This Data Processing Addendum ("DPA") is part of the Terms of Service between Minor Tangent Studios LLC ("LeadScout", "we") and the customer who uses the Service ("Customer", "you"). It applies when we process Personal Data on your behalf and the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA or another data protection law applies. It applies automatically, with no signature needed. If you need a countersigned copy, email support@getleadscout.io.
1. Definitions
"Customer Personal Data" means personal data that you or your leads submit to the Service or that we collect for a Scout at your request, such as lead names, emails, phone numbers and messages, and personal data found in public sources about the businesses you research. "Data Protection Law" means the laws above and any similar law that applies. "Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings in Data Protection Law. "Sub-processor" means a third party we engage to process Customer Personal Data.
2. Roles
You are the controller (or the processor acting for another controller) of Customer Personal Data and we are your processor (or sub-processor). We are the independent controller of your own account data (see our Privacy Policy). Annex 1 describes the processing.
3. Our obligations
We will:
- Process Customer Personal Data only on your documented instructions, which are these terms, the Terms of Service and your use of the Service's features. If we think an instruction breaks Data Protection Law we will tell you.
- Ensure everyone authorized to process it is bound by confidentiality.
- Apply the security measures in Annex 2.
- Respect the sub-processor conditions in section 5.
- Help you respond to data subject requests, taking into account the nature of the processing. If a data subject contacts us directly about Customer Personal Data, we will refer them to you unless the law requires otherwise. You can delete a lead's scouts and your whole account in the app.
- Notify you without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting Customer Personal Data, with the information we have to help you meet your own obligations.
- Help with data protection impact assessments and prior consultations where reasonably needed, at your cost if the help is substantial.
- On deletion of your account, delete Customer Personal Data from our live systems. Copies in backups are overwritten as backups rotate (see the Privacy Policy). On request made before deletion we will give you your reports in a common format.
- Make available the information needed to show we comply with this DPA and allow audits as in section 7.
4. Your obligations
You confirm that you have a lawful basis and have given all required notices for the Customer Personal Data you submit, that your instructions comply with Data Protection Law, and that you will not submit special-category or children's data or other data the Service is not designed for. You are responsible for your leads' requests as a controller.
5. Sub-processors
You give us general authorization to use the sub-processors in Annex 3. We will give at least 14 days' notice (by email or on our website) before adding or replacing one. You may object on reasonable data protection grounds in that period; if we can't resolve it, you may stop using the Service and delete your account. We have a written agreement with each sub-processor imposing obligations no less protective than this DPA and remain responsible for their performance.
6. International transfers
We and our sub-processors may process Customer Personal Data in the United States and other countries. Where Data Protection Law requires a transfer mechanism, the following apply and are incorporated by reference:
- EEA: the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor) and, where you are a processor, Module Three, with: Clause 7 docking clause included; Clause 9(a) Option 2 general authorization with the notice period in section 5; Clause 11 optional language omitted; Clause 17 Option 1 and Clause 18 the law and courts of Ireland; Annexes I to III completed by Annexes 1 to 3 below.
- UK: the UK International Data Transfer Addendum to the EU SCCs, in the form issued by the ICO, with the tables completed by this DPA.
- Switzerland: the EU SCCs above, with references to the GDPR read as the Swiss FADP and the Swiss FDPIC as competent authority.
- Where available, we may instead rely on the EU-US Data Privacy Framework certification of the recipient.
If there is a conflict, the SCCs prevail over this DPA, and this DPA over the Terms of Service, as to Customer Personal Data.
7. Audits
Once a year, or after a personal data breach, you may ask us for the information reasonably needed to confirm we comply with this DPA, and we will answer in writing. If that is not enough, you may carry out an audit on 30 days' notice, during business hours, at your cost, under confidentiality, without access to other customers' data and in a way that doesn't disrupt our operations. The SCCs' audit rights are exercised this way.
8. US state privacy laws
Where CCPA/CPRA or a similar US state law applies, we are your "service provider" or "processor". We will not sell or share Customer Personal Data, retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the Service and those permitted by law, or combine it with other data except as the law allows. We will tell you if we can no longer meet our obligations, and you may take reasonable steps to stop and remediate unauthorized use. We certify that we understand these restrictions.
9. Liability and term
Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law or the SCCs say otherwise. This DPA lasts as long as we process Customer Personal Data for you. Sections that by nature survive, do.
10. Contact
Data protection contact: support@getleadscout.io.
Annex 1: Details of processing
| Data exporter | The Customer |
|---|---|
| Data importer | Minor Tangent Studios LLC, 55 Everglades Blvd, #110-52, Naples, FL 34120 |
| Data subjects | The Customer's leads and prospects; people connected to the businesses the Customer researches (owners, staff, reviewers); people named in notes the Customer enters |
| Categories of data | Names, business and personal email addresses, phone numbers, job roles, messages submitted through forms, website and social-profile links, and information about the person's business found in public sources |
| Sensitive data | None intended. The Service is not designed for special-category data |
| Nature and purpose | Storing lead and request data, researching the named business from public sources with automated tools and AI models, generating and delivering reports, and supporting the Customer |
| Frequency | Continuous, each time a Scout is requested or a lead is submitted |
| Duration and retention | Until the Customer deletes the Scout or account, then as described in section 3(8) |
| Competent supervisory authority | The supervisory authority of the Customer's establishment or representative; where the Customer is not established in the EEA, the Irish Data Protection Commission |
Annex 2: Security measures
- Encryption of data in transit between users, the Service and sub-processors.
- Database access limited to our application servers; row-level security denies direct database API access; each customer's data is scoped to their account in code.
- Passwords handled by a dedicated authentication provider and stored only as hashes; optional two-factor authentication for all users and mandatory for administrators; bot protection on sign-in and sign-up.
- Rate limiting and abuse controls on sign-in, public forms and webhooks.
- Outbound webhooks are signed and blocked from reaching private or internal network addresses.
- Generated reports are displayed in a sandboxed frame and rendered to PDF in an isolated browser with scripts and network access disabled.
- AI requests are sent with zero data retention required, so model providers don't store prompts or outputs or use them for training.
- Least-privilege access to production systems and secrets; secrets kept outside source control.
- Automated tests and migration checks on code changes; logging of errors.
- Personal data breach response process as described in section 3(6).
Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Authentication, database hosting | US East (N. Virginia) |
| Vercel Inc. | Application hosting, background workflows, AI Gateway | United States (and global edge network) |
| OpenAI OpCo, LLC and other providers available through Vercel AI Gateway, all with zero data retention required | Generating report text from request details and public web content | United States |
| Exa Labs, Inc., via Vercel AI Gateway | Web search queries during research | United States |
| Firecrawl (Mendable AI, Inc.) | Searching and reading public web pages | United States |
| Sequenzy | Sending report and service emails | United States |
| Cloudflare, Inc. | Bot protection (Turnstile) on sign-in and sign-up forms | Global |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | United States |
Stripe, Inc. processes payments as an independent controller and is not a sub-processor of Customer Personal Data.
