Data Processing Agreement

Last updated:

This Data Processing Agreement (“DPA”) forms part of and is incorporated into the upcell Terms of Service and any applicable Order Form (collectively, the “Agreement”) between upcell, LLC (“upcell”) and the Client identified in the applicable Order Form (“Client”).

This DPA governs the processing of personal data by upcell and Client in connection with the Service, and applies where either party processes personal data of individuals located in the European Economic Area, the United Kingdom, Switzerland, California, or other jurisdictions whose laws impose obligations on the processing of personal data. It addresses both (a) Customer Personal Data, which upcell processes on Client’s behalf as a Processor, and (b) upcell Information, which upcell and Client each process as independent Controllers. This DPA supplements and does not replace the Agreement. In the event of a conflict between this DPA and the Agreement with respect to data processing, this DPA controls.

By executing an Order Form that incorporates this DPA, or by accepting the upcell Terms of Service where this DPA is incorporated by reference, Client agrees to the terms of this DPA.

  1. Definitions

Capitalized terms used but not defined in this DPA have the meanings given in the Agreement or in applicable Data Protection Laws. The following definitions apply:

Applicable Data Protection Laws means all laws and regulations applicable to the processing of personal data under this DPA, including (as applicable) the GDPR, UK GDPR, the Swiss Federal Act on Data Protection, CCPA/CPRA, and any other applicable national, state, or local privacy laws.

B2B Activities means Client’s business-to-business sales, marketing, recruiting, and business development activities, as further specified in the Agreement.

CCPA means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2022 (CPRA).

Controller means the party that determines the purposes and means of processing personal data.

Customer Personal Data means personal data submitted to or processed through the Service by or on behalf of Client in connection with Client’s use of the Service, including Client’s own contact records that Client or an Authorized User submits for matching, enrichment, or delivery. For the avoidance of doubt, Customer Personal Data does not include upcell Information.

Data Privacy Framework or DPF means the EU-U.S. Data Privacy Framework and, as applicable, the UK Extension to the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce and as may be amended, superseded, or replaced.

Data Privacy Framework Principles means the Principles and Supplemental Principles contained in the relevant Data Privacy Framework, as may be amended, superseded, or replaced.

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council.

Processing has the meaning given under Applicable Data Protection Laws and includes any operation performed on personal data, including collection, storage, use, disclosure, deletion, and transfer.

Processor means the party that processes personal data on behalf of the Controller.

Protected Data means Customer Personal Data and upcell Information collectively.

Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Protected Data in the possession or control of the party concerned.

Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission under Decision 2021/914, as may be updated from time to time.

Sub-Processor means any third party engaged by upcell to process Customer Personal Data on upcell’s behalf in connection with the Service.

UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B.1.0, issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018.

UK GDPR means the GDPR as it forms part of UK domestic law by virtue of the European Union (Withdrawal) Act 2018.

upcell Information means the business contact data that upcell compiles, validates, maintains, and licenses to Clients through the Service, including data and insights upcell derives from it, as defined in the Agreement and as further described in Exhibit A, Part 2.

  1. Roles and Scope of Processing

2.1 Scope and Application. In connection with the Service, both parties process personal data. This DPA applies to all Protected Data. Sections 3 through 12 apply solely to Customer Personal Data and solely where and to the extent upcell acts as Processor. Section 13 applies solely to upcell Information and solely where and to the extent each party acts as an independent Controller.

2.2 Respective Roles. The parties agree that (a) with respect to Customer Personal Data, Client is the Controller and upcell is the Processor; and (b) with respect to upcell Information, upcell and Client each process as independent Controllers.

2.3 No Joint Controllership. Except as expressly agreed in writing, the parties do not act as joint controllers with respect to any Protected Data, and nothing in this DPA or the Agreement is intended to establish a joint controllership arrangement under Article 26 GDPR or any equivalent provision of Applicable Data Protection Laws.

2.4 Hybrid Operations. Where Client or an Authorized User submits Client’s own records to the Service for matching against upcell Information, upcell acts as Processor with respect to the records that Client submits, and as independent Controller with respect to the upcell Information that upcell discloses in response.

2.5 Controller Responsibilities. Client is responsible for (a) ensuring it has a lawful basis for processing Customer Personal Data and for instructing upcell to process it; (b) ensuring that data subjects have been provided with appropriate notice of processing where required; (c) the accuracy, quality, and legality of Customer Personal Data; and (d) ensuring that Client’s use of the Service complies with Applicable Data Protection Laws.

