PlumPMM Data
Processing Agreement
Incorporated into the PlumPMM Terms of Service
| Effective: 7/14/2026| Version 1.0
This Data Processing Agreement (“DPA”)
forms part of the PlumPMM Terms of Service available at https://www.plumpmm.com/terms
or other agreement between PlumPMM LLC
(“PlumPMM,” “Processor”) and the
customer (“Customer,” “Controller”) (the “Agreement”) and
governs PlumPMM’s Processing of Personal Data on
Customer’s behalf. By agreeing to the Agreement, Customer also agrees to this
DPA; no separate signature is required. If there is a conflict between this DPA
and the Agreement regarding the Processing of Personal Data, this DPA controls.
Capitalized terms not defined here have
the meaning in the Agreement. The following terms have the meanings given:
“Data Protection Laws” all laws applicable to the Processing
of Personal Data under the Agreement, including the EU General Data Protection
Regulation 2016/679 (“GDPR”), the UK GDPR and UK Data Protection Act 2018,
Swiss data protection law, US state privacy laws including the California
Consumer Privacy Act as amended (“CCPA”), and the additional regimes listed in
Annex 5.
“Controller, Processor, Data Subject,
Personal Data, Processing, and Personal Data Breach” have the meanings given in the GDPR
(and equivalent terms such as “business,” “service provider,” and “consumer”
under the CCPA, and the equivalents in Annex 5, apply correspondingly).
“Customer Personal Data” Personal Data contained within Customer
Data that PlumPMM Processes on Customer’s behalf
under the Agreement.
“Permitted Purpose” Processing Customer Personal Data
solely to provide, secure, maintain, and support the Services for Customer in
accordance with the Agreement, this DPA, and Customer’s documented instructions
— and not for any other purpose.
“Sub-processor” a third party engaged by PlumPMM to Process Customer Personal Data.
“Authorized Affiliate” any of Customer’s affiliates that is
permitted to use the Services under the Agreement and whose Personal Data is
Processed under this DPA; Customer enters into this
DPA on behalf of itself and such Authorized Affiliates.
“Standard Contractual Clauses (SCCs)” (a) for the EU, the clauses annexed to
Commission Implementing Decision (EU) 2021/914; and (b) for the UK, the UK
International Data Transfer Addendum to the EU SCCs (“UK Addendum”).
The parties acknowledge that, for
Customer Personal Data, Customer is the Controller and PlumPMM
is the Processor; where Customer is itself a Processor acting for a third-party
Controller, PlumPMM is a Sub-processor. Under the
CCPA, PlumPMM acts as a service provider and
not as a “third party.” This DPA applies to PlumPMM’s
Processing of Customer Personal Data for the duration of the Agreement, and to
Customer and its Authorized Affiliates. The subject matter, nature, purpose,
duration, types of Personal Data, and categories of Data Subjects are described
in Annex 1.
(a) PlumPMM will Process Customer Personal Data
only for the Permitted Purpose and on Customer’s documented instructions
(including as set out in the Agreement and this DPA) — unless required by law,
in which case PlumPMM will inform Customer (unless
legally prohibited).
(b) PlumPMM will not “sell” or “share” Customer Personal
Data (as defined under the CCPA), retain, use, or disclose it for any purpose
other than the Permitted Purpose, or combine it with other personal information
except as permitted by the CCPA. PlumPMM certifies it
understands and will comply with these restrictions.
(c) PlumPMM will not use Customer Personal Data to
train, fine-tune, or improve any AI or machine-learning models, and its agreements with AI
Sub-processors prohibit such training.
(d) Customer is responsible for the
accuracy and legality of Customer Personal Data and for having the necessary
rights, legal bases, and notices/consents for PlumPMM
to Process it for the Permitted Purpose.
PlumPMM will ensure that personnel authorized
to Process Customer Personal Data are bound by confidentiality obligations and
are trained on their data-protection responsibilities, and
will limit access to those who need it to provide the Services.
PlumPMM will implement and maintain
appropriate technical and organizational measures to protect Customer Personal
Data against Personal Data Breaches, taking into account
the state of the art, the costs of implementation, and the nature, scope, and
purposes of Processing, as described in Annex 2. PlumPMM
regularly tests and evaluates the effectiveness of these measures.
(a) Customer provides general authorization
for PlumPMM to engage Sub-processors to Process
Customer Personal Data. The current Sub-processors are listed in Annex 3
and at https://plumpmm.com/subprocessors.
