Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer") and [TBD: legal entity name] ("Outsquid"). It applies where Outsquid processes personal data on the Customer's behalf and data protection law, such as the GDPR or UK GDPR, requires such an agreement.
1. Roles
The Customer is the controller of the personal data in its prospects, emails and replies. Outsquid is the processor and processes that data only on the Customer's documented instructions, which are the Terms, this DPA, and the Customer's use of the product.
2. Scope of processing
- Subject matter: providing the Outsquid cold email service.
- Duration: for as long as the Customer's account is active, then until deletion under section 8.
- Nature and purpose: storing prospect lists, sending campaign emails from the Customer's mailboxes, syncing replies, tracking opens, clicks and unsubscribes, and reporting on results.
- Data subjects: the Customer's prospects and contacts, and the Customer's own users.
- Categories of data: names, email addresses, job titles, companies, locations, time zones, other fields the Customer chooses to upload, email content and engagement events.
3. Outsquid's obligations
Outsquid will:
- process the data only on the Customer's instructions, and tell the Customer if it believes an instruction breaks the law;
- ensure that people authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (section 5);
- help the Customer respond to data subject requests and meet its security, breach notification and impact assessment obligations, taking into account the nature of the processing;
- make available the information needed to demonstrate compliance with this DPA.
4. Sub-processors
The Customer authorises Outsquid to use the sub-processors listed below. Outsquid will tell the Customer about any new sub-processor at least 14 days in advance; the Customer may object on reasonable data protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| [TBD: hosting provider] | Application servers and database | [TBD] |
| Stripe | Subscription billing and payments | [TBD] |
| Sign-in with Google; Gmail sending and reply sync for connected mailboxes | [TBD] | |
| Microsoft | Outlook / Microsoft 365 sending and reply sync for connected mailboxes | [TBD] |
| Umami | Cookieless website analytics | EU / US |
| [TBD: transactional email provider] | Account emails (verification, password reset, alerts) | [TBD] |
5. Security measures
- Encryption in transit (HTTPS/TLS).
- Mailbox access tokens and passwords encrypted at rest (AES-256-GCM).
- Each organization's data kept separate, with access limited by role.
- Internal access limited to what is necessary to run and support the service.
6. Personal data breaches
Outsquid will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data, and provide the information the Customer needs to meet its own obligations.
7. International transfers
Where personal data is transferred outside the EEA or UK, Outsquid relies on an adequacy decision or the Standard Contractual Clauses. [TBD: transfer mechanism and module]
8. Deletion and return
When the Customer's account ends, the Customer can export its prospects first. Outsquid then deletes Customer data within [TBD: retention period after account deletion], unless the law requires it to be kept.
9. Signing
This DPA applies automatically to customers who need it. To receive a countersigned copy, email [TBD: privacy@ address].
Last updated 2026-10-04