Snapshot 50166
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Data Processing Agreement Last Updated: 21st September 2026 This Data Processing Agreement (the “DPA”) forms part of and is incorporated into the agreement between FUTUREBLINK Inc. and the customer identified in that agreement (the “Agreement”). FUTUREBLINK Inc., a corporation incorporated under the laws of the State of Delaware, United States, Delaware file number 10627023, whose mailing address is 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States (“Processor”, “we”, “us”); and the customer identified in the Agreement (“Controller”, “you”). Where a conflict arises between this DPA and the Agreement in respect of the processing of personal data, this DPA prevails. 1. Definitions Capitalised terms not defined here have the meaning given in the Agreement or in Applicable Data Protection Law. Applicable Data Protection Law means Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR together with the Data Protection Act 2018. The California Consumer Privacy Act as amended by the CPRA (the “CCPA”) applies only as and where set out in section 12. Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority have the meanings given in the GDPR, and the equivalent terms in the UK GDPR are construed accordingly. Sub-processor means any third party engaged by us to process personal data on your behalf. Standard Contractual Clauses means the clauses adopted by the European Commission in Decision 2021/914 and, for UK transfers, the UK International Data Transfer Addendum. 2. Roles and scope 2.1 Roles. In respect of customer personal data, you are the controller and we are the processor. Where you are yourself a processor acting for a third-party controller, you warrant that you have the authority to appoint us as a sub-processor and to enter into this DPA. 2.2 Independent controller activities. We act as an independent controller in respect of account administration data, billing data, support correspondence, security and abuse-prevention logging, and product telemetry relating to your authorised users. That processing is governed by our Privacy Policy and not by this DPA. 2.3 Duration. The subject matter of the processing is the provision of the services. Processing continues for the term of the Agreement and for the retention and deletion periods in section 11. 2.4 Nature and purpose. We process personal data to host and operate the services, which comprise: storage and management of prospect and contact records; composition, scheduling and delivery of outbound email sequences; connection to and synchronisation with mailboxes you authorise; receipt, classification and routing of inbound replies; tracking of email opens, clicks and replies; mailbox warm-up and deliverability monitoring; email address verification; AI-assisted drafting of message content; scheduling of meetings; and integration with third-party systems you authorise. 2.5 Categories of data subject. Prospects and recipients contacted through the services; your authorised users and personnel; correspondents who reply to messages sent through the services; and invitees who book meetings through the services. 2.6 Categories of personal data. Contact and professional data — name, business email address, telephone number, job title, employer, employer domain, professional social profile URLs, location, and other attributes in records you upload. Communications content — the content of outbound messages, inbound replies, threads, subject lines, signatures and attachments transiting or stored by the services, including content in connected mailboxes within the scope of the authorisation granted. Engagement and technical data — open, click, bounce, reply and unsubscribe events; timestamps; IP addresses; user-agent and device information; message and thread identifiers. Account and authentication data — user names, email addresses, hashed credentials, multi-factor authentication secrets, API keys, and access and refresh tokens for systems you connect. Scheduling data — meeting times, attendee names and email addresses, and notes submitted at booking. 2.7 Special categories. The services are not designed or intended for processing special categories of personal data within the meaning of Article 9 GDPR, personal data relating to criminal convictions and offences, or personal data of children. You must not upload or submit such data. Free-text message content is not filtered and may incidentally contain such data; we apply the measures in section 7 to all personal data regardless of category. 2.8 Your responsibilities. You warrant that you have a valid lawful basis for the processing you instruct, that you have given all required notices and obtained all required consents, that you have the right to transfer personal data to us, and that your use of the services complies with all applicable law governing electronic direct marketing, including GDPR Article 6(1)(f) and Recital 47, the ePrivacy Directive 2002/58/EC as implemented nationally, the UK Privacy and Electronic Communications Regulations 2003, and any equivalent regime applicable to the recipients you choose to contact. You are responsible for honouring opt-out and unsubscribe requests you receive. 3. Our obligations 3.1 We process personal data only on your documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we inform you before processing unless the law prohibits it on important grounds of public interest. 