(b) PlumPMM will impose data-protection
obligations on each Sub-processor that are no less protective than those in
this DPA and remains responsible for its Sub-processors’ performance.
(c) PlumPMM will give Customer advance notice (by
updating the list and/or email subscription) of any new or replacement
Sub-processor. Customer may object on reasonable, documented data-protection
grounds within [thirty (30)] days; the parties will work in good faith
to resolve the objection, and if they cannot, Customer may terminate the
affected Services.
Taking into account the nature of the Processing, PlumPMM will assist Customer by appropriate technical and
organizational measures, insofar as possible, to respond to Data Subjects’
requests to exercise their rights. If PlumPMM
receives such a request directly, it will, unless legally required to respond,
direct the Data Subject to Customer or forward the request to Customer. PlumPMM will also provide reasonable assistance with
Customer’s data protection impact assessments and prior consultations with supervisory
authorities.
PlumPMM will notify Customer without undue
delay (and in any event within [seventy-two (72)] hours) after
becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to
help Customer meet its own notification obligations. Notification is not an
acknowledgment of fault or liability.
If PlumPMM
receives a legally binding request from a public authority to disclose Customer
Personal Data, PlumPMM will, unless legally
prohibited, notify Customer before disclosing, and will challenge any request
that it considers unlawful or overbroad. PlumPMM will
disclose only the minimum Personal Data necessary to comply.
On termination or expiry of the
Agreement, PlumPMM will, at Customer’s choice, delete
or return Customer Personal Data within [thirty (30)] days, and delete
existing copies except to the extent retention is required by law. Data in
routine backups is deleted on the ordinary backup cycle.
PlumPMM will make available information
reasonably necessary to demonstrate compliance with this DPA and, on reasonable
prior notice and subject to confidentiality, allow for and contribute to
audits, including by providing third-party audit reports or certifications
where available.
(a) PlumPMM may Process and transfer Customer
Personal Data to countries outside the EEA, UK, and Switzerland, including the
United States, where a valid transfer mechanism applies.
(b) Where required, the parties agree that
the EU Standard Contractual Clauses are incorporated by reference and
apply to such transfers, with PlumPMM as “data
importer” and Customer as “data exporter,” using: Module
Two (Controller-to-Processor) where Customer is a Controller, and Module
Three (Processor-to-Processor) where Customer is a Processor. The clauses
are completed as set out in Annex 4.
(c) For transfers subject to the UK GDPR,
the UK Addendum applies to the EU SCCs. For transfers subject to Swiss
law, the EU SCCs apply with the adaptations required by Swiss law. For other
jurisdictions, the transfer terms in Annex 5 apply.
(a) Each party’s liability arising out of
or related to this DPA, whether in contract, tort, or under any other theory of
liability, is subject to the limitations and exclusions of liability set out
in the Agreement. Any reference in the Agreement to the liability of a
party means the aggregate liability of that party and all of
its affiliates under the Agreement and this DPA together.
(b) The limitations of liability do not
apply to a Data Subject’s rights
under the SCCs or Data Protection Laws, or to any liability that cannot be
limited or excluded by applicable law.
(c) Regulatory fines carve-out. Neither party is liable to the other
for, and each party is solely responsible for, any administrative fine or
penalty imposed on it by a supervisory authority under the GDPR, UK GDPR, or
other Data Protection Laws to the extent the fine arises from that party’s own
violation. Neither party will indemnify the other for such fines.
This DPA is governed by the law and
jurisdiction of the Agreement, unless Data Protection Laws or the SCCs require
otherwise. Except as amended here, the Agreement remains in effect. In the
event of a conflict between this DPA and the SCCs, the SCCs prevail as to
transfers governed by them.
|
Item |
Detail |
|
Subject matter |
PlumPMM’s
provision of the B2B positioning and messaging Services to Customer. |
|
Duration |
The term of the Agreement plus any deletion/return
period. |
|
Nature and purpose |
Hosting, storage, generation, analysis, and
processing of Customer Data (including AI-assisted generation of positioning
and messaging) to provide the Services (the Permitted Purpose). |
|
Types of Personal Data |
Business contact details of Customer’s Authorized
Users (name, email, job title); and any Personal Data contained in content
Customer submits or has collected from public sources, such as names, job
titles, and business contact details of Customer’s prospects or market
contacts. |
|
Categories of Data Subjects |
Customer’s Authorized Users;
Customer’s prospects, leads, and business contacts represented in Customer
Data. |
|
Sensitive data |
None intended. Customer must not submit
special-category data. |
|
Frequency |
Continuous, for the duration of the Agreement. |
PlumPMM maintains measures including the
following.
