Third Party Index

Snapshot 44774

Document
Data processing addendum
URL
https://leadmagic.io/legal/dpa
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
215602 bytes
SHA-256 (raw)
aafdef4d37970ee1806a40027533cf672ffb0bb32d095eef39dc68b74eaebfe8
SHA-256 (normalized text)
9d00ea9f20828a42e79f58161316dab01ed91c6e4d84a73cf74924d8809c68fe

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
New
Unlimited Search is live — zero-credit People, Company & Jobs Search at 5–10 RPSUnlimited Search is live
Try Unlimited
Data Processing Agreement
Last Updated: August 28, 2026
1. Parties and Incorporation
This Data Processing Agreement ("DPA") is between Lead Magic Corporation ("LeadMagic," "we," or "us") and the customer that accepts the LeadMagic Terms of Service or an applicable Order Form ("Customer"). It forms part of those Terms or Order Form. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls for that subject only.
This DPA applies where LeadMagic processes Customer Personal Data as a processor or service provider under the EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, and other applicable data protection laws ("Data Protection Laws").
2. Definitions
Customer Personal Data — personal data Customer or its Authorized Users upload or submit to the Services for processing on Customer's behalf (for example contact lists, CSV uploads, or API query payloads).
LeadMagic Database Data — independently sourced business contact and firmographic data that LeadMagic maintains as an independent controller.
Account and Usage Data — account, billing, authentication, security, fraud-prevention, and product-usage data about Customer and its Authorized Users, for which LeadMagic is an independent controller.
Authorized Users — individuals Customer permits to access the Services under Customer's account.
Services — the LeadMagic platform, APIs, and related products described in the Terms.
Subprocessor — a third party engaged by LeadMagic to process Customer Personal Data on LeadMagic's behalf to help deliver the Services, as identified on our Subprocessors List.
"Controller," "processor," "personal data," "processing," "business," "service provider," "sell," and "share" have the meanings in applicable Data Protection Laws.
3. Roles
For Customer Personal Data, Customer is the controller (or "business") and LeadMagic is the processor (or "service provider"). For LeadMagic Database Data and Account and Usage Data, LeadMagic is an independent controller (or "business"). Controller activities are governed by our Privacy Policy and Data Use Policy, not by LeadMagic's processor obligations under this DPA.
When the Services return results drawn from LeadMagic Database Data, LeadMagic does so as an independent controller of that database. Ending the Services does not require LeadMagic to delete LeadMagic Database Data.
4. Scope of Processing
Subject matter and nature: providing the Services, including receiving Customer inputs, performing platform processing, and returning Service outputs.
Duration: the subscription term plus any period needed for deletion, return, backups, legal holds, or dispute resolution.
Types of personal data: business contact and related fields Customer chooses to submit (for example name, work email, title, company, phone, professional profile URL, and similar identifiers), plus technical metadata generated by use of the Services.
Data subjects: individuals whose data Customer submits (for example prospects, customers, employees, or contractors).
Customer's documented instructions are Customer's configuration and use of the Services under the Terms. LeadMagic may refuse instructions that appear unlawful or outside the scope of the Services. Customer is solely responsible for the lawfulness of its instructions and for having a valid legal basis to submit Customer Personal Data.
5. Customer Obligations
Comply with Data Protection Laws in its use of the Services and processing of outputs
Not submit special-category data, children's data, payment card data, government identity numbers or documents, consumer-report data, or other data prohibited by the Terms or Acceptable Use Policy
Ensure any notices, consents, and rights needed for LeadMagic to process Customer Personal Data as processor are in place
Remain responsible for Authorized Users and for access controls in Customer's account
6. LeadMagic Obligations
When processing Customer Personal Data as processor, LeadMagic will:
Process Customer Personal Data only on Customer's documented instructions (including this DPA), unless required by law; if legally permitted, LeadMagic will inform Customer of such a legal requirement before processing
Ensure persons authorized to process Customer Personal Data are under appropriate confidentiality obligations
Implement appropriate technical and organizational measures designed to protect Customer Personal Data, taking into account the nature of the Services (including encryption in transit, access controls, logging, and secure development practices)
Not sell or share Customer Personal Data (as defined under the CCPA), and not retain, use, or disclose it except to provide the Services, for security and fraud prevention, or as otherwise permitted for a service provider under the CCPA or required by law
Not use Customer Personal Data to build or update a shared contact database made available to other customers
Provide reasonable assistance with data subject requests, DPIAs, and supervisory consultations to the extent required by Data Protection Laws and related to LeadMagic's processing as processor (LeadMagic may charge a reasonable fee for assistance that is excessive or beyond what the law requires)
Notify Customer without undue delay, and in any event within seventy-two (72) hours where feasible, after becoming aware of a personal data breach affecting Customer Personal Data, and share information reasonably available to assist Customer's response (notification timing may be delayed where legally required by law enforcement)
