Data Processing Agreement
Last updated: 4 October 2026
In short
- When you keep prospects and conversations in Opusend, you decide what is done with that personal data, and we process it only for you. This agreement is the contract the GDPR requires for that (Article 28).
- It is part of our Terms of Service: you accept it when you accept them, with nothing to sign.
- We keep the data confidential and secure, use only the subprocessors we list and tell you before we add one, help you answer the people whose data it is, and tell you within 48 hours of finding a breach that affects it.
- Where the law requires it for data coming from the EEA, the UK or Switzerland, the European Commission's Standard Contractual Clauses apply.
- You can export the data at any time. When you leave, it is deleted within 30 days, and gone from backups within 30 more.
This box is a summary. The full agreement below is what applies.
1. Parties, scope and order of precedence
This Data Processing Agreement (the "DPA") is between the customer that has accepted Opusend's Terms of Service (the "Customer") and Opusend, as defined in the Terms. It forms part of the Terms and is accepted with them. It applies whenever Opusend processes Customer Personal Data in providing the Service, and lasts as long as it does.
If this DPA conflicts with the Terms, this DPA prevails on the processing of personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.
2. Definitions
- Data Protection Law: the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other data protection law that applies to the processing under this DPA, each as amended.
- Customer Personal Data: personal data within the Customer Data defined in the Terms, which Opusend processes on behalf of the Customer.
- Subprocessor: a third party Opusend engages to process Customer Personal Data.
- Standard Contractual Clauses or SCCs: the clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021. UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- "Controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR.
3. Roles and the Customer's responsibilities
The Customer is the controller of Customer Personal Data, or a processor acting for its own controller, in which case Opusend is its subprocessor and the Customer passes on to its controller what this DPA requires. Opusend is the Customer's processor.
The Customer is responsible for the lawfulness of the processing it instructs. In particular, it will: have a lawful basis for collecting, storing and contacting each data subject; give data subjects the information Articles 13 and 14 GDPR require; honour their objections, opt-outs and erasure requests; keep the data accurate; make sure its instructions comply with Data Protection Law; and not use the Service to process special categories of personal data (Article 9 GDPR), data about criminal convictions or offences (Article 10 GDPR), or data about children.
4. Processing only on the Customer's instructions
Opusend processes Customer Personal Data only on the Customer's documented instructions, including on transfers to a third country, unless the law to which Opusend is subject requires otherwise; in that case Opusend tells the Customer before processing, unless that law forbids it. The Customer's instructions are: the Terms and this DPA; the Customer's and its users' use and configuration of the Service, such as which prospects to save, which pages to read, which messages to draft, send or schedule, which work emails to look up and what to delete; and any other written instruction the parties agree. Opusend tells the Customer at once if, in its opinion, an instruction infringes Data Protection Law.
Opusend does not sell Customer Personal Data, does not use it for its own purposes, and does not combine one customer's Customer Personal Data with another's, with two exceptions the Customer authorises here: Opusend may compile statistics about the use of the Service that identify no data subject and no customer; and, when the Customer looks up a work email, Opusend keeps the result its lookup provider returns in its own lookup cache, as an independent controller, under the terms and limits described in its Privacy Policy. The details of the processing are in Annex 1.
5. Confidentiality
Opusend ensures that every person it authorises to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law, and has access only to the extent needed to provide, support and secure the Service or to comply with the law.
6. Security
Opusend implements and maintains the technical and organisational measures in Annex 2, which take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, and the risks for data subjects, as Article 32 GDPR requires. Opusend may update these measures as long as the overall level of protection does not decrease.
7. Subprocessors
- General authorisation. The Customer gives Opusend general written authorisation to engage Subprocessors. The current Subprocessors, with what each does, where, and the transfer safeguard, are listed on the Subprocessors page, which forms Annex 3.
- Notice of changes. Opusend gives at least 30 days' notice before a new Subprocessor processes Customer Personal Data, by email to the workspace owner and by updating that page. Where a Subprocessor must be replaced urgently to keep the Service secure or running, Opusend gives notice as soon as it can.
