Data Processing Addendum (DPA)
Effective: August 23, 2026, Last updated: September 9, 2026
This Data Processing Addendum ("DPA") is incorporated into and forms part of the
PipelinePulse Terms of Service (the "Agreement") between PipelinePulse, Inc.,
a North Carolina S-corporation ("Provider" or "PipelinePulse"), and the customer
entity that accepts the Agreement ("Customer"). It governs Provider's processing
of personal data on Customer's behalf in connection with Customer's use of the
PipelinePulse service (the "Service").
Effective date and acceptance. This DPA is effective as of the date Customer
first accepts the Agreement — by creating an account or otherwise using the
Service — and remains in effect for as long as Provider processes Customer
Personal Data. Customer's use of the Service constitutes acceptance of this DPA;
no signature is required. Where Customer requires a countersigned copy for its
records, Provider will make one available on request. Capitalized terms not
defined here have the meanings given in the Agreement.
Updates. Provider may update this DPA from time to time; material changes will
be notified as provided in the Agreement, and continued use of the Service after
an update's effective date constitutes acceptance of the updated DPA.
Provider's data-export and business-continuity commitments (wind-down, data-out)
are addressed in the Agreement and in Annex 4; this DPA addresses the processing
of personal data.
1. Definitions
- "Customer Data" — the data Customer and its authorized users submit to, or
generate through, the Service, including proposal content and documents,
recipient and stakeholder information, document-engagement telemetry, and
e-signature records.
- "Customer Personal Data" — personal data contained in Customer Data that
Provider processes on Customer's behalf: information about Customer's personnel
and about the recipients and reviewers of Customer's proposals. Annex 1
describes the processing.
- "Controller" and "Processor" — as commonly defined in Data
Protection Laws (including, when applicable, Regulation (EU) 2016/679, the
"GDPR"): the Controller determines the purposes and means of processing;
the Processor processes on the Controller's documented instructions.
- "Data Protection Laws" — all data protection and privacy laws applicable
to the processing of Customer Personal Data under this DPA, including U.S.
federal and state laws (e.g., the CCPA where applicable) and, from the point
it applies to the parties' processing, the GDPR and UK GDPR.
- "Personal Data Breach" — a breach of security leading to accidental or
unlawful destruction, loss, alteration, unauthorized disclosure of, or
access to Customer Personal Data.
- "Subprocessor" — a third party engaged by Provider to process Customer
Personal Data in support of the Service (Annex 3).
2. Roles of the parties
Customer is the Controller of Customer Personal Data; Provider is the
Processor, acting only on Customer's documented instructions. The parties
agree the Agreement, this DPA, and Customer's configuration and use of the
Service are Customer's complete documented instructions. Customer's own systems
remain Customer's system of record.
3. Customer responsibilities
Customer is responsible for: (a) the accuracy and lawful collection of
Customer Personal Data submitted to the Service, including any notice or
lawful basis required to share proposal-recipient information with Provider;
(b) its configuration choices in the Service (e.g., viewer-consent posture,
gate fields, link expiry); and (c) ensuring its instructions comply with Data
Protection Laws.
4. Provider obligations as Processor
Provider will:
1. Process only on instructions (§2), and not sell Customer Personal Data
or use it for advertising, profiling beyond the Service's engagement
analytics, or any purpose other than providing and supporting the Service.
2. Confidentiality — ensure persons authorized to process Customer
Personal Data are bound by confidentiality obligations.
3. Security — maintain the technical and organizational measures described
in Annex 2, and not materially reduce the overall protection of Customer
Personal Data during the term.
4. Breach notification — notify Customer **without undue delay, and no
later than seventy-two (72) hours** after becoming aware of a Personal Data
Breach. The notice will describe the nature of the breach, the categories
of data affected, measures taken or planned, and a contact point, and
Provider will provide timely updates as the investigation proceeds. The
same commitment applies to breaches reported to Provider by a Subprocessor.
5. Assistance — provide reasonable assistance with data subject requests
(access, correction, deletion), data protection impact assessments, and
regulator consultations, taking into account the nature of the processing.
6. Deletion and return — on termination of the Service or on Customer's
request, delete or return Customer Personal Data per the retention schedule
in Annex 4: complete export available per the Agreement;
deletion within thirty (30) days of termination or request; backup
copies age out fully within a further seven (7) days under Provider's
rolling backup retention; written confirmation of deletion on request.
Deletion is performed with verified operator tooling, not best-effort.
5. Subprocessors
Customer authorizes the Subprocessors listed in Annex 3. Provider will give
thirty (30) days' advance written notice before adding or replacing a
Subprocessor; Customer may object on reasonable data-protection grounds, and
if the parties cannot resolve the objection Customer may terminate the
affected Service. Provider remains responsible for its Subprocessors'
performance to the standard of this DPA.
