Legal
Data Processing Addendum
This addendum forms part of the service agreement between the client ("Controller") and OutLead Me ("Processor") and applies whenever OutLead Me processes personal data on the Controller's behalf. It is intended to satisfy Article 28 of the GDPR and UK-GDPR and equivalent obligations under the Privacy Act 2020 (New Zealand) and other applicable data-protection laws. A signed, counter-party version is available on request to admin@outleadme.com.
1. Roles
The Controller determines the purposes and means of processing. OutLead Me acts as Processor and only processes personal data on documented instructions from the Controller (the service agreement, this DPA, and campaign briefs).
2. Subject matter + duration
Processing continues for the duration of the service agreement and any wind-down period. On termination, personal data is transferred to the Controller (via GoHighLevel sub-account ownership) and OutLead Me does not retain copies except where required by law.
3. Nature + purpose of processing
- Sourcing B2B contact data from lawful providers.
- Enriching records from publicly available sources.
- Loading records into the Controller's CRM (GoHighLevel).
- Sending outbound email sequences.
- Recording engagement (opens, clicks, replies, bounces, unsubscribes).
- Producing reports for the Controller.
4. Categories of data + data subjects
Data subjects: business contacts at target companies (typically decision-makers in roles the Controller specifies).
Categories: full name, business email, job title, company name, company website, professional profile URLs, location (country / region), and engagement metadata. We do not process special-category data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR); the Controller must not instruct us to do so.
5. Sub-processors
The Controller authorises OutLead Me to engage sub-processors listed in our Privacy Notice. We notify the Controller of any addition or replacement with 15 days' prior notice; the Controller may object on reasonable data-protection grounds.
OutLead Me remains liable to the Controller for the acts and omissions of its sub-processors in respect of the processing.
6. International transfers
Where personal data is transferred outside the UK / EEA, transfers are covered by Standard Contractual Clauses and the UK IDTA where applicable, plus supplementary technical and organisational measures.
7. Security
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access controls; access reviewed quarterly and revoked within one business day of offboarding.
- Unique credentials and MFA on all admin systems.
- Written information-security and acceptable-use policies for staff.
- Personnel authorised to process personal data are bound by written confidentiality obligations that survive termination of their engagement.
8. Assistance to the Controller
Taking into account the nature of the processing and information available, OutLead Me provides reasonable assistance to the Controller in responding to data-subject requests, carrying out DPIAs, consulting supervisory authorities, and meeting security and breach-notification obligations, at cost.
9. Breach notification
OutLead Me notifies the Controller without undue delay (and in any event within 48 hours) of becoming aware of a personal-data breach affecting the Controller's data, with the information the Controller reasonably needs to meet their own notification obligations.
10. Audit
OutLead Me makes available information reasonably necessary to demonstrate compliance with this DPA, including sub-processor lists and security summaries. Controller audits are conducted no more than annually, with 30 days' notice, and are covered by confidentiality.
11. Return + deletion on termination
On termination, personal data remains with the Controller inside the transferred GoHighLevel sub-account. Any residual copies held by OutLead Me are deleted within 30 days, save for (a) suppression / unsubscribe records retained to honour opt-outs, and (b) records required to be retained by law. On written request, OutLead Me will certify deletion in writing.
12. Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the service agreement (and, absent one, our Terms of Use). Nothing in this DPA limits either party's liability where such limitation is prohibited by applicable data-protection law.
13. Order of precedence
In the event of conflict between this DPA and the service agreement in respect of the processing of personal data, this DPA prevails. In the event of conflict between this DPA and any Standard Contractual Clauses or UK IDTA incorporated into the arrangement, the SCCs / IDTA prevail.
Last updated: July 2026.
