Between the Customer ("Controller") and LEADSMIND AI LTD, a company incorporated in England and Wales under number 17014114, 167-169 Great Portland Street, London W1W 5PF, United Kingdom ("Processor", "XP ONE").

Processor contact for any question relating to this addendum: contact@xp-one.io

This addendum is entered into under Article 28 of GDPR (EU) 2016/679 and its UK GDPR equivalent. It is accepted together with the Terms of Service and requires no separate signature; a signed copy can be provided on request.

1. Purpose

XP ONE processes personal data on behalf of and on the documented instructions of the Customer, solely for the purpose of performing the Service.

2. Description of the processing

ItemContent
Subject matterProvision of a platform for collecting, organising, enriching and prospecting business contacts
DurationTerm of the subscription, plus 30 days' retention
NatureCollection, structuring, storage, enrichment, consultation, transmission, export, erasure
PurposeThe Customer's B2B commercial prospecting
Categories of data subjectsThe Customer's prospects and business contacts; users designated by the Customer
Categories of dataProfessional identity (first name, last name), job title, employer, public profile URL, business email, business phone, public engagement signals, content of messages sent by the Customer
Special category dataNone. The Customer must not process special categories of data (Article 9 GDPR) or criminal offence data through the Service

3. XP ONE's obligations

XP ONE undertakes to:

  1. process data only on the Customer's documented instructions, including for transfers outside the EU/UK; and inform the Customer if an instruction appears to infringe applicable law;
  2. ensure that persons authorised to process the data are bound by an obligation of confidentiality;
  3. implement the technical and organisational measures set out in Annex 2;
  4. comply with the conditions for engaging sub-processors (clause 4);
  5. assist the Customer, so far as possible, in responding to data subject requests; where a request is addressed to us directly, we forward it to the Customer without delay and do not respond ourselves, unless instructed otherwise;
  6. assist the Customer with data protection impact assessments, prior consultations and security of processing;
  7. notify the Customer without undue delay, and within 48 hours at the latest of becoming aware of it, of any personal data breach, with the information the Customer needs to notify its supervisory authority;
  8. at the Customer's choice expressed at the end of the service, delete or return all data and destroy existing copies, save where retention is legally required. Absent instruction within 30 days of the end of the contract, the data is deleted or anonymised;
  9. make available to the Customer all information necessary to demonstrate compliance and allow for audits, under the conditions of clause 6.

4. Sub-processors

The Customer gives general authorisation for XP ONE to engage the sub-processors listed in Annex 1.

Any addition or replacement is notified to the Customer at least 30 days in advance. The Customer may object on reasonable, documented data protection grounds; failing agreement, the Customer may terminate the subscription without penalty and obtain a pro rata refund of the unused portion of the period paid for.

XP ONE imposes on each sub-processor, by contract, obligations equivalent to those set out here, and remains fully liable for their performance.

5. International transfers

Data is hosted in the United Kingdom and the European Union. EU ↔ UK transfers rely on the European Commission's adequacy decision of 28 June 2021 for the United Kingdom. Any transfer to a non-adequate third country is covered by the standard contractual clauses (SCCs 2021/914) or the UK International Data Transfer Addendum, together with a transfer impact assessment.

6. Audit

The Customer may, at most once a year and on 30 days' written notice, request the documentation evidencing compliance, or arrange an audit by an independent third party bound by confidentiality. Audits take place during business hours, without disrupting operations, at the Customer's cost, unless the audit reveals a material breach.

7. Customer obligations and warranties

The Customer warrants that it:

  1. has a valid lawful basis for each processing operation carried out through the Service, in particular legitimate interests for B2B prospecting, and has carried out the corresponding balancing test;
  2. informs data subjects in accordance with Article 14 GDPR, no later than first contact, including the source of the data;
  3. handles objection requests without delay and removes from its campaigns any person who has objected;
  4. complies with applicable prospecting rules (GDPR, ePrivacy, national rules, terms of the platforms used);
  5. uploads and processes no special category data and no data relating to minors through the Service;
  6. maintains its own record of processing activities.

The Customer is solely responsible for the lawfulness of the processing it determines and indemnifies XP ONE against any resulting claim.

8. Liability

XP ONE's liability under this addendum is subject to the liability cap set out in the Terms of Service, except where applicable law provides otherwise.

9. Governing law

This addendum is governed by the laws of England and Wales, without prejudice to the mandatory application of GDPR to processing concerning individuals located in the European Union. Exclusive jurisdiction of the courts of England and Wales.

Annex 1 — Authorised sub-processors

Sub-processorPurposeLocation
Amazon Web ServicesDatabase hostingFrankfurt, EU
DigitalOceanApplication hostingLondon, UK
StripePayment and fraud preventionEU / United States (SCCs)
SentryTechnical monitoring and error detectionEU / United States (SCCs)
MailjetEmail sending and verificationEU
UnipileConnection to LinkedIn and WhatsApp messagingEU
FullEnrichBusiness contact enrichmentEU
ChecknumberPhone number verificationEU

List current as at the date of this document; changes are notified in accordance with clause 4.

Annex 2 — Technical and organisational measures

  • Encryption: TLS for all communications; encryption at rest by the hosting provider; irreversibly hashed passwords.
  • Access control: signed token authentication, strict data segregation per account, named administrator access limited to a need-to-know basis.
  • Logging: traceability of administrative access and sensitive operations.
  • Backups: regular database backups with tested restoration.
  • Development: code review, automated testing, separate production and test environments, secrets managed outside the source code.
  • Sub-processors: a data processing agreement is systematically put in place.
  • Incident management: detection, qualification and notification to the Customer within 48 hours.