When you use Leads Ranger, you decide what happens to the contact data in your workspace and we act on your instructions. This addendum is the contract that says so, in the form your legal, privacy or procurement team expects to see. It is already in force: accepting our Terms accepts this.
The short version
This summary is for convenience only. The numbered sections below are the binding text.
This Data Processing Addendum ("DPA") forms part of the Terms & Conditions between you ("Customer") and Leads Ranger ("Processor", "we", "us"). It applies whenever we process Personal Data on your behalf in providing the Service.
It is accepted automatically when you accept the Terms, so there is nothing to sign for it to be in force. If your procurement process needs a countersigned copy on your own paper, write to us and we will arrange it.
In the event of a conflict, this DPA prevails over the Terms and the Privacy Policy in relation to the processing of Personal Data carried out on your behalf.
"Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Supervisory Authority" have the meanings given in the GDPR. "Data Protection Law" means the GDPR, the UK GDPR and the Data Protection Act 2018, applicable United States state privacy laws, and any other data protection or privacy law applicable to the processing.
| Data | Customer | Leads Ranger |
|---|---|---|
| Personal Data inside your workspace (contacts, recipients, message content, notes, uploads) | Controller | Processor, acting only on your instructions |
| Your own account, billing and support data | Data Subject or Controller of your staff data | Independent Controller, governed by the Privacy Policy |
| Aggregated and de-identified service statistics | Not applicable | Controller, provided the data cannot be attributed to a Data Subject |
You are responsible for the lawfulness of the Personal Data you provide and of the instructions you give, including having a lawful basis for the processing and for the outreach itself, and for providing any notice or obtaining any consent required by Data Protection Law.
| Item | Detail |
|---|---|
| Subject matter | Provision of the Leads Ranger lead generation, outreach and customer relationship Service. |
| Duration | For the term of the Terms, plus the retention period described in section 8. |
| Nature and purpose | Collection, organisation, storage, retrieval, use, transmission, enrichment, analysis, generation of content, and deletion, in each case as needed to provide the Service you have configured. |
| Categories of Data Subject | Your business contacts, prospects, leads and recipients; your Users and staff; and any other individual whose Personal Data you choose to place in the workspace. |
| Categories of Personal Data | Business contact details (name, business email address, business phone number, job title, employer, business address, website, public business profile information), correspondence content and metadata, engagement records, notes and commercial status information, and any other data you upload. |
| Special category data | None. The Service is not designed for it and you must not upload it. See section 5 of the Acceptable Use Policy. |
| Frequency | Continuous, for the duration of the Service. |
We implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. Those measures include, at a minimum:
Why this list is at the level it is
We describe our controls at the level a Controller needs in order to assess them, and no lower. Publishing the specific configuration of a security control would help the people those controls exist to stop. A customer with a documented security review requirement can request further detail under a confidentiality agreement, and we will provide what is reasonable.
You are responsible for your own side of the security boundary: the strength and secrecy of your credentials, who you invite into your workspace, what access you grant them, and the security of the third-party services you connect.
The Service gives you the tools to access, correct, export and delete the Personal Data in your workspace directly, which will normally let you answer a request without involving us. Where you cannot, we will provide reasonable assistance, taking into account the nature of the processing.
If a Data Subject contacts us directly about data in your workspace, we will not respond substantively. We will tell them you are the Controller, and forward the request to you promptly.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. We will provide further information as the investigation progresses.
Notifying you is not an admission of fault or liability. Notifying Data Subjects and Supervisory Authorities in your own capacity as Controller is your responsibility, and we will give you the reasonable assistance you need to do it.
We will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities, to the extent they relate to our processing and to information that is not otherwise available to you.
We process Personal Data in the Islamic Republic of Pakistan and in the countries where our sub-processors operate. Pakistan is not the subject of an adequacy decision by the European Commission or the United Kingdom.
Where Personal Data is transferred out of the EEA, the United Kingdom or Switzerland, the parties agree that the European Commission Standard Contractual Clauses (Module Two, Controller to Processor) are incorporated into this DPA by reference and apply to that transfer, with:
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with the tables completed by reference to the same sections. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Federal Data Protection and Information Commissioner.