Data Processing Agreement
Our standard Art. 28 GDPR agreement for customers. The full signed version is available on request; the terms below are the ones every customer gets.
Roles
For company-level intelligence LeadRadar acts as an independent controller of public data. For the customer's CRM and accounting data, the professional contacts the customer chooses to activate, and the customer's users, LeadRadar is the processor and the customer is the controller. Processor: LeadRadar [legal entity, registration number, registered address].
Subject matter and duration
Processing needed to provide the LeadRadar service as described in the order form, for the term of the subscription plus the deletion period below.
Processor obligations
- Process only on documented instructions, including on transfers.
- Confidentiality for all staff with access.
- Security measures listed on the Security page (tenant isolation with row-level security, encryption in transit and at rest, audit trail, access reviews).
- Assist the customer with data-subject requests and DPIAs.
- Notify personal-data breaches without undue delay and no later than 48 hours after becoming aware.
- Delete or return all customer data within 30 days after termination; backups purge within a further 35 days.
- Make available the information needed to demonstrate compliance and allow audits, once a year or after an incident, with reasonable notice.
Sub-processors
Listed on the Security & sub-processors page. New sub-processors are announced 30 days in advance; the customer may object on reasonable data-protection grounds.
Transfers
Processing takes place in the EU. Any transfer outside the EU/EEA requires an adequacy decision or Standard Contractual Clauses and is listed per sub-processor.
Requesting the agreement
Write to dpo@leadradar.example with your company details. We return the signed DPA, the sub-processor list and the technical and organisational measures annex. Enterprise customers may use their own template; we review it within ten working days.
Items highlighted like this are filled in per customer or before launch. We describe controls we operate; we do not present GDPR compliance, AI Act conformity or ISO certification as achieved results until verified.