Leadalise

Data Processing Agreement

What a DPA with Leadalise covers, and how to request one signed for your organization.

Our role under your DPA

For your own account and usage data, we act as a data controller. For business-contact data processed through the Service about the companies and prospects you research — names, job titles, business emails, and inferred buying signals — we act as a data processor on your instructions, as your Privacy Policy and DPA describe. Our standard DPA covers that processor relationship.

Sub-processors

We rely on a small set of sub-processors to run the Service: cloud hosting and database infrastructure, workflow-automation infrastructure for signal detection and report generation, AI language-model providers for analysis and drafting, and our payment processor (Paddle, as merchant of record). We keep this list to what is operationally necessary and will notify enterprise DPA signatories of material changes to it.

International transfers

Our infrastructure providers may process data outside your country of residence, including in the United States. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses, provided by those infrastructure providers.

Do you need to sign anything?

No. The agreement below is in force as soon as you subscribe — including the Standard Contractual Clauses and the UK Addendum, which both parties are deemed to have signed. If your procurement process still needs a countersigned PDF, or you want it executed on your own paper, email support@leadalise.com and we will sign this document as written.

The cards above are the plain-language summary. The agreement itself follows — it is what actually binds us. See also our Terms of Service and Privacy Policy.

Data Processing Agreement

Last updated: 11 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Yertay Kemelbekov, an individual trading as "Leadalise," based in Almaty, Republic of Kazakhstan ("Leadalise," "Processor," "we") and the customer agreeing to those Terms ("Customer," "Controller," "you"). It governs our processing of personal data on your behalf when you use the Leadalise platform (the "Service").

This DPA applies automatically. By subscribing to the Service you accept it; no signature is required for it to be in force. If your procurement process needs a countersigned copy — for example with your own Standard Contractual Clauses annexes — email support@leadalise.com and we will execute this document as written.

Where this DPA conflicts with the Terms of Service on the subject of personal data, this DPA prevails.

1. Definitions

"GDPR" means Regulation (EU) 2016/679; "UK GDPR" means the GDPR as incorporated into UK law by the Data Protection Act 2018. "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Sub-processor" and "Supervisory Authority" have the meanings given in the GDPR. "Data Protection Law" means the GDPR, the UK GDPR, the Swiss FADP, applicable US state privacy laws, and any other data protection law applicable to a Party's processing under this DPA.

2. Roles of the Parties

You are the Controller of the personal data processed through the Service about third parties — the business contacts and company representatives you research, monitor and analyse. You determine which companies to monitor, which contacts to enrich, and what to do with the output.

We are the Processor for that data and process it only on your documented instructions.

We are an independent Controller for a separate, limited set of data: your own account, billing and usage data, our security and abuse logs, and aggregated or de-identified usage statistics. That processing is described in our Privacy Policy and is not governed by this DPA.

Where we obtain business data from licensed providers and public sources before any customer asks for it, we act as a Controller for the purpose of assembling and maintaining that data set, and as your Processor from the point at which the data is made available in your account. We say this plainly because the alternative — describing the entire pipeline as pure processing — would not survive scrutiny, and a DPA that misstates the roles protects neither party.

3. Your Instructions

Your instructions to us are: this DPA, the Terms of Service, and your configuration and use of the Service (the segments you define, the companies you add, the reports and enrichments you request). We will not process personal data on your behalf for any other purpose.

We will inform you if, in our opinion, an instruction infringes Data Protection Law. We may process personal data as required by the law applicable to us, and where that law permits it, we will inform you before doing so.

You warrant that you have a lawful basis for the processing you instruct, that your use of contact data complies with the direct-marketing and anti-spam law applicable to you and to the individuals you contact, and that you will honour objection, opt-out and erasure requests those individuals send you.

