Data Processing Agreement (DPA)

Last Updated: January 1, 2025

â„šī¸ For B2B Customers: This DPA governs how we process personal data on your behalf when you use our Service.

1. Definitions

  • "Controller" means you, the customer using our Service
  • "Processor" means LeadZ, processing data on your behalf
  • "Data Subject" means individuals whose personal data is processed
  • "Personal Data" has the meaning given in GDPR
  • "Processing" has the meaning given in GDPR
  • "Sub-processor" means third parties we engage to process data

2. Scope and Application

This DPA applies when LeadZ processes Personal Data on your behalf as a Processor. This includes:

  • Customer contact information you input
  • Job and service records
  • Communication records (SMS, email)
  • Photos and documents uploaded
  • Payment information (processed by Stripe)

3. Your Obligations as Controller

As Controller, you warrant that:

  • You have a lawful basis for processing Personal Data
  • You have provided required notices to Data Subjects
  • You have obtained necessary consents
  • Processing instructions comply with applicable laws
  • You will not cause us to violate data protection laws

4. Our Obligations as Processor

We will:

  • Process Personal Data only on your documented instructions
  • Ensure confidentiality of personnel processing data
  • Implement appropriate technical and organizational security measures
  • Engage Sub-processors only with your consent
  • Assist you in responding to Data Subject requests
  • Assist you with data protection impact assessments
  • Delete or return data upon termination
  • Make available information necessary to demonstrate compliance

5. Sub-processors

You authorize us to engage the following Sub-processors:

  • Supabase: Database and file storage (US, EU)
  • Stripe: Payment processing (US, EU)
  • Twilio: SMS, voice, WhatsApp (US)
  • SendGrid: Email delivery (US)
  • AWS: Cloud infrastructure (global)

We will notify you of any changes to Sub-processors with 30 days' notice. You may object on reasonable data protection grounds.

6. Data Subject Rights

We will assist you in fulfilling Data Subject rights requests:

  • Access: Provide tools to export data
  • Rectification: Allow data correction through the platform
  • Erasure: Delete data upon request (within legal limits)
  • Restriction: Temporarily restrict processing
  • Portability: Export data in machine-readable format
  • Objection: Stop processing for specific purposes

Requests should be submitted through our GDPR Compliance dashboard or by emailing privacy@lead-z.com.

7. Security Measures

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls
  • Two-factor authentication
  • Regular security audits and penetration testing
  • 24/7 monitoring and logging
  • Incident response procedures
  • Employee training and background checks

8. Data Breach Notification

In the event of a Personal Data breach, we will:

  • Notify you without undue delay (within 72 hours of discovery)
  • Provide details of the breach's nature and impact
  • Describe measures taken to address the breach
  • Provide recommendations to mitigate potential harm

You remain responsible for notifying supervisory authorities and Data Subjects as required by law.

9. International Data Transfers

Personal Data may be transferred to countries outside the EEA. We ensure protection through:

  • Standard Contractual Clauses (SCCs) approved by the EU Commission
  • Adequacy decisions where available
  • Binding Corporate Rules for Sub-processors
  • Additional safeguards as required by law

10. Audits and Inspections

You have the right to audit our compliance with this DPA:

  • We will provide information to demonstrate compliance
  • You may conduct audits with reasonable notice (30 days)
  • Audits must not unreasonably interfere with operations
  • You may use independent auditors bound by confidentiality
  • Audit costs are your responsibility

We provide annual SOC 2 reports and security certifications as evidence of compliance.

11. Data Return and Deletion

Upon termination of the Service:

  • You have 30 days to export your data
  • After 30 days, we will delete all Personal Data
  • Backups are deleted within 90 days
  • We may retain data as required by law (e.g., financial records for 7 years)

12. Liability and Indemnification

Liability for data protection violations is governed by our Terms of Service. Each party indemnifies the other for losses caused by breach of this DPA.

Nothing in this DPA reduces either party's liability under data protection laws.

13. Term and Termination

This DPA takes effect when you accept it and remains in effect until termination of the Service. Sections relating to data deletion, confidentiality, and liability survive termination.

14. Governing Law

This DPA is governed by the laws of [Your Jurisdiction]. For EU customers, GDPR provisions take precedence.

15. Contact

Data Protection Officer: dpo@lead-z.com

Legal Department: legal@lead-z.com

Address: [Your Business Address]

Acceptance

By using LeadZ for business purposes, you acknowledge that you have read, understood, and agree to this Data Processing Agreement.

For signed DPA with custom terms, contact legal@lead-z.com.