2.6 Scope of Processing. upcell processes Customer Personal Data solely to provide the Service as described in the Agreement and as further specified in Exhibit A, Part 1 (Processing Details — Customer Personal Data). upcell will not process Customer Personal Data for any other purpose, including upcell’s own commercial purposes, without Client’s prior written consent. Without limiting the foregoing, upcell will not use Customer Personal Data to build, augment, enrich, verify, or otherwise improve upcell Information or upcell’s proprietary database.

2.7 Instructions. Client’s instructions to upcell are set out in the Agreement and this DPA. If upcell receives an instruction that it believes violates Applicable Data Protection Laws, upcell will promptly notify Client. upcell may suspend processing of the affected data until Client provides a lawful instruction.

  1. Confidentiality of Customer Personal Data

3.1 Confidentiality Obligation. upcell will treat Customer Personal Data as confidential. upcell will ensure that personnel authorized to process Customer Personal Data are subject to binding confidentiality obligations and are trained on data protection requirements applicable to their role.

3.2 Limitation on Access. upcell will limit access to Customer Personal Data to personnel who need access to provide the Service, and will ensure such access is revoked when no longer required.

  1. Security Measures

4.1 Technical and Organizational Measures. upcell will implement and maintain appropriate technical and organizational security measures (“TOMs”) to protect Customer Personal Data against unauthorized access, accidental loss, destruction, alteration, or disclosure, taking into account the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of natural persons. Such measures include as a minimum:

  • Encryption of Customer Personal Data in transit using TLS and at rest

  • Access controls and authentication requirements for personnel accessing Customer Personal Data

  • Regular security testing and vulnerability assessments

  • Hosting with outsourced data center providers maintaining industry-standard security certifications

  • Application monitoring and logging

  • Incident response procedures including defined escalation paths

4.2 Updates to Security Measures. upcell may update or modify its security measures from time to time, provided that such updates do not materially reduce the overall level of protection afforded to Customer Personal Data.

4.3 Client Responsibilities. Client is responsible for implementing appropriate security measures within its own systems and for the security of Customer Personal Data after it has been delivered to Client’s CRM or other systems.

  1. Security Incident Notification

5.1 Notification. In the event that upcell becomes aware of a confirmed Security Incident affecting Customer Personal Data, upcell will notify Client without undue delay and, where required by Applicable Data Protection Laws, within seventy-two (72) hours of becoming aware of the Security Incident.

5.2 Notification Content. upcell’s notification will, to the extent known at the time of notification, include: (a) a description of the nature of the Security Incident; (b) the categories and approximate number of data subjects affected; (c) the categories and approximate volume of Customer Personal Data affected; (d) the likely consequences of the Security Incident; and (e) the measures taken or proposed to address the Security Incident. Where not all information is available at the time of initial notification, upcell will provide additional information as it becomes available.

5.3 Cooperation. upcell will reasonably cooperate with Client’s investigation of a Security Incident and with any notification obligations Client may have to data subjects or supervisory authorities. Client is solely responsible for determining whether a Security Incident requires notification to data subjects or supervisory authorities under Applicable Data Protection Laws and for making any such notifications.

5.4 No Acknowledgment of Fault. upcell’s notification of or response to a Security Incident will not constitute an acknowledgment of fault or liability.

  1. Sub-Processors

6.1 Authorization. Client provides general authorization for upcell to engage Sub-Processors to process Customer Personal Data in connection with the Service, subject to the requirements of this Section 6.

6.2 Current Sub-Processors. upcell’s current Sub-Processors are listed in Exhibit B to this DPA. upcell will impose data protection obligations on each Sub-Processor that are no less protective than those in this DPA.

6.3 Changes to Sub-Processors. upcell will notify Client of any intended addition or replacement of Sub-Processors by updating the Sub-Processor list at upcell.io/legal/subprocessors and providing Client with thirty (30) days’ prior written notice. If Client reasonably objects to a new Sub-Processor on data protection grounds, Client must notify upcell in writing within thirty (30) days of the notice. The parties will work in good faith to resolve the objection. If the objection cannot be resolved within thirty (30) days, either party may terminate the affected portion of the Service on thirty (30) days’ written notice without liability for early termination, and Client will be entitled to a pro-rata refund of any prepaid fees for the terminated portion of the Service unused as of the effective date of termination.

6.4 Liability. upcell remains liable to Client for the acts and omissions of its Sub-Processors to the same extent as if upcell had performed the processing directly.

  1. Data Subject Rights

7.1 Assistance. upcell will provide reasonable assistance to Client in responding to data subject requests to exercise rights under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection), taking into account the nature of processing and the information available to upcell.

7.2 Redirection. If upcell receives a data subject request directly in relation to Customer Personal Data for which Client is the Controller, upcell will promptly redirect the data subject to Client and will not respond to the request on Client’s behalf without Client’s prior written authorization.

