Data Processing Agreement
Effective as of September 1, 2026
This Data Processing Agreement is Exhibit A to the Sprootal Terms of Service and forms an integral part of that agreement.
This exhibit contains a data processing agreement within the meaning of article 28 paragraph 3 of the General Data Protection Regulation (GDPR). This data processing agreement (DPA) forms an integral part of the general terms and conditions of Sprootal (Navigatio B.V.).
1 Definitions
1.1
In addition to the terms defined elsewhere in this DPA, these terms have the following meaning:
- Agreement
- means the Terms of Service together with its Exhibits, including this DPA.
- Annex
- means an annex to this DPA.
- Article
- means an article of this DPA.
- GDPR
- means Regulation (EU) 2016/679 (General Data Protection Regulation).
- Person Concerned
- means the natural person to whom Personal Data relates.
- Data Breach
- means a personal data breach as referred to in article 4 paragraph 12 GDPR.
- Personal Data
- means any information relating to an identified or identifiable natural person.
- Processing
- means an operation or set of operations with respect to the Personal Data for the purposes of the Services, as described in Annex A.
- Services
- means Sprootal’s services agreed to in the Agreement.
- Sub-Processor
- means a (sub)processor engaged by Sprootal that processes Personal Data on behalf of the Customer.
- Terms of Service
- means Sprootal’s terms of service.
1.2
Terms that are not defined in this DPA have the meaning given to them in the Terms of Service.
2 Provider Services
2.1
Sprootal is considered to be the processor with regard to the Processing of Personal Data. The Customer is considered to be the controller.
2.2
Insofar as Sprootal processes Personal Data other than for the Services, Sprootal applies to those processing operations as an independent controller within the meaning of the GDPR and this Data Processing Agreement does not apply.
2.3
Sprootal may anonymize Personal Data. Once data is anonymized so that it no longer relates to an identifiable natural person, it is no longer Personal Data. Sprootal may use such anonymized data at its own discretion, including for its own business purposes, and this Data Processing Agreement does not apply to that use.
2.4
The Customer is and remains responsible for (i) the lawfulness of the Processing, (ii) providing any mandatory information to Data Subjects, (iii) having a valid basis for the Processing, and (iv) determining the purposes and means of the Processing. The Customer makes sure that its instructions comply with the GDPR.
2.5
This Data Processing Agreement applies from the effective date of the Agreement and ends when Sprootal no longer processes Personal Data for the purpose of the Services on behalf of the Customer, or at the time the Agreement ends and all obligations under Article 11 have been fulfilled.
3 Instructions
3.1
Sprootal will only carry out the Processing on the basis of documented instructions from the Customer. This includes instructions that follow from (the execution of) the Agreement and the use of the services by or on behalf of the Customer. The Customer gives instructions through the agreed channels. Any instruction that goes beyond the standard functionality of the Services counts as additional work. Sprootal may charge for such work at its then current rates.
3.2
If Sprootal believes that an instruction violates the GDPR or other applicable regulations, Sprootal will notify Customer without delay. Sprootal may also suspend or refuse an instruction that it reasonably regards as unlawful, technically unfeasible or outside the scope of the Services. Sprootal is not liable for consequences that follow from instructions given by the Customer.
4 Confidentiality
4.1
Sprootal ensures that individuals acting under its authority and having access to Personal Data (including employees) have committed themselves to confidentiality or are subject to an appropriate legal obligation of confidentiality. The Customer keeps confidential all information it receives about Sprootal's security measures, audit results and Subprocessors. The Customer treats this information as Sprootal's confidential information.
5 Security
5.1
Sprootal takes appropriate technical and organizational measures to protect Personal Data against loss or any form of unlawful Processing, taking into account the state of the art, the implementation costs, and the nature, scope, context and purposes of the Processing and the risks of varying likelihood and severity to the rights and freedoms of natural persons.
5.2
The (minimum) security measures are included in Annex B. Sprootal may update these measures, provided that the security level is not substantially reduced as a whole.
5.3
The security measures taken by Sprootal are without prejudice to the Customer’s obligations in this regard. The Customer remains fully responsible for its own use of the Services. The Customer protects its login details, systems and devices. The Customer also makes its own backups of Personal Data. The Customer assesses whether the measures fit the nature of the Personal Data it processes. The Customer does not submit special categories of Personal Data unless the Parties agree otherwise in writing.
6 Sub-processors
6.1
The Customer hereby grants Sprootal general permission to engage Sub-processors for (Processing in the context of) the service or parts thereof.
6.2
The Subprocessors known at the time of signing (if any) are listed in Annex C.
