Data Processing Addendum

Last updated: October 1, 2026

This Data Processing Addendum ("DPA") forms part of the Terms and Conditions (the "Terms") between Audienceful LLC ("Audienceful," "we," "us," or "our") and the customer that has agreed to the Terms ("Customer" or "you"). It applies whenever Audienceful processes Customer Personal Data on your behalf in providing the Services.

No signature is required. This DPA is incorporated into the Terms and takes effect automatically when you accept them. If your organization needs a countersigned copy for its records, email support@audienceful.com with "DPA" in the subject line and we will send one.

1. Definitions

Capitalized terms not defined here have the meaning given in the Terms.

  • "Data Protection Laws" means all data protection and privacy laws that apply to the processing of Customer Personal Data under the Terms, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as it forms part of UK law ("UK GDPR") and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
  • "Customer Personal Data" means personal data that Customer (or someone acting for Customer) submits to, or collects through, the Services and that Audienceful processes on Customer's behalf, for example, the contacts on your lists and the data collected through your signup forms. It does not include the account, billing, and usage data Audienceful processes as a controller, which is covered by our Privacy Policy.
  • "Subprocessor" means a third party engaged by Audienceful that processes Customer Personal Data.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • "Controller," "processor," "data subject," "personal data," "processing," and "supervisory authority" have the meanings given in the GDPR. "Business," "service provider," "sell," and "share" have the meanings given in the CCPA.

2. Roles of the parties

For Customer Personal Data, Customer is the controller (or a processor acting for its own controller) and Audienceful is a processor (or subprocessor). Each party will comply with the Data Protection Laws that apply to it.

Customer is responsible for the lawfulness of the Customer Personal Data it provides and for its instructions to us. In particular, Customer confirms that it has a lawful basis, including any required consent, to collect the Customer Personal Data and to send email and SMS messages to its contacts, consistent with the Terms and our Acceptable Use Policy.

3. Processing instructions

Audienceful will process Customer Personal Data only on Customer's documented instructions, unless required to do otherwise by law (in which case we will tell you before processing, unless the law prohibits it). Customer's instructions are:

  • the Terms and this DPA;
  • processing initiated by Customer and its users through the Services, including through its settings, the API, integrations Customer connects, and requests to the AI agent; and
  • other reasonable written instructions Customer gives us that are consistent with the Terms.

We will tell you if we believe an instruction infringes Data Protection Laws. The details of the processing are set out in Annex I below.

Audienceful will not use Customer Personal Data to train AI models, and will not sell Customer Personal Data or use it for advertising.

4. Confidentiality

Audienceful will ensure that everyone authorized to process Customer Personal Data is bound by an appropriate duty of confidentiality, and will limit access to those who need it to provide, secure, and support the Services.

5. Security

Audienceful will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing. Our current measures are described in Annex II below. We may update them over time, provided the overall level of protection is not reduced.

6. Subprocessors

Customer gives Audienceful general authorization to engage Subprocessors. Our current Subprocessors are listed in Annex III below.

  • Contracts. We will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those in this DPA, and we remain responsible for each Subprocessor's performance of those obligations.
  • Changes. We will update the list in Annex III at least 14 days before a new Subprocessor begins processing Customer Personal Data. To be notified by email, write to support@audienceful.com with "Subprocessor updates" in the subject line.
  • Objections. Customer may object to a new Subprocessor on reasonable data protection grounds by emailing us within that 14-day period. We will work with you in good faith to resolve the objection. If we cannot, either party may terminate the affected Services, and we will refund any prepaid fees for the unused portion of the term.

Third-party services that Customer chooses to connect to its workspace (for example, a CRM, form, or e-commerce integration) are not Audienceful Subprocessors. Data shared with them is shared at Customer's direction and is governed by Customer's own agreement with that provider.

7. Data subject requests

Taking into account the nature of the processing, Audienceful will assist Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. The Services let Customer view, edit, export, unsubscribe, and delete contacts directly. If we receive a request directly from one of your contacts, we will not respond to it ourselves (other than to tell the requester to contact you), and we will forward it to you promptly where we can identify you as the relevant customer.

