Data Processing Agreement

Beyond the Edge Lead Engine · Version 2026-08-04.v2-beta

1. Parties, scope, and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Use between Sebastien Vautier (professionally known as Sebastien Ricci), a sole proprietor trading as Beyond the Edge Studio, Las Vegas, Nevada, USA (the "Processor", "we"), and the customer organization identified by the account (the "Controller", "you"). It applies to personal data contained in Customer Data that we process on your behalf in providing the Beyond the Edge Lead Engine. You are the controller of Customer Data; we process it only as described here. This DPA is incorporated by reference into the Terms and takes effect automatically for any customer subject to applicable data protection law; no signature is required, and we will provide a countersignable copy on request.

2. Definitions

"Personal data", "processing", "data subject", "supervisory authority", and "personal data breach" have the meanings given by applicable data protection law, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA"). "Customer Data" means the data you bring to or create in the Service, as defined in the Terms. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

3. Details of processing (Annex I)

Subject matter and purpose: hosting and operating a business-to-business outreach platform on your instructions, including storing business contacts, drafting and sending your messages through your own connected inboxes, receiving replies, managing pipeline and tasks, building pages, and administering your client contracts and payments. Nature of processing: collection, storage, organization, retrieval, consultation, use, transmission, restriction, erasure. Duration: the term of the Terms plus the deletion window in Section 11. Frequency: continuous. Categories of data subjects: your leads and business contacts (business owners and their staff), your own users, and your clients who sign contracts. Categories of personal data: business contact details (name, business email address, business telephone number, business postal address), correspondence content including messages you send and replies you receive, notes and ratings your team records, public web-presence information about the business, contract signer details (name, email, signature record reference, network address), and payment references (never card numbers). Special categories of data: none are intended, requested, or should be submitted; the Service is not designed to process them and you must not use it to do so. Competent supervisory authority: determined by your establishment; where the SCCs apply and you have no EU establishment, the authority of the member state of your Article 27 representative or of the data subjects concerned.

4. Your instructions and your responsibilities

We process Customer Data only on your documented instructions: those given through the Service's features, the Terms, and this DPA. We will inform you if, in our opinion, an instruction infringes data protection law, and may suspend that instruction until it is resolved. You are responsible for the lawfulness of the data you bring to the Service, for having a lawful basis for your outreach, for providing any notice the law requires to the people you contact, and for honoring the requests they make to you as controller. The Terms restrict outreach through the Service to recipients in the United States; you remain responsible for compliance wherever your data subjects are located.

5. Confidentiality and personnel

We ensure that every person authorized to process Customer Data is bound by an obligation of confidentiality and accesses Customer Data only as needed to operate and support the Service. Access is limited to the operator of the Service and is exercised through the same role-based controls described in Annex II.

6. Security (Annex II: technical and organizational measures)

We implement the measures below. They describe this system as built, not a generic template. We may improve them but will not materially reduce overall protection during a subscription term.

7. Subprocessors

You give a general authorization for us to engage subprocessors. The current list, what each handles, and where it processes data is published and dated at /legal/subprocessors. We will update that page before a new subprocessor begins handling personal data, and you may subscribe to be notified by writing to us. You may object on reasonable data-protection grounds within 15 days of the update; if we cannot resolve the objection, you may terminate the affected feature or the Terms and receive a pro-rata refund of prepaid fees for the terminated portion. Every subprocessor is bound by written terms no less protective than this DPA, and we remain fully responsible for their performance. Providers you connect yourself, and business-data sources from which we merely retrieve information, are not our subprocessors; the reasons are explained on that page.

8. Assistance with your obligations

Taking into account the nature of the processing, we assist you in fulfilling data subject requests. The Service lets you search and correct contact records, suppress an address permanently so that it is never contacted again, and permanently delete your entire organization, all without our involvement. TWO THINGS ARE NOT YET SELF-SERVICE and we state that rather than implying otherwise: there is no export function, and there is no way to erase one individual contact record while keeping the rest of the workspace. Until both exist we perform them manually on your written request, without charge, within the timescales in Section 8 of the Privacy Policy. Considering the information available to us, we also assist you with security, breach notification, and data protection impact assessments. If we receive a request from a data subject that identifies you, we will promptly forward it and will not respond to it ourselves except to direct the person to you or as required by law, save that we will apply suppression to stop further contact where that is what is asked, because leaving a person to be contacted again while the request is routed would defeat it.

9. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, to the extent that information is available to us, with further information supplied as it becomes known. We will cooperate with your reasonable investigation and remediation. Notification is not an acknowledgement of fault.

10. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits or certifications published by our infrastructure providers. Where applicable law requires an audit right, you or an independent auditor you mandate may audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, without access to any other customer's data or to our credentials, and at your expense, and we may satisfy the request with existing documentation where it reasonably answers the questions asked.

11. Deletion and return

You can request an export at any time during the term and we will provide it manually (see Section 8), and you can permanently delete your organization in-app at any time. On termination of the Terms you may, at your choice, obtain an export on request within 30 days and we will then delete Customer Data from live systems. In-app deletion is immediate in live systems and comprehensive: it removes every organization-scoped record and stored file, and we do not currently hold back billing history, terms-acceptance records or the suppression list from that erasure. You should therefore export anything you are required to keep before deleting. Where a subprocessor holds a copy incidental to its function, deletion follows that provider's own schedule.

12. International transfers

Customer Data is processed in the United States and in the regions used by the subprocessors listed at /legal/subprocessors. Where processing is subject to the GDPR and personal data is transferred to us in the United States, the parties incorporate the SCCs by reference, with MODULE TWO (controller to processor) applying, you as data exporter and us as data importer. The optional docking clause (Clause 7) applies. For Clause 9, OPTION 2 (general written authorization) applies with the 15-day notice period in Section 7 above. For Clause 11, the optional independent dispute-resolution body is NOT selected. For Clause 17, the SCCs are governed by the law of Ireland. For Clause 18(b), the forum is the courts of Ireland. Annex I is Section 3 above, Annex II is Section 6 above, and Annex III is the subprocessor page. For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum (version B1.0) to the SCCs, with Tables 1 to 3 completed by the corresponding information in this DPA and Table 4 selecting neither party as able to end the Addendum on changes. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority read as the Federal Data Protection and Information Commissioner, and the term 'member state' read so that data subjects in Switzerland may enforce their rights in Switzerland. Where a mechanism in this section conflicts with the remainder of this DPA, the mechanism prevails for the transfer it governs.

13. CCPA service-provider terms

To the extent the CCPA applies, we act as your "service provider". We will not sell or share Customer Data, will not retain, use, or disclose it for any purpose other than performing the services specified in the Terms or as otherwise permitted by the CCPA, will not retain, use, or disclose it outside the direct business relationship between us, and will not combine it with personal information from other sources except as the CCPA permits. We certify that we understand these restrictions and will comply with them. We will notify you if we determine we can no longer meet our obligations, and you may take reasonable steps to stop and remediate unauthorized use.

14. Liability, precedence, and term

Each party's liability under this DPA is subject to the limitations of liability in the Terms, except where applicable data protection law does not permit that limitation. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls; if the SCCs conflict with this DPA, the SCCs control for the transfer they govern. This DPA is governed by the same law and dispute terms as the Terms, except where Section 12 specifies otherwise for the clauses it incorporates. This DPA takes effect when you accept the Terms and continues for as long as we process Customer Data on your behalf.