Data Processing Agreement

Data Processing Agreement (DPA)

This document constitutes a Data Processing Agreement (DPA) in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR). It is entered into between Reached (Processor) and the Customer identified in Article 1 (Controller). It supplements Reached’s Terms of Use.

Article 1 — Parties

In connection with the use of Reached: Notlead (owner and publisher of the Reached solution) acts as a Processor within the meaning of the GDPR for the personal data collected and processed on the Customer’s behalf. The Customer acts as the Controller.

Article 2 — Purpose and term

This Agreement sets out the conditions under which Reached processes personal data on the Customer’s behalf in connection with the use of the Reached service (parallel dialer, call recording, transcription, and CRM synchronization). It takes effect on the date of signature and remains in force for the duration of the contractual relationship between the parties. It ends automatically upon termination of the service agreement, subject to Article 15. Reached also acts as a Controller for its own internal processing activities (account management, billing, customer support, and service security), which are not covered by this Agreement.

Article 3 — Nature and purposes of processing

As part of the service, Reached performs the following processing activities on the Customer’s behalf: storage and management of imported contacts and leads; management of prospecting campaigns and calls; recording of outgoing telephone calls; automatic transcription of calls, where enabled; AI-generated call summaries; synchronization of data with connected CRMs; call logging (date, duration, outcome, and notes); and reporting and analysis features for sales activity. The nature of processing includes collection, storage, organization, consultation, transmission, recording, and deletion.

Article 4 — Categories of data and data subjects

Categories of data: identification data (first name, last name, job title, company); contact details (telephone numbers and email addresses); interaction data (call audio recordings, transcriptions, summaries, and notes); professional data (industry, position, and LinkedIn profile); and technical data (usage and connection logs). Categories of data subjects: the Customer’s prospects and professional contacts, and service users designated by the Customer. No special-category data within the meaning of Article 9 GDPR is processed as part of the service. The Customer must not import such data.

Article 5 — Reached’s obligations as Processor

Reached undertakes to process personal data only on the Customer’s documented instructions, including with regard to transfers outside the European Union; ensure the confidentiality of processed data and ensure that authorized persons are bound by confidentiality obligations; implement the technical and organizational security measures described in Article 9 and Appendix 1; appoint sub-processors only under the conditions of Article 8; notify the Customer in the event of a data breach under Article 11; assist the Customer with its obligations under Articles 10 and 12; delete or return personal data at the end of the service under Article 15; maintain a record of processing categories carried out on the Customer’s behalf; make available the information necessary to demonstrate GDPR compliance and enable audits under Article 13; and promptly inform the Customer if, in Reached’s opinion, an instruction infringes the GDPR.

Article 6 — Customer obligations as Controller

The Customer undertakes to provide Reached with clear and lawful instructions; ensure that data provided to Reached has been lawfully collected and is supported by a valid legal basis (legitimate interest in B2B contexts; prior consent in B2C contexts, except where legally permitted otherwise); inform data subjects of the use of Reached to process their data; inform call recipients about call recording, its purpose, and their right to object; honor all objections to prospecting and exclude affected people from campaigns; comply with applicable telemarketing rules, including consumer protection requirements, calling hours, electronic communications rules, and caller-identification rules; and comply with its obligations as Controller under the GDPR.

Article 7 — Data location and transfers

No transfer of data to third countries is carried out without appropriate safeguards, such as the European Commission’s standard contractual clauses or any other mechanism recognized as compliant under applicable law.

Article 8 — Sub-processors

The Customer authorizes Reached to use sub-processors in connection with the service. Reached undertakes to impose contractual data-protection obligations on those sub-processors that are equivalent to those in this Agreement and remains fully liable to the Customer for their performance. Reached will inform the Customer of any addition or replacement of a sub-processor with reasonable prior notice, giving the Customer the opportunity to raise reasoned objections.

Article 9 — Data security

Reached implements technical and organizational measures appropriate to the risk, including AES-256 encryption of sensitive data in databases; encrypted HTTPS/TLS connections for all transmissions; Row Level Security (RLS) access controls so each customer can access only its own data; secure authentication with session management and automatic expiration; restricted production-environment access for authorized personnel; daily automated backups; and access and audit logs, system logging, and monitoring. Further details are provided in Appendix 1.

Article 10 — Data subject rights

If data subjects exercise their GDPR rights directly with Reached, including rights of access, rectification, erasure, restriction, portability, or objection, Reached will inform the Customer without undue delay so that the Customer can respond. Reached will assist the Customer, through appropriate technical and organizational measures, in responding to such requests within a reasonable period.

Article 11 — Personal data breaches

In the event of a personal data breach, Reached will notify the Customer within 72 hours of becoming aware of the incident, in accordance with Article 33 GDPR. The notification will include at least: the nature of the breach; the categories and approximate number of affected data subjects; the personal data concerned; the likely consequences of the breach; and the measures taken or contemplated to remedy the breach.

Article 12 — Assistance to the Customer

To the extent reasonable and taking into account the nature of the processing, Reached will assist the Customer in meeting its obligations relating to security, breach notification, data protection impact assessments (DPIAs), and prior consultation with the supervisory authority.

Article 13 — Audit and review

The Customer may audit Reached’s compliance measures once per year, provided that 30 days’ prior written notice is given; the audit does not compromise the security or confidentiality of other customers’ data; and its scope and frequency remain reasonable. Reached may provide its compliance documents in advance, including a GDPR attestation and a description of its security measures, in order to limit the need for on-site audits.

Article 14 — Retention period

Unless otherwise instructed by the Customer in documented form or required by law, personal data is retained for the durations applicable to the service.

Data category

Retention period

Leads, contacts, and campaigns

For the duration of the contract, then deleted (Article 15)

Call recordings

90 days

Transcripts and summaries

90 days

Call logs

2 years

Article 15 — Data at the end of the contract

Upon termination of the agreement or at the Customer’s request, and at the Customer’s option, Reached undertakes to return the Customer’s personal data in a structured and commonly used format, or permanently delete all of the Customer’s personal data within a maximum of 30 days, unless otherwise required by law. Upon request, Reached will provide a confirmation of destruction and ensure that sub-processors also carry out the deletion.

Article 16 — Order of priority and changes to the DPA

In the event of a conflict between this Agreement and Reached’s Terms of Use, this Agreement prevails with respect to the processing of personal data. Any amendment to this Agreement, including amendments resulting from regulatory, technical, or organizational developments, will be the subject of a written addendum or prior notice to the Customer.

Article 17 — Governing law

Article 17 — Governing law

This Agreement is governed by French law. In the event of a dispute, the courts of Paris, France will have jurisdiction.