PlumPMM Data Processing Agreement

Incorporated into the PlumPMM Terms of Service | Effective: 7/14/2026| Version 1.0

This Data Processing Agreement (“DPA”) forms part of the PlumPMM Terms of Service available at https://www.plumpmm.com/terms or other agreement between PlumPMM LLC (“PlumPMM,” “Processor”) and the customer (“Customer,” “Controller”) (the “Agreement”) and governs PlumPMM’s Processing of Personal Data on Customer’s behalf. By agreeing to the Agreement, Customer also agrees to this DPA; no separate signature is required. If there is a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA controls.

1. Definitions

Capitalized terms not defined here have the meaning in the Agreement. The following terms have the meanings given:

“Data Protection Laws” all laws applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and UK Data Protection Act 2018, Swiss data protection law, US state privacy laws including the California Consumer Privacy Act as amended (“CCPA”), and the additional regimes listed in Annex 5.

“Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach” have the meanings given in the GDPR (and equivalent terms such as “business,” “service provider,” and “consumer” under the CCPA, and the equivalents in Annex 5, apply correspondingly).

“Customer Personal Data” Personal Data contained within Customer Data that PlumPMM Processes on Customer’s behalf under the Agreement.

“Permitted Purpose” Processing Customer Personal Data solely to provide, secure, maintain, and support the Services for Customer in accordance with the Agreement, this DPA, and Customer’s documented instructions — and not for any other purpose.

“Sub-processor” a third party engaged by PlumPMM to Process Customer Personal Data.

“Authorized Affiliate” any of Customer’s affiliates that is permitted to use the Services under the Agreement and whose Personal Data is Processed under this DPA; Customer enters into this DPA on behalf of itself and such Authorized Affiliates.

“Standard Contractual Clauses (SCCs)” (a) for the EU, the clauses annexed to Commission Implementing Decision (EU) 2021/914; and (b) for the UK, the UK International Data Transfer Addendum to the EU SCCs (“UK Addendum”).

2. Roles and Scope

The parties acknowledge that, for Customer Personal Data, Customer is the Controller and PlumPMM is the Processor; where Customer is itself a Processor acting for a third-party Controller, PlumPMM is a Sub-processor. Under the CCPA, PlumPMM acts as a service provider and not as a “third party.” This DPA applies to PlumPMM’s Processing of Customer Personal Data for the duration of the Agreement, and to Customer and its Authorized Affiliates. The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex 1.

3. Processing of Customer Personal Data

(a)      PlumPMM will Process Customer Personal Data only for the Permitted Purpose and on Customer’s documented instructions (including as set out in the Agreement and this DPA) — unless required by law, in which case PlumPMM will inform Customer (unless legally prohibited).

(b)     PlumPMM will not “sell” or “share” Customer Personal Data (as defined under the CCPA), retain, use, or disclose it for any purpose other than the Permitted Purpose, or combine it with other personal information except as permitted by the CCPA. PlumPMM certifies it understands and will comply with these restrictions.

(c)     PlumPMM will not use Customer Personal Data to train, fine-tune, or improve any AI or machine-learning models, and its agreements with AI Sub-processors prohibit such training.

(d)     Customer is responsible for the accuracy and legality of Customer Personal Data and for having the necessary rights, legal bases, and notices/consents for PlumPMM to Process it for the Permitted Purpose.

4. Confidentiality of Processing

PlumPMM will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and are trained on their data-protection responsibilities, and will limit access to those who need it to provide the Services.

5. Security

PlumPMM will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Personal Data Breaches, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of Processing, as described in Annex 2. PlumPMM regularly tests and evaluates the effectiveness of these measures.

6. Sub-processors

(a)      Customer provides general authorization for PlumPMM to engage Sub-processors to Process Customer Personal Data. The current Sub-processors are listed in Annex 3 and at https://plumpmm.com/subprocessors.

(b)     PlumPMM will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for its Sub-processors’ performance.

