1. Purpose & Scope
This Data Processing Addendum ("DPA") applies where SalesGPT.work processes Personal Data on behalf of the Customer as a Processor in connection with the Service.
2. Definitions
Capitalized terms have the meanings set out in GDPR and other applicable data protection laws.
3. Roles of the Parties
- Customer acts as Controller of Customer Data.
- SalesGPT.work acts as Processor of Customer Data.
- SalesGPT.work acts as Controller for account, billing, and website data.
4. Details of Processing
| Subject Matter | Purpose | Data Subjects | Personal Data |
|---|---|---|---|
| Provision of Service | Hosting, analytics, enrichment, automation, support | Employees, prospects, leads, end users | Contact data, CRM fields, messages, prompts, logs |
5. Customer Instructions
Processor processes Customer Data only on documented instructions from Customer and as required to provide the Service.
6. Processor Obligations
- Ensure confidentiality of authorized personnel.
- Implement appropriate technical and organizational measures.
- No training of models on Customer Data.
- No resale or secondary use of Customer Data.
7. Subprocessors
Customer grants general authorization for Subprocessors. A current list is available at /subprocessors.
8. Security Measures
Industry-standard security measures are implemented, including encryption, access controls, monitoring, and incident response.
9. Data Subject Rights
Processor assists Customer in responding to data subject requests.
10. Security Incidents
Customer will be notified without undue delay and within 72 hours of a confirmed Security Incident.
11. Deletion & Return
Upon termination, Customer Data will be deleted or returned, subject to backup retention obligations.
12. Audits
Audits are permitted subject to reasonable notice. SOC 2 or equivalent reports may be provided instead.
13. International Transfers
EU Standard Contractual Clauses (Module Two) and UK IDTA apply where relevant.
14. Order of Precedence
This DPA prevails over conflicting terms related to data protection.
15. Liability
Liability is capped as set out in the underlying agreement, subject to applicable law.
16. Government Access
Processor will notify Customer of legally binding access requests where permitted by law.
17. AI & Enrichment
AI outputs are decision-support only. Customer is responsible for lawful basis and verification.
18. Regional Compliance
This DPA supports GDPR, UK GDPR, CPRA, PIPEDA, Québec Law 25, and India’s DPDP Act.
19. Governing Law
Governing law follows the underlying agreement. SCCs are governed by EU law.
20. Annexes
Annex I: SCCs · Annex II: Security Measures · Annex III: Subprocessors