Data Processing Agreement

Effective 12 August 2026.

This Data Processing Agreement (“DPA”) applies to the processing of personal data by LLC GENERECT (“Generect”) on behalf of a customer, and forms part of the Terms of Service. It is accepted together with the Terms of Service — there is nothing to sign. A countersigned copy is available on request at [email protected].

1. Definitions and scope

“Generect” means LLC GENERECT, acting as Data Processor.

“Customer” means the entity that has accepted Generect’s Terms of Service and acts as Data Controller.

“Services” means the B2B contact and company data services Generect provides to the Customer: search, enrichment, verification and export of business contact and company records, delivered through Generect’s API, its web application, and its integrations.

“Customer Personal Data” means personal data that the Customer submits to the Services, or instructs the Services to process on its behalf — for example a list of company domains, contact identifiers or profile URLs supplied for enrichment.

This DPA applies to the processing of Customer Personal Data by Generect as Processor. It is concluded under Article 28(3) GDPR and, where personal data is transferred outside the EEA, under Chapter V GDPR.

What this DPA does not cover

Where Generect determines the purposes and means of processing — in particular for the data in Generect’s own database, which Generect collects and offers to its customers — Generect acts as a Controller rather than as the Customer’s Processor. That processing is governed by the Privacy Policy, not by this DPA.

2. Roles and instructions

2.1 The Customer is the Controller of Customer Personal Data and is responsible for having a lawful basis for the processing it instructs.

2.2 Generect processes Customer Personal Data only (a) as instructed by the Customer through its use of the Services, (b) as necessary to provide, secure and support the Services, and (c) as required by applicable law.

2.3 Generect informs the Customer without undue delay if, in Generect’s opinion, an instruction infringes applicable data-protection law.

3. Nature, purpose, duration and categories

The nature and purpose of the processing, the categories of data subjects and of personal data, and the duration, are set out in Annex I.

4. Security

4.1 Generect implements appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. Those measures are described in Annex II.

4.2 Generect ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and process it only as needed to perform their duties.

5. Sub-processors

5.1 The Customer grants Generect general authorisation to engage sub-processors for the provision of the Services. Generect maintains a current list of sub-processors in Annex III and imposes on each sub-processor data-protection obligations no less protective than those in this DPA.

5.2 Generect may appoint a new sub-processor, or replace an existing one, subject to the conditions in section 5.1, and will notify the Customer at least 30 days in advance by updating Annex III and notifying the Customer by email. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected Services.

5.3 Generect remains liable for its sub-processors’ performance of their data-protection obligations.

6. International transfers

Where Generect transfers Customer Personal Data outside the EEA or the UK, it does so on the basis of an adequacy decision or, absent one, the European Commission’s Standard Contractual Clauses together with any supplementary measures required. Hosting locations, including those outside the EEA, are identified in Annex III.

7. Data subject rights

Generect assists the Customer, by appropriate technical and organisational measures and insofar as reasonably possible, in responding to requests from data subjects exercising their rights. If Generect receives such a request directly and it concerns Customer Personal Data, Generect refers it to the Customer without undue delay and does not respond to it substantively itself, unless legally required to do so.

8. Personal data breach

Generect notifies the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably available to it so that the Customer can meet its own notification obligations.

9. Audits and information

Generect makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and permits audits, including inspections, by the Customer or an auditor it mandates. Audits take place on reasonable notice, during business hours, subject to confidentiality, and no more than once per year unless a breach or a supervisory authority requires otherwise.

10. Deletion and return

On termination of the Services, and on the Customer’s written request, Generect deletes or returns Customer Personal Data without undue delay, save where retention is required by law.

11. Data protection contact

Data-protection enquiries, requests under this DPA, and requests for a countersigned copy: [email protected].

12. Liability, precedence and changes

12.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.

12.2 In the event of a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA prevails.

12.3 Generect may update this DPA where required by law or to reflect changes to the Services or to its sub-processors, provided the changes do not materially reduce the protection afforded to Customer Personal Data. Material changes are notified at least 30 days in advance.

12.4 Governing law and jurisdiction follow the Terms of Service.

Annex I — Details of the processing

Subject matter. Provision of the Services described in section 1.

Duration. The term of the Customer’s subscription, plus the period described in section 10.

Nature and purpose. Receiving identifiers submitted by the Customer; matching them against Generect’s data sources; returning, verifying and exporting business contact and company records; storing search inputs, results and exclusion lists in the Customer’s workspace; and, where the Customer has enabled an integration, transmitting results to the Customer’s own system such as its CRM.

Categories of data subjects. Employees, officers and other representatives of companies, acting in a professional or business capacity — the business contacts the Customer is researching.

Categories of personal data.

  • Name
  • Business email address
  • Business telephone number
  • Job title and seniority
  • Employer, and the employer’s industry, size and location
  • Professional profile URL
  • Professional work history, where present in the source
  • The Customer’s own account data: name, email, authentication credentials, billing contact

Special categories of data. None requested and none required. The Customer must not submit special-category data to the Services.

Frequency. Continuous, on the Customer’s instruction, for as long as the Customer uses the Services.

Annex II — Technical and organisational measures

  • Encryption in transit. All customer-facing hosts serve HTTPS only, with HTTP redirected to HTTPS.
  • Authentication. JSON Web Tokens for the web application; per-customer API tokens for the API, which the customer can pause, rename or revoke at any time.
  • Credential storage. Passwords are stored as PBKDF2-SHA256 hashes and are subject to a password policy.
  • Secure session handling. Session and CSRF cookies are restricted to secure connections.
  • Tenant isolation. Reading, counting and exporting results, and access to exclusion lists, are scoped to the owning account.
  • Rate limiting. Per-customer throttling on API endpoints, with rate-limit and retry headers on throttled responses.
  • Change control. All production changes go through peer-reviewed pull requests with an automated test gate; direct pushes to production branches are blocked.
  • Monitoring. Application errors are reported to an error-tracking service and reviewed.
  • Payment data. Card data is processed entirely by Stripe and never reaches Generect’s servers.

Generect does not currently hold SOC 2 or ISO 27001 certification. Security questionnaires (CAIQ, SIG or your own) can be requested at [email protected].

Annex III — Sub-processors

The following third parties process Customer Personal Data on Generect’s behalf, or host the systems that do.

  • Hetzner Online GmbH — hosting of the application and database. The application and database run in the EU; the static web assets of the web application are served from the provider’s United States location, which also records web-server access logs.
  • Cloudflare — DNS, CDN and web application firewall.
  • Google (Google Workspace) — business email.
  • Stripe — payment processing and subscription billing.
  • PostHog (EU Cloud) — product analytics and feature flags, hosted in the EU.
  • Sentry — application error monitoring.
  • Intercom — customer support communications.
  • Microsoft Azure (Azure OpenAI) — model-backed features such as filter and search-name generation.

Email verification runs on Generect’s own infrastructure inside the EU and does not involve a third-party verification provider. The documentation site is hosted by Mintlify and Vercel and does not process Customer Personal Data.

Watch how Generect turns cold lists into live B2B contacts.

Book a Demo