Data Processing Agreement

Version 1.0-2026-10-04

This agreement describes how Outbly processes personal data on behalf of customers using Outbly.

1.Parties, scope and order of precedence

This data processing agreement (“DPA”) is part of the agreement between the customer organization (the “Customer”, controller) and Outbly, provider of Outbly (the “Provider”, processor).

Provider: Outbly. Data protection contact: privacy@outbly.com.

Customer: the organization identified when this DPA is signed electronically in the product (organization name, signer, title, date and time).

The DPA applies to personal data the Provider processes on the Customer's behalf. It takes effect on signature and lasts as long as the main agreement (terms / subscription). In case of conflict, the DPA prevails only for the processing of personal data; the main agreement prevails for everything else.

2.Roles of the parties

The Provider acts as processor for data the Customer imports or generates in the service: prospects, contacts, campaigns, messages, replies, notes and CRM data.

The Provider acts as controller, under its own privacy policy and outside this DPA, for: account and user management, billing and payments, security and abuse prevention, support, technical logs, aggregated usage statistics and proof of contractual commitments.

This DPA does not make the Provider a joint controller. If the parties were to jointly determine the purposes and means of a processing, they would enter into a specific agreement.

3.Subject matter, nature, duration and purpose

The Provider processes personal data only to provide the service: storing and enriching B2B prospect and contact data, generating and sending outreach emails from the Customer's connected mailboxes, and handling replies, CRM, integrations and analytics.

Duration: that of the main agreement, then the deletion period described in “Retention, deletion, return and audits”.

Operations: collection (import, entry, browser extension, API), storage, consultation, enrichment, address verification, AI-assisted generation, sending, synchronization with connected tools, deletion.

Categories of data subjects: - The Customer's business prospects and contacts - Users of the Customer's organization

Categories of data: professional identity (name, job title, company), business contact details (email, phone, website, professional profile), message content, engagement events (open, click, reply, bounce, unsubscribe) and technical sending metadata.

Frequency: continuous, depending on the Customer's use of the service.

4.Prohibited data

The Customer must not import or process in the service: special categories of data (GDPR Article 9: health, origin, opinions, trade-union membership, sexual orientation, genetic or biometric data…), data relating to criminal convictions and offences, data of minors, or non-professional personal data.

Any exception requires the Provider's prior written agreement and specific safeguards. The Provider may refuse or delete such data.

5.Instructions

The Provider processes personal data only on the Customer's documented instructions, including those given through the product's configuration (campaigns, settings, integrations, deletions), unless required otherwise by applicable law. It informs the Customer if an instruction appears to infringe data protection law.

6.Confidentiality

The Provider ensures that persons authorized to process personal data are bound by confidentiality and access it only when their role requires it.

7.Security

The Provider implements technical and organizational measures appropriate to the risk. They are described as implemented in the product: - Encryption at rest of integration credentials and secrets (AES-256-GCM); encrypted connections (TLS) - Session tokens stored in hashed form (SHA-256) - Role-based access control and data isolation between organizations - Audit log of sensitive actions, exportable by the Customer - Rate limiting on sensitive routes - Protection of AI features against instruction injection in received messages

The Customer protects its credentials, manages its users' access, keeps its API keys confidential and reports any incident without delay.

No third-party certification (for example ISO 27001 or SOC 2) is claimed by this document. Additional measures (backups, monitoring, disaster recovery): [to be described according to the infrastructure actually deployed].

8.Sub-processors

The Customer gives general authorization for the sub-processors needed to run the service. Those the Provider uses, depending on the features enabled, are: - Hosting and infrastructure: IONOS SE (data center in Germany) - Transactional emails of the service: Resend (Ireland region, European Union) - Payments and subscriptions: Stripe - AI (generation, analysis, reply classification): OpenAI and/or Anthropic, depending on configuration - Web search for AI research: Serper and/or Google Custom Search - Prospecting and enrichment data: Apollo, Prospeo, Apify, Clay or a custom provider, depending on configuration - Email address verification: ZeroBounce and/or NeverBounce - Notifications: Slack; SMS: Twilio (if enabled)

Country of processing, data accessed and transfer safeguards for each sub-processor: [to be completed before publication]. Tools the Customer connects itself (its Google or Microsoft mailbox, CRM, calendar) are chosen by the Customer and are not the Provider's sub-processors.

The Provider imposes on each sub-processor obligations equivalent to this DPA and remains liable to the Customer for their performance. It informs the Customer of any addition or replacement at least 30 days in advance (by email or in the product); the Customer may object in writing on reasonable grounds. Failing a solution, it may terminate the affected part of the service.

