Between the Customer ("Controller") and LEADSMIND AI LTD, a company incorporated in England and Wales under number 17014114, 167-169 Great Portland Street, London W1W 5PF, United Kingdom ("Processor", "XP ONE").
Processor contact for any question relating to this addendum: contact@xp-one.io
This addendum is entered into under Article 28 of GDPR (EU) 2016/679 and its UK GDPR equivalent. It is accepted together with the Terms of Service and requires no separate signature; a signed copy can be provided on request.
1. Purpose
XP ONE processes personal data on behalf of and on the documented instructions of the Customer, solely for the purpose of performing the Service.
2. Description of the processing
| Item | Content |
|---|---|
| Subject matter | Provision of a platform for collecting, organising, enriching and prospecting business contacts |
| Duration | Term of the subscription, plus 30 days' retention |
| Nature | Collection, structuring, storage, enrichment, consultation, transmission, export, erasure |
| Purpose | The Customer's B2B commercial prospecting |
| Categories of data subjects | The Customer's prospects and business contacts; users designated by the Customer |
| Categories of data | Professional identity (first name, last name), job title, employer, public profile URL, business email, business phone, public engagement signals, content of messages sent by the Customer |
| Special category data | None. The Customer must not process special categories of data (Article 9 GDPR) or criminal offence data through the Service |
3. XP ONE's obligations
XP ONE undertakes to:
- process data only on the Customer's documented instructions, including for transfers outside the EU/UK; and inform the Customer if an instruction appears to infringe applicable law;
- ensure that persons authorised to process the data are bound by an obligation of confidentiality;
- implement the technical and organisational measures set out in Annex 2;
- comply with the conditions for engaging sub-processors (clause 4);
- assist the Customer, so far as possible, in responding to data subject requests; where a request is addressed to us directly, we forward it to the Customer without delay and do not respond ourselves, unless instructed otherwise;
- assist the Customer with data protection impact assessments, prior consultations and security of processing;
- notify the Customer without undue delay, and within 48 hours at the latest of becoming aware of it, of any personal data breach, with the information the Customer needs to notify its supervisory authority;
- at the Customer's choice expressed at the end of the service, delete or return all data and destroy existing copies, save where retention is legally required. Absent instruction within 30 days of the end of the contract, the data is deleted or anonymised;
- make available to the Customer all information necessary to demonstrate compliance and allow for audits, under the conditions of clause 6.
4. Sub-processors
The Customer gives general authorisation for XP ONE to engage the sub-processors listed in Annex 1.
Any addition or replacement is notified to the Customer at least 30 days in advance. The Customer may object on reasonable, documented data protection grounds; failing agreement, the Customer may terminate the subscription without penalty and obtain a pro rata refund of the unused portion of the period paid for.
XP ONE imposes on each sub-processor, by contract, obligations equivalent to those set out here, and remains fully liable for their performance.
5. International transfers
Data is hosted in the United Kingdom and the European Union. EU ↔ UK transfers rely on the European Commission's adequacy decision of 28 June 2021 for the United Kingdom. Any transfer to a non-adequate third country is covered by the standard contractual clauses (SCCs 2021/914) or the UK International Data Transfer Addendum, together with a transfer impact assessment.
6. Audit
The Customer may, at most once a year and on 30 days' written notice, request the documentation evidencing compliance, or arrange an audit by an independent third party bound by confidentiality. Audits take place during business hours, without disrupting operations, at the Customer's cost, unless the audit reveals a material breach.
7. Customer obligations and warranties
The Customer warrants that it:
- has a valid lawful basis for each processing operation carried out through the Service, in particular legitimate interests for B2B prospecting, and has carried out the corresponding balancing test;
- informs data subjects in accordance with Article 14 GDPR, no later than first contact, including the source of the data;
- handles objection requests without delay and removes from its campaigns any person who has objected;
- complies with applicable prospecting rules (GDPR, ePrivacy, national rules, terms of the platforms used);
- uploads and processes no special category data and no data relating to minors through the Service;
- maintains its own record of processing activities.
The Customer is solely responsible for the lawfulness of the processing it determines and indemnifies XP ONE against any resulting claim.
8. Liability
XP ONE's liability under this addendum is subject to the liability cap set out in the Terms of Service, except where applicable law provides otherwise.
9. Governing law
This addendum is governed by the laws of England and Wales, without prejudice to the mandatory application of GDPR to processing concerning individuals located in the European Union. Exclusive jurisdiction of the courts of England and Wales.
Annex 1 — Authorised sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Database hosting | Frankfurt, EU |
| DigitalOcean | Application hosting | London, UK |
| Stripe | Payment and fraud prevention | EU / United States (SCCs) |
| Sentry | Technical monitoring and error detection | EU / United States (SCCs) |
| Mailjet | Email sending and verification | EU |
| Unipile | Connection to LinkedIn and WhatsApp messaging | EU |
| FullEnrich | Business contact enrichment | EU |
| Checknumber | Phone number verification | EU |
List current as at the date of this document; changes are notified in accordance with clause 4.
Annex 2 — Technical and organisational measures
- Encryption: TLS for all communications; encryption at rest by the hosting provider; irreversibly hashed passwords.
- Access control: signed token authentication, strict data segregation per account, named administrator access limited to a need-to-know basis.
- Logging: traceability of administrative access and sensitive operations.
- Backups: regular database backups with tested restoration.
- Development: code review, automated testing, separate production and test environments, secrets managed outside the source code.
- Sub-processors: a data processing agreement is systematically put in place.
- Incident management: detection, qualification and notification to the Customer within 48 hours.