3.2 The Agreement, this DPA, your configuration of the services, and your use of the services' documented features together constitute your complete documented instructions. 3.3 We notify you without undue delay if, in our opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing pending resolution. 3.4 We ensure that persons authorised to process personal data are bound by an appropriate duty of confidentiality, are subject to background screening where lawful and proportionate, and receive periodic data protection and security training. 3.5 Access to personal data is restricted to personnel who require it, on a least-privilege and need-to-know basis, and is logged. 3.6 We do not sell or rent personal data, do not retain, use or disclose it for any purpose other than performing the services, and do not combine it with data from other sources except as necessary to perform the services. We do not use your personal data to train, fine-tune or otherwise improve any general-purpose machine learning model. 4. Sub-processors 4.1 You grant us general written authorisation to engage sub-processors, subject to this section. 4.2 The sub-processors in force at the effective date are published at salesblink.io/sub-processors. 4.3 We give you at least thirty (30) days' notice before authorising a new sub-processor or replacing an existing one, by email to your designated notice address and by a dated changelog published alongside that list. 4.4 You may object on reasonable, documented data protection grounds within fifteen (15) days of notice. We will work in good faith to resolve the objection. Where no resolution is reached you may terminate the affected services without penalty, with a pro-rata refund of prepaid fees for the unused term. 4.5 Where a sub-processor must be replaced without notice to preserve the security or continuity of the services, we may do so and will notify you as soon as reasonably practicable. 4.6 We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remain fully liable to you for each sub-processor's performance. 4.7 Integrations you connect. Where you authorise the services to connect to a third-party system under your own account — including CRM platforms, workflow automation services, mailbox providers, chat platforms, and AI clients connecting via the Model Context Protocol — that third party is not our sub-processor. The transfer is made on your instruction and you are responsible for your own relationship with that provider. 5. International transfers 5.1 We are established in the United States. We and our sub-processors process personal data in multiple regions, including the European Economic Area and the United States. The processing location for a given sub-processor depends on the region in which that sub-processor's services are provisioned. We will identify the processing region for any individual sub-processor on your reasonable request. 5.2 Because we are established in the United States, all processing of personal data originating in the EEA or the United Kingdom constitutes a restricted transfer. Each such transfer is made pursuant to the Standard Contractual Clauses, under which you are the data exporter and we are the data importer. Module Two (controller to processor) applies; Module Three (processor to processor) applies where you are yourself a processor; the docking clause applies; the general authorisation option in Clause 9(a) applies with the notice period in section 4.3; the governing law and forum are those of Ireland; for UK transfers the UK International Data Transfer Addendum applies to the same clauses. 5.3 We have conducted, and will maintain, a transfer impact assessment in respect of each such transfer, and will supply a copy on reasonable request. 5.4 If any transfer mechanism relied on is invalidated or superseded, the parties will in good faith adopt a replacement without undue delay. 6. Data subject rights 6.1 Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability and objection. 6.2 The services let you search, export, correct and delete personal data within your account. You use that functionality in the first instance. 6.3 Where we receive a request from a data subject relating to personal data processed on your behalf, we do not respond to the substance other than to direct them to you, and we notify you without undue delay and in any event within five (5) business days. 6.4 Assistance under this section is provided at no additional charge, save that we may charge a reasonable fee for assistance that is manifestly unfounded, excessive or repetitive, having first notified you of the anticipated charge. 6.5 We provide reasonable assistance with data protection impact assessments and with any prior consultation with a supervisory authority. 