Data Processing Agreement Goodfit
PARTIES
This Data Processing Agreement (“Agreement“) forms part of the Contract for
Services (“Principal Agreement“) between
[Company Name], incorporated and registered in England and Wales with company number [Registration Number], whose registered office is at [Address] (the “Company”)
and
GoodFit Limited, incorporated and registered in England and Wales with company number 12583146, whose registered office is at 86-90 Paul Street · 3rd Floor · London EC2A 4NE (the “Processor”)
(together as the “Parties”)
WHEREAS
- The Company acts as a Data Controller.
- The Company wishes to subcontract certain Services, which require the processing of personal data, to the Data Processor.
- The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing,including: i) to the extent that the UK General Data Protection Regulation (as defined in section 3(10) as supplemented by section 205(4) of the DPA 2018) (“UK GDPR”) applies, the law of the United Kingdom which relates to the protection of personal data; and (ii) to the extent that the EU General Data Protection Regulation EU 2016/679 (“EU GDPR”) applies, the law of the European Union or any member state of the European Union to which Customer or Processor is subject, which relates to the protection of personal data.
- The Parties wish to lay down their rights and obligations.
IT IS AGREED AS FOLLOWS:
- Definitions and Interpretation
- Unless otherwise defined herein, capitalised terms and expressions used in this Agreement shall have the following meaning.
- “Agreement” means this Data Processing Agreement and all Schedules;
- “Company Personal Data” means any Personal Data (a) provided by the Company to the Processor, (b) uploaded or input by the Company or its authorised users into the platform, or (c) generated by the Company’s use of the platform (including prompts and outputs), in each case Processed by the Processor on behalf of the Company. For the avoidance of doubt, Company Personal Data does not include Personal Data contained in the Processor’s underlying proprietary database made available to multiple customers;
- “Contracted Processor” means a Subprocessor;
- “Data Protection Laws” means any applicable laws, rules, or regulations relating to privacy, security, data protection, or confidentiality, including but not limited to, as applicable (i) those of the United States, including the California Consumer Privacy Act and its replacement the California Privacy Rights Act (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, and the Connecticut Act Concerning Personal Data Privacy and Online Monitoring; and any other federal or state law in the USA related to Data Privacy (ii) those of the European Union, the European Economic Area, their member states, and the United Kingdom, including Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (“GDPR”), the UK Data Protection Act 2018 as saved into United Kingdom law by virtue of Section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 (“UK GDPR”), and the Swiss Federal Data Protection Act; (iii) those of any other relevant jurisdictions; and (iv) any replacements, additions, successors, implementing requirements or legislation, or amendments to any of the foregoing.
- “EEA” means the European Economic Area;
- “Data Transfer” means:
- a transfer of Company Personal Data from the Company to a Contracted Processor; or
- an onward transfer of Company Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor, in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
- “Services” means the services the Company provides.
- “Subprocessor” means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Company in connection with the Agreement.
- The terms, “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” shall have the same meaning as in the UK GDPR, and their cognate terms shall be construed accordingly.
- Unless otherwise defined herein, capitalised terms and expressions used in this Agreement shall have the following meaning.
- Processing of Company Personal Data
- This Agreement sets out the terms on which the Customer appoints the Processor as data processor for the Customer’s Personal Data and the purposes for which the Processor will process personal data when providing Services under the Principal Agreement.
- Processor shall:
- comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and
- not Process Company Personal Data other than on the Company’s documented instructions, except where required by applicable law, in which case the Processor shall notify the Company of that legal requirement before processing unless such notification is itself prohibited by law.
- The subject matter of the Processing of Company Personal Data by the Processor is to provide the Services pursuant to the Agreement. The duration of the Processing, the nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects Processed under this DPA are further specified in Annex 1 (Description of Processing) of this DPA.
- Company shall:
- ensure any instructions given to the Processor under this Agreement comply with applicable Data Protection Laws;
- have sole responsibility for the accuracy, quality, and legality of the Company’s Personal Data and how the Company acquired the Personal Data it provides to the Processor;
- shall not use the Services (including any AI-enabled features such as AI Researcher) to process Special Categories of Personal Data, to target individuals based on protected characteristics, or to direct automated research at websites or in jurisdictions where such activity would be unlawful;
- agrees that its use of the Services will not violate the rights of any Data Subject, including those that have opted-out from sales or other disclosures of Personal Data;
- comply with any applicable requirement to provide notice to Data Subjects or obtain their consent for the use of the Processor’s services; and
- defend and indemnify the Processor against any claim arising from the Company breaching this clause.
