Data Processing Agreement (DPA)
Version 1.1 · Effective: August 28, 2026 · FANARI OÜ (registration code 16648170), Tallinn, Estonia
Standalone copy of the Data Processing Addendum
This page reproduces Section 8 of our Terms of Service as a standalone document (Art. 28(3) GDPR) for customer procurement and compliance reviews. It is automatically part of every customer agreement - no signature is required for it to apply. If your organisation requires a countersigned copy, email info@balticleads.ee with the subject "DPA countersignature" and we will return a signed PDF of this version. In case of conflict, the English text of the Terms of Service prevails.
8. Data Processing Addendum (DPA)
This Section 8 forms a binding Data Processing Agreement under GDPR Article 28(3) between you (the "Controller") and the Provider (the "Processor") in respect of Recipient Data and email content processed by the Provider on your behalf.
8.1 Subject matter, duration, nature and purpose
- Subject matter: processing of Recipient Data and email content for the purpose of operating B2B email campaigns initiated by the Controller
- Duration: for the term of these Terms plus any retention period required by law or specified in the Privacy Policy
- Nature and purpose: ingestion of public registry data, exposure to the Controller via search and filter UI, sending of campaign emails via the Controller's mail credentials, recording of send/reply metadata for the Controller's reporting
- Type of personal data: business contact data (company name, business email, address, registration code, business activity), email message metadata (Message-ID, timestamps), short reply excerpts
- Categories of data subjects: registered business entities and their named representatives where named in public registries; recipients of campaign emails
8.2 Processor obligations (we will)
- Process personal data only on your documented instructions, including transfers outside the EEA where necessary, unless required by EU or Member State law to which we are subject
- Ensure that personnel authorized to process the data are bound by confidentiality
- Implement appropriate technical and organisational measures listed in our Privacy Policy Section 11
- Engage sub-processors only on terms providing equivalent protection and listed in Privacy Policy Section 6; notify you of material changes with at least 30 days advance notice and right to object
- Assist you, taking into account the nature of the processing, in fulfilling your obligation to respond to data subject requests under GDPR Chapter III
- Assist you in complying with Articles 32-36 (security, breach notification, impact assessment, prior consultation)
- At your choice, delete or return all personal data after termination of the Service, subject to legal retention obligations
- Make available all information necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, conducted by you or another auditor mandated by you (subject to mutually agreed reasonable scope and frequency)
- Notify you without undue delay of any personal data breach affecting your data, with sufficient information to allow you to fulfil your obligations under Articles 33-34
8.3 Controller obligations (you will)
- Establish and document a lawful basis for your processing of Recipient Data; the standard basis is GDPR Art. 6(1)(f) legitimate interest as analysed in our Privacy Policy Section 5
- Provide all required transparency information to data subjects in your own communications (e.g. identifying yourself in emails, including unsubscribe and contact for data subject requests)
- Promptly handle data subject requests received directly from Recipients
- Comply with the Acceptable Use Policy in Section 6
- Not provide the Processor with special categories of personal data (Art. 9) or criminal data (Art. 10)
8.4 International transfers
Where the Processor transfers personal data outside the EEA via approved sub-processors (Stripe, Anthropic, Google, Microsoft when used), the Processor relies on Standard Contractual Clauses (Commission Decision (EU) 2021/914) or adequacy decisions, as applicable. For transfers to Anthropic, PBC the Processor relies on the Controller-to-Processor Standard Contractual Clauses (Module Two); a transfer impact assessment is available on request.
8.5 Conflict
In case of conflict between this DPA and other parts of these Terms, this DPA prevails for matters of personal data protection.
8.6 Independent processing by the Provider
For (a) inferring a probable contact address where none is published in a registry, (b) maintaining and enforcing the cross-platform opt-out list described in the Privacy Policy, and (c) automated and manual pre-send compliance screening, the Provider determines the purposes and means of processing and acts as an independent Data Controller, relying on its legitimate interest (Art. 6(1)(f) GDPR) in operating a lawful, abuse-resistant platform. This does not affect your role as Controller for all other Recipient Data processing under this DPA.
Related: Terms of Service · Privacy Policy · Imprint