8. Security incidents

If Audienceful becomes aware of a Security Incident, we will notify Customer without undue delay, and in any event within 72 hours. We will provide the information we reasonably can about the nature of the incident, the data and data subjects affected, its likely consequences, and the measures taken or proposed to address it, and we will update you as more information becomes available. We will take reasonable steps to contain and remediate the incident. Notifying you of a Security Incident is not an admission of fault or liability.

9. Assistance with assessments and consultations

Taking into account the nature of the processing and the information available to us, Audienceful will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that relate to Customer's use of the Services.

10. Return and deletion

Customer can export its Customer Personal Data at any time while its account is active. When Customer deletes its account or workspace, or when the Terms end, Audienceful will delete Customer Personal Data from its active systems within 30 days and from its backups within 90 days. Backup copies are not restored or otherwise processed in the meantime. We may retain Customer Personal Data where required by law, in which case this DPA continues to apply to it and we will process it only as that law requires.

11. Audits and information

On written request, Audienceful will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires.

If that information is not enough to demonstrate compliance, or a supervisory authority requires it, Customer may audit our compliance with this DPA, either itself or through an independent auditor bound by confidentiality. Audits are limited to once per year (unless following a Security Incident or required by a supervisory authority), require at least 30 days' written notice, must be conducted during normal business hours without unreasonably disrupting our operations, and are at Customer's expense. Audits will not include access to other customers' data or to information subject to legal privilege.

Audits are conducted remotely, through document review, written questions, and video calls. An on-site inspection is permitted only where a supervisory authority or Data Protection Laws require one, and is subject to the same conditions. Our infrastructure is hosted by our cloud provider, so the physical security of data centers is evidenced through that provider's independent audit reports rather than by inspection.

Responding to information requests and security questionnaires is free. For time our personnel spend supporting an audit beyond that, Customer will pay our then-current professional services rates, and we will give Customer a written estimate before the audit begins.

12. International transfers

Audienceful and its Subprocessors process Customer Personal Data in the United States and in the other locations listed in Annex III. To the extent Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not been found to provide an adequate level of data protection, the parties agree to the following safeguards, which are incorporated into this DPA by reference:

  • EEA transfers. The SCCs apply, using Module Two (controller to processor) where Customer is a controller and Module Three (processor to processor) where Customer is a processor. For the SCCs: Clause 7 (docking clause) does not apply; under Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 6 of this DPA; the optional wording in Clause 11 does not apply; under Clause 13, the competent supervisory authority is the one determined by Customer's establishment or representative in the EEA; under Clauses 17 and 18, the SCCs are governed by the laws of, and disputes are resolved by the courts of, Ireland. Annexes I and II of the SCCs are completed by Annexes I and II of this DPA, and the list of subprocessors is Annex III.
  • UK transfers. The SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0, in force 21 March 2022). Table 1 is completed with the parties' details in this DPA, Table 2 with the SCC selections above, Table 3 with the Annexes to this DPA, and in Table 4 either party may end the Addendum as set out in its Section 19.
  • Swiss transfers. The SCCs apply with these changes: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to "Member State" do not prevent data subjects in Switzerland from bringing claims where they habitually reside; and the SCCs protect data of legal entities to the extent the FADP does.

If the SCCs conflict with this DPA, the SCCs control. If a transfer mechanism is invalidated or replaced, we will work with Customer in good faith to adopt an appropriate alternative.

13. CCPA

To the extent the CCPA applies to Customer Personal Data, Audienceful is Customer's service provider and Customer discloses the data to us only for the limited and specified business purposes set out in Annex I. Audienceful will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than providing the Services under the Terms, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between Customer and Audienceful; or (d) combine it with personal data we receive from other sources, except as the CCPA permits. Audienceful will comply with the CCPA's applicable obligations, provide the same level of privacy protection the CCPA requires of businesses, and notify Customer if we determine we can no longer meet those obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data. We certify that we understand and will comply with these restrictions.

14. General terms

  • Liability. Each party's liability arising out of or related to this DPA is subject to the limitations of liability in the Terms, except where Data Protection Laws or the SCCs do not allow such a limitation.
  • Order of precedence. If this DPA conflicts with the Terms, this DPA controls as to the processing of Customer Personal Data. If the SCCs conflict with this DPA or the Terms, the SCCs control.
  • Duration. This DPA lasts as long as Audienceful processes Customer Personal Data under the Terms.
  • Updates. We may update this DPA to reflect changes in Data Protection Laws, our Services, or our Subprocessors. Updates will not reduce the overall protection of Customer Personal Data and will be indicated by the "Last updated" date above.

