Legal

Data Processing Agreement

Our data protection agreement with you — covering both the processor relationship for the data you place into Fullinfo, and the joint controllership for data we serve from our database.

Version 1.0 · Effective May 2026

Important

This is Fullinfo’s standard Data Processing Agreement, published for transparency. When you become a Fullinfo customer, the binding DPA is the version attached to your signed Order Form. The Master Subscription Agreement is at /msa.

Joint controllership for disclosure events (Article 26)

This section governs the brief joint controller relationship that exists at the moment Fullinfo discloses personal data from our database to you, in response to a query or as part of an active monitoring update on a Collection.

4.1 Each party's responsibilities

Fullinfo:

  • Provides the legitimate-interest basis for the existence of the Fullinfo database, as set out in our Privacy Policy
  • Provides the suppression mechanism and erasure-cascade so that data subjects who exercise their right of erasure are removed from our database and from all Customer Collections
  • Provides transparency on our data sources and processing in the Privacy Policy
  • Handles data subject requests that come directly to us, with notification to the Customer where the Customer's Collection is affected

Customer:

  • Confirms a lawful basis for the use it makes of records received from Fullinfo (typically legitimate interest for B2B outreach)
  • Honours opt-outs, unsubscribes, and removal requests received directly from data subjects the Customer has contacted
  • Provides transparency to data subjects about where their information came from, where required
  • Complies with applicable anti-spam and outreach laws in the jurisdictions where Customer operates

4.2 Data subject rights

A data subject can exercise their rights with either party. We will coordinate as follows:

  • If a data subject asks Fullinfo to be removed from our database, we remove them from the database, add them to our permanent suppression list, remove them from every Customer Collection containing them, and notify affected Customers (per MSA Section 7).
  • If a data subject asks you to be removed from your systems, you are responsible for handling that request in your systems. If the request also implicates removal from the Fullinfo database, forward the request to privacy@fullinfo.com.
  • We will both respond to access, rectification, restriction, portability, and objection requests within the GDPR-required timeframes (one month, extendable by two months for complex requests).

4.3 Single point of contact

Data subjects may exercise their rights with either party. To make this practical, we publish a single contact point at https://fullinfo.com/data-request/ for any rights related to data in the Fullinfo database. Where a request involves data the Customer holds outside Fullinfo, we will direct the data subject to the Customer where appropriate.

4.4 Regulator inquiries

If a supervisory authority contacts either of us about disclosure events between us, we will inform the other party promptly and cooperate in good faith on a unified response. Each party remains responsible for its own compliance.

Processor relationship for Customer Data (Article 28)

This section governs the processor relationship that exists continuously while you use Fullinfo.

5.1 Subject matter and duration

We process Customer Data to provide the Fullinfo service to you, as described in the MSA and your Order Form. Processing lasts for the duration of your subscription, plus the post-termination period set out in Section 5.10 below.

5.2 Nature and purpose

We process Customer Data for the following purposes:

  • Operating your account (authentication, authorization, session management)
  • Storing and retrieving the Collections, notes, search history, queries, and configuration you create
  • Supporting the active monitoring of contacts and organizations you have added to Collections
  • Delivering the service features described in the MSA, including notifications, exports, and integrations you enable
  • Providing support to your Users when they contact us
  • Generating usage analytics for your own Admin's view of how your team uses the service

We will not use Customer Data for our own marketing, for training general-purpose AI models, or for any purpose beyond providing the service to you.

5.3 Categories of personal data and data subjects

Categories of personal data we process as your processor:

  • User identifiers (name, email address, employer)
  • Authentication data (hashed credentials, session tokens, IP addresses, browser metadata)
  • Activity data (login times, queries run, records viewed, Collections accessed, actions taken)
  • Content you create (notes, custom fields, comments)
  • Communications between you and Fullinfo Support

Categories of data subjects:

  • Your Users (the individuals at your organization who hold seats)
  • Individuals the Customer references in its notes or custom fields

This list does not include data subjects who exist in the Fullinfo database — those are processed under our own controller basis, not as your processor.

