Data Processing Agreement (DPA) — Wrenwire customers (DRAFT)
Status: content and decisions filled in (AI legal analysis, authorized by Piotr in lieu of a lawyer until the SaaS scales) — this is NOT a lawyer’s opinion. The Polish version (Data Processing Agreement (PL)) is the source text. Structure: the DPA is an integral part of the Terms of Service (Terms of Service §9), accepted together with them — no separate signature, as the default path for self-serve customers (SaaS standard). For enterprise customers we additionally offer an optionally signed/countersigned version on request — the click-through version remains the default for everyone else. Distinct from DPA-APIFY.md (there we are the controller engaging a processor; here we are the processor). The Art. 28(3) GDPR checklist is ticked item by item in §4.
Parties: Customer (controller of prospect data) — Provider Geeknauts sp. z o.o. (limited liability company), ul. Ulubiona 34, 32-085 Modlnica, Poland, KRS 0000362389, VAT (NIP) 5130210402, REGON 121307472 (processor, “Processor”).
§1. Subject matter, duration, nature and purpose (Art. 28(3), 1st sentence)
| Element | Content |
|---|---|
| Subject matter | processing of prospect data in the course of providing the Wrenwire service |
| Duration | term of the service agreement + export/deletion window (§8) |
| Nature | collection (on instruction: imports, source integrations), storage, organization, enrichment, analysis (including company profiling — fit scoring), content generation based on the data, transmission to tools designated by the Customer, erasure |
| Purpose | the Customer’s B2B outbound campaigns |
| Categories of data subjects | representatives and contact persons of prospect companies (business data); the Customer’s end users are out of scope (there the Provider is controller — privacy policy) |
| Categories of data | identification and business contact data (name, job title, business email, phone, professional profile URL), company data (name, address, website, technologies, buying signals), prospect correspondence synced from the Customer’s tools |
| Special categories | excluded — the Customer undertakes not to enter such data |
§2. Customer (controller) representations
- The Customer warrants it has a legal basis for processing prospect data (as a rule: Art. 6(1)(f) GDPR) and will fulfil information duties (Art. 13/14) towards data subjects.
- The Customer is responsible for the lawfulness of data sources it imports or connects (own lists, Snov.io account, other integrations).
- Customer instructions are given via the Service’s interface and API (configuration, running jobs) and — exceptionally — via the support channel in documented form.
§3. Instructions and scope of processing
- The Processor processes data only on the Customer’s documented instructions (Art. 28(3)(a)), including as regards third-country transfers, unless required by EU or Member State law — in which case the Processor informs the Customer before processing, unless prohibited.
- The Processor immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
- The Processor does not use the Customer’s prospect data for its own purposes, in particular not for AI model training. The Processor may use usage data only in anonymized and aggregated form (not attributable to any specific Customer, prospect, or natural person) for Service improvement and internal statistics — see ToS §10.3.
§4. Processor obligations — Art. 28(3) checklist
| Point | Obligation | Implementation |
|---|---|---|
| (a) | processing on documented instructions | §3 |
| (b) | personnel authorized and bound to confidentiality | access limited to Provider personnel bound to confidentiality — via employment/contractor agreements that include confidentiality clauses, or standalone confidentiality undertakings for external personnel who lack such a clause; no separate per-person NDA process is required |
| (c) | Art. 32 measures | Annex 1 (TOMs) |
| (d) | subprocessor conditions | §7 |
| (e) | assistance with data subject rights (Ch. III) | §5 |
| (f) | assistance with Art. 32–36 duties (security, breaches, DPIA) | §6 |
| (g) | deletion or return after end of services | §8 |
| (h) | information and audits | §9 |
§5. Data subject rights
- The Service provides self-service tooling for the Customer: access/ export, rectification, deletion of a prospect record, suppression list (objection/opt-out — permanent record).
- If a data subject contacts the Processor directly, the Processor forwards the request to the Customer without undue delay (at the latest within 5 business days) and does not respond on the merits in its own name (beyond acknowledging receipt), unless the request concerns data for which the Processor is controller.
- Assistance beyond self-service tooling:
[LAWYER/PIOTR TO DECIDE: chargeable or not].
§6. Personal data breaches and Art. 32–36 support
- The Processor notifies the Customer of a personal data breach without undue delay, no later than 48 hours after becoming aware, providing the Art. 33(3) information known to the Processor (description, categories and approximate numbers, likely consequences, remedial measures).
