01Scope and roles
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between you (the “Customer”) and GTMRouter (the “Provider”) and applies whenever we process personal data on your behalf in providing the Service. It applies automatically; you do not need to sign it. If you require a countersigned copy for your records, email founders@gtmrouter.dev.
For Customer Content and Recipient Data, as defined in our Privacy Policy, you are the controller and we are the processor. For your account, keys, ledger and billing records we are an independent controller, and this DPA does not apply.
“Data Protection Law” means the UK GDPR and Data Protection Act 2018, the EU GDPR, and any other privacy law applicable to the processing. Terms defined in Data Protection Law have the same meaning here.
02Processing on your instructions
We process personal data only on your documented instructions, which are: the Terms, this DPA, and the API calls made with your keys, including calls made by agents you have connected. We will inform you if, in our opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is resolved.
We may process personal data otherwise than on your instructions only where required by law, in which case we will tell you before processing unless the law prohibits it.
Suppression records are maintained under our own legal obligation to honour opt-outs and are retained after this DPA ends; you agree that this is a lawful instruction.
03Confidentiality
We ensure that every person we authorise to process personal data is bound by an appropriate duty of confidentiality, and that production access is limited to personnel with a demonstrated need.
04Security
We implement the technical and organisational measures described in Annex 2, and we keep them under review. We may update them, provided the level of protection does not decrease.
05Sub-processors
You give general written authorisation for us to engage the categories of sub-processor listed in Annex 3, and the named providers within them. The current named list is available on request from founders@gtmrouter.dev.
We will give you at least 14 days’ notice by email before adding or replacing a sub-processor that processes Customer Content. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith; where no resolution is possible, you may close your account and receive a refund of unspent purchased credits.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance.
06International transfers
We may transfer personal data outside the UK and the EEA only under a lawful transfer mechanism: an adequacy decision, the UK International Data Transfer Addendum, or the EU Standard Contractual Clauses (module two, controller to processor, or module three, processor to processor, as appropriate), together with any supplementary measures a transfer risk assessment requires. Where the Clauses apply between us, they are incorporated by reference, with you as data exporter and us as data importer, and the details in Annex 1 completing their annexes.
07Assistance
Taking into account the nature of the processing, we will assist you, by appropriate technical and organisational measures, in responding to data subject requests, and in meeting your obligations regarding security, breach notification, data protection impact assessments and prior consultation. Where a request from a data subject reaches us directly, we will suppress the address if asked and forward the request to you without undue delay.
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Content, and will provide the information reasonably needed for your own notifications as it becomes available.
08Return and deletion
You may export your Customer Content through the API and the Console at any time. When your account closes we erase Customer Content within 30 days, except suppression records and any data we are required by law to retain, which we continue to protect under this DPA for as long as we hold it.
09Audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28, including a description of our measures, our sub-processor list and summaries of any independent assessments we hold. Where that information is insufficient to meet a requirement of Data Protection Law, we will allow an audit by you or an independent auditor bound by confidentiality, no more than once in any 12 months, on at least 30 days’ notice, during business hours, in a manner that does not disrupt the Service or compromise other customers, at your cost.
10Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. Where this DPA conflicts with the Terms on a data protection matter, this DPA prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
11Annex 1 — Details of the processing
| Subject matter | Provision of the GTMRouter Service: lead discovery, contact enrichment, email verification, company signals, sending capacity, campaign drafting and launch, reply handling and LLM passthrough, executed on the Customer’s instructions. |
|---|---|
| Duration | For as long as the Customer holds an account, plus the deletion period in the Terms. |
| Nature and purpose | Retrieval, storage, enrichment, verification, transmission and classification of business contact data for the Customer’s own outbound sales and marketing. |
| Categories of data subject | The Customer’s prospects, leads and correspondents (business contacts in their professional capacity); the Customer’s own users. |
| Categories of personal data | Name, job title, employer, work email address, work telephone number, professional profile URL, company and role signals, email content and reply content, deliverability status, opt-out status. |
| Special category data | None. The Customer must not submit it. |
| Frequency | Continuous, as the Customer’s agents call the API. |
| Competent supervisory authority | The Information Commissioner’s Office (UK), or the authority of the Customer’s EEA establishment where EU GDPR applies. |
12Annex 2 — Technical and organisational measures
- Encryption: TLS for all data in transit; encryption at rest for databases and backups; backups additionally encrypted with a key held outside the storage provider.
- Authentication: no stored passwords; single-use emailed sign-in links or codes, or Google sign-in; API keys stored only as one-way hashes, scoped per verb, with optional spend limits; OAuth grants revocable from the Console.
- Authorisation and human control: server-enforced human confirmation before any purchase of sending capacity or campaign launch; suppression applied at draft, re-checked at launch and propagated to live campaigns.
- Integrity and accountability: append-only credit ledger; append-only audit log of every administrative action, including the actor and the authentication method.
- Resilience: encrypted backups every 12 hours held in two independent locations, with point-in-time recovery on the primary database and periodic test restores.
- Isolation: every resource is namespaced to a workspace; provider references are never exposed to customers; lookups run only through mapping tables.
- Containment: the ability to pause every campaign in a workspace, confirmed with the sending provider, within minutes of an abuse or compromise signal.
- Least privilege and change control: production changes ship only through the deployment pipeline from committed, reviewed code; irreversible operations require founder approval and a verified backup.
- Sub-processor management: written contracts, category disclosure, named list on request, 14 days’ notice of change.
13Annex 3 — Authorised sub-processor categories
| Category | Purpose | Location |
|---|---|---|
| Business-data providers (lead search, enrichment, verification, signals) | Answering data verbs on the Customer’s instruction | United States, EU, UK |
| Sending infrastructure provider | Domains, mailboxes, warming, sending and reply retrieval | United States |
| AI model providers (Anthropic, OpenAI) via an AI model routing provider | LLM passthrough | United States |
| Payment processing (Stripe) | Credit purchases | United States, EU |
| Cloud hosting, database and backup providers | Running the Service and storing data | United States, EU |
| Email delivery providers | Sign-in links, notifications and service email to the Customer | United States |
The named list of current providers within each category is available from founders@gtmrouter.dev.