Skip to main content
Home

Legal document

Data Processing Agreement (DPA)

How lead and outreach data is processed on your behalf in Searchlize.

Last updated:

This Data Processing Agreement (the "DPA") is entered into under Article 28 of Regulation (EU) 2016/679 ("GDPR") between you as the controller (the "Customer") and the operator of Searchlize as the processor. It is incorporated into and forms part of the Terms of Service and takes effect when you accept the Terms or use the Service. It governs processing of personal data that the operator carries out on your behalf(in particular sending outreach from your connected mailbox and syncing data to your CRM). The operator's processing as an independent controller (e.g., account data and lead sourcing) is governed instead by the Privacy Policy. A countersigned copy is available on request — see section 12.

1. Parties

  • Processor: Mieszko Ziarkowski, działalność nierejestrowana, ul. Zielona 25, 32-080 Bolechowice — email contact@searchlize.com, data protection contact contact@searchlize.com.
  • Controller: the Customer — the account holder using the Searchlize service, as identified in the account and billing details.

2. Subject-matter, nature, purpose and duration

The Processor processes personal data on behalf of the Controller solely to provide the Service under the Terms — namely queuing and sending outreach from the Controller's connected mailbox, receiving the first reply, and synchronizing lead/contact data with the Controller's CRM, together with the technical processing necessary for those features. The nature of the processing is described in Annex I. Processing lasts for the term of the Terms and any retention period required by law thereafter.

3. Processing on documented instructions

The Processor processes personal data only on the Controller's documented instructions, including as to transfers to third countries. The Controller's instructions are given through the Terms, this DPA, and the configuration and actions the Controller takes in the Service. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law (Art. 28(3), final paragraph).

4. Processor obligations (Art. 28(3))

  • (a) Instructions:process only on the Controller's documented instructions (section 3).
  • (b) Confidentiality: ensure that persons authorized to process the data are bound by confidentiality.
  • (c) Security: implement the technical and organizational measures required by Art. 32, as set out in Annex II.
  • (d) Sub-processors: engage sub-processors only under the conditions in section 6 and Art. 28(2) and (4).
  • (e) Assistance with data-subject rights: taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise data-subject rights (Chapter III GDPR).
  • (f) Assistance with security and compliance: assist the Controller in ensuring compliance with Arts. 32–36 (security, personal data breach notification, data protection impact assessment, prior consultation), taking into account the information available to the Processor.
  • (g) Deletion or return:at the Controller's choice, delete or return all personal data after the end of the provision of services, and delete existing copies, unless storage is required by law (section 11).
  • (h) Audits and information: make available all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections (section 9).

5. Controller obligations

The Controller warrants that it has a lawful basis and, where required, the consents necessary for the processing it instructs (including for outreach — see the Terms), that its instructions are lawful, and that it will fulfil its own controller obligations toward data subjects, including information duties and responding to objections.

6. Sub-processors

The Controller gives the Processor general authorization to engage the sub-processors listed in Annex III. The Processor imposes on each sub-processor, by contract, data-protection obligations equivalent to those in this DPA, and remains fully liable to the Controller for the performance of each sub-processor's obligations. The Processor will inform the Controller of any intended addition or replacement of a sub-processor with reasonable prior notice (e.g., via the Service or by email), giving the Controller the opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Controller may terminate the affected part of the Service.

7. International transfers

Where a sub-processor processes personal data outside the EEA, the Processor ensures an appropriate transfer mechanism under Chapter V GDPR — the EU-US Data Privacy Framework where the recipient is certified, and otherwise the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module 2 controller-to-processor or Module 3 processor-to-processor, as applicable), with supplementary measures where appropriate.

8. Personal data breach

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides the information reasonably available to help the Controller meet its obligations under Arts. 33–34 GDPR.

9. Audits

On reasonable prior written request and no more than once a year (or following a breach or a regulator's requirement), the Processor makes available the information necessary to demonstrate compliance and allows for and contributes to audits conducted by the Controller or an independent auditor bound by confidentiality, during business hours and without unreasonable disruption. The Processor may satisfy audit requests by providing relevant third-party certifications or reports where available.

10. Deletion and return of data

On termination of the Service, and at the Controller's choice, the Processor deletes or returns the personal data processed on the Controller's behalf and deletes existing copies, unless retention is required by law. Self-service account deletion in the Service triggers this deletion (typically completed within 30 days); residual copies in backups are purged on the normal backup rotation.

11. Liability, term and precedence

This DPA lasts as long as the Processor processes personal data on the Controller's behalf. Liability is governed by the Terms. In the event of a conflict between this DPA and the Terms on matters of personal data protection, this DPA prevails. If the Processor determines the purposes and means of a given processing, it is a controller for that processing (Art. 28(10)).