6.3
Sprootal will inform the Customer prior to engaging a new Subprocessor or replacing a Subprocessor. The Customer may object to a new Subprocessor within ten (10) working days after notification, stating reasons, in writing on reasonable privacy or security grounds. If the Parties do not resolve the situation within thirty (30) days, the Customer may, as its only remedy, terminate (opzeggen) the affected Services, subject to payment of any fees due for the remainder of the then-current Subscription Term. If the Customer does not object in time, the Customer approves the new Subprocessor.
6.4
Sprootal imposes obligations on each Subprocessor in an agreement that are materially equivalent to the obligations under this Processing Agreement, including in any case obligations regarding confidentiality, security, transfer and assistance.
6.5
Sprootal remains liable to Customer for the fulfilment of the obligations by Subprocessors, without prejudice to any limitations of liability in the Agreement.
7 Transfers outside the EEA
7.1
Sprootal will process Personal Data within the European Economic Area (EEA) as much as possible. If Personal Data is or may be transferred to a country outside the EEA, Sprootal ensures that an appropriate transfer mechanism is in place (e.g., an adequacy decision or EU Standard Contractual Clauses), and that additional measures are taken where necessary. Sprootal maintains an up-to-date list on its website of the locations where Personal Data is processed and informs the Customer of new transfers outside the EEA.
8 Data breaches
8.1
Sprootal will report a Data Breach to the Customer without unreasonable delay after it has become aware of it, and in any event within seventy-two (72) hours where feasible, so that it can be reported to data subjects and/or the regulator in a timely manner if necessary. A notification about a Data Breach does not entail any admission of fault or liability for that breach. The Customer does not make public statements about a Data Breach that name Sprootal without Sprootal's prior written consent, unless the law requires such a statement.
8.2
The notification contains, if available: (i) the nature of the Data Breach, (ii) the (probable) consequences, (iii) the measures taken or intended to be taken, and (iv) the point of contact for follow-up.
8.3
Sprootal will promptly take reasonable steps to investigate, mitigate, and (where possible) remedy the Data Breach.
8.4
Sprootal shall provide Customer with reasonable assistance in complying with reporting obligations towards the regulator and/or Data Subjects.
9 Assistance to the Customer
9.1
Sprootal shall, to the extent reasonably possible and taking into account the nature of the Processing, assist the Customer with:
- responding to requests from Data Subjects (such as access, rectification, erasure, restriction, data portability, objection);
- conducting data protection impact assessments (DPIA) and prior consultation with the supervisor;
- demonstrating compliance with the obligations under article 28 GDPR.
9.2
If a Data Subject submits a request directly to Sprootal, Sprootal will forward this request to the Customer to the extent permitted by law. Sprootal will do so within a commercially reasonable timeframe.
9.3
Prior to Sprootal's assistance to the Customer pursuant to any provision of the Data Processing Agreement, the Parties shall determine Sprootal's remuneration for this in good mutual consultation. In the absence of agreements made, Sprootal may charge fees as its then-current market rates.
10 Audit and information
10.1
Sprootal will make available, upon request, information that is reasonably necessary to demonstrate compliance with the DPA.
10.2
The Customer is entitled to have an audit carried out once per calendar year, provided that:
- the audit is announced in writing at least thirty (30) days in advance;
- the audit takes place during normal business hours;
- the audit is carried out by an independent, knowledgeable and certified auditor who is bound by a duty of confidentiality that can be regarded as adequate by Sprootal;
- the audit does not unreasonably disrupt Sprootal's business operations; and
- the Customer reimburses Sprootal's reasonable costs associated with the supervision/handling of the audit.
Sprootal may reject an audit or auditor if one or more of these conditions is not (fully) fulfilled. The Customer treats all audit findings as Sprootal's confidential information.
10.3
Sprootal may reasonably require that any available (third-party) assurance reports (e.g., SOC2/ISO) be used before an on-site audit takes place.
11 Return and disposal of Personal Data
11.1
Once Sprootal no longer needs the Personal Data for the achievement of the purposes as described in Annex A, Sprootal will (at the discretion of Customer) delete or return the Personal Data to Customer, except insofar as storage of the Personal Data is required by law or Sprootal processes it as an independent controller. Any associated costs will be borne by the Customer.
11.2
Sprootal may retain Personal Data to the extent and for as long as this is necessary to comply with or exercise rights under the Agreement, mandatory retention obligations or for the establishment, exercise or substantiation of a legal claim, provided that the Personal Data remains subject to appropriate security and confidentiality.
