Data Processing Agreement (DPA)
Version 2026-09-01, last updated 1 September 2026; effective for each Customer when concluded under Section 2
This Data Processing Agreement ("DPA") supplements and forms an integral part of the Terms and Conditions (the "Main Agreement") between Benjamin Wagner, operating as Customermates, An den Kasernen 25, 68167 Mannheim, Germany (the "Provider" or "Processor"), and the customer (the "Customer" or "Controller"). It governs the processing of personal data carried out by the Provider on behalf of the Customer within the framework of the software-as-a-service offering, including the optional connected-account feature (email, messaging and social-network operations, and calendar) and the hosted Mate AI assistant, in accordance with Art. 28 GDPR.
This version takes effect for a Customer only when concluded under Section 2. Publication, display, or access to this document does not by itself conclude or amend a DPA for an existing customer.
1. Subject Matter, Roles, and Duration
The subject matter of this DPA is the processing of personal data that the Provider performs on behalf of and on the documented instructions of the Customer in performing the Main Agreement.
With respect to the personal data covered by this DPA, in particular the Customer's CRM records, connected mailboxes, messages, contacts, calendars, social content and engagement data, profiles, relationship requests, Sales Navigator search and list data, and customer-controlled content included in a Mate request, the Customer acts as the controller and the Provider acts as the processor within the meaning of Art. 4 GDPR. The underlying communication platforms that the Customer connects (for example Google, Microsoft, LinkedIn, Meta/WhatsApp, Meta/Instagram, and Telegram) act as independent controllers for their own services.
This allocation does not affect the Provider's role as an independent controller for its own website, account, billing, security, and support data, which is described in the Provider's privacy policy and is not the subject of this DPA.
This DPA takes effect together with the Main Agreement and remains in force for as long as the Provider processes personal data on behalf of the Customer, irrespective of the termination of the Main Agreement, until all such data has been deleted or returned in accordance with Section 11.
2. Conclusion and Parties
The parties to this DPA are the Provider named above and the Customer, who is identified by the account and company data held in the Customer's account.
This DPA is concluded in electronic form within the meaning of Art. 28(9) GDPR when an authorised system administrator accepts the Main Agreement and this identified DPA version during onboarding on behalf of the business Customer. A later identified version amends this DPA only when an authorised system administrator accepts it electronically through the managed-service legal-update flow after the notice described in Section 10 of the Main Agreement. Updating the list maintained at Subprocessors under Section 9 does not constitute an amendment to this DPA and remains subject to the separate notice and objection procedure in that section. On request, the Provider provides the Customer with a copy of this DPA in text form.
Where the Customer does not itself determine the purposes and means of the processing, but makes the Service available to its own customers under its own agreement, for example as a reseller or partner, the Customer acts as a processor toward those customers and the Provider acts as a subprocessor. In that case, every reference in this DPA to the Customer as controller is to be read as a reference to the Customer acting on the documented instructions of its own customer. The Customer warrants that it is authorised to conclude this DPA and to issue the instructions given under it, and that the relevant controller has authorised the engagement of the Provider as a subprocessor. The Customer remains responsible toward the Provider for all obligations under this DPA.
This DPA covers only the managed Service operated by the Provider. Running the software on infrastructure independently controlled by a self-host operator does not by itself appoint the Provider as processor, and personal data covered by this DPA is not transmitted to the Provider merely because the software is installed or updated. The independent operator determines its own infrastructure, providers, purposes, and means of processing and is responsible for its own processor agreements and transfer safeguards. Any support, managed operation, Enterprise service, or other activity through which the Provider actually receives personal data requires the separately applicable agreement.
