Parties. Quicklead Technology Private Limited (“Quicklead”, the processor) and the customer entity that accepts the agreement (“Customer”, the controller).
Definitions. “GDPR” means Regulation (EU) 2016/679 and, as applicable, the UK GDPR and the Data Protection Act 2018. Controller, processor, personal data, processing, personal data breach and data subject carry the meanings given in the GDPR.
1. Roles and scope
For personal data contained in Customer’s workspace, Customer is the controller and Quicklead Technology Private Limited is the processor. This DPA forms part of the agreement between the parties and applies for as long as Quicklead processes that data. Where Quicklead determines the purposes and means of processing, for example its own account records and the Email Finder database, Quicklead acts as controller and this DPA does not apply to that processing.
2. Processing on documented instructions
Quicklead processes personal data only on the Customer’s documented instructions, which are the agreement, this DPA, and the configuration the Customer sets in the product. Quicklead will inform the Customer if an instruction appears to infringe applicable data protection law, and will not process for its own purposes.
3. Confidentiality
Every person authorised to process personal data is bound by a written confidentiality obligation that survives the end of their engagement, and receives data protection training appropriate to their role.
4. Security
Quicklead implements the technical and organisational measures in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects.
5. Sub-processors
The Customer grants a general authorisation for the sub-processors listed on the sub-processor page. Quicklead gives at least 30 days’ notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected service without penalty. Quicklead imposes data protection obligations on each sub-processor no less protective than those in this DPA, and remains fully liable for their performance.
6. Data subject rights
Taking into account the nature of the processing, Quicklead assists the Customer by appropriate technical and organisational measures in fulfilling requests under Chapter III. The product provides self-serve export, correction and deletion. Where a data subject contacts Quicklead directly about Customer data, Quicklead will not respond substantively but will forward the request to the Customer without undue delay.
7. Personal data breach
Quicklead notifies the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer personal data, with the information available at that time, and provides further information as the investigation progresses. Quicklead assists the Customer with its own notification obligations under Articles 33 and 34.
8. DPIAs and prior consultation
Quicklead provides reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of processing and the information available to it. Our own DPIA covering the AI features is available on request.
9. Deletion and return
At the Customer’s choice, Quicklead deletes or returns all personal data at the end of the service, and deletes existing copies unless retention is required by law. Workspace data is deleted within 30 days of account closure. Encrypted backups age out on their normal cycle and are not restored for any other purpose.
10. Audit and information
Quicklead makes available the information necessary to demonstrate compliance with Article 28, including its completed CAIQ, the sub-processor list, penetration test summaries and, once issued, its SOC 2 Type II report. Quicklead permits and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable notice, no more than once a year unless required by a supervisory authority or following a breach.
11. International transfers
Where Quicklead processes personal data outside the EEA or the UK, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), incorporated by reference, with module two or three as applicable, and by the UK International Data Transfer Addendum for UK exports. A transfer impact assessment is available on request. Quicklead is established in India and primary hosting is in the United States.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the agreement. Where this DPA conflicts with the agreement on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Annex I — Description of processing
Categories of data subject. The Customer’s prospects and business contacts, and the Customer’s own users.
Categories of personal data. Name, LinkedIn profile URL and public profile fields (headline, current company, role, location, industry, summary, education, skills), business email address, business phone number where present, message and reply content, campaign and pipeline status, and for Customer users, name, work email and authentication data.
Special category data. None is requested or required. The Customer must not upload special category data, and the product is not designed to process it.
Nature and purpose. Operating LinkedIn and email outreach campaigns on the Customer’s instruction, including sequencing, message personalisation, lead scoring, inbox routing and CRM synchronisation.
Duration. For the term of the agreement, plus the deletion window in clause 9.
Frequency. Continuous, for as long as campaigns are running.
Annex II — Technical and organisational measures
Access control. Role-based access on least privilege, individual named accounts, multi-factor authentication on administrative access, quarterly access review, and audit logging of administrative actions.
Encryption. TLS 1.2 or above for data in transit. AES-256 for data at rest, including database storage and backups. LinkedIn session credentials are encrypted at rest and are not visible to staff in plaintext.
Tenant isolation. Each customer workspace holds its own prospect, campaign and connection collections. Agency accounts can isolate each client workspace separately.
Change management. Peer review on every production change, version control, and the ability to roll back.
Logging and monitoring. Centralised application and infrastructure logging with alerting on anomalous activity.
Vendor management. Security review before any new sub-processor is engaged, and a written data processing agreement with each.
Incident response. A documented runbook, one-business-day acknowledgement, and 48-hour breach notification to affected customers.
Resilience. Encrypted automated backups, with restoration procedures documented. Tested disaster recovery evidence is in progress and is not yet claimed.
Personnel. Confidentiality obligations, background checks where lawful, and data protection training appropriate to role.
Annex III — Sub-processors
The authorised sub-processor list is published and maintained at quicklead.io/sub-processors and is incorporated into this DPA by reference. Customers on a signed DPA receive at least 30 days’ notice by email before any addition or replacement takes effect.
Annex IV — Contact
Privacy and security contact: [email protected]. An EU and UK Article 27 representative is being appointed and will be named here and in the privacy policy on completion.