Data Processing Addendum
- Effective date:
- [To be provided]
01Scope
This Data Processing Addendum ("DPA") describes how ReachEase processes customer data on behalf of a workspace when the workspace uses the service. It supplements the Terms of Use and applies where ReachEase processes personal data as part of providing the service. Placeholder fields will be completed once confirmed.
02Roles of the parties
For customer data processed through the service, the workspace generally acts as the controller that determines the purposes of processing, and ReachEase acts as a processor that handles the data on the workspace's behalf and in accordance with its instructions and this DPA.
03Processing instructions
ReachEase processes customer data to provide the service and in line with the workspace's documented instructions, including as configured through the product. We will not use customer data for purposes outside providing the service except where permitted by the agreement or required by applicable law.
04Confidentiality
We treat customer data as confidential and make it available to personnel and providers only on a need-to-know basis to provide the service, under appropriate obligations of confidentiality.
05Security commitments
We maintain technical and organizational measures intended to protect customer data appropriate to the nature of the service. This addendum describes those commitments at a high level; it does not assert any specific encryption standard, certification, or control that has not been separately verified.
06Subprocessors
No subprocessors listed. [To be provided]
07Data subject requests
Where a workspace receives a request from an individual to exercise rights over their personal data, ReachEase will, taking into account the nature of the processing, provide reasonable assistance to help the workspace respond, to the extent the service allows.
08Incident notification
If we become aware of a security incident affecting customer data processed through the service, we will notify the affected workspace without undue delay and provide information reasonably available to us to help the workspace meet its own obligations.
09Deletion and return
On termination of the service, or on request where reasonably practicable, we will delete or return customer data in accordance with the agreement and applicable law, subject to any retention we are legally required or permitted to maintain.
10International transfers
Where customer data is processed in a location other than where the workspace or its data subjects are based, we take steps intended to handle such transfers consistently with this DPA and applicable law. This section applies where cross-border processing is relevant.
11Audit information
On reasonable request, and subject to appropriate confidentiality and scope limits, we will make available information reasonably necessary to demonstrate compliance with this DPA. The specific mechanisms will be confirmed as part of finalizing this addendum.
12Annex — description of processing
Subject matter: provision of the ReachEase LinkedIn outreach service to the workspace.
Nature and purpose: processing customer data to operate campaigns, imports, sequences, LinkedIn sender distribution, and the unified inbox.
Categories of data and data subjects, duration of processing, and other specifics: [To be provided] once confirmed with the workspace and counsel.
Questions about this policy?
Contact us at [To be provided].