3. Nature and Purpose of the Processing
The Provider processes personal data solely for the purpose of providing the contractual services under the Main Agreement. The processing comprises:
- the core CRM service: creating, storing, displaying, searching, linking, exporting, and deleting the Customer's CRM records, in particular contacts, organisations, deals, services, tasks, notes, and custom fields; the administration of users and permissions; activity and audit logging; product notifications; and the delivery of webhooks to endpoints configured by the Customer;
- where activated, the connected-account feature: connecting the Customer's own email, messaging, social-network, and calendar accounts; retrieving, sending, synchronizing, and displaying messages, contacts, and calendar events; retrieving and displaying social posts, comments, reactions, and person or company profiles; listing, sending, accepting, withdrawing, or declining relationship requests; running Sales Navigator lead and company searches; viewing existing lead or account lists and adding entries to them; and storing a copy of synchronized content where described in the Privacy Policy;
- when a user invokes Mate interactively: storing the Mate conversation, assembling the requested prompt and recent conversation, retrieving authorised CRM or connected-account context through tools, sending the necessary request context through Vercel AI Gateway to the selected model at the downstream provider identified at Subprocessors, receiving and storing generated output, presenting proposed actions, enforcing existing permissions, carrying out authorised CRM or connected-account operations, waiting for a separate confirmation where product policy requires one, and recording turns, model rounds, approvals, tool receipts and results, and UI-command results; and
- where the managed Service offers Routines or other saved or automated Mate runs: storing the saved instruction, owner, trigger, limits, guardrail and run state; optionally analysing a saved event-triggered instruction through the model-provider chain for possible trigger loops before execution; starting an ordinary Mate conversation manually, on a schedule, or on a configured in-product event, including an event arising from CRM activity or connected-account synchronisation; including the event name and relevant record identifier in the initial instruction; retrieving authorised context through tools; enforcing the owner's current permissions and applicable confirmation controls; carrying out permitted operations, including actions that may occur without separate case-by-case confirmation; and recording the resulting conversation, run, model rounds, tool activity, results, and status.
The connected-account feature is powered by the transport provider UNIPILE SAS, which is engaged as a subprocessor subject to Section 9. Authentication takes place in a Unipile-hosted flow in which the Customer's user enters the relevant provider credentials or completes the provider's OAuth flow. Those credentials or the OAuth authorization are processed within that flow; the Provider receives neither provider passwords nor OAuth tokens and retains only an opaque account identifier and non-secret account metadata.
4. Categories of Data Subjects and Personal Data
Categories of data subjects. The processing concerns the Customer's own users; any natural persons whose personal data the Customer stores in the CRM, for example contacts, leads, prospects, customers, suppliers, partners, and their employees; correspondents with whom the Customer communicates; and other people returned or affected by connected-account operations, including post and comment authors, reactors, profile subjects, parties to relationship requests, Sales Navigator leads, and company representatives.
Categories of personal data. Depending on how the Customer configures and uses the service, the processing may cover:
- CRM record data, including names, contact details, company and role, deal and task data, free-text notes, and customer-defined custom fields;
- audit and activity logs recording actions taken in the Customer's account;
- Mate prompts and saved instructions, recent conversation text, generated output, tool definitions, tool inputs and results, approval and confirmation state, UI-command results, model-round records, Routine owner and trigger configuration, schedules, event names and relevant record identifiers, limits, guardrail and run state, loop-risk findings, model and provider identifiers, timestamps, and the company and user identifiers needed to associate those records with the Customer;
- content from the Customer's account that the Customer attaches to or reproduces in a support or feedback request;
- connected-account metadata (for example the connected account's identifier, type, and status);
- email content, including subject, body, sender and recipient addresses, and attachments;
- chat and direct-message content across the connected social and messaging channels;
- contact and participant profile data, including name, avatar, LinkedIn headline or occupation, profile URL, and the email address, phone number, or handle used as an identifier;
- social posts and engagement data, including post or comment text, authors, reactors, timestamps, reaction types, and counters;
- person and company profile and relationship data, including provider identifiers, names, profile URLs and images, descriptions, employment, location, industry, network distance, connection status, and request messages;
- Sales Navigator search inputs, results, and list data, including search URLs and filters, lead and company profiles, list names and membership, and saved status;
- calendar events, including attendee email addresses and RSVP status;
- message and account metadata; and
- the raw inbound payloads received from the underlying providers.
Attachment binaries are streamed or proxied on demand and are not stored by the Provider; only attachment metadata is stored. Because message, contact, calendar, social, relationship, and search content is determined by the Customer, its correspondents, and the underlying platforms, it may contain further categories of personal data, including special categories of personal data under Art. 9 GDPR where the Customer determines such content. The Customer, as controller, is responsible for the lawfulness of the content and operations it initiates through the service.
