Data Processing Agreement
Last updated: June 26, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller," "you") and Sales Blitz AI LLC ("Processor," "we," "us") for the provision of Sales Blitz services. This DPA governs the processing of personal data by Sales Blitz on your behalf, in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.
To execute this DPA for your organization, contact security@salesblitz.ai with your company name, signatory name and title, and billing email. We will return a countersigned copy within 2 business days.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that the Controller submits to the Service or that the Processor processes on the Controller's behalf. "Processing" means any operation performed on Personal Data, including collection, storage, use, retrieval, transmission, and deletion. "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller. "Data Subject" means the identified or identifiable person to whom Personal Data relates.
2. Scope of Processing
2.1 Subject Matter
The Processor processes Personal Data to provide the Sales Blitz platform, a sales intelligence platform with an optional sending add-on. This includes account management, building the Controller's account and contact book (research, enrichment, buying-committee mapping, account grading, and entry angles), monitoring public buying signals and delivering a signal feed, and, for Controllers who enable the deliverability add-on, sending outreach on the Controller's behalf and delivering signals into the Controller's own connected systems such as Salesforce and Slack.
2.2 Duration
Processing begins on the date the Controller creates an account and continues until the Controller deletes their account or the service agreement terminates, plus 30 days for final data deletion.
2.3 Nature and Purpose
The Processor processes Personal Data for the purpose of providing sales intelligence and, optionally, outreach delivery as described in the Sales Blitz Terms of Service. Processing activities include storing user profiles, researching target companies and contacts using publicly available data and enrichment providers, grading and ranking accounts, monitoring public signals, delivering the signal feed, and, for the deliverability add-on, personalizing and sending outreach and syncing activity into the Controller's connected systems.
2.4 Types of Personal Data
| Category | Examples | Source |
|---|---|---|
| Account Data | Name, email, authentication credentials | User-provided at registration |
| Profile Data | Company name, website, who the Controller sells to | User-provided; supplemented by our research |
| Account & Contact Data (the book) | Prospect names, titles, company names, email addresses, role and tenure data, buying-committee mapping | User-selected accounts; enriched from public sources and enrichment providers |
| Research Data | Publicly available company information, news, funding, public posts | Web research (public sources) |
| Signal Data | Job changes, new-in-seat moves, posts, funding events, buying windows, website visits | Public signal providers; the Controller's connected systems |
| Outreach Data (add-on) | Drafted and sent messages, reply content, send/open/reply/bounce events | Generated from the book; sent and received via the Controller's connected sending accounts |
| Usage Data | Feature usage, timestamps, interaction patterns | Automatically collected |
| Payment Data | Billing address, payment method (handled by Stripe) | User-provided via Stripe |
2.5 Categories of Data Subjects
The Controller's employees and authorized users of the Service. Also the Controller's prospective customers and contacts, the people in the accounts the Controller chooses to cover.
3. Obligations of the Processor
3.1 Processing Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, unless required by applicable law. The Controller's instructions are defined by the functionality of the Service as described in the Terms of Service and this DPA.
3.2 Confidentiality
The Processor ensures that persons authorized to process Personal Data are bound by confidentiality obligations.
3.3 Security Measures
The Processor implements appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Authentication via Clerk with multi-factor authentication support
- Encrypted, per-account storage of connected-system access tokens
- Rate limiting and spend controls on all API endpoints
- Content Security Policy (CSP) and security headers
- Access controls limiting production system access to authorized personnel
- Automated database backups with point-in-time recovery
- Application logging and monitoring for security events
- Incident response procedures with defined notification timelines
A detailed description of security measures is available at salesblitz.ai/security.
3.4 Sub-Processors
The Controller provides general written authorization for the Processor to engage Sub-Processors. The current list of Sub-Processors is in Annex A below. The Processor will notify the Controller at least 14 days before adding or replacing a Sub-Processor, via email to the address on file. If the Controller objects, the parties will work in good faith to resolve the concern. If no resolution is reached, the Controller may terminate the affected service component.
