Data Processing Agreement
Last updated: 26 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service and describes how Greenfield processes personal data on behalf of its customers (data controllers).
1. Roles and Responsibilities
- Data Controller — The customer organisation that determines the purposes and means of processing personal data.
- Data Processor — Greenfield, which processes personal data on behalf of the Data Controller.
- Data Subject — The individual whose personal data is processed (e.g., contacts, customers).
2. Scope of Processing
Greenfield processes the following categories of personal data on behalf of the Data Controller:
- Contact names, email addresses, phone numbers, and LinkedIn URLs
- Professional information (job title, company, department)
- Sales and marketing activity data (interactions, notes, follow-up dates)
- Opportunity and pipeline data
3. Data Controller Obligations
The Data Controller is responsible for:
- Ensuring a lawful basis exists for processing personal data uploaded to the platform.
- Obtaining necessary consents from data subjects before importing their data.
- Respecting opt-out requests and honouring data subject rights.
- Providing data subjects with this DPA and the Privacy Policy upon request.
4. Sub-Processors
Greenfield engages the following sub-processors to deliver the Service:
- Cloud hosting provider — for application hosting and data storage.
- AI service providers — for AI-powered features such as content generation and summaries.
- Email delivery services — for sending platform notifications and communications.
The Data Controller will be notified of any new sub-processors and may object in accordance with UK GDPR Article 28.
5. Data Security Measures
Greenfield implements the following technical and organisational measures:
- Encryption of data in transit (TLS 1.2+) and at rest.
- Role-based access control (RBAC) with row-level security (RLS).
- Audit logging of all create, update, and delete actions.
- Regular security reviews and vulnerability assessments.
- Secure data deletion upon contract termination.
6. Data Retention and Deletion
Personal data is retained for the duration of the customer relationship. Upon termination, data is deleted within 90 days, except where retention is required by law (up to 6 years for financial records).
7. Data Subject Rights
Greenfield assists the Data Controller in fulfilling data subject requests, including:
- Right of access — providing a copy of stored personal data.
- Right to rectification — correcting inaccurate data.
- Right to erasure — deleting personal data upon request.
- Right to data portability — exporting data in a structured format.
Data subjects can opt out of marketing communications at any time via our opt-out page.
8. Breach Notification
In the event of a personal data breach, Greenfield will notify the Data Controller without undue delay and no later than 72 hours after becoming aware of the breach. Notification will include the nature of the breach, likely consequences, and measures taken.
9. International Data Transfers
Where personal data is transferred outside the UK, Greenfield ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions.
10. Audit Rights
The Data Controller may audit Greenfield's compliance with this DPA, subject to reasonable notice and confidentiality obligations.