Where the Customer instructs Mate to process personal data, the Customer must limit the data and access to what is necessary for the requested task and ensure an applicable legal basis, purpose limitation, transparency, data minimisation, and safeguards appropriate to the risk. Before instructing Mate to process special categories of personal data under Art. 9 GDPR, data relating to criminal convictions and offences under Art. 10 GDPR, financial-account information, or government-issued identifiers, the Customer must satisfy every additional legal requirement applicable to that data. Separate entitlement, metering, usage, cost, credit, billing, security, and diagnostic records that the Provider processes as an independent controller are outside this DPA, as stated in Section 1 and the Privacy Policy. Those separate records contain identifiers, model and token counts, costs, credits, plan and billing status, timestamps, and security or diagnostic status, but do not themselves store prompt, conversation, generated-output, tool-input, or tool-result content.
5. Instructions of the Controller
The Provider processes the personal data covered by this DPA only on the documented instructions of the Customer, including with regard to the transfer of personal data to a third country or an international organisation, unless required to do otherwise by Union or Member State law to which the Provider is subject; in that case the Provider informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
The Customer's documented instructions are constituted by this DPA, the Main Agreement, and the Customer's use and configuration of the service (including the accounts it connects and the actions it initiates through the product). Where Routines are offered, configuring and activating the saved instruction, owner, trigger, limits, and connected permissions constitutes a standing documented instruction for each resulting run until the Routine is disabled or materially changed. Additional or amended instructions must be given in text form.
The Provider informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
6. Obligations and Rights of the Controller
The Customer is responsible for the lawfulness of the processing and of the instructions it issues. In particular, the Customer is responsible for having a legal basis for the personal data it uploads, imports, or ingests into the service; for purpose limitation, transparency, data minimisation, access restrictions, and safeguards appropriate to the risk; for fulfilling its information duties toward data subjects; for satisfying the additional requirements applicable to special categories of personal data under Art. 9 GDPR and data relating to criminal convictions and offences under Art. 10 GDPR; and for the accuracy of the personal data it processes through the service. Before activating or materially changing a Routine, the Customer must review its instruction, owner, trigger, data scope, permissions, limits, possible side effects, and safeguards and must monitor its operation and results.
The Customer is entitled to issue instructions to the Provider on the processing of personal data on its behalf, to obtain information about that processing, and to exercise the audit rights set out in this DPA.
7. Confidentiality
The Provider ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the personal data only on the instructions of the Customer.
8. Security of Processing (Art. 32 GDPR)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, the Provider implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. These measures comprise in particular: encryption of personal data in transit by TLS, and encryption at rest for the production database and its backups; role-based access control, individual named accounts, and authentication for all administrative access; segregation of Customer data by company account at the data layer; logging and monitoring of access and of security-relevant events; measures to restore the availability of and access to personal data in a timely manner after a physical or technical incident; and a process for regularly testing and evaluating the effectiveness of these measures.
9. Subprocessors
The Customer grants the Provider a general written authorization to engage subprocessors. The Provider maintains a current page of its processors, subprocessors, and other recipients at Subprocessors. Only the entries expressly identified there as processing personal data covered by this DPA on the Customer's behalf are incorporated into this DPA as subprocessors, including their identity, purpose, and location.
Before a subprocessor processes personal data on the Customer's behalf, the Provider enters into a written contract that imposes the same data-protection obligations required by this DPA in accordance with Art. 28(2) and (4) GDPR. Disclosing a contractual gap does not replace that written contract or authorize processing. Where a subprocessor fails to fulfil its data-protection obligations, the Provider remains fully liable to the Customer for the performance of those obligations.
For the connected-account feature, the Provider uses UNIPILE SAS (RCS Roanne 885265595, 168 rue de la Rotonde, 42153 Riorges, France) as a subprocessor for connected email, messaging, social-network, and calendar data and operations. This includes retrieving social posts and engagement, looking up person and company profiles, managing relationship requests, and performing Sales Navigator searches and list operations initiated by the Customer. The executed supplier DPA identifies the Provider as controller and Unipile as processor; in the downstream processing governed by this DPA, the Customer is controller, the Provider is processor, and Unipile performs the supplier role described here. The supplier DPA's annex lists personal master data, contact data, professional data, information disclosed or contained in public directories, and IP addresses, while the operational scope also includes the categories listed in Section 4. Further details are set out at Subprocessors.
