Data Processing Agreement
This Data Processing Agreement ("DPA") is part of the Terms of Service between WarpLeads, Inc. ("WarpLeads", "we", "us"), which operates SalesBullet.ai, and the customer ("you"). It applies when we process personal data on your behalf while providing SalesBullet, and it sets out the terms that the GDPR, the UK GDPR and similar laws require between a controller and its processor.
No signature needed: this DPA takes effect when you accept the Terms, and it's the same for every customer — we can't sign or negotiate customers' own DPA forms. If you need a signed copy for your records, write to support@salesbullet.ai from your account's email address.
1. Definitions
- Data Protection Laws — the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other data-protection law that applies to the processing under this DPA.
- Customer Personal Data — personal data in Your Data (as defined in the Terms) that we process on your behalf.
- Sub-processor — a provider we engage that processes Customer Personal Data.
- Security Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- SCCs — the standard contractual clauses approved by the European Commission's Implementing Decision (EU) 2021/914.
Words such as controller, processor, data subject, processing and supervisory authority have the meaning the GDPR gives them.
2. Roles and scope
For Customer Personal Data, you're the controller — or a processor acting for your own clients, in which case we're your sub-processor — and we're your processor. Annex 1 describes the processing.
This DPA doesn't cover data we decide about ourselves, as a controller, under our Privacy Policy: our lead database, your account and billing data, and data we need to keep SalesBullet secure. Paddle, our Merchant of Record, processes payment data as its own controller.
3. Instructions
We process Customer Personal Data only on your documented instructions: the Terms, this DPA, the way you use and set up SalesBullet, and other written instructions we agree with you. If the law requires us to process it otherwise, we'll tell you first, unless the law forbids that. We'll tell you if we believe an instruction breaks Data Protection Laws.
You're responsible for your instructions and for having a legal basis for the processing — including for contacting the people in your campaigns — and for giving them the information the law requires.
4. Confidentiality
Everyone we authorize to process Customer Personal Data is bound by confidentiality, and has access only as far as their work needs it.
5. Security
We protect Customer Personal Data with appropriate technical and organizational measures, described in Annex 2. We may update them as technology and risks change, but never in a way that lowers the overall level of protection.
6. Sub-processors
You authorize us to use Sub-processors; Annex 3 lists what they do. Each is bound by a written contract with data protection obligations no less protective than this DPA, and we remain responsible to you for their work.
We'll send you the current list of our named Sub-processors and where they process data on request, and tell you by email at least 30 days before we add or replace one. You may object on reasonable data-protection grounds within that time. If we can't resolve the objection together, you may end the service concerned, and we'll refund what you prepaid for the period after it ends.
7. Helping you
SalesBullet lets you find, export, correct and delete your contacts and add people to your do-not-contact list, so you can answer data subjects' requests yourself. If a data subject asks us directly about Customer Personal Data, we'll pass the request to you and won't answer it ourselves unless you ask us to.
Taking into account the nature of the processing and the information available to us, we'll give you reasonable help with security, with Security Incident notifications, and with data-protection impact assessments and prior consultations with supervisory authorities.
8. Security Incidents
We'll tell you without undue delay after we become aware of a Security Incident, and give you what we know — its nature, the categories and approximate number of data subjects and records concerned, its likely consequences, and what we've done or propose to do about it — with updates as we learn more. We'll take reasonable steps to contain it and limit its effects. Telling you about a Security Incident isn't an admission of fault.
9. Deleting and returning data
While you use SalesBullet you can export and delete Customer Personal Data in the app. When your account is deleted or the Terms end, we delete Customer Personal Data within 30 days, unless the law requires us to keep part of it — then we keep it protected and use it only for that purpose.
10. Information and audits
We'll make available the information you need to show that we meet this DPA. If that isn't enough, you — or an independent auditor bound by confidentiality — may audit our compliance once a year, with at least 30 days' notice, during business hours and without access to other customers' data or disruption to our service; more often only if a supervisory authority requires it or after a Security Incident. You bear the costs of your audit.
