Data Processing Agreement

Last updated: June 26, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller," "you") and Sales Blitz AI LLC ("Processor," "we," "us") for the provision of Sales Blitz services. This DPA governs the processing of personal data by Sales Blitz on your behalf, in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.

To execute this DPA for your organization, contact security@salesblitz.ai with your company name, signatory name and title, and billing email. We will return a countersigned copy within 2 business days.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person that the Controller submits to the Service or that the Processor processes on the Controller's behalf. "Processing" means any operation performed on Personal Data, including collection, storage, use, retrieval, transmission, and deletion. "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller. "Data Subject" means the identified or identifiable person to whom Personal Data relates.

2. Scope of Processing

2.1 Subject Matter

The Processor processes Personal Data to provide the Sales Blitz platform, a sales intelligence platform with an optional sending add-on. This includes account management, building the Controller's account and contact book (research, enrichment, buying-committee mapping, account grading, and entry angles), monitoring public buying signals and delivering a signal feed, and, for Controllers who enable the deliverability add-on, sending outreach on the Controller's behalf and delivering signals into the Controller's own connected systems such as Salesforce and Slack.

2.2 Duration

Processing begins on the date the Controller creates an account and continues until the Controller deletes their account or the service agreement terminates, plus 30 days for final data deletion.

2.3 Nature and Purpose

The Processor processes Personal Data for the purpose of providing sales intelligence and, optionally, outreach delivery as described in the Sales Blitz Terms of Service. Processing activities include storing user profiles, researching target companies and contacts using publicly available data and enrichment providers, grading and ranking accounts, monitoring public signals, delivering the signal feed, and, for the deliverability add-on, personalizing and sending outreach and syncing activity into the Controller's connected systems.

2.4 Types of Personal Data

Category Examples Source
Account Data Name, email, authentication credentials User-provided at registration
Profile Data Company name, website, who the Controller sells to User-provided; supplemented by our research
Account & Contact Data (the book) Prospect names, titles, company names, email addresses, role and tenure data, buying-committee mapping User-selected accounts; enriched from public sources and enrichment providers
Research Data Publicly available company information, news, funding, public posts Web research (public sources)
Signal Data Job changes, new-in-seat moves, posts, funding events, buying windows, website visits Public signal providers; the Controller's connected systems
Outreach Data (add-on) Drafted and sent messages, reply content, send/open/reply/bounce events Generated from the book; sent and received via the Controller's connected sending accounts
Usage Data Feature usage, timestamps, interaction patterns Automatically collected
Payment Data Billing address, payment method (handled by Stripe) User-provided via Stripe

2.5 Categories of Data Subjects

The Controller's employees and authorized users of the Service. Also the Controller's prospective customers and contacts, the people in the accounts the Controller chooses to cover.

3. Obligations of the Processor

3.1 Processing Instructions

The Processor shall process Personal Data only on documented instructions from the Controller, unless required by applicable law. The Controller's instructions are defined by the functionality of the Service as described in the Terms of Service and this DPA.

3.2 Confidentiality

The Processor ensures that persons authorized to process Personal Data are bound by confidentiality obligations.

3.3 Security Measures

The Processor implements appropriate technical and organizational measures to protect Personal Data, including:

A detailed description of security measures is available at salesblitz.ai/security.

3.4 Sub-Processors

The Controller provides general written authorization for the Processor to engage Sub-Processors. The current list of Sub-Processors is in Annex A below. The Processor will notify the Controller at least 14 days before adding or replacing a Sub-Processor, via email to the address on file. If the Controller objects, the parties will work in good faith to resolve the concern. If no resolution is reached, the Controller may terminate the affected service component.

3.5 Data Subject Rights

The Processor will assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. The Processor provides self-service data deletion within the application and processes manual requests within 30 days.

3.6 Data Breach Notification

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach. Notification will include the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.

3.7 Data Protection Impact Assessment

The Processor will provide reasonable assistance to the Controller for data protection impact assessments and prior consultations with supervisory authorities, to the extent required under applicable law.

3.8 Deletion and Return

Upon termination of the service agreement or upon the Controller's request, the Processor will delete all Personal Data within 30 days, unless retention is required by applicable law. The Controller may request a data export before deletion.

4. Obligations of the Controller

The Controller warrants that it has a lawful basis for processing Personal Data submitted to the Service, including a legitimate basis for contacting the prospects in its book. It further warrants that it has provided appropriate notice to Data Subjects where required, that its instructions to the Processor comply with applicable data protection law, and that it will promptly notify the Processor of any Data Subject requests or complaints related to the processing.

5. International Data Transfers

Sales Blitz processes data primarily in the United States. For transfers of Personal Data from the EEA, UK, or Switzerland to the US, the parties rely on the EU-US Data Privacy Framework (DPF) where applicable, and Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914) where DPF coverage does not apply. The SCCs are incorporated by reference and available upon request.

6. Audit Rights

The Controller may audit the Processor's compliance with this DPA once per year, with 30 days' written notice. Audits shall be conducted during business hours and shall not unreasonably interfere with the Processor's operations. The Processor may satisfy audit requests by providing its SOC 2 report, penetration test summary, or other third-party audit documentation.

7. Liability

Each party's liability under this DPA is subject to the limitations set forth in the underlying service agreement (Terms of Service). Nothing in this DPA limits either party's liability for breaches of data protection law to the extent such limitation is prohibited by applicable law.

8. Term

This DPA takes effect when the Controller begins using the Service and remains in effect until all Personal Data is deleted or returned per Section 3.8.

Annex A: Sub-Processor List

Delivery and data vendors are described by function rather than by name. The named vendor for any function is available on request under the notification process in Section 3.4.

Sub-Processor Purpose Data Categories Location
Supabase, Inc. Database hosting, vector storage, file storage All application data United States (AWS us-east-1)
Anthropic, PBC AI language model (research, grading, drafting) Company/contact info, research context, prompts United States
Google LLC Text embeddings for search Research text for semantic indexing United States
Clerk, Inc. User authentication and identity Name, email, auth credentials, session data United States
Stripe, Inc. Payment processing Billing info, payment methods United States (PCI DSS Level 1)
Vercel, Inc. Application hosting, edge functions HTTP requests, session cookies United States (multi-region edge)
Railway Corp. Worker service hosting Processing queue data, API calls United States (US-West)
Resend, Inc. Transactional email delivery Recipient email, notification content United States
Web research provider Public web search for research Search queries (company/industry terms) United States
Data enrichment provider Contact and company data enrichment Company/contact lookup queries United States
Signal data providers Public buying-signal monitoring Account/person identifiers, public events United States
Email delivery provider (add-on) Sending outreach for Controllers on the deliverability add-on Prospect emails, prospect metadata, campaign data, delivery events United States
LinkedIn delivery provider (add-on) Running LinkedIn steps for Controllers on the deliverability add-on Prospect profile identifiers, message content United States
Cloudflare, Inc. DNS & DDoS protection Domain routing, traffic metrics United States

The Controller's own connected systems (such as Salesforce and Slack) are not sub-processors. They are the Controller's systems, accessed under the authorization the Controller grants and revocable at any time.

Annex B: Standard Contractual Clauses

For international transfers requiring SCCs, the EU Commission Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference. A copy is available upon request at security@salesblitz.ai.

Execution

To execute this DPA, email security@salesblitz.ai with your company name, signatory name and title, and billing email address. We will return a countersigned PDF copy within 2 business days.