Data Processing Agreement (DPA)

Personal-data processing — Article 28 GDPR

Version dated August 6, 2026

1. Purpose and scope

This data processing agreement (the "DPA") is entered into between NEURAWARE, a French SAS registered with the Paris Trade Register under no. 932 207 616, with its registered office at 66 avenue des Champs-Élysées, 75008 Paris, France ("Neuraware"), and the client of the Service (the "Client").

The DPA forms an integral part of the terms of service(the "Terms") and applies automatically to every Client using the Service, as from account creation. It governs, in accordance with Article 28 of Regulation (EU) 2016/679 (the "GDPR"), the processing of personal data carried out by Neuraware on the Client's behalf. In the event of a conflict with the Terms regarding data protection, the DPA prevails.

2. Roles

For the processing described in section 3, the Client is the controller (it determines the targets, messages and purposes of its campaigns) and Neuraware acts as processor, exclusively on the Client's instructions. Processing for which Neuraware is itself the controller (account, billing, technical logs) is described in the privacy policy and falls outside the DPA.

3. Description of the processing

  • Subject matter: running the Client's outreach campaigns from the accounts it connects (prospect identification, preparation and sending of messages, sorting of replies, writing assistance).
  • Duration: the term of the contract entered into under the Terms, until deletion of the data (section 10).
  • Nature: collection, structuring, storage, consultation, use, disclosure by transmission, erasure.
  • Purpose: the Client's professional outreach.
  • Categories of data: professional prospect data (identity, role, company, public profile URL, business contact details); connected-account data (conversations, contacts, messaging metadata).
  • Categories of data subjects: prospects targeted by the Client; correspondents and contacts of the connected accounts; the Client's users.

The Service is not designed to process special categories of data (Article 9 GDPR); the Client undertakes not to submit any for processing.

4. The Client's documented instructions

Neuraware processes the data only on the Client's documented instructions. The documented instructions consist of: the Terms, this DPA and the campaign configuration performed by the Client within the Service (targeting, messages, pacing). Neuraware informs the Client if, in its opinion, an instruction infringes the GDPR or other applicable provisions. Neuraware may depart from the instructions only where required by Union or Member State law, in which case it informs the Client unless legally prohibited. The data is never used to train third-party models.

5. Confidentiality of personnel

Neuraware ensures that the persons authorized to process the data are bound by an appropriate contractual or statutory duty of confidentiality and process the data solely for the needs of the Service.

6. Security

Neuraware implements the appropriate technical and organizational measures within the meaning of Article 32 GDPR, including: encryption of data in transit, per-workspace data segregation, strict need-to-know access control, logging of access and operations. These measures are reviewed regularly in light of the state of the art and the risks.

7. Sub-processors

The Client grants Neuraware a general authorization to engage sub-processors for the performance of the Service, within the following categories:

  • website and application hosting;
  • database hosting (European Union);
  • secure payment provider;
  • infrastructure providers for connecting to professional platforms and enriching professional data;
  • artificial-intelligence model providers;
  • audience-measurement tool (EU hosting).

The named list of sub-processors is available upon request through the contact form. Neuraware gives the Client prior notice of any addition or replacement (email or in-Service notification); the Client has thirty (30) days to raise a reasoned objection. Failing a reasonable solution, the Client may terminate in accordance with the Terms. Neuraware imposes on each sub-processor, by contract, obligations equivalent to those of this DPA and remains fully liable to the Client for their performance.

8. Assistance to the Client

Taking into account the nature of the processing, Neuraware assists the Client:

  • in responding to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection): Neuraware forwards to the Client without delay any request it receives directly and provides the relevant technical means (search, export, deletion of the data concerned);
  • in complying with the obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), in light of the information available to it.

9. Personal data breaches

Neuraware notifies the Client of any personal data breach without undue delayafter becoming aware of it, documenting its nature, the categories and approximate number of data subjects and records concerned, its likely consequences and the measures taken or proposed. Notifications to the supervisory authority and to data subjects in respect of the Client's processing are the Client's responsibility, as controller; Neuraware provides its assistance.

10. Fate of the data at the end of the contract

Throughout the term of the contract, the Client may export its data from the Service. At the end of the contract, Neuraware deletesthe data processed on the Client's behalf, save for any legal retention obligation, in accordance with the retention periods set out in the privacy policy.

11. Audit

Neuraware makes available to the Client the information necessary to demonstrate compliance with this DPA. The Client may additionally have an audit carried out, under the following conditions: at most once (1) per twelve (12)-month period, upon thirty (30) days prior written notice, at the Client's expense, during business hours and without disrupting the Service. An audit gives access neither to the data of Neuraware's other clients nor to the trade secrets of Neuraware or its sub-processors; the auditor, who may not be a competitor of Neuraware, is bound by a confidentiality undertaking.

12. Transfers outside the European Union

Application data is hosted within the European Union. Where a sub-processor processes data outside the European Union, the transfer is governed by the European Commission's standard contractual clauses, supplemented where appropriate by additional measures.

13. Liability

Each party's liability under the DPA is subject to the limitations and exclusions set out in section 12 of the Terms (cap and public-policy exceptions), which apply in the aggregate to the Terms and the DPA taken together.

14. Term, governing law and jurisdiction

The DPA takes effect upon account creation and remains in force for as long as Neuraware processes data on the Client's behalf. It is governed by French law; any dispute falls within the exclusive jurisdiction of the courts of Paris, as provided in the Terms.