4. Details of Processing (GDPR Article 28(3))

| | | |---|---| | Subject matter | Provision of the Leadalise B2B buying-signal platform | | Duration | The term of your subscription, plus the retention period in Section 10 | | Nature and purpose | Collection, storage, structuring, enrichment, scoring, analysis and generation of reports about target companies and their representatives, for the Customer's B2B sales and business-development activity | | Categories of Data Subjects | Business representatives and employees of the companies the Customer monitors — typically decision-makers in the roles the Customer sells to; and the Customer's own users of the Service | | Types of Personal Data | Name; job title and seniority; employer and company affiliation; business email address; business contact number where the Customer requests one; professional profile links; publicly reported role and leadership changes; and derived assessments (signal strength, need hypothesis, likely buying-committee role) about the individual in their professional capacity | | Special categories | None. We do not intentionally process special-category data under GDPR Article 9, or criminal-offence data under Article 10, and the Service is not designed to collect it |

5. Confidentiality

We ensure that every person authorised to process personal data under this DPA is bound by an obligation of confidentiality, and we limit access to production data to those who need it to operate, secure or support the Service.

6. Security (GDPR Article 32)

We implement appropriate technical and organisational measures, described in Annex II. We may update those measures over time; we will not reduce the overall level of security during the term of your subscription.

7. Sub-processors

You give general written authorisation for us to engage the Sub-processors listed in Annex I. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will give you at least 30 days' notice before adding or replacing a Sub-processor that processes personal data you control, by email to your account address and by updating Annex I. If you reasonably object on data-protection grounds within that period, we will work with you in good faith to find an alternative; if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of your current term.

8. Assistance with Data Subject Rights

The Service gives you direct access to the personal data it holds for your account, so that you can respond to access, rectification and erasure requests yourself. Where you cannot, we will provide reasonable assistance at no additional cost.

If a Data Subject contacts us directly about data processed on your behalf, we will not respond substantively on your behalf; we will inform them that we act as a processor, refer them to you where we can identify you as the relevant Controller, and notify you without undue delay.

Independently of this DPA, any individual may ask us directly to access, correct or remove their business contact details from our own data set, and we honour those requests without requiring proof of residency or a stated reason. Doing so may remove that individual from your account as well.

9. Personal Data Breach

We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a Personal Data Breach affecting personal data processed on your behalf. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a point of contact.

We will assist you with your own obligations under GDPR Articles 33 and 34, and — taking into account the nature of processing and the information available to us — with data protection impact assessments and prior consultations under Articles 35 and 36.

10. Deletion and Return

On termination of your subscription you may export your data from the Service in CSV and PDF form for as long as your account remains accessible.

At your written request, and in any case within 90 days of termination, we will delete personal data processed on your behalf, except where retention is required by law applicable to us or is necessary to resolve a dispute, in which case we will retain it only for as long and only for that purpose, and continue to protect it under this DPA. Backups are purged on their ordinary rotation cycle.

Aggregated and de-identified data that cannot reasonably be used to identify you or any individual is not subject to this Section.

11. Audits and Information

We will make available to you the information reasonably necessary to demonstrate compliance with GDPR Article 28, including this DPA, our Annexes, and a completed security questionnaire on request.

We do not currently hold a SOC 2 or ISO 27001 certification, and we say so rather than implying one. Where you have a documented regulatory requirement to audit, we will agree in good faith on a proportionate remote audit, no more than once in any 12-month period unless required by a Supervisory Authority, subject to reasonable notice, confidentiality, and reimbursement of our reasonable costs.

12. International Transfers

We are established outside the European Economic Area, the United Kingdom and Switzerland, and personal data may be processed on infrastructure located outside those territories, including in the United States.

Where personal data protected by the GDPR is transferred to us or to a Sub-processor in a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914):

  • Module Two (Controller to Processor) applies to transfers from you to us, with you as data exporter and us as data importer;
  • Module Three (Processor to Processor) applies where you are yourself a processor for your own customer;
  • the optional docking clause (Clause 7) applies; under Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in Section 7; under Clause 11 the optional independent dispute-resolution body does not apply; under Clause 17 the governing law is the law of Ireland; under Clause 18(b) the forum is the courts of Ireland;
  • Annex I, II and III of the SCCs are populated by Section 4, Annex II and Annex I of this DPA respectively.

For personal data protected by the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum (version B1.0), with Tables 1–3 populated as above and Table 4 specifying that neither party may end the Addendum as set out in Section 19. For personal data protected by the Swiss FADP, references to the GDPR are read as references to the FADP, references to Member State law as references to Swiss law, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.

