Effective: 27 September 2026
1. Parties and relation to the Terms of Service
1.1 This data processing agreement (the “Agreement”) is entered into by the customer of the HypeLead service as controller (the “Customer”) and HypeDigitaly s.r.o., company ID (IČO) 17665655, registered office Velká Hradební 2800/54, 400 01 Ústí nad Labem, Czech Republic, as processor (the “Processor”), under Art. 28 of Regulation (EU) 2016/679 (GDPR).
1.2 The Agreement is part of the HypeLead Terms of Service (the “Terms”). The Customer accepts it together with the Terms at sign-up. On the protection of personal data, the Agreement prevails over the Terms.
1.3 If you would like a signed copy of the Agreement, write to info@hypedigitaly.ai. A signed copy has the same content as this version.
1.4 Terms have the meaning given in the GDPR and the Terms.
2. Subject matter, duration, nature and purpose of processing
2.1 The Processor processes personal data on behalf of the Customer to provide it with the HypeLead service (the “Service”), in particular: managing contacts and companies, preparing and sending campaigns from the Customer’s connected accounts, managing replies in one place, preparing message drafts with artificial intelligence, and related support.
2.2 Processing lasts for the term of the Terms and, after they end, until the data is deleted or returned under section 12.
2.3 Details of the processing are in Annex 1.
2.4 This Agreement does not cover processing for which the Processor is an independent controller, in particular finding and enriching lead data, billing, and the security of the Service. These are described in the Privacy Policy (/legal/privacy).
3. Customer instructions
3.1 The Processor processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless EU or Member State law requires the processing. In that case the Processor informs the Customer in advance, unless that law prohibits it.
3.2 The instructions are this Agreement, the Terms, and the actions that the Customer and its users take in the Service. The Processor keeps records of material actions (for example starting a campaign, turning on AI features, approving a send). These records serve as proof of the instructions.
3.3 If, in the Processor’s opinion, an instruction infringes the GDPR or other data protection law, the Processor informs the Customer without undue delay.
4. Customer obligations
4.1 The Customer is responsible for having a valid legal basis for the processing, for obtaining the data lawfully and for informing the data subjects.
4.2 The Customer does not upload or target:
- special categories of personal data under Art. 9 GDPR,
- personal data relating to criminal convictions and offences under Art. 10 GDPR,
- lists of consumers as outreach recipients.
4.3 The Customer completes the privacy notice page for its recipients in the Service before contacting them for the first time.
5. Confidentiality
5.1 The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
5.2 Only persons who need access to personal data to do their job have it.
6. Security
6.1 The Processor takes technical and organisational measures under Art. 32 GDPR. They are described in Annex 2.
6.2 The Processor may change the measures as long as the overall level of protection is not reduced.
7. Sub-processors
7.1 The Customer gives the Processor general written authorisation to engage sub-processors. The current list is on /legal/subprocessors (Annex 3).
7.2 The Processor announces an intended addition or replacement of a sub-processor at least 15 days in advance, by updating the list and by email to Customers who have subscribed to changes.
7.3 Within 15 days of the announcement, the Customer may object on reasonable data protection grounds. The parties will try to find a solution.
7.4 If no solution is possible, the Customer may, within 30 days, terminate the part of the Service affected by the change, or the Terms as a whole. Some sub-processors (for example hosting or the AI gateway) cannot be replaced; in that case the only solution is to end the affected feature or the Service.
7.5 If a sub-processor must be replaced immediately, for example because of an outage or a security risk, the Processor may act at once and announce the change without undue delay. The right to object is not affected.
7.6 The Processor imposes on each sub-processor, by contract, the same data protection obligations it has under this Agreement. The Processor remains liable to the Customer for their performance.
8. Transfers outside the EEA
8.1 The Processor stores personal data in the European Economic Area.
8.2 Where a sub-processor processes data outside the EEA, the Processor ensures appropriate safeguards under Chapter V GDPR: standard contractual clauses (module 3, processor to processor) with a transfer impact assessment, or the EU-US Data Privacy Framework where the recipient is certified.
8.3 If the Customer is established outside the EEA and it is needed, the parties will add further safeguards on request, for example standard contractual clauses module 4.
