Data Processing Agreement
1. Parties, scope, and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Use between Sebastien Vautier (professionally known as Sebastien Ricci), a sole proprietor trading as Beyond the Edge Studio, Las Vegas, Nevada, USA (the "Processor", "we"), and the customer organization identified by the account (the "Controller", "you"). It applies to personal data contained in Customer Data that we process on your behalf in providing the Beyond the Edge Lead Engine. You are the controller of Customer Data; we process it only as described here. This DPA is incorporated by reference into the Terms and takes effect automatically for any customer subject to applicable data protection law; no signature is required, and we will provide a countersignable copy on request.
2. Definitions
"Personal data", "processing", "data subject", "supervisory authority", and "personal data breach" have the meanings given by applicable data protection law, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA"). "Customer Data" means the data you bring to or create in the Service, as defined in the Terms. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
3. Details of processing (Annex I)
Subject matter and purpose: hosting and operating a business-to-business outreach platform on your instructions, including storing business contacts, drafting and sending your messages through your own connected inboxes, receiving replies, managing pipeline and tasks, building pages, and administering your client contracts and payments. Nature of processing: collection, storage, organization, retrieval, consultation, use, transmission, restriction, erasure. Duration: the term of the Terms plus the deletion window in Section 11. Frequency: continuous. Categories of data subjects: your leads and business contacts (business owners and their staff), your own users, and your clients who sign contracts. Categories of personal data: business contact details (name, business email address, business telephone number, business postal address), correspondence content including messages you send and replies you receive, notes and ratings your team records, public web-presence information about the business, contract signer details (name, email, signature record reference, network address), and payment references (never card numbers). Special categories of data: none are intended, requested, or should be submitted; the Service is not designed to process them and you must not use it to do so. Competent supervisory authority: determined by your establishment; where the SCCs apply and you have no EU establishment, the authority of the member state of your Article 27 representative or of the data subjects concerned.
4. Your instructions and your responsibilities
We process Customer Data only on your documented instructions: those given through the Service's features, the Terms, and this DPA. We will inform you if, in our opinion, an instruction infringes data protection law, and may suspend that instruction until it is resolved. You are responsible for the lawfulness of the data you bring to the Service, for having a lawful basis for your outreach, for providing any notice the law requires to the people you contact, and for honoring the requests they make to you as controller. The Terms restrict outreach through the Service to recipients in the United States; you remain responsible for compliance wherever your data subjects are located.
5. Confidentiality and personnel
We ensure that every person authorized to process Customer Data is bound by an obligation of confidentiality and accesses Customer Data only as needed to operate and support the Service. Access is limited to the operator of the Service and is exercised through the same role-based controls described in Annex II.
6. Security (Annex II: technical and organizational measures)
We implement the measures below. They describe this system as built, not a generic template. We may improve them but will not materially reduce overall protection during a subscription term.
- Tenant isolation: every organization's records carry an organization identifier, and all access runs through a single audited data-access layer that injects that identifier into every statement, refuses any caller-supplied identifier, and refuses to move a record between organizations. Cross-tenant access is prevented structurally rather than by application checks.
- Encryption in transit: TLS on every connection to the Service and to every provider.
- Encryption at rest for credentials and keys: AES-256-GCM with a random initialization vector per value, keyed by a deployment secret that is never stored with the data. Encrypted values are never returned to any client.
- Authentication: PBKDF2-SHA256 password hashing at 100,000 iterations with a random 128-bit salt and constant-time verification; optional TOTP two-factor authentication; an optional additional workspace passcode.
- Sessions: opaque 256-bit random tokens stored server-side with a 7-day lifetime; the browser holds only an httpOnly, SameSite=Lax cookie, marked Secure over HTTPS. No browser local storage is used.
- Access control: three roles (administrator, manager, agent) enforced on the server on every request; billing and contract administration are restricted to administrators.
- Request integrity: a cross-site request forgery guard on every state-changing request; inbound webhooks rejected unless their cryptographic signature verifies.
- Abuse limiting: sign-in failures limited per address-and-account pair and per account; password reset and signup limited per network address.
- Auditability: an append-only audit log records security-relevant and outreach-relevant actions, including sends, blocks, bounces and opt-outs.
- Outreach safeguards that operators cannot disable: per-inbox volume caps on a rolling window, an enforced randomized interval between sends, permanent organization-wide suppression of opt-outs and hard bounces, one-click unsubscribe headers on every message, and automatic slowing then pausing of an inbox whose complaint rate rises.
- Deletion: an administrator can permanently erase the entire organization after typing the organization name to confirm; the erasure cascades across every organization-scoped table and stored file.