12 Liability and indemnification
12.1
The liability of the Parties in connection with this Data Processing Agreement is subject to the liability provisions and any limitations in the Agreement, except to the extent that mandatory law prescribes otherwise. Any liability of Sprootal under this Data Processing Agreement counts towards the aggregate liability cap in the Agreement. Sprootal is not liable for indirect or consequential damage. Notwithstanding the foregoing, in no event shall Sprootal’s aggregate liability under this Data Processing Agreement exceed the fees paid by the Customer under the Agreement in the twelve (12) months preceding the event giving rise to the claim.
12.2
Customer indemnifies Sprootal (including its directors, employees and third parties engaged by Sprootal) against all claims, damages, fines, penalties, measures, orders, sanctions, costs and expenses related to or arising from unlawful Processing, the Customer's instructions, a breach of this DPA by the Customer, and other violations of the GDPR by the Customer.
13 Final provisions
13.1
This Data Processing Agreement is an integral part of the Agreement. In the event of a conflict, this Data Processing Agreement shall prevail insofar as it concerns the Processing of Personal Data. The provisions on confidentiality, liability, indemnification and return and disposal survive termination (eindigen) of the Agreement.
13.2
Amendments to this Data Processing Agreement are only valid if agreed in writing by the Parties. Sprootal may still amend this Data Processing Agreement where a change in law or guidance from a supervisor requires it. Sprootal informs the Customer of such an amendment in advance.
Annex A. Processing description
- Processing subject
- Personal Data contained in the Customer Data that the Customer, its Permitted Users, or a Third-Party Platform connected by the Customer submits to, or generates within, the Services.
- Purposes
- Providing the Services to the Customer, namely: operating the Customer’s contact and company records; connecting the Customer’s own LinkedIn and email accounts; planning, scheduling and delivering outreach actions and messages on the Customer’s behalf; synchronising and displaying conversations; enriching contact records through the data providers the Customer enables; generating AI-assisted drafts, classifications and suggestions; and providing Support, security monitoring and technical diagnostics.
- Processing nature
- Collection, recording, organisation, structuring, storage, retrieval, consultation, use, enrichment, transmission to the platforms the Customer has connected, restriction, erasure and destruction — carried out by automated means.
- Data subject categories
- Permitted Users of the Customer (including invited and former users); the Customer’s prospects, leads and contacts; participants in conversations conducted through the Customer’s connected accounts; individuals named as representatives on company records; and individuals who contact the Customer through the Services.
- Personal data categories
- Identity data (name, avatar); contact details (email addresses, telephone numbers, location); professional data (job title, headline, summary, current and past employers, education, languages, certifications, skills); LinkedIn identifiers and public profile attributes (profile URL, member and provider identifiers, connection and follower counts, network distance, premium/creator/open-to-work indicators); communication content (messages, drafts, subjects, attachments, reactions, read receipts and timestamps); free-text notes and custom fields defined by the Customer; account and authentication data of Permitted Users (password hash, two-factor secret, session tokens, IP address, user agent); billing and account-administration data; and usage, activity and audit logs recording which Permitted User performed which action.
- Special categories of personal data
- None. The Services contain no field intended for special categories of Personal Data, and the Customer must not submit such data — see Section 6.4(b) of the Terms of Service and Article 5.3 of this DPA. Where the Customer uses free-text fields (notes, custom properties, message content), the Customer remains responsible for ensuring that no special-category data is entered.
- Processing duration
- For the duration of the Subscription Term, followed by the post-termination export and deletion periods set out in Section 5.3 of the Terms of Service and Article 11 of this DPA. Technical, security and activity logs are deleted automatically on the fixed schedules below.
Automated deletion schedules applied within the Services:
| Data | Retention |
|---|---|
| Security audit logs, API audit logs, webhook logs and webhook deliveries | 90 days |
| Contact timeline activities (tag, stage, list, assignment, blacklist and social-signal events) | 365 days |
| All other contact activity records | 90 days |
| Completed and failed scheduled outreach actions | 7 days |
| Delivered signal events / expired signal events | 7 days / 30 days |
| Cron execution records | 30 days |
| Product analytics events / session replays (where enabled) | 30 days / 7 days |
| Soft-deleted campaigns (permanent removal) | 30 days |
Annex B. Technical and organizational measures
Sprootal applies the technical and organizational measures set out below. Specific algorithms, parameters, thresholds and retention figures are deliberately not published here; they are provided to the Customer on request, subject to the confidentiality obligations in Section 10 of the Terms of Service. Sprootal may update these measures in accordance with Article 5.2 of this DPA, provided the level of security is not substantially reduced as a whole.