For the storage of the personal data processed on the Customer's behalf, the Provider engages Databricks, Inc. (Neon) (https://neon.com) as the contracted subprocessor operating the managed PostgreSQL database through Neon, LLC. The Provider has configured its primary production database in the AWS Frankfurt region (eu-central-1). This is a selected product setting and not a contractually guaranteed data-residency commitment; the Provider informs the Customer of a change of region using the notification procedure set out in this Section. The Neon Platform Services Product Specific Schedule dated 5 August 2026 adds Grafana Labs in the United States to the full current Databricks subprocessor list. That list identifies some cloud and AI providers as customer-selected; the Provider has not selected an AI-backed Databricks service for its Neon database. Databricks is established in a third country, and the transfer mechanism for restricted transfers to Databricks is indicated at Subprocessors.
Forward Email, LLC hosts and stores the Provider's final operator mailbox and is not used for the connected-account feature or ordinary CRM processing. Where the Customer attaches or reproduces personal data covered by this DPA in a support or feedback request delivered to that mailbox, Forward Email stores and otherwise processes that fragment as a subprocessor. For ordinary account and business correspondence, it supports processing for which the Provider is an independent controller and which is outside this DPA. Forward Email's standard data processing agreement is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers; details are stated at Subprocessors.
For Mate, the Provider uses Vercel AI Gateway, operated by Vercel Inc., to route model requests and responses to the selected downstream model provider identified at Subprocessors. The gateway and downstream provider receive only the request content and metadata needed for the requested generation, which may include the customer-controlled categories listed in Section 4. Their identities, purposes, provider terms, locations, transfer information, retention limitations, and current operating boundaries are stated at Subprocessors. The Customer's interactive use of Mate or, where offered, its configuration and activation of a Routine constitutes an instruction to use this provider chain for each request, safety analysis, and resulting run. This instruction does not replace the Provider's obligation to ensure that every required Art. 28 contract and Chapter V transfer safeguard is in force before the relevant processing.
Where the Provider itself decides to add or replace a subprocessor, it informs the Customer before that subprocessor begins processing personal data on the Customer's behalf and allows the Customer a reasonable opportunity to object before processing begins. Where an existing supplier gives notice of an intended addition or replacement in its own supply chain, the Provider informs the Customer without undue delay after receiving that notice. If the supplier notice provides an objection period, the Provider states the remaining period in its notice to the Customer. The Customer may object in text form without undue delay on reasonable data-protection grounds. Where the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected service in accordance with the Main Agreement. For supplier-originated changes, the Provider does not promise a fixed advance-notice period that its supplier contracts do not guarantee.
10. Assistance to the Controller
Taking into account the nature of the processing, the Provider assists the Customer, by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under Arts. 12 to 23 GDPR. Where a data subject addresses such a request directly to the Provider, the Provider forwards it to the Customer without undue delay and does not respond to it itself unless instructed by the Customer.
The Provider further assists the Customer in ensuring compliance with the obligations under Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Provider. In particular, the Provider notifies the Customer without undue delay after becoming aware of a personal data breach affecting the personal data processed on the Customer's behalf, and provides the information reasonably necessary for the Customer to meet its own notification and communication obligations under Arts. 33 and 34 GDPR.
11. Deletion or Return of Data
When the Customer disconnects a connected account, the Provider deletes that account's stored threads, messages, participants, and calendar data from its own systems and requests that Unipile remove the corresponding account. The Provider has no contractual per-account deletion right against Unipile and can only make that request. Where a connected account is instead removed automatically, in particular on a failed payment, on expiry of a trial period or after prolonged inactivity, the stored data is at present only deactivated and marked as deleted in the Provider's systems; the Customer may require its deletion at any time. Raw inbound records that could not be associated with a connected account cannot currently be attributed to a Customer for per-account export or deletion and are retained for error analysis without a fixed period.
Archiving a Mate conversation does not delete it. When an authorised user permanently deletes an archived conversation, the Provider deletes that conversation and its messages, turn requests, model-round records, approvals, tool receipts and results, and UI-command results from its active database. Separate usage and billing records processed by the Provider as an independent controller remain outside this DPA and may be retained for metering, accounting, audit, and abuse-prevention purposes; CRM records created or changed through Mate remain ordinary Customer records until deleted under the rules that apply to those records. Active Mate conversations have no automatic age-based expiry during the contract. An express support escalation may reproduce recent conversation text in the Provider's support correspondence.
