Data Processing Agreement
Version dated July 26, 2026
This agreement applies only where SprintLead processes personal data on the customer’s documented instructions. It does not classify SprintLead as a processor for processing whose purposes and means SprintLead determines itself.
1. Role matrix
SprintLead is a controller for account management, security, billing, fraud prevention, its global suppression list, its choice and governance of sources, and product data it creates for its own purposes. It is a processor for customer imports, CRM notes, campaigns, and messages processed exclusively on customer instructions. When a customer reuses data supplied by SprintLead for its own outreach, the parties generally act as independent controllers unless they jointly document the relevant purposes and means.
2. Subject matter, duration and instructions
Processor operations cover the account lifetime and hosting customer imports and notes, preparing content, technically executing approved campaigns, and requested Gmail functions. Gmail sending uses gmail.send only in a contractually permitted mode. Automatic reply tracking requires a separate gmail.readonly grant and remains unavailable to public users pending Google verification. SprintLead processes this data only on documented instructions unless law requires otherwise.
3. Article 28 schedule — data and people
Data subjects are customer users, prospects, business contacts and customers. Data categories include identity, role, contact details, company, location, imports, notes, messages, replies, objections, relationship history and technical data. Operations include collection on instruction, structuring, hosting, access, generation, transmission, logging, restriction and deletion. The purpose is the customer’s lawful B2B CRM and outreach. Processing lasts for the account term and the deletion period below. Sensitive data must not be imported or used for outreach.
4. SprintLead’s obligations
SprintLead binds authorized personnel to confidentiality, applies appropriate security measures, assists the customer with data-subject requests, impact assessments and required consultations, notifies breaches without undue delay after becoming aware of them, and keeps information needed to demonstrate compliance with this agreement.
5. Security
Measures include encryption in transit, encryption of Gmail tokens at rest, organization-scoped access controls, least privilege, logging of sensitive operations, sending limits, deletion controls and protected backups. The customer remains responsible for its accounts, recipients and access configuration.
6. Subprocessors and transfers
The customer authorizes providers needed for the service, including Vercel, Supabase, Google, OpenAI, Stripe, Resend and Inngest when used. SprintLead contractually governs them and provides advance notice of a material change so the customer can raise a reasoned objection. Each international transfer mechanism must be verified and documented; this clause is not by itself a transfer safeguard.
7. Return and deletion
At the end of the service or on the customer’s lawful instruction, SprintLead returns or deletes data processed on the customer’s behalf, then destroys copies, except where retention is required by law, needed for security, or necessary for a minimal suppression record. Backup data remains isolated until documented rotation.
8. Information and audit
On reasonable request, SprintLead provides available compliance information and permits audits required by Article 28. A routine additional audit may be arranged once a year, but that limit does not apply after an incident, on documented concern, or at an authority’s request. Notice, confidentiality and scope must remain proportionate.
9. Customer responsibilities
The customer determines a legal basis, complies with the recipient country’s rules and channel conditions, provides required information, ensures outreach relevance, handles rights requests and objections, and ensures its instructions are lawful. SprintLead informs the customer if an instruction appears to breach applicable law.
10. Priority and governing law
For processor operations, this agreement prevails over the general terms. It is governed by French law, without limiting mandatory powers and venues provided by the GDPR.