Annex I: Details of processing

Parties. Data exporter: Customer, as identified in its Audienceful account, acting as controller (or processor). Data importer: Audienceful LLC, 220 W Congress St Fl 2nd Floor #3302, Detroit, MI 48226, United States, acting as processor (or subprocessor). Contact: support@audienceful.com, with "DPO" in the subject line. Activities: providing the Services described in the Terms.

Categories of data subjects.

  • Customer's contacts, subscribers, and prospects
  • People who submit Customer's signup forms or otherwise interact with Customer's emails, SMS messages, and published pages
  • Customer's authorized users, to the extent their personal data appears in Customer's content
  • Any other individuals whose personal data Customer chooses to include in the Services

Categories of personal data.

  • Contact details, such as email address, name, and phone number
  • Custom fields and tags Customer defines and populates
  • Data synced from integrations Customer connects
  • Engagement data, such as email opens, clicks, unsubscribes, bounces, and form submissions, including associated IP addresses, approximate location, and device or browser information
  • Content Customer creates or uploads, including emails, SMS messages, images, files, and AI agent conversations

Special categories of data. None. Customer agrees not to submit special categories of personal data (such as health, biometric, or religious data) or government identification or payment card numbers to the Services.

Frequency of transfer. Continuous, for as long as Customer uses the Services.

Nature and purpose of processing. Hosting and storing Customer Personal Data; managing contact lists and audiences; sending email and SMS messages Customer creates or schedules; running automations; tracking and reporting on engagement; collecting signup form submissions; syncing data with integrations Customer connects; generating, editing, and analyzing content with the AI agent at Customer's request (contacts are referenced to AI providers by internal identifier only, and contact email addresses, names, and custom field values are not disclosed to them); providing support; and maintaining the security and reliability of the Services.

Duration and retention. For the term of the Terms, plus the deletion period described in Section 10.

Subprocessor transfers. As listed in Annex III, for the same subject matter, nature, and duration as above.

Annex II: Security measures

  • Encryption. Data is encrypted in transit using TLS. Data stored with our hosting provider is encrypted at rest, and passwords are never stored in plain text.
  • Access control. Production access is limited to personnel who need it, using individual accounts and least-privilege permissions. Support staff and contractors do not have access to customers' contact list data.
  • Workspace isolation. Customer Personal Data is logically separated by workspace, and the AI agent can only access the workspace it is used in.
  • Infrastructure. The Services run on managed cloud infrastructure with physical security, redundancy, and network protections provided by our hosting provider.
  • Monitoring. We log and monitor the Services for errors, abuse, and suspicious activity.
  • Resilience. We take regular backups and maintain procedures to restore availability and access to data after an incident.
  • Incident response. We maintain a process for investigating, containing, and notifying affected customers of Security Incidents.
  • Vendor management. We review Subprocessors' security and privacy practices before engaging them, and bind them to written data protection terms.
  • Data minimization. We collect and keep only the data needed to provide the Services, and delete it as described in Section 10.

Annex III: Subprocessors

All Subprocessors are based in the United States. Transfers to them rely on the Standard Contractual Clauses or, where the recipient participates in it, the EU-U.S. Data Privacy Framework.

Subprocessor Purpose Data involved
DigitalOcean Cloud hosting, databases, and object storage, including files uploaded to the AI agent All Service data
Mailgun Email delivery and engagement tracking Recipient email addresses, message content, and open, click, and bounce events
Stripe Payment processing Billing and payment data
OpenRouter AI routing gateway for all model requests AI agent requests and the workspace content in them. No data from your contact records
Google AI model provider (chat, image generation, summarization), reached through OpenRouter AI agent requests routed to it
OpenAI AI model provider (chat fallback, embeddings), reached through OpenRouter AI agent requests routed to it
Anthropic AI model provider (chat fallback), reached through OpenRouter AI agent requests routed to it
Sentry Error monitoring Diagnostic data from application errors, which may incidentally include Service data