7.3 Suppression. upcell maintains a suppression file for individuals who have submitted opt-out or deletion requests through upcell’s Privacy Center at upcell.io/data-claim. Upon a verified request, upcell permanently suppresses the individual’s record platform-wide, and excludes suppressed individuals from data subsequently delivered through the Service. upcell retains the data reasonably necessary to give continuing effect to that suppression, including to prevent the record from being re-collected, and makes no other use or disclosure of that data. Client is responsible for honoring data subject requests it receives directly in relation to data within Client’s own systems. Client’s obligations with respect to upcell Information already delivered are set out in Section 13.6.

7.4 Government and Law Enforcement Requests. upcell will notify Client of any request for the disclosure of Customer Personal Data by a governmental or regulatory body or law enforcement authority (including any data protection supervisory authority) unless otherwise prohibited by law or a legally binding order of such body or agency.

  1. Data Protection Impact Assessments and Prior Consultation

Where required by Applicable Data Protection Laws, upcell will provide reasonable assistance to Client in conducting data protection impact assessments (DPIAs) and in any required prior consultation with supervisory authorities, in each case solely to the extent such assistance relates to upcell’s processing of Customer Personal Data and taking into account the information available to upcell.

  1. Audit Rights

9.1 Information and Audit. upcell will make available to Client, upon reasonable written request, information necessary to demonstrate compliance with this DPA. upcell will permit, and contribute to, audits and inspections conducted by Client or a mutually agreed independent auditor, subject to the following conditions: (a) Client provides at least thirty (30) days’ prior written notice; (b) audits are conducted no more than once per calendar year absent a confirmed Security Incident or a request from a supervisory authority; (c) audits are conducted during normal business hours and in a manner that minimizes disruption to upcell’s operations; and (d) the auditor is subject to binding confidentiality obligations.

9.2 Third-Party Certifications. upcell may satisfy its audit obligations under this Section 9 by providing Client with copies of relevant third-party audit reports, certifications, or security assessments, to the extent they cover the processing of Customer Personal Data under this DPA.

  1. International Data Transfers

10.1 Transfer Mechanisms. To the extent that the processing of Protected Data under this DPA involves a transfer of personal data from the EEA, the UK, or Switzerland to a country not recognized as providing an adequate level of data protection, the parties will comply with the requirements of Applicable Data Protection Laws governing such transfers, and the receiving party will ensure that a lawful transfer mechanism is in place.

10.2 Data Privacy Framework. upcell participates in and certifies its compliance with the Data Privacy Framework. Where and to the extent the Data Privacy Framework applies, upcell will rely on it to lawfully receive personal data in the United States, and upcell will (a) provide at least the same level of privacy protection as is required by the Data Privacy Framework Principles; and (b) notify Client if upcell determines that it can no longer meet its obligation to provide that level of protection, in which event upcell will cease the affected processing or take other reasonable and appropriate steps to remediate.

10.3 Standard Contractual Clauses. To the extent legally required, including where the Data Privacy Framework does not cover a transfer or ceases to provide a valid transfer mechanism, the parties are deemed to have entered into and signed the Standard Contractual Clauses, which are incorporated into this DPA and completed as set out in Exhibit C. Specifically:

(a) Module Two (Controller to Processor) applies to transfers of Customer Personal Data from Client, as Controller and data exporter, to upcell, as Processor and data importer.

(b) Module One (Controller to Controller) applies to transfers of upcell Information from upcell, as Controller and data exporter, to Client, as Controller and data importer.

10.4 UK Transfers. For transfers of Protected Data from the UK to which the UK Extension to the EU-U.S. Data Privacy Framework does not apply, the UK Addendum applies in addition to the SCCs and is incorporated into this DPA, completed as set out in Exhibit C.

10.5 Swiss Transfers. For transfers of Protected Data subject to the Swiss Federal Act on Data Protection to which the Swiss-U.S. Data Privacy Framework does not apply, the SCCs apply with the modifications set out in Exhibit C.

10.6 SCC Hierarchy. Where the SCCs apply, in the event of a conflict between the SCCs and this DPA, the SCCs will prevail with respect to the international transfer of Protected Data.

10.7 Sub-Processor Transfers. upcell will ensure that any international transfer of Customer Personal Data by a Sub-Processor is subject to an appropriate transfer mechanism under Applicable Data Protection Laws.

  1. CCPA and US State Privacy Laws

11.1 Service Provider Status. For the purposes of the CCPA, upcell acts as a “Service Provider” with respect to Customer Personal Data. upcell will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than providing the Service as specified in the Agreement and this DPA; (c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between the parties; or (d) combine Customer Personal Data with personal information received from other sources except as permitted by the CCPA.

