Our data protection agreement with you — covering both the processor relationship for the data you place into Fullinfo, and the joint controllership for data we serve from our database.
Version 1.0 · Effective May 2026
Between Fullinfo B.V. and you, the Customer. Version 1.0. Effective when you sign up. Last updated: May 2026.
This Data Processing Agreement ("DPA") sets out how Fullinfo B.V. ("Fullinfo," "we," "us") and the Customer ("you") handle personal data in connection with your use of the Fullinfo service.
The Fullinfo Master Subscription Agreement (MSA) is the broader contract between us. The DPA is the data-protection-specific part of that contract. If anything in the MSA conflicts with the DPA on a data protection question, the DPA wins. For everything else, the MSA wins.
This DPA gives effect to:
Fullinfo plays three distinct roles depending on which data is moving and why.
1. Controller (sole) of the Fullinfo database. We collect, structure, enrich, and maintain the contact and organization records in our database from open-web sources. We decide what to collect, how to organize, and how long to keep it. This is our product. We act under our own legitimate-interest legal basis. Our Privacy Policy describes the details.
2. Joint controller with you (briefly, at disclosure). When one of your Users queries our service and we serve back personal data records, we become joint controllers with you for that disclosure event. The disclosure is to you as an organization, not to the individual User. Sharing the disclosed records within your organization through shared Collections does not create a further disclosure event. Once records are in your systems outside Fullinfo, you become the sole controller. Article 26 GDPR governs this arrangement. Section 4 of this DPA sets out the specifics.
3. Processor for you (continuously, for your Customer Data). The personal data you place into Fullinfo on your own behalf — User account information (names, emails, IP addresses, login activity), search queries your Users run, notes you add against records, Collections you create and curate, configuration choices, exports you trigger — is Customer Data. You are the controller of Customer Data. We process it on your documented instructions. Article 28 GDPR governs this arrangement. Section 5 of this DPA sets out the specifics.
Terms used here have the meanings given in the GDPR unless defined otherwise. Specifically:
This section governs the brief joint controller relationship that exists at the moment Fullinfo discloses personal data from our database to you, in response to a query or as part of an active monitoring update on a Collection.
Fullinfo:
Customer:
A data subject can exercise their rights with either party. We will coordinate as follows:
Data subjects may exercise their rights with either party. To make this practical, we publish a single contact point at https://fullinfo.com/data-request/ for any rights related to data in the Fullinfo database. Where a request involves data the Customer holds outside Fullinfo, we will direct the data subject to the Customer where appropriate.
If a supervisory authority contacts either of us about disclosure events between us, we will inform the other party promptly and cooperate in good faith on a unified response. Each party remains responsible for its own compliance.
This section governs the processor relationship that exists continuously while you use Fullinfo.
We process Customer Data to provide the Fullinfo service to you, as described in the MSA and your Order Form. Processing lasts for the duration of your subscription, plus the post-termination period set out in Section 5.10 below.
We process Customer Data for the following purposes:
We will not use Customer Data for our own marketing, for training general-purpose AI models, or for any purpose beyond providing the service to you.
Categories of personal data we process as your processor:
Categories of data subjects:
This list does not include data subjects who exist in the Fullinfo database — those are processed under our own controller basis, not as your processor.
You instruct us to process Customer Data:
If we believe an instruction violates applicable law, we will tell you and may decline to act on it until the issue is resolved.
Our personnel who process Customer Data are bound by written confidentiality obligations or are subject to professional confidentiality obligations under applicable law. They process Customer Data only on documented instructions from you (through your use of the service or otherwise).
We implement appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The current measures are set out in Annex 2 (Technical and Organisational Measures). We may update them as needed to reflect changes in risk, technology, or operations; we will not reduce the overall level of protection.
You give us general authorization to engage sub-processors to provide the service. The current list of sub-processors is in Annex 1.
When we plan to add or replace a sub-processor, we will notify you in writing at least 30 days in advance, identifying the new sub-processor and what it will do. The notification will be sent to the Admin's email address on file.