On written request after termination, delete or return Customer Personal Data, subject to backup cycles, legal retention, security, and operational limits. LeadMagic Database Data and Account and Usage Data are not covered by this deletion obligation
Make available information reasonably necessary to demonstrate compliance, primarily via questionnaires, third-party audit reports, and remote evidence. On-site audits apply only if required by Data Protection Laws, under NDA, with reasonable notice, no more than once every twelve (12) months (unless a material breach of this DPA), and at Customer's expense. Audits may not access other customers' data or LeadMagic trade secrets
LeadMagic understands the CCPA service-provider restrictions above and will comply with them for Customer Personal Data.
7. Subprocessors
Customer authorizes LeadMagic to engage the Subprocessors identified on our Subprocessors List, including their affiliates that assist in providing the listed services. LeadMagic will impose data-protection terms on Subprocessors that are no less protective than this DPA, and remains responsible to Customer for Subprocessor performance under this DPA.
That list covers infrastructure and platform Subprocessors that process Customer Personal Data on LeadMagic's behalf. It does not list LeadMagic-owned or operated infrastructure, workforce-only tools that do not process Customer Personal Data, or independently sourced database suppliers where LeadMagic acts as an independent controller (see the Subprocessors List, Privacy Policy, and Data Use Policy).
LeadMagic will post material additions or replacements of Subprocessors on that page and, where required by Data Protection Laws or a signed DPA, give at least fifteen (15) days' prior notice. Customers with a signed DPA may request email notice at [email protected]. Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve an objection, either party may terminate the affected Services; LeadMagic is not required to operate those Services without a necessary Subprocessor. Pre-approved Subprocessors already listed do not require a new objection window when LeadMagic continues to use them.
8. International Data Transfers
LeadMagic may process Customer Personal Data in the United States and other countries where LeadMagic or its Subprocessors operate. Where a transfer from the EEA, UK, or Switzerland requires a transfer mechanism, LeadMagic will rely on the European Commission Standard Contractual Clauses (Module 2: controller to processor), the UK International Data Transfer Addendum or IDTA, and/or another lawful mechanism. LeadMagic will provide a completed SCC / UK Addendum package on reasonable request to [email protected].
Customer remains responsible for assessing whether its own use of the Services requires additional Customer-side transfer assessments, notices, or filings. LeadMagic does not provide legal advice.
9. Intellectual Property
As between the parties, Customer retains all rights in Customer Personal Data. LeadMagic and its licensors retain all rights in the Services, software, APIs, documentation, databases, matching and verification logic, models, and LeadMagic Database Data. This DPA does not transfer ownership of either party's intellectual property. Customer receives no license to LeadMagic intellectual property except the limited rights to use Service outputs under the Terms. Customer will not reverse engineer or attempt to derive trade secrets from LeadMagic systems used to process Customer Personal Data.
10. Liability and Indemnity
Each party's aggregate liability arising out of or related to this DPA is subject to the limitations of liability in the Terms, except to the extent Data Protection Laws prohibit that limitation. Nothing in this DPA expands LeadMagic's liability beyond the Terms. Customer will defend and indemnify LeadMagic against third-party claims, damages, and costs arising from Customer Personal Data, Customer's unlawful instructions, or Customer's downstream use of Service outputs, except to the extent caused by LeadMagic's breach of this DPA.
11. Governing Law and Venue
This DPA is governed by the laws of the Commonwealth of Massachusetts, without regard to conflict-of-laws rules. Subject to any injunctive-relief rights in the Terms, the state and federal courts in Suffolk County, Massachusetts have exclusive jurisdiction over disputes arising out of this DPA. The parties consent to personal jurisdiction there and waive venue and forum non conveniens objections. The UN CISG does not apply.
12. Term and Contact
This DPA takes effect when Customer first uses the Services in a way that involves Customer Personal Data (or on the Order Form effective date, if earlier) and continues until LeadMagic ceases processing Customer Personal Data. Sections that by their nature should survive (including confidentiality, intellectual property, liability, indemnity, governing law, and deletion limits) survive termination.
Privacy / DPA contact: [email protected]. Legal notices: [email protected]. Lead Magic Corporation, 160 Gould Street, Suite 320, Needham, MA 02494, United States.
Are you an individual, not a customer?
The agreement above governs personal data a customer sends us to process on their behalf. If you are an individual who wants your own information deleted, corrected, or opted out of sale or sharing, that is a different request with its own form — and it asks for the identifiers we need to actually find your records.
Submit a privacy request
Only want to opt out of the sale or sharing of your information? Do Not Sell or Share My Personal Information
Contact Us
Questions about this DPA belong with the customer agreement, not the individual privacy form:
Lead Magic Corporation
160 Gould Street, Suite 320
Needham, MA 02494
United States
DPA / legal: [email protected]
Support: [email protected]
Your privacy, your choice
Necessary cookies run the site. With permission, analytics improve it and ad cookies measure campaigns. Cookie Policy.