Data Processing Addendum
Effective 5 August 2026
When you put other people’s contact details into Prospexly, you are the controller of that data and we process it for you. This sets out the terms — scope, security, sub-processors, transfers, breach notification and deletion. It applies automatically on every plan, with nothing to request or sign.
1. Scope, and why it applies without you signing anything
This addendum forms part of the Terms of Service and takes effect automatically when you start using the service. There is no separate document to request, countersign and file. It applies to every customer, on every plan, including Free.
That is deliberate. A DPA that only exists once procurement has asked for it protects the customers who knew to ask, which is exactly backwards — the obligations are the same whether or not anyone raised them.
If your organisation requires a countersigned copy on its own paper, write to legal@prospexly.com.
2. Roles of the parties
You are the controller of the personal data you put into the service about other people — contacts you import, leads discovered on your behalf, the people you email, and anything you record about them.
We are the processor of that data. We process it only on your documented instructions, which for these purposes means: the actions you take in the product, the settings you configure, and this addendum.
For your own account data — your name, your email address, your billing record — we are the controller, and the Privacy Policy governs it instead.
3. Subject matter and duration of processing
Subject matter. Providing the Prospexly service: lead discovery, enrichment, CRM storage, email generation, sending and reply detection.
Duration. For as long as your account is open, plus the 30-day recovery window described in section 9.
Categories of data subject. Business contacts and decision-makers at organisations you prospect into, and any other individual whose record you choose to store.
Categories of personal data. Business contact details — first name, last name, job title, work email address, work telephone number, employer, location, professional profile links — along with correspondence you send, engagement events such as opens, clicks and replies, and any notes you write.
Special category data. None is requested and none is required. The product is built for business contact data. Do not upload health data, biometric data, data about criminal convictions, or anything else in a special category; we have not designed the safeguards those categories require.
4. Our obligations
We will:
- Process personal data only on your instructions, unless a law we are subject to requires otherwise, in which case we will tell you before processing unless that law forbids it.
- Ensure that anyone authorised to access personal data is bound by an obligation of confidentiality.
- Implement the technical and organisational measures described in section 6 and on our security page.
- Assist you, so far as we reasonably can, with data subject requests, data protection impact assessments, and consultations with a supervisory authority.
- Make available the information you need to demonstrate our compliance with these obligations.
- Delete or return personal data at the end of the service, as described in section 9.
We will not use your data to train AI models. Content is sent to the AI provider to fulfil the specific request you made and for no other purpose.
5. Your obligations
As controller, you are responsible for:
- Having a lawful basis for the personal data you put into the service and for the use you make of it, including sending email to it.
- Providing whatever privacy information the people in your CRM are entitled to. Discovery results carry the source page each fact came from, which is what lets you tell somebody where their record originated.
- Responding to requests from those people. The export and deletion functions in the product exist so you can do that without needing us.
- Not uploading special category data, and not using the service for automated decision-making with a legal or similarly significant effect on an individual.
6. Security measures
The measures below are the ones this addendum commits us to. The security page explains how each is implemented.
- Tenant isolation enforced twice. Every table carrying customer data has row-level security in the database, and every query in the application also filters on the owning account. Either alone would be a single point of failure.
- Encryption in transit for all connections, and encryption at rest for stored data. Mailbox credentials carry an additional layer of AES-256-GCM application-level encryption and are never returned by any API.
- Access control. Administrative access uses a separate identity system from customer accounts, so compromising a customer session grants no administrative capability.
- Audit logging of administrative actions, including denied ones, with hashed IP addresses.
- Data minimisation in logs. Tokens, keys, passwords and full email bodies are never written to logs. IP addresses are stored only as salted hashes.
7. Sub-processors
You give general authorisation for us to engage the sub-processors below. Each is bound by terms no less protective than this addendum.
- Supabase
- Database, authentication and file storage. Sends the platform's account emails. Account details, and every CRM record you create or import — companies, contacts, opportunities, messages.
- Vercel
- Application hosting, serverless functions and aggregate performance analytics. Request metadata in transit, and page performance measurements that carry no account identifier.
- The Gemini API performs grounded lead discovery, enrichment and email drafting. Google OAuth authorises a Gmail mailbox you choose to connect. The search criteria and the record context you submit for a generation, and — only if you connect a Gmail mailbox — the tokens that let us send on your behalf.
- Microsoft
- OAuth authorisation for a Microsoft 365 mailbox you choose to connect. Mailbox authorisation tokens, only if you connect a Microsoft 365 mailbox.
- Stripe
- Payment processing and subscription billing. Billing email, subscription state and payment metadata. Card numbers are entered directly with Stripe and never reach our servers.
- Upstash
- Redis used for rate limiting and for caching public company facts. Hashed IP addresses for rate limiting, and cached public business facts. No private CRM data is cached.
Before adding or replacing a sub-processor we will give notice in the application. If you reasonably object on data protection grounds, tell us at privacy@prospexly.com within 30 days. If we cannot resolve the objection you may terminate the affected part of the service and receive a refund of the unused prepaid portion.
8. International transfers
Our sub-processors operate globally, so personal data may be transferred outside the UK and the European Economic Area, including to the United States. Each transfer relies on the receiving provider’s Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, or an adequacy decision covering the destination.
Where the Standard Contractual Clauses apply, they are incorporated into this addendum by reference, with you as data exporter and us as data importer.
9. Return and deletion
You can export everything at any time while your account is open: CSV from any list, or a complete JSON and CSV bundle from your settings.
When you close your account, data is soft-deleted and kept recoverable for 30 days. An account closed by mistake is a support request during that window rather than a permanent loss. After 30 days it is permanently deleted, except where law requires us to retain a record — billing, principally — and except for backups, which age out on their own retention cycle and are not used to restore individual records.
If you need deletion sooner than the 30-day window, ask at privacy@prospexly.com and we will action it.
10. Personal data breach
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. The notification will describe what happened, what data was affected, what we have done, and what we recommend you do.
We will not wait for a complete investigation before telling you. A partial notice that arrives in time to be useful is worth more than a complete one that arrives after your own notification deadline has passed.
To report a suspected breach or a vulnerability to us, write to security@prospexly.com.
11. Audits
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this addendum. Where an on-site audit is genuinely required, we will cooperate on scope, timing and confidentiality so that it does not compromise other customers’ data.
12. General
Where this addendum conflicts with the Terms of Service on the subject of personal data, this addendum prevails.
This addendum is governed by the same law as the Terms of Service, and is between you and LKM Software Ltd.