11. International transfers
Where Customer Personal Data protected by the GDPR is transferred to us or a Sub-processor in a country without an adequacy decision, the SCCs apply and are part of this DPA: Module Two (controller to processor) where you're a controller, and Module Three (processor to processor) where you're a processor. In them, Clause 7 (docking) applies; under Clause 9, option 2 (general authorization, with the 30 days' notice in section 6) applies; the optional wording in Clause 11 doesn't apply; under Clause 13, the supervisory authority is the one competent for you; under Clauses 17 and 18, the SCCs are governed by the law of the EU Member State where you're established — or Ireland's, if that law doesn't allow third-party beneficiary rights — and disputes go to the courts of that Member State. The annexes of this DPA are the SCCs' annexes.
For data protected by the UK GDPR, the UK International Data Transfer Addendum to the SCCs applies as well. For data protected by Swiss law, the SCCs apply with the changes Swiss law requires: the Swiss Federal Data Protection and Information Commissioner is the competent authority, and "Member State" includes Switzerland, so data subjects there can enforce their rights where they live.
12. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms, as far as Data Protection Laws allow; nothing limits data subjects' rights under the SCCs. If documents conflict on the processing of Customer Personal Data, the SCCs come first, then this DPA, then the Terms. This DPA lasts as long as we process Customer Personal Data for you.
Annex 1 — The processing
| Parties | Data exporter: you, the customer, as a controller or a processor; contact — your account's email address. Data importer: WarpLeads, Inc., as a processor; contact — support@salesbullet.ai. |
|---|---|
| Subject matter and duration | Providing SalesBullet under the Terms, for as long as they last and until the data is deleted (section 9). |
| Nature and purpose | Storing and organizing your contacts and lists; verifying the email addresses you ask us to check; sending your email and LinkedIn campaigns and warming up your email accounts; finding and reading replies, bounces and auto-replies; Automatic Enrichment and Automatic Personalization; AI reply labels and suggested replies; AI avatar videos; webhooks to your own tools; support. |
| Data subjects | Your contacts — prospects, customers and business partners, whether you upload them or add them from our lead database; people who reply to or write to your connected accounts; you and your team, as the senders in the email and LinkedIn accounts you connect; and people whose likeness or voice you use for AI avatars (yourself, or with their permission). Your SalesBullet account itself — its name, email and password — isn't covered: it's ours to look after under the Privacy Policy (section 2). |
| Personal data | Names; job titles and company details; business email addresses and phone numbers; LinkedIn profiles; location; the content of messages and replies; notes and labels; research results and AI-written text; campaign activity such as sent, replied and bounced; photos and voice samples for avatars. |
| Sensitive data | None intended — the Terms don't allow uploading it. |
| Frequency | Continuous, while you use SalesBullet. |
Annex 2 — Security measures
- Location: SalesBullet's servers and database are hosted in Germany, in the European Union.
- Encryption in transit: HTTPS for the app, the API and the website; encrypted connections to email servers (TLS for IMAP and SMTP).
- Encryption of secrets: passwords and access tokens of connected accounts are stored encrypted; user passwords are stored only as hashes.
- Access control: every request is signed in and checked against the user's workspaces, so each workspace's data stays apart; access to production systems is limited to the people who need it.
- Data minimization: from a connected mailbox only messages about your campaigns are stored; AI providers get only the data each task needs; export files and lead research are deleted after 30 days, logs within 30 days.
- Availability: monitoring and alerts for failures, background work that retries safely, and regular database backups.
- Development: changes are reviewed and tested before release.
- Providers: Sub-processors are chosen for their security and bound by data-protection contracts.
- Incidents: a process to detect, contain and assess Security Incidents and notify customers.
Annex 3 — Sub-processors
Only providers that process Customer Personal Data are Sub-processors — the ones that only send us data, or get none of yours, aren't.
| What they do | Customer Personal Data they process |
|---|---|
| Cloud hosting, database and file storage | All Customer Personal Data |
| AI model providers | The contact and message details each task needs — research, personalization, reply labels and suggestions, avatars |
| Web research provider | Your contacts' names, companies and websites, for Automatic Enrichment |
| Email verification provider | The email addresses you ask us to check |
| LinkedIn integration provider | Your connected LinkedIn accounts, campaign messages and replies |
| Email warm-up network | Your connected email accounts taking part in warm-up |
| Email-account provider | The email accounts you buy from us, and their emails |
| Transactional email | Our emails to your team, such as reply notifications — a lead's name and the start of their reply |
The named list, with where each processes data, is available on request (section 6).