11.2 CCPA Cooperation. upcell will cooperate with Client in responding to verifiable consumer requests received by Client under the CCPA, including requests to know, delete, correct, or opt out of sale or sharing, to the extent such requests relate to Customer Personal Data processed by upcell on Client’s behalf.

11.3 Businesses with Respect to upcell Information. With respect to upcell Information, each party is a “Business” as that term is defined in the CCPA, and each party will comply with its own obligations under the CCPA and other applicable US state privacy laws applicable to it in that capacity, including with respect to consumer rights of access, deletion, correction, and opt-out of sale or sharing.

11.4 Data Broker Obligations. To the extent upcell qualifies as a “data broker” under Applicable Data Protection Laws, upcell will maintain all required registrations and will process consumer deletion and opt-out requests received through any state-administered accessible deletion mechanism, including California’s Delete Request and Opt-Out Platform, within the timeframes required by law, and will give effect to such requests in accordance with Section 13.6.

11.5 Verification. Solely where and to the extent the CCPA applies to such processing, the party disclosing personal information to the other retains the right, upon reasonable notice, to (a) take reasonable and appropriate steps to ensure that the receiving party uses that personal information in a manner consistent with the disclosing party’s obligations under the CCPA, and (b) stop and remediate any unauthorized processing of that personal information.

11.6 Provision of Equivalent Protection. For personal information subject to the CCPA, each party will provide the same level of privacy protection to personal information received from the other party as the disclosing party is required to provide under the CCPA, and will notify the other party if it determines that it can no longer meet its obligations under the CCPA.

  1. Retention and Deletion of Customer Personal Data

12.1 Retention During Term. upcell will retain Customer Personal Data for the duration of the Agreement and as set out in the Terms of Service: transaction and enrichment logs are retained for the duration of Client’s subscription plus thirty (30) days following termination.

12.2 Deletion on Termination. Upon expiration or termination of the Agreement, upcell will, at Client’s election, delete or return all Customer Personal Data within thirty (30) days, except to the extent upcell is required by Applicable Data Protection Laws to retain it. Where retention is required by law, upcell will notify Client, limit further processing to the minimum necessary, and delete such data as soon as the retention obligation expires. Customer Personal Data stored in backups, replicas, and snapshots is not automatically purged but instead ages out of the system as part of the data lifecycle; during that period such data remains subject to access controls, is not used for any active processing, and is placed on a suppression list so that it is not re-collected, re-shared, or sold following a valid deletion or opt-out request. upcell reserves the right to alter the data purging period in order to address technical, compliance, or statutory requirements.

12.3 Suppression File. Notwithstanding the above, upcell may retain suppression records (i.e., records of individuals who have exercised data subject rights) indefinitely and solely for the purpose of honoring those rights on an ongoing basis. This is consistent with regulatory guidance and upcell’s obligations under Applicable Data Protection Laws.

  1. upcell Information — Independent Controller Processing

13.1 Independent Controller Obligations. With respect to upcell Information, each party will (a) ensure that it is not subject to any prohibition or restriction that would prevent or restrict it from disclosing or receiving upcell Information as contemplated by this DPA; (b) independently ensure that it has a lawful basis for its own processing of upcell Information and that such processing complies with Applicable Data Protection Laws; (c) comply with its obligations under Applicable Data Protection Laws, including Articles 13 and 14 GDPR, and ensure that all required transparency notices have been provided and are kept up to date, sufficient in scope to enable each party to process upcell Information in accordance with Applicable Data Protection Laws; (d) ensure that upcell Information it processes is adequate, relevant, and limited to what is necessary in relation to the permitted purpose; and (e) ensure that upcell Information is transferred between the parties by secure means.

13.2 Permitted Purpose. upcell discloses upcell Information to Client for Client’s B2B Activities. Client will process upcell Information only for its B2B Activities or as otherwise expressly permitted under the Agreement, and in each case in accordance with Applicable Data Protection Laws, the EU ePrivacy Directive 2002/58/EC (as amended), and all applicable country-specific marketing and telemarketing regulations. Client is solely responsible for any communications it sends using upcell Information.

13.3 upcell Representations. upcell represents and warrants that (a) upcell Information consists of business contact data relating to individuals acting in their professional or employment capacity; (b) upcell has compiled upcell Information in compliance with applicable United States federal and state privacy laws; (c) upcell has the right to license upcell Information to Client as contemplated by the Agreement; and (d) upon a verified opt-out or deletion request received from a data subject through its Privacy Center, upcell will permanently suppress the individual’s record platform-wide and exclude suppressed individuals from upcell Information subsequently delivered through the Service. Except as expressly set out in this Section 13.3 and in the Agreement, upcell Information is provided on an “as is” basis and upcell makes no representation or warranty as to its accuracy, completeness, or currency.

