Data Processing Agreement
How Sequenz processes personal data for you as your processor under the GDPR: the terms, security measures, sub-processors and international-transfer safeguards for the lead and prospect data in your workspace.
On this page
This Data Processing Agreement forms part of, and is incorporated into, the Terms of Service between:
- Sequenz Ltd (company number 17499883, registered in England and Wales; registered office 128 City Road, London, EC1V 2NX, United Kingdom) — the Processor ("we", "us"); and
- the Customer organisation that accepts it — the Controller ("you").
Effective date: the date you accept it in-app (the signing/acceptance flow is described in Section 13 and surfaced on our DPA page). Version: 1.5.3
This DPA governs our processing of personal data within your Customer Data on your behalf, under Article 28 of the GDPR. Where it conflicts with the Terms of Service on data-protection matters, this DPA prevails.
1.Roles
1.1 For the lead/prospect personal data you process through the Service, you are the Controller and we are the Processor. You determine the purposes and means; we act only on your documented instructions.
1.2 For the personal data of your own account holders and users, we act as Controller under our Privacy Policy — that data is outside the scope of this DPA.
1.3 You warrant that you have a lawful basis for the processing you instruct (typically Art. 6(1)(f) legitimate interests for B2B outreach) and that your instructions comply with applicable law.
Back to top2.Subject matter and duration
2.1 Subject matter: processing of personal data necessary to provide the AI-assisted sales-outreach Service.
2.2 Duration: for the term of your subscription, plus the wind-down/deletion period in Section 11.
Back to top3.Nature and purpose of processing
We process personal data only to provide the Service, including: lead ingestion (CRM sync, CSV upload, Google Sheets), enrichment of fields you provide, AI-assisted sequence personalisation, multi-channel outbound (email via your own Gmail/Outlook mailbox, LinkedIn via server-side execution on a Customer-delegated session, egressing through a dedicated IP address, WhatsApp via the Meta WhatsApp Business Cloud API), deliverability and suppression management, engagement/reply tracking, Calendly meeting ingestion, and hosting/storage — all on your documented instructions.
Back to top4.Categories of data subjects and personal data
4.1 Data subjects: your business prospects and contacts.
4.2 Categories of personal data (as actually stored by the Service):
- Contact identity: business email, first/last/full name, job title, seniority, phone number, LinkedIn profile URL.
- Company / professional: company name, company domain, industry, company size.
- Geography: location, time zone.
- Outreach metadata: send, open, click, reply, and bounce events; sequence enrolment state; tags and custom fields you map.
- Communication content: rendered outbound message bodies/subjects across email, LinkedIn, and WhatsApp.
- Consent & suppression: WhatsApp opt-in records (timestamp, source, consent-text version), unsubscribe events, suppression entries.
4.3 You must not instruct us to process special categories of data (Art. 9) or criminal-offence data. The Service is not designed for such data.
Back to top5.Controller and Processor obligations (Article 28)
5.1 Documented instructions. We process personal data only on your documented instructions (including this DPA, the Terms, and your in-product configuration), unless required by EU/member-state law — in which case we inform you first unless legally prohibited.
5.2 Confidentiality. Personnel authorised to process personal data are bound by confidentiality obligations.
5.3 Security. We implement the technical and organisational measures in Section 8 (Art. 32).
5.4 Sub-processors. We engage sub-processors only under Section 6.
5.5 Assistance — data-subject rights. Taking into account the nature of the processing, we provide tooling and reasonable assistance for you to fulfil data-subject requests (Arts. 15–22): a per-email/per-message unsubscribe mechanism (Art. 21), per-workspace suppression, a right-to-be-forgotten flow with immediate prospect-data deletion and a 30-day workspace cleanup (Art. 17), and an Article 20 portability export (CSV/JSON). Note: the portability export is not available for accounts under 7 days old (an anti-scraping safeguard).
5.6 Assistance — Articles 32–36. We assist you with security-of-processing, breach notification, data-protection impact assessments, and prior consultation, taking into account the information available to us.