- Right to object. The Customer may object to a new Subprocessor on reasonable data protection grounds within the notice period by writing to [email protected]. The parties will discuss the objection in good faith. If Opusend cannot offer a reasonable alternative, the Customer may end the affected part of the Service before the change takes effect, and Opusend refunds the fees paid in advance for the period after it ends.
- Same obligations. Opusend imposes on each Subprocessor, by contract, data protection obligations that offer at least the protection of this DPA, in particular sufficient guarantees on security. Opusend remains fully liable to the Customer for each Subprocessor's performance of those obligations.
8. International transfers
Opusend is established in Albania, for which the European Commission has not adopted an adequacy decision. Opusend transfers Customer Personal Data outside the EEA, the UK or Switzerland only with a safeguard that Data Protection Law accepts: an adequacy decision, the EU-U.S. Data Privacy Framework (and its UK extension or the Swiss-U.S. framework) where the recipient is certified, or the SCCs.
To the extent the Customer's transfer of Customer Personal Data to Opusend is a restricted transfer under Data Protection Law, the parties enter into the SCCs, which are incorporated here by reference, as follows:
- Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) where it is a processor. The Customer is the data exporter and Opusend the data importer.
- Clause 7 (docking clause) applies. Under Clause 9, option 2 (general written authorisation) applies, with the notice period in section 7 of this DPA. The optional wording in Clause 11 does not apply.
- Under Clause 13, the competent supervisory authority is that of the EU Member State in which the Customer is established or, if it is not established in the EU, in which its representative under Article 27 GDPR is established.
- Under Clause 17, option 2 applies: the SCCs are governed by the law of the EU Member State in which the Customer is established or, where that law does not allow for third-party beneficiary rights, by the law of Ireland. Under Clause 18, disputes are resolved by the courts of the EU Member State in which the Customer is established, or otherwise of Ireland.
- Annex I of the SCCs is completed by Annex 1, Annex II by Annex 2 and Annex III by Annex 3 of this DPA.
- For transfers subject to the UK GDPR, the UK Addendum applies, completed with the information above; either party may end it as its Table 4 allows. For transfers subject to Swiss law, the SCCs apply with the references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and "Member State" read so that data subjects in Switzerland can bring claims where they habitually reside.
If the SCCs are replaced, or a different mechanism becomes the one Data Protection Law requires for this transfer, the parties will use that one instead.
9. Requests from data subjects
The Service lets the Customer access, correct, export, restrict (for example by blacklisting a prospect) and delete Customer Personal Data itself. If Opusend receives a request from a data subject about Customer Personal Data, it tells the Customer without undue delay and does not answer it, except to tell the person to contact the Customer, unless the Customer authorises it. Taking into account the nature of the processing, Opusend gives the Customer reasonable help, by appropriate technical and organisational measures, to answer requests to exercise data subjects' rights.
10. Personal data breaches
Opusend notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact for more information; Opusend sends what is not yet known as soon as it is. Opusend takes reasonable steps to contain the breach and limit its effects. A notice is not an admission of fault or liability.
11. Impact assessments and consultations
Taking into account the nature of the processing and the information available to it, Opusend gives the Customer reasonable help with its data protection impact assessments and its prior consultations with a supervisory authority under Articles 35 and 36 GDPR, as they relate to the Service.
12. Deletion and return at the end
The Customer can export Customer Personal Data at any time while it has an account: the CRM as a CSV file, and everything in the account as one JSON file. When the Customer closes its account, Opusend holds Customer Personal Data for 30 days, during which the Customer may ask for it to be restored or returned, and then deletes it. Copies in Opusend's database backups are deleted when those backups roll off, within 30 more days. On request, Opusend deletes it at once instead, and confirms the deletion in writing. This does not apply to data that the law requires Opusend to keep, which Opusend protects and keeps only for as long as required.
13. Information and audits
Opusend makes available to the Customer the information needed to demonstrate compliance with Article 28 GDPR and this DPA, including this DPA, the Security page and written answers to a reasonable security questionnaire once a year. If that information is not enough to demonstrate compliance, or a supervisory authority requires it, Opusend allows and contributes to audits, including inspections, by the Customer or an independent auditor it mandates who is bound by confidentiality, on at least 30 days' written notice, during business hours, no more than once in any 12 months except after a personal data breach or at an authority's request, without access to other customers' data, and in a way that does not disrupt the Service. The Customer bears the costs of its audit.