(c)     PlumPMM will give Customer advance notice (by updating the list and/or email subscription) of any new or replacement Sub-processor. Customer may object on reasonable, documented data-protection grounds within [thirty (30)] days; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Services.

7. Data Subject Rights and Assistance

Taking into account the nature of the Processing, PlumPMM will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subjects’ requests to exercise their rights. If PlumPMM receives such a request directly, it will, unless legally required to respond, direct the Data Subject to Customer or forward the request to Customer. PlumPMM will also provide reasonable assistance with Customer’s data protection impact assessments and prior consultations with supervisory authorities.

8. Personal Data Breach Notification

PlumPMM will notify Customer without undue delay (and in any event within [seventy-two (72)] hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations. Notification is not an acknowledgment of fault or liability.

9. Government and Legal Disclosure Requests

If PlumPMM receives a legally binding request from a public authority to disclose Customer Personal Data, PlumPMM will, unless legally prohibited, notify Customer before disclosing, and will challenge any request that it considers unlawful or overbroad. PlumPMM will disclose only the minimum Personal Data necessary to comply.

10. Return and Deletion

On termination or expiry of the Agreement, PlumPMM will, at Customer’s choice, delete or return Customer Personal Data within [thirty (30)] days, and delete existing copies except to the extent retention is required by law. Data in routine backups is deleted on the ordinary backup cycle.

11. Audits

PlumPMM will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits, including by providing third-party audit reports or certifications where available.

12. International Transfers

(a)      PlumPMM may Process and transfer Customer Personal Data to countries outside the EEA, UK, and Switzerland, including the United States, where a valid transfer mechanism applies.

(b)     Where required, the parties agree that the EU Standard Contractual Clauses are incorporated by reference and apply to such transfers, with PlumPMM as “data importer” and Customer as “data exporter,” using: Module Two (Controller-to-Processor) where Customer is a Controller, and Module Three (Processor-to-Processor) where Customer is a Processor. The clauses are completed as set out in Annex 4.

(c)     For transfers subject to the UK GDPR, the UK Addendum applies to the EU SCCs. For transfers subject to Swiss law, the EU SCCs apply with the adaptations required by Swiss law. For other jurisdictions, the transfer terms in Annex 5 apply.

13. Liability

(a)      Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. Any reference in the Agreement to the liability of a party means the aggregate liability of that party and all of its affiliates under the Agreement and this DPA together.

(b)     The limitations of liability do not apply to a Data Subject’s rights under the SCCs or Data Protection Laws, or to any liability that cannot be limited or excluded by applicable law.

(c)     Regulatory fines carve-out. Neither party is liable to the other for, and each party is solely responsible for, any administrative fine or penalty imposed on it by a supervisory authority under the GDPR, UK GDPR, or other Data Protection Laws to the extent the fine arises from that party’s own violation. Neither party will indemnify the other for such fines.

14. General

This DPA is governed by the law and jurisdiction of the Agreement, unless Data Protection Laws or the SCCs require otherwise. Except as amended here, the Agreement remains in effect. In the event of a conflict between this DPA and the SCCs, the SCCs prevail as to transfers governed by them.

Annex 1 — Description of Processing

Item

Detail

Subject matter

PlumPMM’s provision of the B2B positioning and messaging Services to Customer.

Duration

The term of the Agreement plus any deletion/return period.

Nature and purpose

Hosting, storage, generation, analysis, and processing of Customer Data (including AI-assisted generation of positioning and messaging) to provide the Services (the Permitted Purpose).

Types of Personal Data

Business contact details of Customer’s Authorized Users (name, email, job title); and any Personal Data contained in content Customer submits or has collected from public sources, such as names, job titles, and business contact details of Customer’s prospects or market contacts.

Categories of Data Subjects

Customer’s Authorized Users; Customer’s prospects, leads, and business contacts represented in Customer Data.

Sensitive data

None intended. Customer must not submit special-category data.

Frequency

Continuous, for the duration of the Agreement.

Annex 2 — Technical and Organizational Security Measures

PlumPMM maintains measures including the following.

