Data Processing Agreement
Last updated
This agreement is part of the Terms of Service between you, the customer, and Joan Gumban, a sole trader in Davao City 8000, Philippines, trading as Galactic Outreach ("we"). You accept it with the Terms. It applies whenever we process personal data on your behalf, under the EU GDPR or the UK GDPR, in providing the service.
Roles
For the data in your campaigns you are the controller and we are your processor. For your own account details we are the controller, and the Privacy Policy covers those instead.
What is processed
- Subject and duration: providing the service, for as long as your account exists.
- Nature and purpose: collecting business contact details from public sources when you run a lead search, storing and organising them, writing the emails you configure, sending them through the email provider you connect, and recording what happens to them.
- Personal data: business email addresses; names and roles where a business publishes them; company, website, phone number, city and country; the emails written to each person; and their delivery events, bounces, complaints, opens, clicks and unsubscribes.
- Data subjects: people at the businesses your campaigns find, contact or decide not to contact.
What we commit to
- We process the data only on your documented instructions: the Terms, this agreement and what you set in the dashboard. If an instruction appears to us to break data protection law, we will tell you.
- Only Joan Gumban has access to the data. Anyone given access in future will first be bound to confidentiality.
- We keep the measures below in place, and improve them as the risk requires.
- We help you answer requests from the people in your campaigns. The dashboard lets you export, correct and erase their data and add them to the do-not-contact list; for anything it cannot do, write to us.
- We help you with security, breach notification and any impact assessment, as far as the nature of the processing allows.
- We tell you of a personal data breach affecting your data without undue delay, and within 48 hours of becoming aware of it, with what we know at the time.
- When your account is closed, we delete your campaign data: the database records, the files on the server and your provider keys. You can export it first. Copies in the database host's backups are deleted as those backups expire.
- We give you the information you need to show that this agreement is kept, answer written questions about it, and allow an audit by an auditor you appoint, at your cost, on reasonable notice, once a year or when a supervisory authority requires it.
Security measures
- All traffic is encrypted in transit (HTTPS).
- Each customer's data is separated in the database by row-level security, so one account cannot read another's.
- Email provider keys are held in Supabase Vault, not in the application database.
- The data is stored in the EU, in Germany.
- Production access is limited to the operator.
- Anyone who unsubscribes is suppressed automatically, and so is anyone who bounces or complains once your provider's webhook is connected.
Sub-processors
You authorise us to use the sub-processors below. Each is bound by data protection terms at least as protective as these, including a lawful transfer mechanism where it handles data outside the EU. We will tell you by email 30 days before adding or replacing one. You may object; if we cannot resolve the objection, you may close your account.
- Hetzner Online GmbH: the server the application runs on, in Germany.
- Supabase: the database, in Frankfurt.
- Cloudflare: the network every request passes through on its way to the server.
- Resend: the emails we send you ourselves, such as a run report, which can name the addresses in that run.
The email provider you connect (Resend, Amazon SES, Mailgun or SendGrid) is not our sub-processor. You choose it and hold the account, so it processes the data for you directly, under your own agreement with it.
Transfers outside the EU
The data is stored in Germany, but we run the service from the Philippines, which has no adequacy decision from the European Commission. Our access to the data is therefore a transfer. For it, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, controller to processor, are incorporated into this agreement, with you as data exporter and us as data importer:
- Clause 7, the docking clause, does not apply.
- Clause 9: option 2, general written authorisation, with the 30 days' notice above.
- Clause 11: the optional redress wording does not apply.
- Clause 13: the supervisory authority of the EU country where you are established, or where your representative is.
- Clauses 17 and 18: the law and the courts of Ireland.
- Annexes I, II and III are the sections above: what is processed, the security measures, and the sub-processors.
For data subject to the UK GDPR, the UK's International Data Transfer Addendum to those clauses applies as well. If the clauses conflict with anything else in this agreement or the Terms, the clauses win.
Everything else
Liability under this agreement is subject to the limits in the Terms. If this agreement and the Terms conflict on data protection, this agreement wins. For a signed copy, write to hello@galacticoutreach.com.
Questions about this page: hello@galacticoutreach.com