6. Data subject requests
If Provider receives a request directly from a data subject relating to
Customer Personal Data (e.g., a proposal recipient requesting deletion),
Provider will forward it to Customer without undue delay and will not respond
substantively except to direct the person to Customer, unless legally
required. Provider will act on Customer's resulting instructions within
thirty (30) days.
7. Retention
Provider retains Customer Personal Data per the schedule in Annex 4.
Retention limits for ephemeral data are enforced automatically in the
platform (scheduled purge jobs), not merely documented. A legal hold or
active dispute suspends deletion until resolved, after which the schedule
resumes.
8. California (CCPA)
To the extent the CCPA applies, Provider acts as Customer's "Service
Provider": Provider will not sell or share Customer Personal Data, will not
retain, use, or disclose it outside the direct business relationship or for
any purpose other than the business purposes in this DPA, and certifies it
understands these restrictions.
9. Processing location & international transfers; GDPR roadmap
9.1 Customer Personal Data is processed and stored in the United States
(Annex 3). Provider will not transfer Customer Personal Data outside the
United States without ensuring a lawful transfer mechanism under applicable
Data Protection Laws.
9.2 GDPR roadmap. Provider is pursuing full GDPR alignment of the Service
on an ongoing basis. If and when Customer Personal Data includes data subjects
in the EU/EEA or UK, the parties will promptly execute the applicable Standard
Contractual Clauses (and UK Addendum, as applicable), which will be
incorporated into this DPA by amendment to Annex 1. The definitions and
obligations of this DPA are drafted to be compatible with GDPR Article 28 so
that such an amendment does not require renegotiating the body of this DPA.
10. Demonstration of compliance
On Customer's reasonable written request (no more than annually, unless
following a Personal Data Breach), Provider will make available the current
Security & Data Protection Overview and respond in writing to reasonable
security questionnaires. Provider does not currently hold SOC 2 or ISO 27001
certification and does not represent otherwise.
11. General
This DPA is subject to the limitations of liability in the Agreement. If this
DPA conflicts with the Agreement, this DPA controls as to the processing of
Customer Personal Data. Obligations survive termination until all Customer
Personal Data is deleted or returned.
---
Annex 1 — Details of processing
- Data subjects: Customer's personnel (sales reps, administrators);
recipients and reviewers of Customer's proposals (prospects, their
colleagues to whom a proposal is forwarded).
- Categories of personal data: name, business email address, phone
number, job title, company; document engagement telemetry (view sessions,
time-on-page, forwards); e-signature records (typed or drawn signature
image, signer name/title, email-verification status, timestamps, document
hash). No IP addresses are stored for document-viewing or engagement
telemetry (coarse country-level geolocation only), and no device
fingerprinting is used. One disclosed exception: at signature execution,
the signing audit record captures the signer's IP address as electronic-
signature evidence, governed by Customer's own "Audit Trail Rigor"
configuration: region-aware (the default — masked/truncated for
EU/EEA/UK signers and when the country is unknown, full otherwise),
always-masked, or always-full. This value is used solely for the
executed contract's legal defensibility, never for analytics.
No special categories of data are intended to be processed.
- Nature and purpose: hosting and delivering proposal documents;
tracking engagement and notifying Customer; capturing and sealing
e-signatures; providing the API and webhooks Customer configures.
- Duration: for the term of Customer's use of the Service, then per
Annex 4.
Annex 2 — Security measures
As described in the PipelinePulse Security & Data Protection Overview
(current version available on request), including: PostgreSQL Row-Level
Security as the tenant-isolation enforcement boundary; private storage
buckets with per-organization UUID prefixes and server-brokered short-lived
signed URLs; TLS in transit and encryption at rest; hashed API keys;
encrypted webhook secrets with HMAC-signed deliveries; email-verified
e-signature finalization with SHA-256 document hashing; daily backups with a
7-day rolling window.
Annex 3 — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel, Inc. | Application hosting | United States |
| Supabase, Inc. (on AWS) | Database, authentication, file storage, realtime | United States (US-East) |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery | United States |
| PostHog, Inc. | Product analytics | European Union (Germany) — PostHog EU Cloud |
| Zoho (Zoho Corporation ) | Marketing and CRM| United States |
Annex 4 — Retention schedule
| Data | Retention | Enforcement |
|---|---|---|
| Customer content (proposals, revisions, executed contracts, signature records) | Life of the account | Deleted within 30 days of termination/request |
| Account & engagement data (profiles, stakeholders, sessions, notifications, ledger) | Life of the account | Deleted within 30 days of termination/request |
| Backups | 7-day rolling window | Deleted data ages out fully within 7 days of primary deletion |
| Operational logs (hosting platforms) | ≤ 30 days | Platform-managed |
| Sandbox captured email | 30 days | Automatic scheduled purge |
| Webhook test echoes | 7 days | Automatic scheduled purge |
| Email verification codes (join flow) | ~15 minutes | TTL, single-use |
| Legal hold / active dispute | Deletion suspended until resolved | Manual |