This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and EnrichLoops. It applies whenever we process personal data on your behalf and a data protection law applies to that processing.
You do not need to sign anything. Accepting the Terms accepts this DPA. If your procurement process needs a countersigned copy, email support@enrichloops.com and we will sign one.
Short version (not part of the agreement): The identifiers you send us are yours, and we only process them to run the Service for you. The company information we return is compiled by us, and we are the controller of that. We use a small number of sub-processors, listed in Annex C. If something goes wrong we tell you quickly.
1. Scope and roles
You are the controller of the personal data you submit through the Service ("Customer Personal Data"). You decide why and how it is processed, and you are responsible for having a lawful basis to send it to us.
We are the processor of that data. We process it only to provide the Service, and only on your instructions.
We are an independent controller of two other things, which this DPA does not cover:
- The company records we compile and return, which we produce from publicly available and licensed sources for our own account.
- Account, billing, support, and website data about you and your users.
Our Privacy Policy covers both of those.
2. Definitions
"Personal data", "processing", "controller", "processor", "sub-processor", "data subject", and "personal data breach" carry the meanings given in the GDPR. Equivalent terms in other applicable laws, including the UK GDPR, PIPEDA, and US state privacy laws, are read to have the closest matching meaning.
"Data Protection Law" means any privacy or data protection law that applies to a party's processing under the Terms.
3. Details of processing
The subject matter, duration, nature, purpose, data types, and categories of data subjects are set out in Annex A.
Your instructions to us are: the Terms, this DPA, the settings and configuration you choose in the dashboard, and the API calls you make. Any other instruction must be agreed in writing, and we may charge for work that goes beyond the Service.
We will tell you if we think an instruction breaches Data Protection Law. We may pause that part of the processing until it is resolved.
4. Our obligations
We will:
- Process Customer Personal Data only on your documented instructions, unless a law we are subject to requires otherwise. If that happens we will tell you first, unless the law forbids it.
- Ensure that everyone we authorise to process the data is bound by confidentiality.
- Implement and maintain the security measures in Annex B.
- Assist you, taking into account the nature of the processing and what is available to us, with your obligations around security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
- Not sell Customer Personal Data, share it for cross-context behavioural advertising, or use it for our own purposes, including to build or improve our company records.
That last point is the important one: what you send us stays yours and does not feed our data product.
5. Sub-processors
You give us general authorisation to use sub-processors. The current list is in Annex C.
Before we add or replace a sub-processor, we will update that list and notify you by email at least 30 days beforehand. You can subscribe to those notices at support@enrichloops.com.
If you have a reasonable, documented objection on data protection grounds, tell us within those 30 days. We will try to offer an alternative. If we cannot, you may cancel the affected part of the Service without penalty and we will refund any prepaid fees for the unused period.
Each sub-processor is bound by written terms no less protective than this DPA. We remain responsible to you for their performance.
6. Security measures
We maintain appropriate technical and organisational measures to protect Customer Personal Data, described in Annex B. We may change them as the Service evolves, but not in a way that materially reduces the level of protection.
You are responsible for the security of your own side: keeping API keys secret, controlling who has access to your account, and configuring the Service appropriately.
7. Data subject requests
The Service gives you access to, and the ability to delete, the data you have submitted.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively. We will forward the request to you promptly, or tell the person to contact you. Where you need more help to answer a request within your legal deadline, we will provide reasonable assistance at no charge.
8. Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, and in any case within 72 hours.
The notice will describe what we know: the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, the steps we are taking, and a contact point. Where we cannot provide all of it at once, we will send what we have and follow up.
We will not make a public statement identifying you without your consent, unless a law requires it.
9. International transfers
We are based in Canada and process data in Canada, the United States, and the European Union.
For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, the following apply in this order:
- Where the receiving country benefits from an adequacy decision, that decision. The European Commission has recognised Canada as providing adequate protection for personal data received by organisations subject to PIPEDA.