9.Data location and transfers

Customer data for this deployment is hosted in the region: European Union. Transfers outside the European Economic Area, notably to some AI or data providers, are made only with appropriate safeguards (standard contractual clauses for transfers, an adequacy decision or another mechanism provided by the GDPR), identified for each sub-processor. These transfer clauses are separate from this DPA.

10.Artificial intelligence

Some features send content (prospect data, messages, instructions) to AI providers to generate or classify text. The Provider does not use Customer data to train its own models. AI providers receive only what is needed for the requested function; their retention and training terms are those of their own contract: [to be verified and completed for each provider].

By default, AI-generated emails require human approval. The Customer remains responsible for reviewing, approving and sending content, including when it enables automatic sending.

11.Assistance and data subject rights

The Provider helps the Customer respond to data subject requests (access, rectification, erasure, restriction, objection, portability), notably through the suppression list, data export and deletion, and for data protection impact assessments where required.

If the Provider receives a request directly about data processed on the Customer's behalf, it does not answer on the merits unless instructed by the Customer or required by law; it forwards it to the Customer within a reasonable time.

12.Suppression list

For each customer organization, the service keeps a suppression list (email addresses, domains, companies). It is fed by unsubscribes, opt-out replies, bounces, complaints and the Customer's manual or imported additions. It is checked before every send and prevents any new send to a suppressed entry.

It is specific to each organization: a suppression requested with one customer does not automatically apply to other customers. It holds only the suppressed value, the reason, the source and the date, and is not used for any other purpose. It is kept as long as the organization exists, so the person is not contacted again, and deleted with the organization.

13.Commercial outreach: Customer responsibilities

The Provider supplies a technical tool. It is not a legal adviser, an outreach agency, or a guarantor of deliverability or of a campaign's compliance.

The Customer is solely responsible for: the lawfulness of its campaigns and the legal basis chosen; informing individuals; the professional relevance of recipients and message; the source and quality of its data; the content, frequency and legal notices of its messages; honoring the right to object; and compliance with the rules of each targeted country and of its mailbox providers.

It must not use the service for spam, misleading messages, impersonation, phishing, fraud, harassment, circumventing an objection, unlawfully obtained lists or any unlawful content. The Provider may suspend a feature or account in case of serious risk or clearly abusive use, with notice and, where possible, time to remedy.

14.Personal data breaches

The Provider notifies the Customer within a maximum of 48 hours after confirming a personal data breach affecting the Customer's data, by email to the organization's owners. The notification states, as far as information is available: the nature of the incident, the categories and approximate volumes of data concerned, likely consequences, measures taken and a contact point. It may be completed in stages.

A mere security alert without confirmed access to data is not a breach. The Customer remains responsible for notifying the supervisory authority and affected individuals; the Provider does not contact those individuals without instruction or legal obligation.

15.Retention, deletion, return and audits

During the contract, data is kept as long as the Customer keeps it in its workspace; it can export or delete it at any time from the product. Technical and audit logs are kept for 12 months for security and evidence, then automatically purged; proof of signature of this DPA is kept for the duration of the contract.

At the end of the contract, the Customer may export its data for 30 days. After that, the Provider deletes active data, or returns it at the Customer's choice, unless the law requires retention. Copies in backups are deleted on their normal rotation cycle and are not used operationally. Deleting the organization from the product erases its data and cancels the subscription.

The Provider makes available the information needed to demonstrate compliance (audit log, description of security measures). Audits are limited to one per twelve-month period, except after an incident or at an authority's request, on at least 30 days' written notice, without access to other customers' data and without harming the service's security or availability. Reports and security questionnaires are preferred. Contact: privacy@outbly.com.

16.Liability

The Customer warrants that it has the rights, legal bases and authorizations needed to entrust the data to the Provider, and remains responsible for its instructions, recipient lists and campaign content. The Provider is liable for breaches attributable to it, within the limits set by the main agreement.

[Liability cap, exclusions, indemnification and handling of third-party claims: to be drafted with a lawyer — do not publish without validation.]

17.Changes, governing law and miscellaneous

The Provider may amend this DPA for legal, technical or security reasons, informing the Customer in advance; the signed version stays applicable until the new version is accepted. Notices are sent by email to the organization's owners and to privacy@outbly.com. Electronic signature in the product constitutes acceptance.

If a clause is invalid, the others remain applicable. Governing law and jurisdiction: French law; the courts with jurisdiction over the Provider's registered office.

Data Processing Agreement · Outbly