You may object to a proposed sub-processor in writing, with substantiated reasoning, within 14 days of the notification. If we cannot reasonably accommodate your objection, you may terminate your subscription with effect from the date the new sub-processor begins processing. Termination on this basis is treated equivalently to termination for cause by you under MSA Section 10.3, including pro-rata refund of any unused term.
We require each sub-processor to be bound by data protection obligations no less protective than those in this DPA, by a written contract.
If a sub-processor is located outside the European Economic Area (EEA) and the country has not received a European Commission adequacy decision, we ensure an appropriate transfer mechanism is in place — typically the 2021 Standard Contractual Clauses (SCCs) combined with supplementary measures as needed.
Annex 1 identifies which sub-processors involve transfers and which mechanism applies.
If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notification will include, to the extent then known:
We will provide updates as the investigation progresses and reasonable assistance to you in your own notification obligations to supervisory authorities and data subjects.
When your subscription ends:
We maintain records of our processing activities as required by Article 30 GDPR. On reasonable request, we will provide you with the information you need to maintain your own records.
To the extent you are unable to fulfil a data subject's request using the self-service tools in the Fullinfo product, we will provide reasonable assistance — taking into account the nature of the processing — so that you can respond within the GDPR-required timeframes. Examples include providing data extracts, deletions on your behalf, or technical clarifications.
Once per year (or more often if required by a supervisory authority or after a breach), you may request information necessary to demonstrate our compliance with this DPA. We will respond within 30 days with documentation, reports, or written answers.
If you reasonably believe the documentation we provide is not sufficient, you may request an audit. Audits are conducted with at least 60 days' notice, during business hours, at your expense, and may not unreasonably disrupt our operations or compromise the data of other customers. Audit findings are confidential.
We may satisfy audit requests by providing third-party certifications (such as ISO 27001 or SOC 2) where available.
If a supervisory authority contacts us regarding our processing of Customer Data on your behalf, we will inform you promptly (unless legally prohibited from doing so) and cooperate as required by GDPR.
The MSA's liability provisions apply, with the data-protection-specific cap set out in MSA Section 9.
Where joint and several liability is required by law (for example, under Article 82 GDPR for damages to data subjects), each party is liable as required by law and may seek contribution from the other party for the portion of damages attributable to the other party's fault.
We may update this DPA from time to time. For material changes — changes that adversely affect your rights or our processing obligations — we will provide at least 30 days' notice. You may object to material changes by notifying us; if we cannot reasonably accommodate the objection, you may terminate your subscription as described in MSA Section 10.
For non-material changes (clarifications, factual updates to sub-processor lists, security measure improvements), notice is not required, but we will keep the current version available at https://fullinfo.com/dpa/ and note the date of the most recent update.
This DPA is effective for the duration of the MSA. It survives termination of the MSA to the extent necessary to complete final data return or deletion, to respond to data subject requests in flight, or to cooperate with supervisory authorities on matters arising during the subscription.
For any matter relating to this DPA, contact privacy@fullinfo.com.
The following sub-processors process Customer Data on Fullinfo's behalf. We may update this list as described in Section 5.7.
| Sub-processor | Role | Location of processing | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | Frankfurt (EU) and Ohio (US) | EU: none required. US: 2021 SCCs |
| Google (Gemini API) | AI and machine learning processing for enrichment, entity resolution, and search ranking | EU and US | 2021 SCCs where applicable |
| Google Workspace | Email, document collaboration, and productivity for Fullinfo personnel | EU and US | 2021 SCCs |
| Auth0 (Okta, Inc.) | Authentication, identity, and session management | EU and US | 2021 SCCs |
| Atlassian (Jira) | Internal product engineering, support ticketing | EU and US | 2021 SCCs |
| Slack Technologies | Internal communications, including support-related communications about Customer accounts | US | 2021 SCCs |
Last updated: May 2026.
The current authoritative list is at https://fullinfo.com/dpa/. To be notified of changes to this list, email privacy@fullinfo.com.
The following measures describe the controls Fullinfo applies to protect Customer Data. We update them as risk, technology, and operations evolve; we will not reduce the overall protection level.
Last updated: May 2026.