13.4 Client Representations. Client represents and warrants that (a) it will process upcell Information in compliance with Applicable Data Protection Laws, the EU ePrivacy Directive 2002/58/EC (as amended), and all applicable country-specific marketing and telemarketing regulations; (b) it will maintain a publicly accessible privacy notice that satisfies the transparency requirements applicable to its processing of upcell Information; and (c) it will comply with its obligations under Section 13.6.

13.5 Security. Each party will implement and maintain technical and organizational measures appropriate to the risk in respect of upcell Information in its possession or control, at a standard no less than that required by Applicable Data Protection Laws and consistent with good industry practice. Client will be able to demonstrate its compliance with this Section to upcell upon reasonable written request.

13.6 Opt-Out Propagation. upcell publishes a list of record identifiers corresponding to individuals who have exercised opt-out or deletion rights (the “Suppression List”), available at https://app.upcell.io/opted-out-contacts or through such other mechanism as upcell may designate in writing. The Suppression List contains record identifiers and opt-out dates only and does not contain personal data. Client will retain the upcell record identifier associated with each record of upcell Information it receives, and will review the Suppression List no less than once every thirty (30) days. Within thirty (30) days of a record identifier appearing on the Suppression List, Client will either (a) permanently delete the corresponding record from all systems within Client’s control, including CRM systems, enrichment workflows, sequences and cadences, exports, integrations, and other downstream repositories where upcell Information may reside; or (b) document and retain an independent legal basis for its continued processing of that record. Suppression, or cessation of active use, does not satisfy the deletion obligation under clause (a). This Section 13.6 survives termination or expiration of the Agreement.

13.7 Data Subject Rights. Each party will provide such assistance as is reasonably required to enable the other party to respond to requests from data subjects to exercise their rights under Applicable Data Protection Laws within the applicable time limits. Data subjects seeking to exercise rights in relation to upcell Information held by upcell may submit a request through upcell’s Privacy Center at upcell.io/data-claim. Client is responsible for responding to requests it receives in relation to upcell Information within Client’s own systems.

13.8 Security Incidents. Each party will comply with its own obligations under Applicable Data Protection Laws to report a Security Incident affecting upcell Information to the competent supervisory authority and, where applicable, to affected data subjects, and will promptly notify the other party of any such Security Incident affecting upcell Information transferred between the parties.

13.9 Onward Disclosure. Client will not sell, license, sublicense, or otherwise make upcell Information available to any third party except as expressly permitted by the Agreement. Where the Agreement permits disclosure to a third party, Client will impose obligations on that third party no less protective than those in this Section 13.

  1. Liability

Each party’s liability under this DPA and under the Standard Contractual Clauses is subject to the limitations and exclusions set out in the Agreement, and each party’s aggregate liability arising out of or relating to this DPA and the Standard Contractual Clauses will be subject to those limitations and exclusions. Nothing in this DPA limits either party’s liability to data subjects or supervisory authorities under Applicable Data Protection Laws, to the extent such liability cannot be limited by contract.

  1. Term and Termination

This DPA is effective as of the date the Agreement becomes effective and continues for the duration of the Agreement. Termination of the Agreement automatically terminates this DPA. Sections 3 (Confidentiality), 5 (Security Incident Notification), 10 (International Data Transfers), 12 (Retention and Deletion), 13.6 (Opt-Out Propagation), 13.9 (Onward Disclosure), and 14 (Liability) survive termination of this DPA.

  1. General

16.1 Order of Precedence. In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Protected Data. In the event of a conflict between this DPA and the SCCs, the SCCs control with respect to international transfers of Protected Data.

16.2 Amendments. upcell may update this DPA from time to time where necessary to reflect changes in Applicable Data Protection Laws, changes to the Standard Contractual Clauses or the UK Addendum, or the addition or replacement of Sub-Processors in accordance with Section 6.3. upcell will provide thirty (30) days’ prior written notice of any such update. Any other amendment to this DPA requires the written agreement of both parties.

16.3 Governing Law. This DPA is governed by the same governing law as the Agreement, except that with respect to the SCCs, the governing law provisions of the SCCs apply.

16.4 Entire Agreement. This DPA, together with the Agreement and any applicable SCCs, constitutes the complete agreement between the parties with respect to the processing of Protected Data and supersedes all prior agreements or understandings on this subject.

Exhibit A — Processing Details

Part 1 — Customer Personal Data (Controller to Processor)

Subject Matter of Processing

upcell processes Customer Personal Data to provide its B2B sales intelligence and CRM enrichment platform, including the upcell Chrome extension, the upcell platform, and the upcell API.

