Data Processing Agreement
Last updated: June 1, 2025
Who this applies to: This DPA applies to business users who process personal data of third parties (e.g. prospects) through LeadScry in the context of GDPR. If you are an individual user researching leads for your own outreach, the standard Privacy Policy applies.
1. Definitions
2. Nature and purpose of processing
The Processor processes personal data on behalf of the Controller for the following purpose:
- →Generating AI-powered lead intelligence reports based on publicly available data about named individuals and companies
- →Storing analysis results in the Controller's account for retrieval and reference
- →Running targeted web searches using prospect identifiers provided by the Controller
3. Types of personal data processed
- →Names of individuals (prospects)
- →Professional information (job titles, company affiliation)
- →Online identifiers (website URLs, LinkedIn profile URLs, social handles)
- →Publicly available professional activity (hiring signals, publications, funding news)
LeadScry does not process special category data (health, biometric, financial, or protected category information) and must not be used for such purposes.
4. Obligations of the Processor
OIBL Group (as Processor) agrees to:
- →Process personal data only on documented instructions from the Controller
- →Ensure persons authorised to process personal data are bound by confidentiality obligations
- →Implement appropriate technical and organisational security measures (Article 32 GDPR)
- →Not engage sub-processors without prior written authorisation from the Controller (general authorisation is deemed given by accepting these terms for the sub-processors listed in Section 6)
- →Assist the Controller in responding to data subject rights requests
- →Delete or return all personal data upon termination of the service relationship
- →Provide all information necessary to demonstrate compliance with GDPR obligations
5. Obligations of the Controller
The Controller agrees to:
- →Ensure a lawful basis exists for processing prospect personal data through LeadScry (e.g. legitimate interests under GDPR Article 6(1)(f))
- →Provide prospects with appropriate privacy notices where required
- →Use LeadScry only for the purposes described in these terms
- →Not instruct the Processor to process personal data in a way that would violate applicable law
6. Sub-processors
The Processor uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | EU (AWS) |
| Groq | AI model inference | USA |
| Vercel | Application hosting | Global (Edge) |
| Serper.dev | Google search API | USA |
For transfers to the USA, appropriate safeguards (Standard Contractual Clauses or equivalent) are in place where required.
7. Security measures
Technical and organisational measures include: TLS encryption in transit, AES-256 encryption at rest, row-level security on all database tables, role-based access controls, and regular security reviews.
8. Data breach notification
In the event of a personal data breach, the Processor will notify the Controller without undue delay — and in any case within 72 hours of becoming aware of the breach — where the breach is likely to result in a risk to data subjects.
9. Termination and deletion
Upon termination of the service relationship, the Processor will delete all personal data processed on behalf of the Controller within 30 days, unless required to retain it by applicable law.
10. Governing law
This DPA is governed by the laws of England and Wales, consistent with the main Terms of Service.
11. Contact
To request a signed DPA or for GDPR enquiries: leadscry@gmail.com
This DPA framework should be reviewed and executed with the assistance of a qualified legal professional before use in a regulated context.