Data Processing Agreement

Last updated: 10 October 2026

Provided by Inverge. Contact: cdkraan@gmail.com.

Draft Article 28 GDPR terms for customer review. Company identity, security measures, provider contracts and deletion commitments must be confirmed before this agreement is incorporated into your contract.

1. Scope and roles

This draft is between Inverge B.V. (placeholder identity; processor) and the customer identified in the customer agreement (controller, or a processor appointing Inverge as sub-processor). It describes processing under Article 28 GDPR. It becomes binding only when confirmed and incorporated into an accepted customer agreement; publication alone does not execute it.

2. Subject, nature and purpose

Subject: personal data you upload, import, collect through the website snippet or exchange through connected channels.

Nature: storage, organisation, AI-assisted drafting and analysis, sending messages you approve or allow, and synchronising with tools you connect.

Purpose: providing the Inverge Outbound and Inbound features you use. Duration: the term of your subscription plus the deletion period below.

3. Categories of data and data subjects

Data subjects: your prospects, leads, customers, website visitors and your own team members.

Data: names, work contact details, job titles, company details, messages and notes, website activity (pages, referrer, random visitor ID) and form or chat input. Special categories of data are not required and should not be uploaded.

4. Our obligations

Process personal data only on your documented instructions, including for international transfers.

Ensure everyone with access is bound by confidentiality.

Apply appropriate technical and organisational measures (section 7).

Assist you with data subject requests, security, breach notification and impact assessments, taking into account the nature of the processing.

Notify you without undue delay after becoming aware of a personal data breach affecting your data, sharing available details and follow-up information to support your obligations.

Immediately inform you if, in our opinion, an instruction infringes applicable data protection law. Process outside your instructions only when legally required and inform you beforehand unless the law prohibits it.

Make available the information needed to demonstrate compliance, and allow reasonable audits with advance notice.

5. Sub-processors

You give general authorisation for the sub-processors listed on our sub-processors page. We impose equivalent data protection obligations on each and remain responsible for them.

We will announce new sub-processors at least 30 days in advance. You may object on reasonable data protection grounds; if we cannot resolve it, you may terminate the affected service.

6. International transfers

Transfers outside the EEA must have a valid GDPR Chapter V safeguard, such as an applicable adequacy decision or executed Standard Contractual Clauses (Commission Decision 2021/914), with assessments and supplementary measures where necessary. Provider-specific arrangements must be confirmed before this draft is accepted.

7. Security measures

Account-scoped permissions and encrypted storage of customer tool keys. Hosting encryption, backup measures and access-log coverage must be confirmed in the final security annex.

Per-account row-level access controls so customers can only reach their own data.

Role-based staff access (admin, support, sales, finance) checked on the server for every action.

Log minimisation and redaction; actual provider retention and deletion periods must be documented in the final security annex.

Public website endpoints restricted to sites you have allowlisted; outbound website fetching limited to public addresses.

AI safeguards: factual answers only from approved Knowledge, human handoff, and sending limits you control.

8. Deletion and return

At the customer's choice, return or delete personal data after the service ends and delete copies unless law requires retention. Requests can be made through the privacy contact. A verified deletion deadline, return format and backup expiry schedule must be agreed before accepting this draft; no automatic export or deletion flow is asserted here.

9. Your responsibilities

You are responsible for having a legal basis for the data you process, informing data subjects, obtaining consent for website tracking where ePrivacy rules require it, and respecting objections to outreach.

10. Contact

Privacy and DPA questions: cdkraan@gmail.com. Need a countersigned copy for your records? Email us and we'll send one.