- Infrastructure: physical and network security, redundancy, and platform patching are provided by Cloudflare, whose certifications are published by them.
7. Subprocessors
You give a general authorization for us to engage subprocessors. The current list, what each handles, and where it processes data is published and dated at /legal/subprocessors. We will update that page before a new subprocessor begins handling personal data, and you may subscribe to be notified by writing to us. You may object on reasonable data-protection grounds within 15 days of the update; if we cannot resolve the objection, you may terminate the affected feature or the Terms and receive a pro-rata refund of prepaid fees for the terminated portion. Every subprocessor is bound by written terms no less protective than this DPA, and we remain fully responsible for their performance. Providers you connect yourself, and business-data sources from which we merely retrieve information, are not our subprocessors; the reasons are explained on that page.
8. Assistance with your obligations
Taking into account the nature of the processing, we assist you in fulfilling data subject requests. The Service lets you search and correct contact records, suppress an address permanently so that it is never contacted again, and permanently delete your entire organization, all without our involvement. TWO THINGS ARE NOT YET SELF-SERVICE and we state that rather than implying otherwise: there is no export function, and there is no way to erase one individual contact record while keeping the rest of the workspace. Until both exist we perform them manually on your written request, without charge, within the timescales in Section 8 of the Privacy Policy. Considering the information available to us, we also assist you with security, breach notification, and data protection impact assessments. If we receive a request from a data subject that identifies you, we will promptly forward it and will not respond to it ourselves except to direct the person to you or as required by law, save that we will apply suppression to stop further contact where that is what is asked, because leaving a person to be contacted again while the request is routed would defeat it.
9. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, to the extent that information is available to us, with further information supplied as it becomes known. We will cooperate with your reasonable investigation and remediation. Notification is not an acknowledgement of fault.
10. Audits and information
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits or certifications published by our infrastructure providers. Where applicable law requires an audit right, you or an independent auditor you mandate may audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, without access to any other customer's data or to our credentials, and at your expense, and we may satisfy the request with existing documentation where it reasonably answers the questions asked.
11. Deletion and return
You can request an export at any time during the term and we will provide it manually (see Section 8), and you can permanently delete your organization in-app at any time. On termination of the Terms you may, at your choice, obtain an export on request within 30 days and we will then delete Customer Data from live systems. In-app deletion is immediate in live systems and comprehensive: it removes every organization-scoped record and stored file, and we do not currently hold back billing history, terms-acceptance records or the suppression list from that erasure. You should therefore export anything you are required to keep before deleting. Where a subprocessor holds a copy incidental to its function, deletion follows that provider's own schedule.
12. International transfers
Customer Data is processed in the United States and in the regions used by the subprocessors listed at /legal/subprocessors. Where processing is subject to the GDPR and personal data is transferred to us in the United States, the parties incorporate the SCCs by reference, with MODULE TWO (controller to processor) applying, you as data exporter and us as data importer. The optional docking clause (Clause 7) applies. For Clause 9, OPTION 2 (general written authorization) applies with the 15-day notice period in Section 7 above. For Clause 11, the optional independent dispute-resolution body is NOT selected. For Clause 17, the SCCs are governed by the law of Ireland. For Clause 18(b), the forum is the courts of Ireland. Annex I is Section 3 above, Annex II is Section 6 above, and Annex III is the subprocessor page. For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum (version B1.0) to the SCCs, with Tables 1 to 3 completed by the corresponding information in this DPA and Table 4 selecting neither party as able to end the Addendum on changes. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority read as the Federal Data Protection and Information Commissioner, and the term 'member state' read so that data subjects in Switzerland may enforce their rights in Switzerland. Where a mechanism in this section conflicts with the remainder of this DPA, the mechanism prevails for the transfer it governs.
13. CCPA service-provider terms
To the extent the CCPA applies, we act as your "service provider". We will not sell or share Customer Data, will not retain, use, or disclose it for any purpose other than performing the services specified in the Terms or as otherwise permitted by the CCPA, will not retain, use, or disclose it outside the direct business relationship between us, and will not combine it with personal information from other sources except as the CCPA permits. We certify that we understand these restrictions and will comply with them. We will notify you if we determine we can no longer meet our obligations, and you may take reasonable steps to stop and remediate unauthorized use.
14. Liability, precedence, and term
Each party's liability under this DPA is subject to the limitations of liability in the Terms, except where applicable data protection law does not permit that limitation. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls; if the SCCs conflict with this DPA, the SCCs control for the transfer they govern. This DPA is governed by the same law and dispute terms as the Terms, except where Section 12 specifies otherwise for the clauses it incorporates. This DPA takes effect when you accept the Terms and continues for as long as we process Customer Data on your behalf.