- Otherwise, the EU Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this DPA by reference and completed using the details in Annexes A, B, and C. The UK International Data Transfer Addendum applies to UK transfers, and the Swiss amendments apply to Swiss transfers.
10. Audits
We will make available the information reasonably needed to demonstrate compliance with this DPA, normally by responding to a security questionnaire and providing our current documentation.
If that is not enough for your regulator or your own obligations, you may audit us, or appoint an independent auditor who is not our competitor, on 30 days' written notice, no more than once every 12 months, during business hours, without unreasonable disruption, and subject to confidentiality. You bear the cost unless the audit finds a material breach of this DPA. An audit may follow a personal data breach at any time.
11. Deletion and return
You can export or delete Customer Personal Data at any time while your account is open.
On termination, we delete Customer Personal Data within 30 days, unless you ask for a return of it first, or a law requires us to keep it. Backups are purged on their normal rotation cycle, and data in them stays protected under this DPA until it is gone.
Operational logs that may contain limited personal data, such as IP addresses and request metadata, are retained for up to 12 months as described in our Privacy Policy.
12. Liability and order of precedence
Each party's liability under this DPA is subject to the limits and exclusions in the Terms.
If there is a conflict, the Standard Contractual Clauses win over this DPA, and this DPA wins over the rest of the Terms, but only on data protection matters. Everything else in the Terms continues to apply, including governing law and forum.
This DPA ends when the Terms end, or when we stop processing Customer Personal Data, whichever is later.
Annex A — Details of processing
| Subject matter | Provision of the EnrichLoops company enrichment Service. |
| Duration | The term of the Terms, plus the deletion period in Section 11. |
| Nature and purpose | Receiving identifiers submitted by Customer, matching them against our company records, returning results, and delivering them to Customer's configured destinations. Metering, logging, support, and security. |
| Categories of data subjects | Customer's authorised users. Individuals connected to the businesses Customer looks up, in their professional capacity. |
| Categories of personal data | Identifiers submitted for lookup, which may include business email addresses, company domains, and public professional profile URLs. Account and contact details of authorised users. Technical data such as IP addresses, timestamps, and request metadata. |
| Special category data | None. The Service is not designed to receive it and Customer must not submit it. |
| Frequency | Continuous, on Customer's API calls and scheduled jobs. |
| Retention | Per Section 11. |
Annex B — Technical and organisational measures
Encryption. TLS 1.2 or higher for all data in transit. Encryption at rest for databases, object storage, and backups.
Access control. Role-based access on a least-privilege basis. Multi-factor authentication on all administrative and infrastructure accounts. Access reviewed when roles change and revoked on departure.
Credentials. API keys are stored hashed and displayed in full only once, at creation. Customers can rotate and revoke keys from the dashboard.
Network and application security. Isolated production environment, no direct public access to data stores, rate limiting and abuse detection on the API, and dependency vulnerability scanning with prompt patching of critical issues.
Logging and monitoring. Audit logging of administrative and data access actions, retained and monitored for anomalies.
Resilience. Encrypted backups taken on a regular schedule, with restore procedures tested periodically.
Segregation. Customer data is logically separated by account, and access is scoped by API key.
Personnel. Everyone with access is bound by confidentiality obligations and briefed on data handling.
Incident response. A documented process for detecting, escalating, and notifying on security incidents, aligned with Section 8.
Deletion. Documented deletion procedures covering primary storage and backup rotation.
Annex C — Sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Fly.io | Application and API hosting | United States, European Union |
| Supabase | Primary application database | United States, European Union |
| Upstash | Caching, rate limiting, and job queues | United States, European Union |
| Cloudflare | DNS, content delivery, and network security | Global edge network |
| Stripe | Payment processing and subscription billing | United States, European Union |
| Vercel | Website hosting and website analytics | United States, European Union |
| PostHog | Product analytics | United States, European Union |
| Google Workspace | Business email, documents, and support correspondence | United States, European Union |
We will keep this list current and give notice of changes as described in Section 5.
Contact
Data protection questions, and requests for a countersigned copy: support@enrichloops.com