- Encryption in transit.
- All public traffic is served over HTTPS with certificates issued and renewed automatically; plain HTTP entry points are not exposed. Traffic between Sprootal’s own hosts does not cross the public internet in clear text: it travels over an encrypted private network tunnel, and the database itself accepts only TLS connections. Session cookies are set HttpOnly, Secure (in production) and SameSite=Lax.
- Credential storage.
- No credential is stored in a form that can be read back. Passwords and recovery codes are kept only as salted hashes; API keys only as a hash alongside a short non-secret prefix used to identify them; two-factor secrets under an authenticated cipher whose key lives outside the database, and without which the application refuses to start in production.
- Authentication.
- Passwords are hashed with a deliberately slow, salted password-hashing function whose work factor is reviewed periodically. Sessions are signed tokens validated on every request against a server-side session record, so a revoked session stops working immediately; a maximum session age is enforced. Optional two-factor authentication (TOTP) is available, with replay protection and single-use hashed recovery codes.
- Access control and tenant isolation.
- Access is governed by a resource-and-action permission model with roles, evaluated on every privileged operation. Every tenant-owned record carries a team identifier, and the data-access layer forces the caller’s team scope onto queries and mutations, so one customer’s data cannot be reached from another customer’s session. Public API keys carry explicit scopes, an expiry and a revocation flag.
- Secrets management.
- All configuration is read through a single validated configuration layer that fails startup if a required secret is missing or malformed. Production secrets are injected into the runtime from an operator-controlled store; no secret is committed to the source repository.
- Logging and auditability.
- Separate ledgers record user and team actions with IP address and user agent, security-relevant events with severity, before-and-after snapshots of changed records, public API calls, and a per-contact actor trail. Application logs and error reports pass through redaction that strips authorization headers, cookies, API keys, tokens and passwords before the event leaves the process.
- Rate limiting and abuse protection.
- Per-route rate limits apply to authentication, sensitive account flows and the public API, backed by a persistent counter store. Bot verification protects public authentication forms, and sign-up rejects known disposable email domains.
- Backups.
- The production database is backed up by an automated job that keeps several daily and weekly generations, with an encrypted copy held off-site in separate object storage under its own retention policy. Write-ahead logs are archived continuously in addition to those snapshots, so the database can be restored to a chosen point in time rather than only to the most recent one, and a copy of that archive is mirrored to a second host. The restore path is exercised end to end on a recurring drill, not assumed. Backup storage is reachable only by the service account that writes it.
- Minimisation before third-party AI processing.
- Text sent to AI providers is passed through a redaction step that removes email addresses, URLs and telephone numbers, and can additionally remove personal names, before it leaves Sprootal.
- Confidentiality of personnel.
- Persons acting under Sprootal’s authority who have access to Personal Data are bound by confidentiality obligations, as required by Article 4 of this DPA.
Annex C. Sub-processors
Sprootal engages Sub-processors in the categories set out below. The identity of each Sub-processor, the country in which it processes Personal Data and the applicable transfer mechanism are made available to the Customer on request. The notification and objection procedure in Article 6 of this DPA applies to every addition or replacement, in whichever category it falls.
| Category | Purpose |
|---|---|
| Infrastructure hosting | Hosting of the application, database, queues, object storage and encrypted database backups. Processed within the European Economic Area. |
| Messaging connectivity | Connection of the Customer’s own LinkedIn and email accounts, and retrieval and delivery of conversations, messages and invitations through them. |
| Data enrichment providers | Retrieval of public professional profile and company data to enrich contact records and support lead search, where enabled by the Customer. |
| AI processing and vector storage | Generation and classification of message drafts and suggestions, and storage of the resulting embeddings for context retrieval. Input is redacted as described in Annex B. |
| Transactional email delivery | Delivery of account, security and notification email to Permitted Users. |
| Subscription billing | Checkout, invoicing and subscription management, covering account and billing data of the Customer only. |
| In-product support | Support messaging with Permitted Users inside the Services. |
| Error monitoring | Collection of application error reports for diagnostics. Payloads are redacted as described in Annex B. |
| Bot and abuse protection | Verification of requests made to public authentication forms. |
Third-Party Platforms that the Customer connects itself — including LinkedIn and any CRM, calendar or messaging integration the Customer enables — are not Sub-processors of Sprootal. Sprootal transmits data to those platforms on the Customer’s instruction, and the Customer’s relationship with each platform is governed by that platform’s own terms, as set out in Section 7 of the Terms of Service.
The rest of the set: Privacy PolicyTerms of ServiceCookie Policy