7. Security measures 7.1 We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons. 7.2 Those measures include, at minimum: Encryption in transit. TLS is enforced for all connections to the services, to sub-processor APIs, and for internal service-to-service traffic crossing a network boundary. Mail transport uses opportunistic or enforced TLS as supported by the counterparty mail server. Encryption at rest. Databases, object storage and backups are encrypted at rest using the storage-layer encryption provided by the relevant infrastructure sub-processor. Application-layer encryption is additionally applied to application OAuth tokens and multi-factor authentication secrets. Access control. Role-based access control with defined permission tiers is enforced within the application. Administrative access to production infrastructure requires multi-factor authentication and is restricted to named individuals. Access rights, including database access, are reviewed at least quarterly. Secrets management. Production credentials for sub-processors and infrastructure are held in environment configuration on production hosts, are distinct from any credential used in development or local testing, and are not stored in the source repository or the build pipeline's variable store. Network security. Data stores are not exposed to the public internet. Ingress is restricted to defined load balancing and reverse proxy layers. Rate limiting is applied to authentication, signup, password reset and API endpoints, with separately configured thresholds for each. Log minimisation. Application and error logs are not designed to capture message bodies, credentials or authentication tokens. Request objects are not written to logs in full, and logging is keyed on account and user identifiers rather than direct identifiers. Resilience. The services are designed for redundancy across availability zones. Automated backups are taken daily and retained for thirty (30) days, and restore procedures are tested annually. Monitoring and logging. Application errors, performance anomalies, authentication events and administrative actions are logged and monitored. Logs are retained for ninety (90) days. Secure development. Changes are deployed through a controlled continuous integration pipeline with build verification, rather than by direct modification of production systems. The application enforces input sanitisation against injection attacks at the framework level. Personnel. Confidentiality undertakings, security awareness training, and prompt revocation of access on role change or departure. Physical security. Physical and environmental security of data centre facilities is provided by the infrastructure sub-processors identified in the sub-processor list, each of which maintains its own independently audited controls for the facilities concerned. 7.3 We may update our security measures from time to time, provided no update materially reduces the overall level of security. 7.4 Certifications. We do not currently hold a SOC 2 Type II attestation or ISO/IEC 27001 certification. We make our security documentation available on request under section 9.2. 8. Personal data breach notification 8.1 We notify you without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. 8.2 Notification is made to your designated security contact by email and in-product notice, and describes, to the extent known and supplemented as more information becomes available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the name and contact details of our data protection contact; the likely consequences; and the measures taken or proposed to address it and mitigate its effects. 8.3 We take reasonable steps to contain, investigate and remediate the breach, preserve relevant evidence, and provide you with the cooperation and information reasonably necessary to meet your own notification obligations. 8.4 We will not make any public statement or notification to data subjects or supervisory authorities identifying you without your prior written consent, unless legally compelled, in which case we notify you in advance where lawful. 8.5 Notification under this section is not an acknowledgement of fault or liability. 9. Audit and information rights 9.1 We make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. 9.2 Your audit right is satisfied in the first instance by our provision of current security documentation and a completed security questionnaire. 9.3 Where that information is insufficient, you may on thirty (30) days' written notice conduct an audit no more than once per calendar year, save where an audit is required following a personal data breach or by a supervisory authority. Audits are conducted during business hours, subject to confidentiality undertakings, in a manner that does not unreasonably disrupt our operations, and at your cost. 9.4 An audit does not extend to the premises, systems or data of our other customers, nor to information whose disclosure would breach our obligations to third parties. 10. AI processing 10.1 Where you use AI-assisted features, prompt content — which may include contact records, company information and prior message content — is transmitted to the AI sub-processors identified in the sub-processor list, currently OpenAI and OpenRouter. 10.2 We contract with those sub-processors on terms that prohibit the use of your data for training or improvement of their models. This section 10.2 applies to our default configuration only; where you exercise either option in section 10.3, that section governs instead. 10.3 The services permit you to select a model of your own choosing through the routing sub-processor, and to supply your own API key for that sub-processor. Where you supply your own API key, requests are made under your own account with that provider. We are not a party to the resulting relationship, and the provider is treated as an integration you connect under section 4.7. You are the controller of that onward transfer and are responsible for the terms on which it takes place. Where you select a model other than our default, prompt content is routed to that model's upstream provider, whose retention and training terms apply in place of those described in section 10.2. We do not warrant the data handling terms of any upstream provider you select. We store any API key you supply solely to make requests on your instruction, and use it for no other purpose. 