01Parties, acceptance and scope
This Data Processing Agreement (DPA) is between A1 Consulting Oy (Business ID 3403245-7), Länsisatamankatu 34 A 113, Finland (LeadTerminal, we or processor), and the customer identified in the relevant service order or written acceptance (Customer). It is intended to supplement the LeadTerminal service agreement when we process personal data on Customer’s behalf.
It takes effect only when the parties expressly accept it in writing or through an agreed electronic acceptance process and complete the processing schedules. Merely visiting this page does not execute a DPA.
Contact: info@leadterminal.ai. GDPR terms have their meanings under Regulation (EU) 2016/679.
Where Customer is itself a processor, it must have its controller’s authority to engage us as a subprocessor and to issue the relevant instructions.
02Separate controller activities
This DPA covers Customer-controlled workspace data described in Schedule 1. It does not cover LeadTerminal’s independent decisions about its public-source business directory, account administration, billing, legal obligations or service-security records for which it acts as a controller.
Those activities are described in the privacy policy. Customer is independently responsible for its use of directory results; when results are saved into Customer’s campaigns or workspace for processing on its instructions, that workspace processing falls under this DPA.
Roles follow the actual processing activity, not simply the name assigned to a party.
03Customer instructions and permitted use
We will process Customer personal data only on documented instructions, including the agreed service configuration, authorised user actions and campaign approvals, unless EU or Member State law requires otherwise. In that case we will inform Customer of the legal requirement before processing unless the law prohibits notice on important public-interest grounds.
We will immediately inform Customer if, in our opinion, an instruction infringes applicable EU or Member State data-protection law and may pause the affected processing while the parties resolve it. We will not sell or rent Customer workspace data, use it for our own advertising, add private workspace information to an independently marketed directory, or use it to train general-purpose AI models.
Information may be processed by authorised providers solely for the permitted service purposes under appropriate contractual obligations.
04Email sending, inbox access and customer responsibilities
Customer determines recipients, message content, sending schedules and the lawful purpose of its campaigns. Customer is responsible for required notices, a lawful basis for personal-data processing, applicable electronic-marketing permissions and respecting objections.
Approval of a campaign documents an instruction to send; it is not evidence that recipients consented. Customer must connect only accounts it is authorised to use and control staff access.
Google OAuth uses gmail.send and userinfo.email; Microsoft OAuth uses Mail.Send, User.Read and offline_access. These connections support sending and sender identification, not inbox reading.
IMAP credentials and inbox processing are separate and apply only when configured. Customer must limit connected inboxes and uploaded content to what is necessary.
Delivered messages cannot be recalled by disconnecting an account, and this DPA does not bind recipients or govern their independent copies. Open tracking must be enabled and used only with any notices or permissions required by law.
05Confidentiality and security
We will ensure that people authorised to process Customer personal data are bound by confidentiality obligations and have access only as needed for their duties. We will implement and maintain measures appropriate to the risks under GDPR Article 32, including the agreed measures in Schedule 2, and regularly assess their effectiveness.
Changes must not materially reduce the overall protection. Customer remains responsible for its own devices, user permissions and connected-provider settings.
This DPA does not assert an ISO certification, SOC audit, blanket encryption of all stored data or exclusive EEA processing.
06Subprocessors
Customer gives general written authorisation to the subprocessors identified in the completed Schedule 3 for the stated activities. Before an addition or replacement accesses Customer personal data, we will give Customer at least 30 days’ written notice, including identity, purpose, processing locations and transfer safeguards, so Customer can raise reasonable data-protection objections.
The parties will seek a reasonable alternative; if no compliant solution is available, the affected processing will not proceed with that provider and either party may terminate the affected service, with a proportional refund of unused prepaid fees for it. We will impose equivalent applicable data-protection obligations in a written contract and remain responsible to Customer for the subprocessor’s performance of those obligations.
We will provide information on those arrangements needed to demonstrate compliance, protecting unrelated confidential information. Customer’s own contracted mailbox providers and message recipients are distinguished from our subprocessors in Schedule 3.
07International transfers
We will not transfer Customer personal data outside the EEA, including by remote access, without documented instructions and a valid GDPR Chapter V mechanism. Before such processing, the completed provider schedule must identify the relevant countries and safeguard.
This may be a valid adequacy decision covering the recipient or applicable transfer standard contractual clauses with completed annexes, transfer assessment and necessary supplementary measures. Where no valid safeguard can be maintained, the affected transfer will be suspended.
This bespoke DPA is not itself the European Commission’s international-transfer standard contractual clauses and does not incorporate incomplete transfer clauses merely by mentioning them.
08Requests from individuals
Taking account of the nature of processing, we will assist Customer through appropriate technical and organisational measures to respond to access, correction, deletion, objection, restriction and portability requests within applicable deadlines. We will forward requests relating to Customer-controlled data without undue delay and will not substantively respond except on Customer’s instructions or as legally required.
We may acknowledge receipt and direct the requester to Customer. Customer must tell us which workspace records and instructions are affected.
Directory requests concerning our independent controller activities are handled separately under our privacy policy.
09Personal-data breaches
We will notify Customer without undue delay after becoming aware of a personal-data breach affecting data processed under this DPA. As available, notice will describe the incident, affected categories and approximate numbers of people and records, likely consequences, containment or remediation and a contact for follow-up.