5.7 Deletion / return. On termination we delete or return personal data per Section 11.
5.8 Audit. We make available the information necessary to demonstrate compliance and allow for audits per Section 10.
5.9 Instruction review. We inform you if, in our opinion, an instruction infringes the GDPR or other data-protection law.
Back to top6.Sub-processors
6.1 You provide general authorisation for us to engage the sub-processors listed in Annex B and on our Compliance posture page (the authoritative, live list — 22 as of the effective date).
6.2 We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.
6.3 Change notice. We notify you at least 30 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within 30 days; if we cannot reasonably accommodate the objection, you may terminate the affected part of the Service as your sole remedy.
Back to top7.International transfers
7.1 The primary data store is hosted in the EU (Northflank). Where personal data is transferred outside the EEA, the transfer relies on an adequacy decision (for example the EU–US Data Privacy Framework, where the recipient is certified) or, failing that, on the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 of 4 June 2021 ("the SCCs"), supplemented by a transfer-risk assessment and any supplementary measures it identifies.
7.2 Module. The applicable SCC module depends on the leg of the transfer:
- Module Two (controller to processor) where you, as Controller, transfer personal data to us as Processor and that transfer leaves the EEA;
- Module Three (processor to processor) for onward transfers from us to a sub-processor.
7.3 EEA ⇄ United Kingdom. The Company is established in the United Kingdom while the primary data store is in the EU. Transfers from the EEA to the UK require no additional safeguard: the European Commission renewed its adequacy decisions for the UK on 19 December 2025, valid until 27 December 2031, and that renewal was made in light of the UK Data (Use and Access) Act 2025. Transfers from the UK to the EEA are likewise permitted under the UK's own adequacy regulations.
7.4 Transfers out of the UK to a third country. Where a transfer is subject to the UK GDPR and the destination is not covered by UK adequacy regulations, the EU SCCs alone are not a valid mechanism. For those transfers we rely on the UK International Data Transfer Agreement (IDTA) or the UK International Data Transfer Addendum to the EU SCCs (the "UK Addendum"), issued by the Information Commissioner under section 119A of the Data Protection Act 2018, in each case as applicable to the module identified in 7.2, together with a transfer risk assessment against the "not materially lower" standard introduced by the Data (Use and Access) Act 2025.
7.5 Switzerland. Where the transfer is subject to the Swiss FADP, the SCCs apply with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner.
7.6 The SCCs, the IDTA and the UK Addendum are incorporated into this DPA by reference and take precedence over it to the extent of any conflict. On request we provide copies and the completed module, annex and table details.
Back to top8.Security measures (Article 32)
We maintain, at minimum:
- Encryption — AES-256-GCM for stored credentials and secrets; TLS 1.3 in transit; HSTS.
- Tenant isolation — PostgreSQL row-level security on every tenant-scoped table;
workspace_idinjected from the authenticated session on every query. - Access control — role-based access control; least privilege; two-factor authentication for administrative access; secrets held only in environment configuration, never in source.
- Logging & monitoring — structured logging with PII redaction; append-only admin and GDPR audit logs; error monitoring (Sentry).
- Resilience & input safety — rate limiting, schema validation on all inputs, CSRF/CSP/CORS controls.
- Organisational — confidentiality obligations, vendor due diligence (signed DPA per sub-processor), and a documented incident-response runbook.
A current statement of measures is published on the Compliance posture page. We review these measures at least annually.
Back to top9.Personal-data breach notification (Articles 33–34)
9.1 We notify you without undue delay, and in any case within 24 hours of becoming aware of a personal-data breach affecting your Customer Data, with the information reasonably available (nature of the breach, categories and approximate number of data subjects/records affected, likely consequences, and measures taken/proposed).
9.2 As Controller, you are responsible for any notification to the supervisory authority (within 72 hours under Art. 33) and to affected data subjects (Art. 34); we assist as set out in Section 5.6.