•
Encryption of Customer Data in transit (TLS) and
at rest.
•
Access
control — role-based
access, least-privilege, unique accounts, and multi-factor authentication for
administrative access.
•
Network
and application security
— firewalls/WAF (Cloudflare), isolation of environments, and secure development
practices.
•
Monitoring
and logging of access
and security-relevant events.
•
Resilience
and backups — regular
backups and the ability to restore availability after an incident.
•
Vendor
management — security
diligence and contractual obligations for Sub-processors.
•
Personnel — confidentiality obligations and
security awareness training.
The current Sub-processors that may
Process Customer Personal Data are listed below and maintained at https://plumpmm.com/subprocessors.
This list mirrors Section 10 of the Privacy Policy.
|
Sub-processor |
Purpose of processing |
Processing location |
|
Amazon Web Services, Inc. (AWS) |
Cloud hosting and infrastructure; storage and
processing of Customer Data, including uploaded go-to-market documents and
content from publicly available websites processed by the Services. |
United States |
|
Cloudflare, Inc. |
Content delivery network, DNS routing, caching, and
security/bot protection in front of the application. |
Global edge network |
|
OpenAI,
L.L.C. |
AI model provider used to generate and optimize
automated messaging and other AI features from inputs you provide. Inputs and
outputs are not used to train its models under our agreement. |
United States |
|
Anthropic, PBC |
AI model provider used to generate and optimize
content from inputs you provide. Inputs and outputs are not used to train its
models under our agreement. |
United States |
|
Google LLC (Sign-In) |
Federated authentication for “Continue with Google”
sign-in. |
United States |
|
Google LLC (Workspace) |
Business email and productivity tools used to
communicate with and support Customers and Authorized Users. |
United States |
|
PostHog,
Inc. |
Product analytics on signed-in application usage to
help us understand and improve the Services. |
United States |
|
Resend (Plus Five Five,
Inc.) |
Delivery of transactional and account emails (e.g.,
sign-in, notifications, service messages). |
United States |
|
Paddle.com Inc. (US) / Paddle.com Market Ltd. (RoW) |
Payment processing and billing as our Merchant of
Record, including fraud prevention. |
United States / United Kingdom |
|
GitHub, Inc. |
Tracking and managing customer-submitted issues,
bug reports, and feature requests. |
United States |
Where the EU SCCs apply, they are
completed as follows confirm with counsel:
•
Module
in operation: Module
Two (Controller-to-Processor) or Module Three (Processor-to-Processor), as
applicable per Section 12.
•
Clause
7 (docking): [included].
•
Clause
9 (sub-processors):
Option 2 (general authorization); notice period as in Section 6.
•
Clause
11 (redress): optional
independent dispute-resolution body [not included].
•
Clause
17 (governing law):[Ireland / member state to confirm].
•
Clause
18 (forum): [courts of the member state to
confirm].
•
Annexes
to the SCCs: the
descriptions in Annex 1, security measures in Annex 2, and Sub-processors in
Annex 3 of this DPA populate the corresponding SCC annexes.
•
UK
Addendum: Tables
completed using the information in this DPA; Part 4 “importer/exporter” as set
out in Section 12.
This Annex extends the DPA to
additional jurisdictions. For Customers or Data Subjects in a listed
jurisdiction, the corresponding law is included in “Data Protection Laws,” and
the DPA’s defined terms map to the local equivalents below.
|
Jurisdiction |
Applicable law |
Notes / term mapping |
|
European Economic Area |
GDPR |
Baseline;
“Controller/Processor” as defined in the GDPR. |
|
United Kingdom |
UK GDPR & DPA 2018 |
UK Addendum applies to SCCs (Section 12). |
|
Switzerland |
Swiss FADP |
EU SCCs with Swiss adaptations; supervisory
authority is the FDPIC. |
|
Canada |
PIPEDA |
“Processor” maps to a service provider processing
on the organization’s behalf. |
|
Australia |
Privacy Act 1988 / APPs |
“Personal Data” maps to “personal information”; APP
obligations apply. |
For transfers to or from any listed
jurisdiction, PlumPMM will use the transfer mechanism
required by that jurisdiction’s law; where that jurisdiction recognizes the EU
SCCs or an equivalent, those apply with the necessary adaptations.