# Data Processing Addendum (DPA) — Seed Draft

**Last updated:** 2026-08-22  
This draft is a starting point for seed customers, **not** a substitute for counsel-reviewed contracts.

## Roles

- **Customer (Controller):** decides what personal data to upload (e.g. business contact emails, names, company info) and the purposes of outbound communications.
- **Provider (Processor):** Outreach SaaS processes Customer Data only to provide the service (storage, workflow execution, sending via Customer-configured mailboxes, suppression, logging, platform-operated prospecting capacity).

## Nature of processing

| Item | Description |
|------|-------------|
| Subject matter | Outreach workflow automation |
| Duration | While Customer account is active + 30-day export window after contract end + warm archive |
| Nature | Hosting, queueing, templating, platform-operated prospecting/verification, sending via Customer mailboxes, logging |
| Purpose | Operate Customer’s prospecting workflows |
| Data types | Business contact data Customer uploads or that the service discovers for Customer; mailbox credentials; send logs; unsubscribe emails |
| Data subjects | Customer’s prospects / leads; Customer’s users |

## Provider obligations

1. Process Customer Data only on documented instructions (product configuration + this DPA).
2. Ensure personnel confidentiality.
3. Implement reasonable security (encryption of secrets, access control, audit logs).
4. Assist with data subject requests **to the extent** the product exposes tools (e.g. suppression/unsubscribe). Legal identity verification remains Customer’s duty.
5. After contract end: keep the workspace **read-only for 30 days** so Customer can export CSV; then disable Customer access and warm-archive the workspace. Residual backups may remain for a limited period as required by law or disaster recovery.
6. **Not sell** Customer Data. Not share Customer Data with other customers. Internal anonymized / aggregate analytics (industry stats, product improvement) are allowed.

## Customer obligations

1. Have a lawful basis for processing and contacting data subjects.
2. Configure mailbox credentials securely; do not share accounts. Prospecting API keys are **not** supplied by Customer.
3. Not upload special-category data unless a valid exception applies.
4. Inform recipients as required by applicable law (identity, purpose, unsubscribe).
5. Export needed Customer Data during the 30-day window.

## Subprocessors (illustrative)

- Email providers Customer connects (Microsoft Graph, Tencent Exmail, Gmail)
- Platform-operated prospecting and verification processors (brands not disclosed to Customer)
- Infrastructure host (VPS/cloud) where this deployment runs

Update this list for your production host. Counsel should review before signature.

## International transfers

If Customer Data leaves the country of collection, Customer is responsible for assessing transfer mechanisms required by law. Seed deployments should document hosting region.

## Security incidents

Provider will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data, with known facts and mitigation steps.

## Governing law

Specify governing law / venue before production (e.g. Ontario, Canada or Delaware, USA).