- Notifying the authority and data subjects remains the Customer’s (controller’s) duty; the Processor cooperates.
- The Processor assists the Customer with DPIAs and prior consultations insofar as they concern the Service (Art. 35–36).
§7. Subprocessors
- The Customer gives general authorization for the subprocessors on the list: Subprocessor list (published on the Service’s site).
- The Processor gives at least 30 days’ advance notice of intended additions or changes (email to the Account admin + entry on the list page). The Customer may raise a reasoned objection; if no alternative is feasible, the right to terminate is limited to the affected functionality, proportionate to the extent the objected subprocessor actually supports that functionality — whole-agreement termination is reserved for cases where the objected subprocessor is so central that the Service cannot function without it (AI analysis, to be verified by a lawyer before publication).
- The Processor imposes the same data protection obligations on subprocessors as in this DPA (Art. 28(4)) and remains fully liable for their performance.
- Snov.io and other integrations connected with the Customer’s own account are not the Processor’s subprocessors — they operate under a separate Customer–vendor agreement; the Processor merely transmits data on the Customer’s instructions.
§8. End of processing
- Upon termination the Processor — at the Customer’s choice — deletes or returns (machine-readable export) all prospect data and deletes existing copies, unless EU/Member State law requires storage.
- Window for the choice and export: 30 days after termination; afterwards deletion follows (a cascade covering all personal-data registries, including those outside the main entity registry — implementation: S21). Backup deletion follows the backup rotation cycle, no longer than [TO BE COMPLETED: rotation period].
§9. Audits
- The Processor makes available information necessary to demonstrate Art. 28 compliance (TOMs documentation, subprocessor list, security test summaries).
- The Customer may audit (itself or via an authorized auditor that is not a competitor of the Processor) once per 12 months, with 30 days’ notice, during business hours, without disrupting operations; each party bears its own costs. The standard documentary audit (described above, once per 12 months) is included at no extra cost; additional bespoke or on-site audits, requested more frequently, or requiring dedicated Processor staff time beyond the documentary review, are billable at the Processor’s standard hourly rate agreed in advance. A documentation audit is used first.
§10. Third-country transfers
Processing takes place in the EEA (OVH hosting). Transfers to subprocessors in third countries (list: Subprocessor list) rely on the SCCs (processor-to-subprocessor module or as applicable), with TIAs where required. The Processor will not transfer data outside the EEA otherwise without the Customer’s instruction or consent.
§11. Liability and final provisions
- Liability is governed by the Terms (§11 ToS) and Art. 82 GDPR. A breach of this DPA that causes a personal-data breach attributable to the Provider is carved out of the ToS §11.3(c) liability cap; other DPA breaches remain subject to the general cap (AI analysis, to be verified by a lawyer before publication).
- In case of conflict between this DPA and the Terms regarding data protection, the DPA prevails.
- Governing law and jurisdiction — as in the Terms.
Annex 1 — Technical and organizational measures (TOMs)
(as of 2026-07-16 — verified against the codebase; update on architecture changes)
Encryption and pseudonymization
- field-level encryption of sensitive data in the database (AES-256-GCM, per-environment key), passwords: bcrypt;
- TLS 1.2+ for all connections; secrets outside the repository
[TO BE COMPLETED: SOPS — planned M3].
Access control and isolation
- multi-tenant with query-level organization isolation (enforced by an automated em-scoping scanner in CI + a 2-org isolation test);
- RBAC (roles, feature flags); Provider personnel access limited to the necessary minimum.
Business continuity
- database backups (regular, encrypted at rest on EU infrastructure)
[TO BE COMPLETED: schedule and retention — finalized in S23]; restore procedure tested (S23 drill).
Monitoring and incident handling
- centralized error logs on own EU infrastructure (self-hosted, 90-day retention); audit logs (30 days / 72 h);
- breach handling process per §6.
Data lifecycle
- retention policies enforced automatically (retention purge);
- deletion on request: cascade over the personal-data entity registry (S21).
Organizational
- least-privilege access; personnel bound to confidentiality;
- record of processing activities maintained (ROPA.md — split into controller and processor registers once SaaS launches);
- subprocessor review before onboarding (DPA/SCC) — process in §7.
Annex 2 — Subprocessor list
By reference: Subprocessor list.