- The Company instructs Processor to process Company Personal Data as aligned to the categories of data, the categories of data subjects and the purposes of the processing set out in Annex 1, and using sufficient controls as outlined in Annex 2.
- Processor Personnel
- Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know/access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual’s duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
- Security
- Taking into account state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall, in relation to the Company Personal Data implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR and the security measures set out at Annex 2 of this Agreement.
- In assessing the appropriate level of security, Processor shall take into account in particular the risks that are presented by Processing, in particular from a Personal Data Breach.
- Subprocessing
- Company provides general written authorization for the use by the Processor of the Subprocessors identified in Annex 3. Processor shall not disclose or otherwise make available Company Personal Data to any potential or actual Subprocessors without first (a) conducting a reasonable investigation of the recipient’s safeguards to ensure such safeguards are reasonable and consistent with Processor’s obligations under this Agreement; and (b) imposing contractual obligations on the recipient that are at least as protective as those imposed on Processor under this Agreement.
- Processor shall notify Company in writing of any new Subprocessor before authorizing that new Subprocessor to process Company Personal Data, and Company may object on reasonable data-protection grounds to the new Subprocessor within fifteen (15) business days of such notice.
- Where Company objects within the period referred to in 5.2 above, the Parties shall work in good faith to identify an alternative. If no alternative is reasonably available, either Party may terminate the affected portion of the Services on 30 days’ notice, and Company shall be entitled to a pro-rata refund of prepaid fees for the terminated Services. Processor shall be liable for the acts and omissions of any Subprocessors, and their compliance with this Agreement and Data Protection Law.
- If Company does not raise an objection within the period referred to in Clause 5.2, the Sub-processor shall be deemed approved. Once a Sub-processor is authorised (whether through Annex 3 or under this Clause 5), Processor may engage that Sub-processor as soon as a written agreement is in place that imposes data protection obligations on the Sub-processor no less protective than those set out in this Agreement.
- Data Subject Rights
- Taking into account the nature of the Processing, Processor shall assist the Company by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Company obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
- Processor shall:
- promptly notify Company via the details referred to at Clause 14.2 if it receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and
- ensure that it does not respond to that request except on the documented instructions of the Company or as required by Applicable Laws to which the Processor is subject, in which case the Processor shall, to the extent permitted by Applicable Laws, inform the Company of that legal requirement before the Contracted Processor responds to the request.
- The Processor shall provide such assistance at the Company’s reasonable cost, save where the underlying issue results from the Processor’s breach of this Agreement.
- Personal Data Breach
- In the event of any actual or reasonably suspected accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Company Personal Data (“Data Breach”), Processor shall, at its own expense:
- provide prompt notice to Company (without undue delay after becoming aware, and in any event within 72 hours) via the details referred to at Clause 14.2 upon discovery of the Data Breach;
- use best efforts and take all necessary actions to prevent, contain, and mitigate the impact of the Data Breach;
- collect, preserve, and document all evidence concerning the discovery, cause, vulnerability, remedial actions and impact related to such Data Breach, which shall meet reasonable expectations of forensic admissibility; and
- fully cooperate with Company and its designees for purposes of Data Breach response, including if requested by Company, providing notice to individuals or entities whose Personal Data was or may have been affected in a manner and format specified by Company.
- A notification provided by the Processor under this clause shall include:
- the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and to mitigate its possible adverse effects;
- the name and contact details of the data protection contact point at the Processor.
- Where, and insofar as, it is not possible to provide all such information at once in the notification referred to at Clause 7.2, the information shall be provided to the Company as it becomes available without further undue delay.
- Data Protection Impact Assessment and Prior Consultation Processor
Processor shall, at the Company’s reasonable written request, provide reasonable assistance to the Company with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which the Company reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
The Processor shall provide such assistance at the Company’s reasonable cost, save where the underlying issue results from the Processor’s breach of this Agreement.
- Deletion or return of Company Personal Data
- At the Company’s choice, after receipt of a written request the Processor shall return or delete Company Personal Data within thirty (30) business days of the Cessation Date (defined as the date of cessation of the Services involving the Processing of Company Personal Data), save that (a) the Processor may retain Company Personal Data where required by applicable law or contained in routine system backups (which shall be overwritten in the ordinary course), and (b) this obligation does not require deletion of Personal Data contained in the Processor’s underlying proprietary database. Where Processor retains any Company Personal Data the terms of this Agreement shall continue to apply.