        Encryption of Customer Data in transit (TLS) and at rest.

        Access control — role-based access, least-privilege, unique accounts, and multi-factor authentication for administrative access.

        Network and application security — firewalls/WAF (Cloudflare), isolation of environments, and secure development practices.

        Monitoring and logging of access and security-relevant events.

        Resilience and backups — regular backups and the ability to restore availability after an incident.

        Vendor management — security diligence and contractual obligations for Sub-processors.

        Personnel — confidentiality obligations and security awareness training.

Annex 3 — Approved Sub-processors

The current Sub-processors that may Process Customer Personal Data are listed below and maintained at https://plumpmm.com/subprocessors. This list mirrors Section 10 of the Privacy Policy.

Sub-processor

Purpose of processing

Processing location

Amazon Web Services, Inc. (AWS)

Cloud hosting and infrastructure; storage and processing of Customer Data, including uploaded go-to-market documents and content from publicly available websites processed by the Services.

United States

Cloudflare, Inc.

Content delivery network, DNS routing, caching, and security/bot protection in front of the application.

Global edge network

OpenAI, L.L.C.

AI model provider used to generate and optimize automated messaging and other AI features from inputs you provide. Inputs and outputs are not used to train its models under our agreement.

United States

Anthropic, PBC

AI model provider used to generate and optimize content from inputs you provide. Inputs and outputs are not used to train its models under our agreement.

United States

Google LLC (Sign-In)

Federated authentication for “Continue with Google” sign-in.

United States

Google LLC (Workspace)

Business email and productivity tools used to communicate with and support Customers and Authorized Users.

United States

PostHog, Inc.

Product analytics on signed-in application usage to help us understand and improve the Services.

United States

Resend (Plus Five Five, Inc.)

Delivery of transactional and account emails (e.g., sign-in, notifications, service messages).

United States

Paddle.com Inc. (US) / Paddle.com Market Ltd. (RoW)

Payment processing and billing as our Merchant of Record, including fraud prevention.

United States / United Kingdom

GitHub, Inc.

Tracking and managing customer-submitted issues, bug reports, and feature requests.

United States

 

Annex 4 — Standard Contractual Clauses (Completion Details)

Where the EU SCCs apply, they are completed as follows confirm with counsel:

        Module in operation: Module Two (Controller-to-Processor) or Module Three (Processor-to-Processor), as applicable per Section 12.

        Clause 7 (docking): [included].

        Clause 9 (sub-processors): Option 2 (general authorization); notice period as in Section 6.

        Clause 11 (redress): optional independent dispute-resolution body [not included].

        Clause 17 (governing law):[Ireland / member state to confirm].

        Clause 18 (forum): [courts of the member state to confirm].

        Annexes to the SCCs: the descriptions in Annex 1, security measures in Annex 2, and Sub-processors in Annex 3 of this DPA populate the corresponding SCC annexes.

        UK Addendum: Tables completed using the information in this DPA; Part 4 “importer/exporter” as set out in Section 12.

Annex 5 — Jurisdiction-Specific Terms

This Annex extends the DPA to additional jurisdictions. For Customers or Data Subjects in a listed jurisdiction, the corresponding law is included in “Data Protection Laws,” and the DPA’s defined terms map to the local equivalents below.

Jurisdiction

Applicable law

Notes / term mapping

European Economic Area

GDPR

Baseline; “Controller/Processor” as defined in the GDPR.

United Kingdom

UK GDPR & DPA 2018

UK Addendum applies to SCCs (Section 12).

Switzerland

Swiss FADP

EU SCCs with Swiss adaptations; supervisory authority is the FDPIC.

Canada

PIPEDA

“Processor” maps to a service provider processing on the organization’s behalf.

Australia

Privacy Act 1988 / APPs

“Personal Data” maps to “personal information”; APP obligations apply.

For transfers to or from any listed jurisdiction, PlumPMM will use the transfer mechanism required by that jurisdiction’s law; where that jurisdiction recognizes the EU SCCs or an equivalent, those apply with the necessary adaptations.