Annex I — Details of the processing

Categories of data subjects:the Controller's leads and business contacts (representatives and employees of prospect companies), recipients of the Controller's outreach, and the Controller's own representatives and users.

Categories of personal data:business contact details (name, business email, phone, job role), employer/company data and public identifiers (domain, NIP, REGON, KRS, address), message content of outreach and replies, outreach delivery and engagement data (including recipients' IP address and user-agent where tracking is enabled), and connected mailbox metadata. Special categories of data are not intended to be processed; the Controller must not use the Service to process such data except in compliance with law.

Nature and purpose: hosting, transmission, storage and related technical processing to provide the outreach, inbox and CRM-sync features. Duration and frequency: continuous, for the term of the Terms.

Annex II — Technical and organizational measures (Art. 32)

  • Encryption: TLS in transit; encryption at rest (AES-256-GCM) for connected-mailbox credentials and CRM tokens; secrets are never exposed to the browser.
  • Access control and tenant isolation: row-level security enforcing per-tenant data isolation, least-privilege access, and logging of administrative actions.
  • Authentication: managed authentication provider with support for two-factor authentication.
  • Data minimization: processing limited to data relevant to the features used; suppression and opt-out lists supported.
  • Logging and monitoring: application error and performance monitoring and audit logging, with attention to avoiding unnecessary personal data in logs.
  • Resilience: managed database with backups and recovery; backups purged on rotation.
  • Secure development: input validation and protections against server-side request forgery in the site-analysis features; dependency and secret management.
  • Sub-processor assurance: sub-processors engaged under data processing agreements with equivalent obligations.
  • Breach response: a process to detect, assess and notify personal data breaches without undue delay.

Annex III — Sub-processors

The following sub-processors and independent recipients are authorized under section 6. The same list is maintained in the Privacy Policy. The Processor updates this list and notifies the Controller of changes as described in section 6.

Our sub-processors (infrastructure that runs the Service)

ProviderPurposeLocationTransfer safeguard
SupabaseDatabase, user authentication, file storage and realtime.European Union (AWS, Ireland — eu-west-1).Processing within the EEA (European Union).
VercelHosting of the web application and serverless functions.European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
UpstashBackground job queue (QStash) and rate-limiting cache (Redis).European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
StripePayment and subscription processing.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Google (Gemini / Generative AI)AI analysis of website content, lead scoring and generation of message drafts.United States / global.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
OpenRouter (DeepSeek)AI generation of outreach message drafts, routed to the DeepSeek model. Processes lead data and the inputs you provide — never data obtained via Google APIs.United States / global (model inference may occur on DeepSeek infrastructure).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
ResendDelivery of transactional/service email and receipt of the first inbound reply (webhook).United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
PostHogProduct analytics. Browser-side capture and error reporting run only after consent to analytics cookies; server-side product-usage events are pseudonymous (account identifier, no cookies, no personal data in the payload).European Union (EU Cloud).Processing within the EEA (European Union).
SentryApplication error and performance monitoring.European Union / United States (per organization).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Vercel Web AnalyticsCookieless, aggregate visitor and page-view measurement (no cookies, no cross-site tracking, no personal profiles).European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Axiom (optional / when enabled)Log management (where enabled).European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.

Independent data sources and public registers we query

ProviderPurposeLocationTransfer safeguard
SerperSearch-engine results used to discover company domains (receives the search query).United States.Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Rejestr.ioCommercial enrichment from the Polish court register (KRS) and related data.European Union (Poland).Processing within the EEA (European Union).
GUS / REGON (BIR1)Polish Central Statistical Office register lookup (REGON/NIP business data).Poland.Public statutory register / public authority (Poland).
Ministry of Justice — KRSNational Court Register (KRS) company lookup.Poland.Public statutory register / public authority (Poland).
Ministry of Finance — VAT whitelistVAT/NIP taxpayer verification (biała lista podatników VAT).Poland.Public statutory register / public authority (Poland).
Apollo.io (optional / when enabled)Optional global B2B company/contact database enrichment.United States.Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.

Services you connect (you direct the transfer)

ProviderPurposeLocationTransfer safeguard
Google (Gmail API)Sending outreach from the Customer's connected Google mailbox (send-only scope).United States / global.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Microsoft (Outlook / 365)Sending from the Customer's connected Microsoft mailbox; access to the mailbox and profile granted by the Customer via OAuth.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
HubSpot (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Salesforce (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Pipedrive (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.European Union.Processing within the EEA (European Union).
Kommo (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.United States.Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Custom SMTP/IMAP server (optional / when enabled)Sending from a mail server configured by the Customer.Determined by the Customer.Under the Customer's own arrangements with the provider.

12. How to obtain a countersigned DPA

This DPA is effective without signature. If your organization requires a countersigned copy, email contact@searchlize.comwith the subject "Searchlize DPA", including your company name, tax ID (if applicable), and the authorized signatory. We will respond with a copy for signature.