- Audit rights
- The Processor shall make available on reasonable written request information necessary to demonstrate compliance. The Company may, on 30 days’ prior written notice, not more than once per year (except where required by a Supervisory Authority or following a Data Breach), and during normal business hours, conduct or mandate a qualified independent auditor (subject to confidentiality) to audit compliance with this Agreement. Each Party shall bear its own costs unless the audit reveals material non-compliance, in which case the Processor bears the Company’s reasonable costs. The Processor may discharge this obligation by providing its most recent SOC 2 Type II report, ISO 27001 certification or equivalent third-party audit.
- Data Transfer
- The Company consents to the transfers of Company Personal Data to the countries listed in Annex 1 and the Subprocessors listed in Annex 3. Where such transfers take place from the UK or EEA to a third country, the Parties shall rely on the safeguards listed below. If personal data processed under this Agreement is transferred from a country within the European Economic Area to a country outside the European Economic Area and the UK,the Parties shall ensure that the personal data are adequately protected. To achieve this, the Parties shall, unless agreed otherwise, rely on:
- EU or UK approved standard contractual clauses for the transfer of personal data;
- An applicable derogation under the Data Protection Laws; or
- An adequacy decision recognised by the UK government or European Commission.
- Insurance
In addition to any other obligations in the Agreement, Processor shall obtain and maintain, without interruption, a professional liability policy and security and privacy liability policy as follows:
(a) covering liability arising out of Data Breaches or a breach of this agreement;
(b) with limits of liability equaling at least ten million dollars ($10,000,000) per claim or occurrence and in the aggregate;
(c) including an endorsement listing the Company as an additional insured under such policy for claims arising out of the wrongful acts and Data Breaches of Processor or Subprocessors;
(d) issued by an insurance company having a rating of at least A+ in Best’s Key Rating Guide; and
(e) that is primary, and not excess over or contributing with any insurance maintained by the Processor shall deliver to Controller certificates of insurance as evidence of the insurance and limits stipulated above, with provisions for not less than thirty (30) days prior written notice to Controller in the event of material alteration or cancellation of such insurance.
- Material Breach and Indemnification
The following shall be considered Processor’s material breach of the Agreement:
(a) a Data Breach; and
(b) Servicer Provider’s (or its Subprocessors’) failure to comply with any of its obligations set forth in this Agreement. In addition to any indemnification obligations elsewhere in the Agreement, Processor agrees to indemnify, defend, and hold harmless controller and its affiliates, subsidiaries, successors and assigns (and their officers, directors, employees, sublicensees, customers and agents) from and against any and all claims, losses, demands, liabilities, damages, settlements, expenses and costs (including attorneys’ fees and costs), arising from, in connection with, or based on allegations of, any Data Breach or Processor’s (or its Subprocessors’) failure to comply with any of its obligations set forth in this Agreement. This indemnification obligation is subject to the limitations of liability set out in the Principal Agreement.
- General Terms
- Confidentiality. Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
(a) disclosure is required by law;
(b) the relevant information is already in the public domain. - Notices. All notices and communications given under this Agreement must be in writing and will be delivered personally, sent by post or sent by email to the address or email address set out in the heading of this Agreement at such other address as notified from time to time by the Parties changing address.
- Confidentiality. Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
- Governing Law and Jurisdiction
- This Agreement is governed by the laws of England and Wales.
- Any dispute arising in connection with this Agreement, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of London.
Annex 1
1. The purpose of the Data Processor’s processing of personal data on behalf of the Data Controller is:
To provide the Data Controller with access to GoodFit’s B2B data intelligence and go-to-market (GTM) platform (including the GoodFit database, AI-driven enrichment, classification and research features (including the “AI Researcher” functionality) and related dashboards, APIs and integrations) enabling the Data Controller to identify, map, enrich, prioritize, segment and engage accounts and business contacts within its target market for B2B marketing, sales prospecting, lead generation and related GTM activities, in accordance with the Main Services Agreement between the parties.
