Data Processing Agreement

Last updated: 30 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Keplent (“Keplent”, the processor) and the customer using the Service (“you”, the controller). It sets out how we process personal data on your behalf, and is written to meet Article 28 of the GDPR. It applies automatically from the moment you start using the Service — you do not have to sign anything for it to bind us.

1. Roles

You are the controller of the personal data you load into or generate within your workspace — your leads, prospects, contacts, client records and campaign history. You decide why and how it is processed. We are your processor and act only on your documented instructions.

For data we handle in our own right — your account details, billing information, website visitors and waitlist subscribers — we are the controller, and our Privacy Policy applies instead.

2. Your instructions

Using the Service, and configuring it as you do, constitutes your documented instructions. We will not process customer personal data for any other purpose. If a law we are subject to requires us to process it otherwise, we will tell you first unless that law forbids it. We will tell you if, in our opinion, an instruction infringes data protection law.

You are responsible for having a lawful basis for the processing you instruct — including for contacting the people in your lists — and for the notices and opt-outs your local law requires. See section 5 of the Terms.

3. Annex I — details of the processing

ItemDetail
Subject matterProvision of the Keplent platform: lead research and enrichment, outreach campaigns, automations, trend monitoring and client reporting.
DurationFor as long as your subscription is active, plus the deletion period in section 9.
Nature and purposeCollection, storage, structuring, enrichment, analysis, scoring, transmission of messages, generation of reports, and deletion — all as directed by you through the Service.
Types of personal dataBusiness contact details (name, job title, employer, business email, business phone), public professional profile information, firmographic data, message content and correspondence history, engagement records, and any other data you choose to upload.
Categories of data subjectsYour prospects and leads; your clients and their staff; your own employees and workspace users.
Special categoriesNone. The Service is not intended for special category data and you must not upload it.
FrequencyContinuous, for as long as the Service is in use.

4. Confidentiality

We keep customer personal data confidential. Access is limited to personnel who need it to provide or support the Service, each bound by a confidentiality obligation and trained on their responsibilities.

5. Annex II — security measures

We implement appropriate technical and organisational measures under Article 32, including:

  • encryption of data in transit over HTTPS;
  • authentication tokens held in httpOnly, SameSite=Lax cookies, marked Secure in production, so page scripts cannot read them;
  • passwords stored only as salted hashes, never in readable form;
  • role-based access control within workspaces, and least-privilege access to production systems;
  • separation of workspaces so one customer’s data is not reachable from another’s;
  • logging and monitoring of access to production systems;
  • backups, with restoration tested periodically;
  • review of these measures as the Service changes.

We may update these measures over time provided the level of protection is not reduced.

6. Subprocessors

You give general authorisation for us to engage subprocessors. The current list is published at keplent.com/subprocessors. Each is engaged under a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable to you for their performance.

We will notify customers by email at least 30 days before a new subprocessor starts processing. If you object on reasonable data protection grounds within that period, write to support@keplent.com; we will work with you to find an alternative, and if none is workable you may terminate the affected part of the Service without penalty.

7. International transfers

Where personal data is transferred outside the European Economic Area, the transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses, with supplementary measures where a transfer impact assessment calls for them. The mechanism relied on for each provider is shown on the Subprocessors page. Where the Clauses apply, they are incorporated into this DPA by reference, with Annex I and Annex II above completing them.

8. Assisting you

We will, taking into account the nature of the processing:

  • assist you with requests from data subjects exercising their rights, and forward to you without undue delay any request we receive that concerns your data;
  • assist you with data protection impact assessments and prior consultations, where the information is available to us;
  • notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available to us so you can meet your Article 33 deadline;
  • make available the information reasonably necessary to demonstrate compliance with Article 28.

9. Deletion and return

You can export leads, sequences and reports as CSV at any time during your subscription. On termination, and at your choice, we will delete or return customer personal data within 30 days, except where the law requires us to keep it — in which case we keep it only for as long as required and continue to protect it under this DPA. Backups are purged on their normal rotation cycle.

10. Audits

On reasonable written notice, and no more than once a year unless a regulator or a breach requires otherwise, we will answer your reasonable questions about our processing and provide available documentation. Where an on-site audit is genuinely necessary, it will be agreed in advance, conducted during business hours, subject to confidentiality, and arranged so as not to disrupt the Service.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails on matters of data protection. If the Standard Contractual Clauses conflict with either, the Clauses prevail.

12. Getting a signed copy

This DPA is in force without signature. If your procurement process needs a countersigned copy, or you need it attached to a wider agreement, write to support@keplent.com and we will send one.