Data Processing Addendum
Effective date: [PLACEHOLDER: YYYY-MM-DD]
Draft processor agreement. Forms part of the Terms of Service for customers who process personal data of End Users through Directlee.
1. Parties and scope
This DPA is between Directlee ("Processor") and the customer entity that accepts the Terms ("Controller").
It applies to personal data Processor processes on Controller's behalf through the Services (leads, messages, subscribers, tags, notes, activity records, and related metadata).
2. Roles
- Controller determines purposes and means of processing End User data (your marketing, support, and CRM use).
- Processor processes such data only on Controller's documented instructions via the Services and these Terms, unless required by EU/UK law (in which case Processor informs Controller where permitted).
For Customer account data (billing, login), Directlee acts as an independent controller (see Privacy Policy).
3. Processor obligations
Processor will:
- process personal data only for providing the Services;
- ensure personnel confidentiality;
- implement appropriate security measures (see Annex A);
- use subprocessors listed in Subprocessors or notify material changes;
- assist Controller with data subject requests where feasible;
- delete or return personal data on termination per Data Deletion, subject to legal retention;
- notify Controller without undue delay of personal data breaches affecting Controller data where required by law.
4. Controller obligations
Controller will:
- have a lawful basis to collect and process End User data;
- comply with Platform API and marketing rules (Meta, TikTok, etc.);
- configure automations and broadcasts responsibly;
- respond to End User rights requests as primary contact.
5. Subprocessors
Controller authorizes Processor to engage subprocessors in subprocessors.md. Processor remains responsible for subprocessors under applicable law.
Integrations you enable (e.g. exporting leads to Sender.net, syncing to your Brevo list) involve separate controllers/processors chosen by you.
6. Security measures (Annex A summary)
Aligned with docs/core/SECURITY-AUDIT.md:
- Encryption of platform tokens at rest (AES-256-GCM) when production encryption is enabled
- TLS for remote PostgreSQL where configured
- Workspace/org-scoped access controls and RBAC for team members
- Webhook signature verification for Meta/TikTok
- Secure comparison for cron/admin secrets
[PLACEHOLDER: expand with counsel for formal Annex A text]
7. International transfers
See Privacy Policy §7. Processor will use appropriate safeguards for transfers outside the EEA/UK where applicable.
8. Term and termination
This DPA applies while Controller uses the Services. On account or workspace deletion, Processor deletes data per the Data Deletion policy, except where retention is required by law.
9. Contact
privacy / DPA inquiries: contact@directlee.app