We may provide information in stages without undue further delay. We will investigate, take reasonable containment and remediation measures, preserve relevant evidence and cooperate with Customer.
Customer decides notifications to authorities and individuals for its controller activities; we will provide necessary assistance without limiting our own legal obligations. Notice does not by itself admit liability.
10Compliance assistance and audits
Taking account of the processing and information available to us, we will assist Customer with GDPR Articles 32 to 36, including security, breach reporting, impact assessments and prior consultation. We will make available information necessary to demonstrate compliance with Article 28 and allow and contribute to audits and inspections by Customer or its mandated independent auditor.
The parties will coordinate reasonable notice, confidentiality and safeguards for other customers’ information without preventing an effective audit. Urgent incidents, regulatory requests and legal deadlines may require expedited access.
Any agreed reasonable charges for additional assistance must not prevent mandatory assistance or remedying our own non-compliance.
11Return, deletion and duration
At Customer’s choice, we will return Customer personal data in a commonly used, usable format or delete it when the processing service ends. Following account closure or a valid deletion instruction, we will complete deletion from active systems within 30 days and remove remaining backup copies within 90 days of the same event, subject to any shorter mandatory deadline.
These periods are maximum deadlines, not minimum holding periods. Copies awaiting backup expiry remain protected and unavailable for ordinary processing; if restored for disaster recovery, the deletion instruction must be reapplied before ordinary use resumes.
Connected email credentials are removed from active systems immediately when the connection is deleted; this does not recall delivered messages or delete workspace history. We may retain only records required by EU or Member State law, limited to that purpose and period.
Minimal unsubscribe or suppression records may be retained only on a documented lawful basis to prevent further unwanted contact and must not be reused for marketing. We will confirm completion of applicable deletion steps on request.
The deadlines apply to data processed on Customer’s behalf and do not control independent copies held by recipients or Customer’s own mailbox providers.
12Liability, precedence and termination
The service terms’ aggregate liability cap based on fees attributable to the three months preceding the first event giving rise to the claim applies between the parties to the extent lawful; it is not a separate additional cap for this DPA. The exceptions for fraud, wilful misconduct, gross negligence and liability that cannot lawfully be limited continue to apply.
Nothing restricts data subjects’ rights, supervisory powers, mandatory GDPR liability or obligations under applicable transfer clauses. This DPA prevails over conflicting service terms concerning processing on Customer’s behalf; mandatory transfer clauses prevail over both.
If a material processing breach cannot be remedied, or lawful processing cannot continue, Customer may require suspension or terminate the affected processing. Return and deletion obligations survive termination.
Finnish law applies subject to mandatory applicable law.
13Schedule 1 — Processing description
Purpose: providing Customer’s workspace, contact lists, approved outreach, connected sending, configured inbox and reply handling, and requested AI assistance. Operations: collecting, storing, organising, retrieving, generating drafts, transmitting, matching activity, exporting, correcting and deleting data.
Processing is ongoing while the agreed features are used, including scheduled campaigns. Individuals: authorised users, prospects, customers, professional contacts and people included in relevant correspondence.
Data: names, roles, company and contact details, workspace identifiers, lists, campaign instructions, drafts, messages and supported attachments, configured inbox replies, delivery and unsubscribe events, optional tracking events, connection credentials and relevant technical metadata. Special-category and criminal-offence data are outside the intended service and require a separate written agreement and safeguards.
Duration and deletion: active data within 30 days and backup copies within 90 days of closure or a valid deletion instruction, as described above. The service order or written acceptance identifies Customer, its contact and the enabled features.
14Schedule 2 — Security measures
Access: authenticated access to the application and APIs, workspace access checks and server-side handling of connected-account credentials. Transmission: HTTPS on public application endpoints.
Credentials: encryption of newly stored OAuth tokens, with access restricted to server-side operations; this does not represent blanket encryption of every stored record. Backups: scheduled database backups with restricted file access.
Confidentiality and response: the confidentiality, risk-appropriate security, incident-notification and audit obligations in this DPA apply. Deletion: the return and deletion deadlines above apply, including protection of retained backups and reapplication of deletion after restoration.
Detailed security evidence can be provided to Customer under confidentiality arrangements where needed to assess compliance.
15Schedule 3 — Service providers
Providers are used only for relevant enabled features. Hetzner provides application, database and backup hosting and may process workspace data and operational records.
Clerk provides sign-in and user authentication and processes identity and account information; its independent account-controller activities are separate from processing on Customer’s behalf. Anthropic provides requested AI research and drafting and receives the relevant prompts and supplied content.
Amazon Web Services SES handles email delivery when that sending method is used and receives message content, recipient details and delivery metadata. Customer-selected Google, Microsoft and SMTP or IMAP providers operate under the relevant customer-provider arrangement; recipients retain their own delivered copies.
Before acceptance, the provider register must identify each engaged subprocessor’s contracting entity, processing countries, applicable agreement and transfer safeguard. Provider additions and replacements follow the notice and objection procedure above.
16Completion and contact
For a customer-specific DPA or supporting security and provider information, contact info@leadterminal.ai. Acceptance must identify Customer, the enabled features, the agreed provider register and the accepted version.
Publication of this DPA does not by itself constitute acceptance by Customer or execution of an agreement with a service provider.