This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and M&B Marketing SARL ("Processor"). It applies where the Processor handles personal data on the Controller's behalf under GDPR Article 28.
1. Roles and subject matter
- Controller: the customer. The Controller decides what prospect data is collected and why.
- Processor: M&B Marketing SARL. The Processor handles that data only to deliver the service.
Subject matter: cold email outreach infrastructure. Duration: the term of the service. Nature and purpose: sourcing, verifying, sending, and classifying replies to cold email. Categories of data subjects: the Controller's prospects (business professionals). Categories of personal data: name, professional email address, job role, employer, website, and message content.
2. Processor obligations
The Processor will:
- Process personal data only on the Controller's documented instructions.
- Ensure people authorised to process the data are committed to confidentiality.
- Implement the technical and organisational measures described in section 4.
- Not engage another processor without the Controller's general or specific authorisation; the sub-processors in section 5 are authorised.
- Assist the Controller in responding to data subject requests, security incidents, and data protection impact assessments, where relevant.
- Delete or return all personal data on termination of the service.
- Make available the information needed to demonstrate compliance.
3. Controller obligations
The Controller confirms it has a lawful basis for the processing it instructs, typically legitimate interest for B2B outreach, and that it has satisfied any transparency obligations toward data subjects.
4. Technical and organisational measures
The Processor maintains measures appropriate to the risk, including:
- Credentials encrypted at rest.
- Tenant-scoped access so one customer's data is not visible to another.
- Opt-outs enforced in the send path before send, not after.
- Access control and logging around production systems.
5. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| InfraForge | Domain registration, mailboxes, sending relay | EU/US |
| Smartlead | Warmup pool and placement testing | US |
| Stripe | Payment processing | US/EU |
| DataForSEO / Outscraper | Prospect sourcing and enrichment | EU/US |
Transfers to sub-processors outside the EEA rely on the standard contractual clauses or another valid transfer mechanism.
6. Data subject requests
The Processor will notify the Controller of any data subject request it receives and will not respond directly unless the Controller instructs it to. The Controller remains responsible for responding.
7. Security incidents
The Processor will notify the Controller without undue delay of any personal data breach affecting the Controller's data, and will assist the Controller in meeting its breach-notification obligations.
8. Termination
On termination the Processor will delete or return all personal data, and delete existing copies, unless retention is required by law.
9. Governing law
This DPA is governed by French law and forms part of the Terms of Service.