Duration of Processing

For the duration of the Agreement, plus the retention periods specified in Section 12 of this DPA.

Nature and Purpose of Processing

  • Receiving Client’s own contact records submitted by Client or an Authorized User, and matching them against upcell Information

  • Returning matched records to the requesting Authorized User and delivering records to Client’s CRM at Client’s direction

  • Routing enrichment requests through third-party enrichment provider credentials supplied by Client, mapping returned data fields, and delivering enriched records to Client’s CRM

  • Provisioning and administering Authorized User access to the Service

  • Maintaining transaction and enrichment records accessible to Client through the platform

Categories of Personal Data

The categories of personal data include, but are not limited to, the following:

  • Contact records submitted by Client, including name, employer name, job title, business email address, and business telephone number

  • Data returned to Client through third-party enrichment providers using credentials supplied by Client

  • CRM record identifiers used for matching and deduplication

  • Authorized User account data: first name, last name, business email address, user ID assigned at authentication by Client’s identity provider, and export and enrichment activity logs associated with that user ID

Categories of Data Subjects

  • Business professionals acting in their professional or employment capacity whose identifiers or records are submitted to the Service by Client or an Authorized User

  • Client’s personnel provisioned as Authorized Users of the Service

Special Categories of Data

None. upcell does not process special categories of personal data as defined under GDPR Article 9 or equivalent provisions of Applicable Data Protection Laws.

Part 2 — upcell Information (Controller to Controller)

Subject Matter of Processing

upcell compiles, validates, and maintains a proprietary database of business contact data and discloses records from it to Client through the upcell Chrome extension, the upcell platform, and the upcell API, in response to requests initiated by Client or an Authorized User.

Duration of Processing

Continuous for the duration of the Agreement, on a per-request basis.

Nature and Purpose of Processing

Disclosure by transmission of upcell Information to Client, and Client’s subsequent collection, recording, organization, storage, retrieval, consultation, use, erasure, and destruction of that information under its own authority as an independent Controller, for Client’s B2B Activities.

Categories of Personal Data

The categories of personal data include, but are not limited to, the following:

  • Name

  • Job title, department, seniority, and professional role

  • Employer or company name

  • Business location (city, state, or country)

  • Links to publicly available professional profiles

  • Business email address

  • Business telephone number

  • Contact scores and profile summaries derived or generated by upcell

Categories of Data Subjects

Business professionals acting in their professional or employment capacity whose records are contained in upcell’s proprietary database.

Special Categories of Data

None. upcell Information does not include special categories of personal data under GDPR Article 9, personal data relating to criminal convictions and offences under GDPR Article 10, personal email addresses, home addresses, financial information, or health data.

Legal Basis

upcell processes upcell Information on the basis of its legitimate interests under Article 6(1)(f) GDPR. Client determines its own legal basis for its processing of upcell Information following receipt.

Exhibit B — Authorized Sub-Processors

upcell’s current list of authorized Sub-Processors is maintained at:

https://www.upcell.io/legal/subprocessors

This page is updated whenever upcell adds, replaces, or removes a Sub-Processor. upcell will notify Client of any material changes in accordance with Section 6.3 of this DPA. The Sub-Processor list identifies each Sub-Processor by name, processing activity, and location. For Sub-Processors whose identity is competitively sensitive, upcell will disclose full details to enterprise Clients upon written request under a non-disclosure agreement.

Sub-Processors are engaged only in respect of Customer Personal Data. Clause 9 of the SCCs does not apply to Module One.

Exhibit C — Standard Contractual Clauses

Where the Standard Contractual Clauses apply under Section 10.3, the parties are deemed to have entered into and signed them, which form part of this DPA and are completed as set out in this Exhibit C. Signature of, or electronic assent to, the Agreement constitutes signature of the SCCs and, where applicable, the UK Addendum.

C.1 Module and Clause Selections

The following apply to both Module One and Module Two except where stated:

Clause

Selection

Module One (Controller to Controller)

Applies to transfers of upcell Information from upcell (exporter) to Client (importer)

Module Two (Controller to Processor)

Applies to transfers of Customer Personal Data from Client (exporter) to upcell (importer)

Clause 7 (Docking Clause)

Included

Clause 9 (Use of Sub-Processors)

Module Two only. Option 2 (general written authorization) applies, with thirty (30) days’ notice of Sub-Processor changes in accordance with Section 6.3. Clause 9 does not apply to Module One.

Clause 11 (Redress)

The optional language requiring an independent dispute resolution body is not included

Clause 13 (Supervision)

As set out in Section C of the applicable Annex I below

Clause 17 (Governing Law)

Option 1 applies. The law of Ireland governs.