Where Routines are offered, deleting a saved Routine does not itself delete Mate conversations created by its runs. Those conversations remain subject to the preceding paragraph and must be separately deleted through the ordinary Mate deletion controls.
For 30 days after the end of the services relating to processing, the Provider retains the personal data available in its own systems and attributable to the Customer so that the Customer can choose deletion or return in text form. If the Customer chooses deletion, or does not communicate a choice within that period, the Provider deletes the data from its own systems without undue delay after the choice or expiry of the period. If the Customer chooses return within that period, the Provider returns the data in accordance with the Main Agreement and then deletes the remaining copies in its own systems. Union or Member State law requiring continued storage remains unaffected. Limitations affecting data held by subprocessors and unassigned raw inbound records are stated in this Section and at Subprocessors.
Deletion required by this Section is completed in the Provider's active systems without undue delay and in its backups at the latest within 90 days as those backups expire. The Provider instructs its subprocessors to delete the corresponding data; deletion at subprocessor level follows the terms of the respective agreement with that subprocessor.
12. Audits and Information
The Provider makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
To satisfy such requests, the Provider may in the first instance provide relevant documentation, summaries of its technical and organizational measures, and available third-party audit reports or certifications (including those of its subprocessors). On-site inspections take place with reasonable advance notice, during regular business hours, without disrupting the Provider's operations, and subject to appropriate confidentiality undertakings.
13. International Transfers
The Provider processes personal data on the Customer's behalf primarily within the European Union. Before a subprocessor processes that data in a third country, the Provider ensures that an applicable transfer mechanism under Chapter V GDPR is in place and identifies it at Subprocessors. Encryption, data minimization, and other supplementary technical measures do not replace a required Chapter V transfer mechanism.
For the connected-account feature, Unipile states that connected-account data is stored in the EU (France). Its data processing agreement nevertheless permits transfers outside the European Union where Chapter V GDPR safeguards apply, and its subprocessor list names a payment provider in the USA and five proxy providers whose location is not stated. The supplier DPA identifies no specific transfer mechanism for those providers; any affected transfer is subject to the requirement in the preceding paragraph that an applicable Chapter V mechanism be in place first.
For Mate, model requests are routed through Vercel AI Gateway to the selected downstream model provider identified at Subprocessors and may be processed in the United States or other countries used by the gateway, that provider, and their subprocessors. Vercel's data processing addendum incorporates the 2021 EU Standard Contractual Clauses for restricted transfers covered by that addendum. Vercel's current Notices and License Information makes the terms identified for that provider applicable to the route. Before customer-controlled personal data is processed through that route, the Provider must ensure that the required Art. 28 and Chapter V safeguards apply. The current recipient, provider terms, transfer information, and Gateway-level retention controls are stated at Subprocessors; those controls do not alter the application-level storage described in Section 11 or replace the required contractual and transfer safeguards.
14. Liability
Each party is liable in accordance with the statutory provisions, in particular Art. 82 GDPR governing the apportionment of liability between controller and processor. As between the parties, the liability provisions of the Main Agreement apply to this DPA. Mandatory statutory liability, in particular for intent and gross negligence, for injury to life, body, or health, and other liability that cannot be excluded or limited under applicable law, remains unaffected.
15. Order of Precedence
In the event of any conflict between this DPA and the Main Agreement with respect to the processing of personal data on behalf of the Customer, this DPA prevails. In the event of any conflict between this DPA and mandatory data protection law, that mandatory law prevails.
Where the parties have individually concluded a signed data processing agreement, that agreement prevails over this DPA for the Customer concerned.
16. Final Provisions
This DPA is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods. The place of jurisdiction is the registered office of the Provider, insofar as legally permissible. Electronic acceptance under Section 2 satisfies the text-form requirement for the identified DPA version; other amendments and supplements to this DPA must be made in text form. Should any provision of this DPA be or become invalid, the validity of the remaining provisions remains unaffected.
This DPA is provided in German and in English. The German version is authoritative; the English version is a convenience translation.
Benjamin Wagner
An den Kasernen 25
68167 Mannheim
mail@customermates.com
Last Update: 01.09.2026