9. Help with data subject requests
9.1 The Processor helps the Customer meet its obligation to respond to data subject requests. The Service offers tools for export, correction, erasure and adding people to the unsubscribe list.
9.2 If the Processor receives a request that concerns the Customer’s data, it passes it to the Customer without undue delay and does not answer it on the merits itself, unless the Customer authorises it to do so.
10. Personal data breaches
10.1 The Processor notifies the Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware of it.
10.2 The notice contains, as far as known at the time: a description of the breach, the categories and approximate number of people and records concerned, the likely consequences, the measures taken and proposed, and a contact for further information. The Processor adds information that is not yet known as it becomes available.
10.3 The Processor cooperates with the Customer in notifying the authority and informing the people concerned.
11. Impact assessments and cooperation with authorities
11.1 The Processor gives the Customer reasonable help with a data protection impact assessment and with prior consultation of the supervisory authority, taking into account the nature of the processing and the information available to it.
12. Return and deletion at the end
12.1 After the Terms end, the Processor keeps the Customer’s data for 30 days. During that time the Customer can export it (export in CSV format serves as the return of data).
12.2 After the 30 days, the Processor deletes the data. It disappears from backups no later than 30 days after that, when the backups are overwritten.
12.3 After deletion, only data that the law requires to be kept, or that is needed to protect data subjects’ rights, remains: the unsubscribe list and identifier hashes after erasure (so that unsubscribes keep working), audit records (with personal data made unreadable) and records of the Customer’s consents and confirmations.
13. Audits
13.1 The Processor makes available to the Customer the information needed to demonstrate compliance with this Agreement.
13.2 An audit starts in writing: the Customer sends a questionnaire and the Processor answers it within a reasonable time.
13.3 If the written answers are not enough, the Customer or an auditor it appoints, bound by confidentiality, may carry out an on-site audit. The audit must be announced at least 30 days in advance, may be carried out at most once every 12 months (unless there has been a breach or an authority requires it), must not disrupt operations or endanger other customers’ data, and is at the Customer’s cost.
14. Liability
14.1 The parties’ liability is governed by the Terms, including their limits, unless the law provides otherwise.
15. Final provisions
15.1 The Agreement is governed by the law of the Czech Republic.
15.2 If the law changes, the parties will adjust the Agreement as needed. Changes to the Agreement follow the rules for changes to the Terms.
Annex 1 - Details of processing
| Item | Description |
|---|---|
| Data subjects | The Customer’s contacts and prospects, message recipients and senders, the Customer’s users |
| Categories of data | Name, job title, company, work email and phone, public profile link, message and reply content, notes, campaign status, connected account details |
| Special categories | None; uploading them is prohibited |
| Nature of processing | Storage, organisation, search, enrichment, editing, sending, receiving, sorting, generating drafts with artificial intelligence, erasure |
| Purpose | Providing the Service under the Terms and the Customer’s instructions |
| Duration | For the term of the Terms and 30 days after they end, backups a further 30 days |
| Location | EEA (hosting); sub-processors as set out in Annex 3 |
Annex 2 - Technical and organisational measures
- encrypted data transfer (TLS) between the browser, servers and suppliers,
- encrypted storage of access credentials for connected accounts (envelope encryption with the key held separately from the database),
- separation of each customer’s data at database level (row-level security),
- passwords stored with the argon2id algorithm, short-lived access tokens with rotation and reuse detection, limits on login attempts and account lockout after repeated failures, optional two-factor authentication,
- deny by default: every part of the application is closed until we explicitly open it,
- encrypted backups with point-in-time recovery for the last 30 days,
- audit records that cannot be overwritten, with personal data in them erased by making it unreadable,
- removal of passwords, tokens and personal data from system logs and error reports,
- outbound connections from servers routed through a controlled gateway,
- payment cards entered only into a form hosted by Stripe, with no access to the card number,
- speech-to-text on our own servers, with audio deleted right after transcription,
- staff access to data limited to what is necessary,
- a procedure for handling security incidents.
Annex 3 - Sub-processors
The current list of sub-processors, their activities and places of processing is on /legal/subprocessors. The list, as in force at any given time, is part of this Agreement.
Need a signed copy of the agreement? Write to us at info@hypedigitaly.ai.