Clause 18 (Choice of Forum)

The courts of Ireland have jurisdiction.

Annex II (Technical and Organisational Measures)

As set out in Section C.4 below

Annex III (Sub-Processors)

Module Two only. As set out in Exhibit B.

C.2 Annex I — Module Two (Controller → Processor)

A. List of Parties

Data exporter

Field

Entry

Name

The Client identified in the Agreement or applicable Order Form, for itself and on behalf of its Affiliates established in the European Economic Area, the United Kingdom, and Switzerland

Address

As set out in the Agreement or applicable Order Form

Contact person’s name, position, contact details

As set out in the Agreement or applicable Order Form, or as otherwise agreed by the parties

Activities relevant to the data transferred

Submission of Client’s own contact records to the Service for matching, enrichment, and delivery to Client’s CRM; administration of Client’s account and Authorized Users

Signature and date

Signature of, or electronic assent to, the Agreement

Role

Controller

Data importer

Field

Entry

Name

upcell, LLC

Address

6 Liberty Sq PMB 455, Boston, MA 02109, USA

Contact person’s name, position, contact details

Privacy Team; [email protected]

Activities relevant to the data transferred

Provision of the Service, comprising receipt of Client-submitted identifiers and records, matching against upcell’s proprietary database, return of results to the requesting Authorized User, delivery of records to Client’s CRM at Client’s direction, and maintenance of transaction and enrichment records

Signature and date

Signature of, or electronic assent to, the Agreement

Role

Processor

B. Description of Transfer

Categories of data subjects. As set out in Exhibit A, Part 1 (Categories of Data Subjects).

Categories of personal data. As set out in Exhibit A, Part 1 (Categories of Personal Data).

Sensitive data. None. The Service is not designed to process special categories of personal data under GDPR Article 9, personal data relating to criminal convictions and offences under GDPR Article 10, or consumer data. Client is restricted under the Agreement from submitting such data.

Frequency of the transfer. Continuous for the duration of the Agreement.

Nature of the processing. Receipt, matching, structuring, storage, retrieval, consultation, use, transmission to Client’s CRM at Client’s direction, logging, restriction, erasure, and destruction, in each case by automated means and solely to provide the Service in accordance with Client’s instructions.

Purpose(s) of the transfer and further processing. As set out in Exhibit A, Part 1 (Nature and Purpose of Processing).

Retention period. For the duration of the Agreement, plus the retention periods specified in Section 12 of this DPA. Suppression records may be retained indefinitely in accordance with Section 12.3.

Transfers to Sub-Processors. Sub-Processors listed in Exhibit B process Customer Personal Data solely to support provision of the Service, for the duration of the Agreement, on terms no less protective than those in this DPA.

C. Competent Supervisory Authority

The supervisory authority of the EEA Member State in which the data exporter is established; or, where the data exporter is not established in the EEA, the supervisory authority of the Member State in which the data exporter’s representative under Article 27 GDPR is established. Where the transfer is subject to the UK GDPR, the UK Information Commissioner. Where the transfer is subject exclusively to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner.

C.3 Annex I — Module One (Controller → Controller)

A. List of Parties

Data exporter

Field

Entry

Name

upcell, LLC

Address

6 Liberty Sq PMB 455, Boston, MA 02109, USA

Contact person’s name, position, contact details

Privacy Team; [email protected]

Activities relevant to the data transferred

Compilation, validation, and maintenance of upcell’s proprietary business contact database, and disclosure of upcell Information to Client through the upcell Chrome extension, the upcell platform, and the upcell API

Signature and date

Signature of, or electronic assent to, the Agreement

Role

Controller

Data importer

Field

Entry

Name

The Client identified in the Agreement or applicable Order Form

Address

As set out in the Agreement or applicable Order Form

Contact person’s name, position, contact details

As set out in the Agreement or applicable Order Form, or as otherwise agreed by the parties

Activities relevant to the data transferred

Receipt and use of upcell Information for Client’s B2B Activities, subject to the licence and use restrictions in the Agreement and this DPA

Signature and date

Signature of, or electronic assent to, the Agreement

Role

Controller

B. Description of Transfer

Categories of data subjects. As set out in Exhibit A, Part 2 (Categories of Data Subjects).

Categories of personal data. As set out in Exhibit A, Part 2 (Categories of Personal Data).

Sensitive data. None, as set out in Exhibit A, Part 2 (Special Categories of Data).

Frequency of the transfer. Continuous for the duration of the Agreement, on a per-request basis initiated by Client or an Authorized User.