5.4 Customer instructions

You instruct us to process Customer Data:

  • In accordance with the MSA, your Order Form, and any reasonable written instructions you provide
  • For the purposes set out in Section 5.2 above
  • In line with applicable data protection law

If we believe an instruction violates applicable law, we will tell you and may decline to act on it until the issue is resolved.

5.5 Confidentiality

Our personnel who process Customer Data are bound by written confidentiality obligations or are subject to professional confidentiality obligations under applicable law. They process Customer Data only on documented instructions from you (through your use of the service or otherwise).

5.6 Security measures

We implement appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The current measures are set out in Annex 2 (Technical and Organisational Measures). We may update them as needed to reflect changes in risk, technology, or operations; we will not reduce the overall level of protection.

5.7 Sub-processors

You give us general authorization to engage sub-processors to provide the service. The current list of sub-processors is in Annex 1.

When we plan to add or replace a sub-processor, we will notify you in writing at least 30 days in advance, identifying the new sub-processor and what it will do. The notification will be sent to the Admin's email address on file.

You may object to a proposed sub-processor in writing, with substantiated reasoning, within 14 days of the notification. If we cannot reasonably accommodate your objection, you may terminate your subscription with effect from the date the new sub-processor begins processing. Termination on this basis is treated equivalently to termination for cause by you under MSA Section 10.3, including pro-rata refund of any unused term.

We require each sub-processor to be bound by data protection obligations no less protective than those in this DPA, by a written contract.

5.8 International transfers

If a sub-processor is located outside the European Economic Area (EEA) and the country has not received a European Commission adequacy decision, we ensure an appropriate transfer mechanism is in place — typically the 2021 Standard Contractual Clauses (SCCs) combined with supplementary measures as needed.

Annex 1 identifies which sub-processors involve transfers and which mechanism applies.

5.9 Data breach notification

If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notification will include, to the extent then known:

  • The nature of the breach
  • The categories and approximate number of data subjects and records concerned
  • The likely consequences
  • The measures we have taken or propose to take to address the breach and mitigate its effects
  • A contact point for further information

We will provide updates as the investigation progresses and reasonable assistance to you in your own notification obligations to supervisory authorities and data subjects.

5.10 Return and deletion at end of processing

When your subscription ends:

  • We follow the post-termination data handling described in MSA Section 10 (a reactivation grace period during which Collections and Customer Data remain intact, followed by progressive deletion if you do not reactivate)
  • On your written request, we will return Customer Data to you in a commonly used machine-readable format, or delete it, within 30 days
  • We may retain Customer Data after this period only to the extent and for the period required by applicable law, and in that case we will continue to apply the protections of this DPA to the retained data

5.11 Records of processing

We maintain records of our processing activities as required by Article 30 GDPR. On reasonable request, we will provide you with the information you need to maintain your own records.

5.12 Data subject rights assistance

To the extent you are unable to fulfil a data subject's request using the self-service tools in the Fullinfo product, we will provide reasonable assistance — taking into account the nature of the processing — so that you can respond within the GDPR-required timeframes. Examples include providing data extracts, deletions on your behalf, or technical clarifications.

5.13 Audits

Once per year (or more often if required by a supervisory authority or after a breach), you may request information necessary to demonstrate our compliance with this DPA. We will respond within 30 days with documentation, reports, or written answers.

If you reasonably believe the documentation we provide is not sufficient, you may request an audit. Audits are conducted with at least 60 days' notice, during business hours, at your expense, and may not unreasonably disrupt our operations or compromise the data of other customers. Audit findings are confidential.

We may satisfy audit requests by providing third-party certifications (such as ISO 27001 or SOC 2) where available.

5.14 Cooperation with supervisory authorities

If a supervisory authority contacts us regarding our processing of Customer Data on your behalf, we will inform you promptly (unless legally prohibited from doing so) and cooperate as required by GDPR.