Data Processing Agreement
Effective: 17 August 2026 · pursuant to Article 28 GDPR
Parties
The business or organisation identified by the company and account information supplied during registration, checkout, an order form or another principal agreement (the “Controller”), and DataSquads UG (haftungsbeschränkt), Friedrichsgaber Weg 92c, 22848 Norderstedt, Germany, registered with the Local Court of Kiel under HRB 21891 KI and represented by its Managing Director Sebastian Kielmann (the “Processor” or “Xirql”), together the “Parties”.
The person accepting this Data Processing Agreement (“DPA”) for the Controller represents that they have authority to bind the Controller. The Controller’s account administrator and registered business email address are its operational privacy contact unless it provides another contact in text form.
Background
This DPA specifies the Parties’ data-protection obligations for processing in which Xirql handles personal data on the Controller’s behalf. It supplements the principal contract for use of the Xirql platform and is incorporated electronically when accepted during registration or otherwise agreed.
1. Subject matter, scope and duration
- The subject matter is Xirql’s processing of personal data through platform features enabled by the Controller, in particular business research, lead management, scoring, contact, communication and follow-up through connected accounts and communication channels.
- The scope is determined by the principal contract, enabled functions and the Controller’s documented settings and instructions.
- This DPA applies from the start of commissioned processing for the term of the principal contract. Duties that by their nature continue, including deletion, return, confidentiality and evidence duties, remain effective until fulfilled.
2. Nature and purpose of processing
Depending on the Controller’s use, processing may include:
- Research and processing of publicly available professional profile and company information for Controller-specific lead lists and assessments.
- Processing data supplied or made accessible through accounts connected by the Controller.
- Sending and managing connection requests, messages and follow-ups through connected or authorised accounts and services.
- Importing and processing CRM data, CSV or Excel files and other lead data supplied by the Controller.
- AI-assisted lead scoring, prioritisation, summaries, message personalisation and Controller-specific assistance.
- Scheduling reminders, managing contact funnels and creating Controller-specific reports.
The purpose is exclusively to provide the Xirql services instructed by the Controller for its own business purposes.
3. Types of personal data
Depending on use: names, professional positions, company affiliations, business profile information, business contact details such as email address and telephone number, profile URLs, publicly visible professional activities, communication content and metadata, replies and interactions, campaign and funnel status, and CRM fields imported by the Controller.
Processing special categories of personal data under Article 9 GDPR is not intended. The Controller may provide such data only after express prior agreement with Xirql and where legally permitted.
4. Categories of data subjects
Data subjects may include the Controller’s business contacts, prospective customers, decision makers, contacts, existing leads or CRM contacts, as well as employees and other authorised users of the Controller whose data is processed in the platform.
5. Processor obligations
- Xirql processes personal data only on the Controller’s documented instructions, including instructions concerning transfers to a third country, unless Union or Member State law requires processing. Where legally permitted, Xirql informs the Controller of that requirement before processing.
- Xirql does not use personal campaign, CRM, profile or communication data for cross-customer purposes, for other customers, or to train general cross-customer AI models. Xirql may create anonymised or sufficiently aggregated statistics only where the results are no longer personal data and identification is reasonably excluded.
- Xirql ensures persons authorised to process personal data are bound by confidentiality or an appropriate statutory duty.
- Xirql applies measures required by Article 32 GDPR. The measures are described in Appendix 1 and may be updated without reducing the overall agreed level of protection.
- Taking account of the nature of processing and where possible, Xirql assists the Controller through appropriate measures with data-subject rights under Chapter III GDPR.
- Taking account of the nature of processing and information available, Xirql assists with Articles 32 to 36 GDPR, including security, breach notifications, data-protection impact assessments and prior consultations.
- Xirql provides information necessary to demonstrate compliance with Article 28 GDPR and enables audits under section 8.
6. Controller instructions
- Initial instructions arise from the principal contract, this DPA and settings made in the platform. Additional instructions may be issued in text form; oral instructions must be documented promptly.
- Instructions may concern campaign parameters, target groups, exclusion lists, communication channels, scoring criteria, funnel configurations and deletion or export requests.
- Xirql immediately informs the Controller if it considers an instruction to infringe the GDPR or other applicable privacy law and may suspend the affected processing pending clarification.
7. Subprocessors
- The Controller gives general written authorisation for the subprocessors in Appendix 2 for the listed processing activities.
- Xirql will generally notify the Controller in text form or through an agreed electronic channel at least four weeks before adding or replacing a subprocessor. The Controller may object within two weeks on substantiated data-protection grounds.
- The Parties will seek a reasonable solution after a justified objection. If alternative delivery is impossible or disproportionate, the Controller may terminate the affected service component or, if technically inseparable, the principal contract as of the planned engagement date.