3.5 Data Subject Rights
The Processor will assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. The Processor provides self-service data deletion within the application and processes manual requests within 30 days.
3.6 Data Breach Notification
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach. Notification will include the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.
3.7 Data Protection Impact Assessment
The Processor will provide reasonable assistance to the Controller for data protection impact assessments and prior consultations with supervisory authorities, to the extent required under applicable law.
3.8 Deletion and Return
Upon termination of the service agreement or upon the Controller's request, the Processor will delete all Personal Data within 30 days, unless retention is required by applicable law. The Controller may request a data export before deletion.
4. Obligations of the Controller
The Controller warrants that it has a lawful basis for processing Personal Data submitted to the Service, including a legitimate basis for contacting the prospects in its book. It further warrants that it has provided appropriate notice to Data Subjects where required, that its instructions to the Processor comply with applicable data protection law, and that it will promptly notify the Processor of any Data Subject requests or complaints related to the processing.
5. International Data Transfers
Sales Blitz processes data primarily in the United States. For transfers of Personal Data from the EEA, UK, or Switzerland to the US, the parties rely on the EU-US Data Privacy Framework (DPF) where applicable, and Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914) where DPF coverage does not apply. The SCCs are incorporated by reference and available upon request.
6. Audit Rights
The Controller may audit the Processor's compliance with this DPA once per year, with 30 days' written notice. Audits shall be conducted during business hours and shall not unreasonably interfere with the Processor's operations. The Processor may satisfy audit requests by providing its SOC 2 report, penetration test summary, or other third-party audit documentation.
7. Liability
Each party's liability under this DPA is subject to the limitations set forth in the underlying service agreement (Terms of Service). Nothing in this DPA limits either party's liability for breaches of data protection law to the extent such limitation is prohibited by applicable law.
8. Term
This DPA takes effect when the Controller begins using the Service and remains in effect until all Personal Data is deleted or returned per Section 3.8.
Annex A: Sub-Processor List
Delivery and data vendors are described by function rather than by name. The named vendor for any function is available on request under the notification process in Section 3.4.
| Sub-Processor | Purpose | Data Categories | Location |
|---|---|---|---|
| Supabase, Inc. | Database hosting, vector storage, file storage | All application data | United States (AWS us-east-1) |
| Anthropic, PBC | AI language model (research, grading, drafting) | Company/contact info, research context, prompts | United States |
| Google LLC | Text embeddings for search | Research text for semantic indexing | United States |
| Clerk, Inc. | User authentication and identity | Name, email, auth credentials, session data | United States |
| Stripe, Inc. | Payment processing | Billing info, payment methods | United States (PCI DSS Level 1) |
| Vercel, Inc. | Application hosting, edge functions | HTTP requests, session cookies | United States (multi-region edge) |
| Railway Corp. | Worker service hosting | Processing queue data, API calls | United States (US-West) |
| Resend, Inc. | Transactional email delivery | Recipient email, notification content | United States |
| Web research provider | Public web search for research | Search queries (company/industry terms) | United States |
| Data enrichment provider | Contact and company data enrichment | Company/contact lookup queries | United States |
| Signal data providers | Public buying-signal monitoring | Account/person identifiers, public events | United States |
| Email delivery provider (add-on) | Sending outreach for Controllers on the deliverability add-on | Prospect emails, prospect metadata, campaign data, delivery events | United States |
| LinkedIn delivery provider (add-on) | Running LinkedIn steps for Controllers on the deliverability add-on | Prospect profile identifiers, message content | United States |
| Cloudflare, Inc. | DNS & DDoS protection | Domain routing, traffic metrics | United States |
The Controller's own connected systems (such as Salesforce and Slack) are not sub-processors. They are the Controller's systems, accessed under the authorization the Controller grants and revocable at any time.
Annex B: Standard Contractual Clauses
For international transfers requiring SCCs, the EU Commission Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference. A copy is available upon request at security@salesblitz.ai.
Execution
To execute this DPA, email security@salesblitz.ai with your company name, signatory name and title, and billing email address. We will return a countersigned PDF copy within 2 business days.