Back to top10.Audit rights
10.1 We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or a mandated auditor.
10.2 To minimise disruption, audits occur on 30 days written notice, no more than once per 12 months (except following a breach or a regulator's instruction), during business hours, subject to confidentiality. We may satisfy audit requests through up-to-date third-party reports/certifications where available.
Back to top11.Return and deletion on termination
11.1 On termination, and at your choice, we delete or return all Customer Data containing personal data. You may export via the Service's Article 20 mechanism during the subscription and the wind-down window.
11.2 Our deletion lifecycle: anonymisation of identifiable user data begins within 24 hours of a deletion request; full workspace deletion completes within 30 days.
11.3 We retain personal data only where required by EU/member-state law (e.g. billing records for the statutory tax period), and the obligations of this DPA continue to apply to any retained data.
Back to top12.Liability and term
12.1 Liability under this DPA is subject to the limitations in the Terms of Service, except where applicable data-protection law provides otherwise.
12.2 This DPA takes effect on acceptance and remains in force while we process personal data on your behalf.
Back to top13.Acceptance / signing
This DPA is presented for acceptance in-app and is accepted electronically as part of the Customer's agreement to the Terms of Service. The Service records your acceptance. Organisations that require a countersigned copy may request one from legal@sequenz.ai. A signed or electronically accepted DPA is a prerequisite for production-account activation.
Back to topAnnex A — Processing details (summary)
| Item | Detail |
|---|---|
| Subject matter | Provision of the AI-assisted sales-outreach Service |
| Duration | Subscription term + Section 11 wind-down |
| Nature & purpose | Lead ingestion, AI personalisation, multi-channel outbound, deliverability, tracking, hosting |
| Personal-data categories | Section 4.2 |
| Data subjects | Customer's business prospects and contacts |
| Controller | The Customer |
| Processor | Sequenz Ltd (company number 17499883), 128 City Road, London, EC1V 2NX, United Kingdom |
Annex B — Authorised sub-processors
The authoritative, live list is on the Compliance posture page. As of the effective date (22 sub-processors):
Platform infrastructure: Clerk, Inc. (authentication, US); Stripe, LLC (billing, US/EU); Plus Five Five, Inc. / Resend (transactional email, US); Functional Software, Inc. / Sentry (error monitoring, US/EU); PostHog, Inc. (product analytics, EU Frankfurt); Vercel, Inc. (frontend hosting, EU regional); Northflank Ltd. (backend + worker hosting + primary PostgreSQL, EU region); Upstash, Inc. (managed Redis queues, EU); OpenAI OpCo, LLC (AI-written drafts, reply sorting and in-app assistants, US — no training on customer data); Bouncer (a check of the recipient's email domain before sending — the domain only, never the full address); Cloudflare, Inc. (R2 export storage, EU regional); IPRoyal Services FZE LLC (dedicated static-residential egress IP for server-side LinkedIn execution, UAE — Ajman, with the egress IP itself located in the country the Customer's user declared; processes connection metadata only, not message or profile content; engaged only where the Customer has connected a LinkedIn account. As a non-adequate third country, this transfer is made under the EU Standard Contractual Clauses, Module Two, incorporated at Annex I of the sub-processor's data processing agreement); Bright Data Ltd. (the same service for the United Arab Emirates and Saudi Arabia, which the sub-processor above does not serve, Israel — Netanya; Israel is the subject of a European Commission adequacy decision (2011/61/EU, reconfirmed 15 January 2024), so this transfer requires no Article 46 mechanism, and the sub-processor publishes a Data Protection Addendum and has appointed a UK Article 27 representative).
Customer-connected integrations: HubSpot, Inc.; Salesforce, Inc.; Pipedrive OÜ (CRM sync); Calendly LLC (meeting ingestion, US); Google LLC (Google Sheets ingestion; Gmail send via your own mailbox); Microsoft Corporation (Outlook send via Microsoft Graph, your own mailbox); the Company-operated Chrome extension telemetry endpoint (LinkedIn, EU); Meta Platforms, Inc. (WhatsApp Business Cloud API).
Back to topAnnex C — Security measures
See Section 8 and the live statement on the Compliance posture page.
Back to top