10.4 We do not use your personal data to train, fine-tune or evaluate any model of our own. 11. Retention, return and deletion 11.1 We retain personal data for the duration of the Agreement and in accordance with the following retention periods: Trial accounts. Where you do not purchase a paid plan, the account and all associated personal data are deleted within six (6) months of the end of the trial. Paid accounts. Where a subscription is not renewed, the account and all associated personal data are deleted one (1) year after the date on which the subscription lapsed. Message content and attachments. Stored message bodies and attachments held in object storage are deleted at the same time as the account, and are not retained beyond it. Operational logs. Application, error and product telemetry logs, including those held by our monitoring and analytics sub-processors, are retained for ninety (90) days. Backups. Backups are retained for thirty (30) days, as set out in section 11.4. 11.2 On termination or expiry of the Agreement you may, within thirty (30) days, export your personal data using the export functionality of the services or request a copy from us. 11.3 On your written request at any time, we delete or return all personal data processed on your behalf and delete existing copies, at your election, without waiting for the periods in section 11.1 to elapse, unless law requires continued storage. 11.4 Personal data residing in backups is deleted in accordance with our backup rotation schedule, and in any event within thirty (30) days of deletion under section 11.1 or 11.3. Pending expiry of that period such data remains subject to this DPA and is not restored to production systems except as part of a disaster recovery event affecting the services as a whole. 11.5 We may retain personal data to the extent and for the period required by law, or in aggregated and anonymised form from which data subjects cannot be identified. 11.6 We certify deletion in writing on your written request. 12. California Consumer Privacy Act 12.1 This section applies only where, and for so long as, we process personal information (as defined in the CCPA) on behalf of a customer that is a “business” within the meaning of the CCPA. It does not extend the scope of Applicable Data Protection Law defined in section 1 for any other purpose. In respect of such processing we act as a “service provider”. 12.2 We do not sell or share personal information; do not retain, use or disclose it for any purpose other than performing the services specified in this DPA or as otherwise permitted by the CCPA; do not retain, use or disclose it outside the direct business relationship between the parties; and do not combine it with personal information received from other sources, except as permitted by the CCPA. 12.3 We certify that we understand the restrictions in section 12.2 and will comply with them. 12.4 You may take reasonable and appropriate steps to ensure that we use personal information in a manner consistent with your obligations under the CCPA, and to stop and remediate any unauthorised use. 12.5 Where a conflict arises between this section and the remainder of this DPA in respect of personal information subject to the CCPA, this section prevails to the extent of the conflict. 13. Liability 13.1 Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement. 13.2 Section 13.1 does not limit either party's liability to a data subject under Article 82 GDPR, nor liability that cannot lawfully be limited. 14. General 14.1 Term. This DPA takes effect on the effective date of the Agreement and continues until all personal data has been deleted or returned in accordance with section 11. 14.2 Amendment. We may amend this DPA on thirty (30) days' notice where necessary to reflect a change in Applicable Data Protection Law, a decision of a supervisory authority or court, or a change in the services, provided the amendment does not materially reduce the protections afforded to personal data. 14.3 Severance. If any provision is held invalid or unenforceable, the remainder continues in full force and the parties will substitute a valid provision of equivalent commercial effect. 14.4 Governing law. This DPA is governed by the law stated in the Agreement, save where Applicable Data Protection Law or the Standard Contractual Clauses require otherwise. Annex I — Description of processing Populated by sections 2.3 to 2.6 above. Competent supervisory authority: the supervisory authority of the EU Member State in which our Article 27 representative is established, or, where you are established in the EEA, the supervisory authority competent for you. Our data protection contact: Sushant Shekhar, Founder — [email protected] Our EU representative under Article 27 GDPR: Sushant Shekhar — [email protected] Our UK representative under Article 27 UK GDPR: Sushant Shekhar — [email protected] Annex II — Technical and organisational measures Populated by section 7 above. Annex III — List of sub-processors Populated by the list published at salesblink.io/sub-processors. Get in touch If you need a countersigned copy of this DPA, or have questions about how we process personal data, contact [email protected] or write to us.