and erasure requests, and setting and applying their own retention period.

We delete the data produced for an order from our own systems no later than 60 days after delivery. After that we retain only a suppression list of people who have objected, so that they can be kept out of future lists.

If either of us receives a request concerning the other's processing, we forward it without undue delay.

Subject matter and duration of the processing

The following applies where we act as the customer's processor.

Subject matter
Completing, qualifying and structuring personal data in the customer's CRM or in a list the customer has supplied.
Duration
For as long as the engagement lasts, and thereafter until the data has been deleted or returned.
Types of data
Name, job title, employer, work email address, work phone number, town and public professional profile.
Data subjects
Contacts and decision-makers at the customer's existing or prospective customers.
Special categories
Not processed. The customer must not supply such data to us.

Instructions and confidentiality

We process the data only on the customer's documented instructions, being the order, these terms and any later written addition. If we consider an instruction to infringe data protection law, we inform the customer. We never process the customer's data for our own purposes and never add it to our own lead lists.

Everyone at our end who is given access to the data is bound by confidentiality and has received training appropriate to the task. Access is granted only to those who need it to perform the engagement.

Security measures

  • Encryption in transit (TLS) and at rest.
  • Role-based access control with two-factor authentication on all accounts.
  • Logging of access to personal data, and separation between customers' data.
  • Backups with restore capability, and regular restore testing.
  • A procedure for detecting, handling and reporting personal data breaches.

Sub-processors

The customer gives us general authorisation to engage sub-processors. We enter into agreements with each of them imposing at least the same obligations as we carry, and we remain liable for their processing as for our own. The following are engaged today.

SupplierWhat they doWhere
SupabaseDatabase and application platformEU
VercelWebsite and API hostingEU/US
OpenAIAssessing whether a company matches the stated criteriaUS
FirecrawlAutomated reading of companies' public websitesUS
Google (Workspace)Email and delivery of listsEU/US
StripePayments and invoicingEU/US
SlackInternal operational notificationsEU/US

We notify the customer before a sub-processor is added or replaced, at least 30 days in advance. Where the customer raises reasoned objections we discuss them, and if no agreement is reached the customer may terminate the affected service at no cost.

Assistance to the customer

We assist the customer with appropriate technical and organisational measures so that the customer can respond to requests from data subjects. If we receive such a request directly, we do not answer it ourselves but refer the data subject to the customer and inform the customer without undue delay.

We also assist the customer with security, breach notification, impact assessments and prior consultation under Articles 32–36, to the extent the customer needs it and taking into account the information available to us.

In the event of a personal data breach affecting the customer's data, we inform the customer without undue delay and within 24 hours of becoming aware of it at the latest, with the information the customer needs for their own notification.

Deletion and audit

When the engagement ends we delete or return the data at the customer's choice and delete existing copies, unless the law requires them to be retained. We confirm deletion in writing on request.

We make available the information needed to demonstrate compliance with the obligations in Article 28 and allow for audits conducted by the customer or an auditor appointed by the customer. Audits are announced at least 30 days in advance, take place during normal working hours and must not unreasonably disrupt operations.

Need a signed agreement?

These terms apply as the data processing agreement between us and the customer. If your organisation needs a separately signed copy, or wants to use your own template, send it to us and we will execute it.

johan@varmaleads.se

General

These terms apply alongside our general terms and supplement them in respect of personal data. Swedish law applies. The counterparty is Ready Check Group AB, reg. no. 559546-8140, Södra Stapeltorgsgatan 28, 802 53 Gävle.