2. The Data Processor’s processing of personal data on behalf of the Data Controller shall mainly pertain to (the nature of the processing):
Collection, storage, hosting, organization, structuring, retrieval, matching, enrichment, aggregation, transformation (including into derived “data blocks” and scoring), analysis, classification, labelling, consultation, disclosure by transmission and making available of personal data relating to business contacts, together with:
- AI-assisted extraction, classification and summarisation using large language models (including OpenAI GPT-family and embedding models), whether applied to the Processor’s database or, where directed by the Data Controller via AI Researcher, to publicly accessible web content on demand;
- storage and processing of prompts submitted by the Data Controller’s authorised users and the resulting AI-generated outputs; and
- operation, monitoring and support of the Data Controller’s user accounts, configurations (e.g. ICPs, segments, personas) and integrations on the platform.
3. The processing includes the following types of personal data about data subjects:
Contact Info
Business email address (including business email addresses generated from the employer’s known email structure)
Business telephone number (where enriched, including via Surfe)
Current and previous employment history (employer, job title, role, function, seniority, tenure)
Professional/work location (city, region, country)
LinkedIn profile URL and other publicly available professional profile information (e.g. from business social networks and company websites)
Company-level identifiers linked to individuals (e.g. domain, linked company URL IDs)
Account/login credentials of authorised users of the Data Controller (email address and password)
Platform usage data, event logs and audit records relating to authorised users
Prompts, instructions and queries submitted by authorised users of the Data Controller to AI Researcher and other AI features, and the corresponding outputs (to the extent these contain personal data)
4. The processing includes the following type of special categories of data about data subjects:
None intended. The Processor does not seek to process special categories of personal data as defined in Article 9 UK/EU GDPR on behalf of the Data Controller.
The Data Controller acknowledges, however, that publicly sourced employment history and professional profile information may incidentally reveal attributes capable of being treated as special category data (for example, employment by a trade union, a religious organisation, or a political party or campaign). The Data Controller undertakes: (i) not to upload, submit or direct AI Researcher or other platform features to target, infer, segment on or enrich special categories of personal data; (ii) not to use the platform for processing that requires an Article 9 condition unless expressly agreed in writing with the Processor in advance; and (iii) to ensure its lawful basis and any required Article 9 condition are in place for any processing it carries out with personal data obtained via the platform.
5. Processing includes the following categories of data subjects:
Employees, officers, contractors and other business professionals working at companies within the Data Controller’s defined target market (i.e., prospects and potential B2B contacts)
Authorized users of the Data Controller (employees, contractors or other representatives of the Data Controller who are granted access to the GoodFit platform).
6. The Data Processor’s processing of personal data takes place in the following countries:
United Kingdom: Processor’s primary place of business and operations.
United States: primary hosting and processing environment, including via sub-processors.
European Union: via sub-processors PostHog EU (analytics) and Surfe (contact enrichment, France).
AI Researcher may, when directed by the Data Controller, retrieve and process publicly available content from websites hosted in other jurisdictions; such retrieval is initiated on the Data Controller’s instructions.
Transfers outside the UK/EEA are made under appropriate safeguards (EU Standard Contractual Clauses and/or the UK IDTA/Addendum, EU-US Data Privacy Framework, as applicable).
7. The Data Processor’s processing of personal data on behalf of the Data Controller may be performed when the Clauses commence. Processing has the following duration:
Processing shall commence on the effective date of the Clauses and shall continue for the term of the main agreement between the parties, including any renewal period, and shall end upon termination or expiry of that agreement. Following termination, the Processor shall, at the Controller’s choice, return or delete all personal data in accordance with the Clauses, subject to any retention required by applicable law.
Annex 2: Technical and Organisational measures
1. Physical Access Controls
Data Processor shall take reasonable physical access measures to prevent unauthorised persons from gaining access to personal data.
2. Access Controls
Data Processor shall take reasonable measures to prevent personal data from being used without authorization. These controls shall vary based on the nature of the processing undertaken and may include, among other controls, authentication via passwords and/or two-factor authentication, documented access authorization processes, documented change management processes, the logging of access on several levels, restricting direct database and application access rights, and implementing an access management policy.
3. Transmission Controls
Data Processor shall take reasonable measures to ensure that it is possible to check and establish to which entities the transfer of personal data by means of data transmission facilities is envisaged so personal data cannot be read, copied, modified or removed without authorization during electronic transmission or transport.
4. Input Controls
Data Processor shall take reasonable measures to provide that it is possible to check and establish whether and by whom personal data has been entered/modified within data processing systems.
5. Training and Awareness
Data Processor shall ensure that staff with access to Personal Data are trained on data protection and privacy topics.