By accepting this DPA, both parties are deemed to have signed the SCCs and the UK Addendum.

13. US State Privacy Law

Where you are subject to the California Consumer Privacy Act as amended ("CCPA") or to a comparable US state privacy law, we act as your Service Provider (or Processor, under the equivalent state term) and we:

  • process personal information only to provide the Service under this DPA, and for no other business or commercial purpose;
  • do not sell personal information, and do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA;
  • do not retain, use or disclose personal information outside the direct business relationship between you and us;
  • do not combine personal information received from you with personal information from another source, except as permitted to a service provider;
  • notify you if we determine we can no longer meet these obligations, and on notice cease processing or remediate.

We will assist you in responding to verifiable consumer requests to know, delete, correct and opt out.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law does not permit those limits to apply.

15. Term

This DPA takes effect when you accept the Terms of Service and remains in force for as long as we process personal data on your behalf.


Annex I — Sub-processors

Current as of the date at the top of this document. Additions are notified as described in Section 7.

| Sub-processor | Purpose | Primary processing location | |---|---|---| | Supabase (on Amazon Web Services) | Managed database, authentication and application platform | United States | | Vercel | Front-end hosting and content delivery | United States / global edge | | Google Cloud | Virtual machine running the signal-detection and report workflows | United States | | Cloudflare | Network, TLS termination and access control in front of that workflow host | Global edge | | Resend | Transactional email (account, digest, billing and support email) | European Union | | OpenRouter | Gateway to the AI language-model providers used to classify signals and draft report content | United States | | PostHog | Product analytics on our own pages and application | United States | | Paddle.com Market Limited | Merchant of record: billing, invoicing, tax and payment processing | United Kingdom / European Union |

Where you connect your own CRM to the Service, data is additionally exchanged with that provider on your instruction; that provider is your vendor, not our Sub-processor.

Model providers reached through the gateway above process report inputs to generate output and, under the gateway's terms, do not use that content to train their models.

Annex II — Technical and Organisational Measures

Described accurately rather than aspirationally. Measures we have not implemented are named as such.

Encryption. TLS in transit for all traffic to the application, the database and every Sub-processor API. Encryption at rest for the database and object storage, provided by the platform operators.

Access control. Production data access is restricted to the operator. Application-level access is enforced by row-level security in the database, so a customer's records are reachable only by that customer's workspace, not merely hidden by the interface. Administrative actions run through role-checked, audited server functions and are written to an immutable audit log. Multi-factor authentication is enabled on the administrative accounts of the underlying platforms.

Payment data. We never receive or store full card details. Card data flows directly between the payer and Paddle as merchant of record.

Segregation. Customer data is logically segregated by workspace identity enforced in the database. We do not operate single-tenant deployments.

Resilience and backup. Automated daily backups of the production database are performed and monitored by us. Each backup is checked on creation against its own size and checksum, stored in a separate access-controlled cloud bucket under a credential that can create objects but cannot delete or overwrite them, and retained for fourteen daily and four weekly cycles. The restore path is exercised periodically by test restores following a documented procedure. We do not operate point-in-time recovery; the recovery point is the most recent daily backup. Availability monitoring, error alerting, backup-failure alerting and background-job freshness monitoring run continuously and notify the operator.

Logging. Application errors, administrative actions, billing events and security-relevant refusals are logged with timestamps and retained for operational and audit purposes.

Deletion. Account deletion removes customer records and de-identifies the entries that must be retained for audit integrity. Individual removal requests are honoured as described in Section 8.

Personnel. The Service is operated by its founder. There is no wider staff with production access; any future personnel with such access will be bound by confidentiality obligations and trained on this DPA before access is granted.

Not in place today, stated so you can assess it: we hold no SOC 2 or ISO 27001 certification; we do not offer a customer-managed encryption key option; we do not operate a formal bug-bounty programme. If any of that changes, this Annex changes with it.

Annex III — Contact

Data protection contact: support@leadalise.com Processor: Yertay Kemelbekov, an individual trading as Leadalise · Almaty, Republic of Kazakhstan