- Xirql contractually imposes equivalent data-protection obligations on each subprocessor, including sufficient guarantees for technical and organisational measures. Where personal Customer Data is sent to an AI provider, use for that provider’s own general training or product purposes is excluded unless the Controller gives a different lawful instruction.
- For subprocessors outside the EU/EEA, Xirql ensures compliance with Articles 44 et seq. GDPR through an adequacy decision or appropriate safeguards such as European Commission Standard Contractual Clauses.
8. Evidence and audit rights
- The Controller may verify compliance with this DPA to a reasonable extent. Existing documentation, certifications, audit reports or written information should be used first where suitable.
- If those materials are insufficient, the Controller or an independent auditor bound by confidentiality may carry out further checks, including on-site audits. Regular on-site audits require at least two weeks’ notice and take place during ordinary business hours.
- No notice period applies where there is substantiated suspicion of a significant breach, a supervisory authority requires a shorter period, or advance notice would materially compromise the audit.
- The Controller bears reasonable additional costs of an audit exceeding the legally required and customary scope, unless the audit confirms a material breach attributable to Xirql.
9. Personal-data breaches
- Xirql notifies the Controller without undue delay after becoming aware of a personal-data breach affecting data processed under this DPA.
- The notice contains information required by the Controller under Article 33(3) GDPR to the extent then available. Missing information is supplied without undue delay.
- Xirql reasonably assists the Controller with incident assessment, notifications to authorities and communications to data subjects where required.
10. Deletion and return
- At the end of commissioned processing, Xirql deletes the personal data or, at the Controller’s choice, returns it in a common machine-readable format, unless law requires continued storage.
- The Controller may communicate its choice no later than 30 days after the principal contract ends. Without a return request within that period, Xirql may delete the data. Earlier deletion instructions remain possible where technically and contractually feasible.
- Backup data is removed or overwritten under the documented backup and deletion cycle. Until then, it is not used productively for other purposes and is retained only for recovery and security.
- Legally retained data is blocked or separated from regular processing and used only for the statutory retention purpose.
11. Privacy contacts
- The Controller’s privacy contact is its account administrator at the registered business email address unless another contact is notified in text form.
- Xirql’s privacy contact may be reached by post at DataSquads UG (haftungsbeschränkt), Friedrichsgaber Weg 92c, 22848 Norderstedt, Germany, or through the Support function in the application.
12. Liability
Liability is governed by the principal contract and mandatory law. Mandatory claims under Article 82 GDPR remain unaffected.
13. Final provisions
- This DPA prevails over the principal contract for commissioned processing.
- Amendments may be agreed in text form or another electronic form permitted by Article 28 GDPR.
- If a provision is invalid, the remaining provisions remain effective and statutory rules replace the invalid provision.
- The law and venue agreed in the principal contract apply to the extent legally permitted.
Appendix 1: Technical and organisational measures
| Control objective | Measure |
|---|---|
| Physical access | Production systems are hosted in professionally operated data centres. Physical access is controlled by the relevant infrastructure provider. |
| Authentication | Password rules, hashed credential storage, role-based permissions and restricted administrative access. |
| Logical access | Least-privilege access, company-scoped permissions and logging of relevant security events. |
| Transmission | Encrypted transmission using TLS for personal data sent between user devices, Xirql and integrated providers. |
| Input and change traceability | Relevant account, processing and security events are recorded where supported by the platform and infrastructure. |
| Availability | Operational monitoring, database backup and recovery procedures, and controlled deployment and restart processes. |
| Separation | Logical separation of Customer and company data through tenant identifiers, scoped queries and role-based authorisation. |
| Processor control | Contractual Article 28(4) commitments and documented instructions for subprocessors. |
| Review | Security measures are reviewed and adjusted to changing risks and technical developments. |
Appendix 2: Authorised subprocessors
Only providers that may process personal data on the Controller’s behalf are included below. Billing, product analytics or business-administration providers acting solely for Xirql are addressed in the Privacy Policy and are not included merely for that reason.
| Subprocessor | Service | Processing location / transfer safeguard |
|---|---|---|
| Hetzner Online GmbH | Production application hosting, computing, data storage and backups | Germany / European Union. |
| Unipile | Connections to LinkedIn and other Customer-connected accounts; communication processing | France / European Union. |
| Google (Gemini API) | Optional AI-assisted scoring, analysis, generation, summaries and personalisation | Processing locations under Google’s applicable Data Processing Addendum; adequacy decision and/or Standard Contractual Clauses where required. |
| Icypeas | Optional professional contact and company research or enrichment | France / European Union according to the provider’s current service information; applicable safeguards govern any onward transfer. |
Subprocessor list version: 17 August 2026.
← Back to sign in