Nature of the processing. Disclosure by transmission of upcell Information to Client, and Client’s subsequent collection, recording, organization, storage, retrieval, consultation, use, erasure, and destruction of that information under its own authority as an independent Controller.

Purpose(s) of the transfer and further processing. Client’s B2B Activities, as permitted by and subject to the licence and use restrictions set out in the Agreement and Section 13 of this DPA. Client determines its own purposes and legal basis for its processing of upcell Information following receipt.

Retention period. Client retains upcell Information in accordance with the Agreement, Section 13.6 of this DPA, and its own retention policies as an independent Controller. upcell retains records within its own database in accordance with its published privacy policy, save that suppression records are retained indefinitely in accordance with Section 12.3.

Transfers to Sub-Processors. Not applicable. Clause 9 does not apply to Module One.

C. Competent Supervisory Authority

The Irish Data Protection Commission. upcell, as data exporter, is not established in the European Economic Area; its representative appointed under Article 27 GDPR is established in Ireland. Where the transfer is subject to the UK GDPR, the UK Information Commissioner. Where the transfer is subject exclusively to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner.

C.4 Annex II — Technical and Organisational Measures

For Module Two, the technical and organisational measures implemented by upcell as data importer are as follows:

Encryption. Customer Personal Data is encrypted in transit using TLS and at rest using industry-standard encryption algorithms. Encryption keys are managed in accordance with industry-standard key-management practices.

Access control. Authorized Users authenticate through their identity provider before accessing non-public data. Internal access to Customer Personal Data is limited to personnel who require it to provide the Service, granted by role, logged, reviewed periodically, and revoked on role change or departure. Customers access the Service only through the application interface and API, and not directly through the underlying infrastructure.

Network and infrastructure security. The Service is hosted with outsourced data center providers maintaining industry-standard security certifications, whose physical and environmental controls are subject to third-party audit. Network access controls restrict unauthorized traffic reaching production systems.

Logging and detection. System behavior, authentication events, and application requests are logged. Log data is aggregated and monitored, and alerts are routed to responsible personnel.

Incident response. upcell maintains documented incident response procedures, including defined escalation paths, investigation, and a record of confirmed security incidents.

Testing. upcell conducts regular security testing and vulnerability assessment of the Service.

Personnel. Personnel authorized to process Customer Personal Data are subject to binding confidentiality obligations and receive data protection training appropriate to their role.

Sub-processor management. Sub-processors are assessed before engagement and are subject to written agreements imposing data protection obligations no less protective than those in this DPA.

Certification. upcell maintains a SOC 2 Type II report covering the technical and organisational measures described in this Annex II, available to Client upon request under a non-disclosure agreement.

upcell may modify or update these measures at its discretion, provided that such modifications do not result in a degradation of the overall security of the Service.

For Module One, the technical and organisational measures implemented by Client as data importer are those required by Section 13.5 of this DPA. Client will establish and maintain security measures that meet or exceed the standard set out in this Annex II, and will be able to demonstrate its compliance to upcell upon reasonable written request.

C.5 UK Addendum

Where Protected Data is transferred from the UK, the parties are deemed to have entered into the UK Addendum, completed as follows:

Table

Entry

Table 1 (Parties)

As set out in Section C.2(A) or C.3(A) above, as applicable. Key contacts as stated therein.

Table 2 (Selected SCCs, Modules and Clauses)

The SCCs as completed in this Exhibit C, with Module One or Module Two in operation as applicable; Clause 7 included; Clause 11 optional language omitted; Clause 9(a) Option 2 with thirty (30) days’ notice (Module Two only)

Table 3 (Appendix Information)

Annex I as set out in Section C.2 or C.3 above; Annex II as set out in Section C.4 above; Annex III as set out in Exhibit B (Module Two only)

Table 4 (Ending the Addendum)

upcell may end the UK Addendum as set out in Section 19 of the UK Addendum

For transfers subject to the UK Addendum, the governing law is that of England and Wales, the courts of England and Wales have jurisdiction, and the UK Information Commissioner is the competent supervisory authority.

C.6 Swiss Transfers

For transfers of Protected Data subject to the Swiss Federal Act on Data Protection (“FADP”), the SCCs apply with the following modifications:

  • References to the GDPR are to be understood as references to the FADP insofar as the transfer is subject exclusively to the FADP.

  • The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, or, where the FADP and GDPR apply in parallel, both that Commissioner and the supervisory authority identified in Annex I.C.

  • The term “Member State” will not be interpreted so as to exclude data subjects in Switzerland from bringing proceedings in their place of habitual residence in accordance with Clause 18(c).

  • Where the transfer is subject exclusively to the FADP, the governing law is Swiss law and the courts of Switzerland have jurisdiction.