Data Processing Addendum
This addendum applies to Business customers and forms part of the Terms. Requests under it go through the contact form.
1. Roles
For your account data we are the controller (see Privacy Policy). For contact details contained in Licensed Data, each party is an independent controller: we for compiling and providing them, you for whatever you do with them afterwards. We do not process personal data on your instructions and are therefore not your processor.
2. Our commitments
- Sourcing: professional contact channels published by the programmes for affiliate contact; no enrichment from other sources.
- Security, breach notification and assistance with data-subject requests: to the extent applicable law requires of an independent controller.
- Transparency: this policy set is published and versioned.
3. Your commitments
- A lawful basis and a compliant notice for your own use of contact data (legitimate interest for B2B outreach where allowed; consent where required); honouring opt-outs; no resale or enrichment; deletion when no longer needed.
- Appropriate security for Licensed Data you store; no transfer outside your organisation.
- Telling us through the contact form if you receive a complaint that concerns data we supplied, so we can remove it at source.
4. International transfers
Our processors outside the EU/UK are bound by the EU-US Data Privacy Framework and/or Standard Contractual Clauses as listed in the Privacy Policy. If you are outside the EEA and receive EU-origin personal data from us, you are responsible for your own transfer mechanism.
5. Liability and term
Each party is liable for its own processing. This addendum lasts as long as you hold Licensed Data. Governing law as in the Terms. Version 2026-08-29.
These documents are written in good faith for a small data business and reviewed against the rules that apply in the EU/UK and the US. They are not legal advice; where mandatory law in your country grants you more rights than stated here, those rights apply.