14. Liability
Each party's liability under this DPA is subject to the limits and exclusions in the Terms, to the extent Data Protection Law allows. Nothing in this DPA limits the rights of data subjects under the SCCs or under Data Protection Law.
15. Contact
Data protection questions and notices under this DPA: [email protected]. Opusend's details are in the Legal notice.
Annex 1: Details of the processing
| Item | Description | Notes |
|---|---|---|
| Data exporter | The Customer, as identified in its account | Controller, or processor for its own controller |
| Data importer | Opusend, as identified in the Legal notice | Processor. Contact: [email protected] |
| Categories of data subjects | The Customer's prospects and business contacts; the people in conversations with them; people named in the Customer's notes; the Customer's own users | |
| Categories of personal data | Name, headline, job title, company, location and profile addresses on LinkedIn and Sales Navigator; work email address and company phone; the profile and company text the Customer asks the Service to read; messages and emails exchanged with them and the replies; notes, stages, tags, campaigns and activity; AI-generated drafts, summaries and fit scores; for the Customer's users, their account details and the encrypted password of a mailbox they add | No special categories of data are intended or required |
| Frequency | Continuous, for as long as the Customer uses the Service | |
| Nature of the processing | Collection on the Customer's instruction in its own browser, storage, synchronisation across its devices, AI generation, work email lookups, sending and scheduling of messages and emails, reply detection, export and deletion | |
| Purpose | Providing the Service to the Customer under the Terms | |
| Duration and retention | The term of the Terms, then the deletion period in section 12 | Retention within the Service is as in the Privacy Policy |
| Subprocessors | As in Annex 3, for the same nature and purpose, for the duration above |
Annex 2: Technical and organisational measures
- Encryption in transit. All traffic between the extension, the browser and Opusend's servers uses TLS. The app sends HTTP Strict Transport Security for a year, subdomains included.
- Secrets at rest. Account passwords are stored only as salted one-way hashes. The password of a mailbox a user adds is encrypted with AES-256-GCM; the key is kept in a separate file on the server, readable only by the service, outside the database and its backups, with different keys for staging and production. A Gmail access token stays in the user's browser and never reaches the server.
- Access by users. Session cookies are host-only, Secure, HttpOnly and SameSite=Lax. The extension's token is bound to the session that issued it and ends with it. Sign-in is rate limited, password sign-ups confirm their email address, a password reset ends every session, and users can sign out everywhere else.
- Access by staff. The admin console requires a staff role and a second factor, and every staff action on an account is recorded in an audit trail. Server access is by SSH, with a separate restricted system user for each site, so the marketing site cannot reach the app's data. Production secrets are kept out of the code repository.
- Separation of customers. Every customer's data is scoped to its workspace, and every request reads and writes only the signed-in user's workspace, within the limits of their role.
- Application security. The app enforces a strict Content Security Policy and collects violation reports. The extension runs no code fetched from elsewhere, and declares its own Content Security Policy. Public forms are rate limited and guarded against bots.
- Availability and recovery. The database is dumped every night, the dumps are kept for 30 days, and every deploy restores the latest dump into a scratch database to prove it can be restored. Deploys are health checked and can be rolled back. A separate staging environment, with its own database and keys, is tested before production.
- Minimisation. Work email lookups never request personal email addresses or phone numbers. Email addresses in the Gmail inbox that are not the user's leads are dropped in the browser. A mailbox read for replies keeps only the first 8 KB of a lead's reply, for 30 days. The extension's own step log stays in the browser, with profile and email addresses removed.
- Deletion. Closed accounts are erased after their recovery window by one routine, which removes the account's data from every table except the records the Privacy Policy says are kept. Retention sweeps delete lookup cache entries after 12 months and mailbox detections after 30 days.
- Testing and change. Every change passes an automated test suite, including tests that hold the privacy disclosures to what the code does, before it is released.
- Incidents. Security reports are received at [email protected], and personal data breaches are handled and notified as section 10 describes.
Annex 3: Subprocessors
The Subprocessors Opusend uses, with what each does, where it processes data and the safeguard for any transfer, are listed on the Subprocessors page, which is part of this DPA as it stands from time to time under section 7.