This Data Processing Agreement (the "DPA") is entered into by the customer identified on the applicable ordering document ("Customer") and the We-Connect entity identified on the ordering document (We-Connect Systems LLC or an affiliate, "We-Connect"), and governs the processing of Personal Data that Customer provides to We-Connect in connection with the services, the processing of that Personal Data by We-Connect on behalf of Customer, and any Personal Data We-Connect provides to Customer in connection with the services.
This DPA is incorporated into the We-Connect services agreement referenced on the ordering document (the "We-Connect Contract"). Collectively, the DPA (including the SCCs), the We-Connect Contract, and the ordering documents are the "Agreement." In the event of any conflict regarding the processing of Personal Data, the following prevail in order: (a) the SCCs; (b) this DPA; (c) the We-Connect Contract, including the Customer Terms of Service.
1.Definitions
Key defined terms include the Standard Contractual Clauses (the EU SCCs under Commission Implementing Decision 2021/914, and the UK SCCs under Article 46 UK GDPR, each incorporated by reference), Customer Personal Data, Data Protection Requirements (including the EU GDPR, UK GDPR, the Swiss FADP, Brazil's LGPD, PIPEDA, and the CCPA/CPRA), Personal Data Breach, Process, Subprocessor, and Supervisory Authority.
2.Nature of data processing
Each party processes Personal Data received under the Agreement only for the purposes set out in the Agreement. The categories of Personal Data and data subjects are described in Schedule A.
3.Compliance with laws
Each party complies with its obligations under all applicable Data Protection Requirements.
4.Customer obligations
Customer determines the purposes and general means of We-Connect's processing of Customer Personal Data and complies with its controller obligations under Data Protection Requirements. At We-Connect's request, Customer designates a single point of contact for receiving and responding to data-subject requests, and for authorizing We-Connect to fulfill responses on Customer's behalf. The parties each act as independent controllers with respect to their own processing and are not joint controllers.
5.We-Connect obligations
5.1 Processing requirements
We-Connect will process Customer Personal Data only to provide, support, and improve the services and on Customer's instructions, and will not process it for any other purpose. Any use of Customer Personal Data to improve the services is limited to aggregated and de-identified data, consistent with Section 8 and our AI Terms; We-Connect does not use Customer Personal Data to train or improve generalized AI models. We-Connect will inform Customer if it cannot comply with Sections 5–8, or if an instruction appears to violate Data Protection Requirements; will follow Customer's collection instructions; will bind its personnel and Subprocessors to confidentiality; and remains liable for its Subprocessors' acts, binding them to equivalent data-protection and security obligations.
5.2 Notice to Customer
We-Connect will inform Customer of any non-compliance with Sections 5–8, any legally binding law-enforcement request for disclosure (unless legally prohibited from informing Customer), any Supervisory Authority inquiry regarding Customer Personal Data, and any request received directly from Customer's data subjects. We-Connect will not substantively respond to a data-subject request without Customer's prior written authorization.
5.3 Assistance to Customer
We-Connect provides reasonable assistance regarding data-subject requests, the investigation and notification of Personal Data Breaches, and, where appropriate, data protection impact assessments and consultations with a Supervisory Authority.
5.5 Security
We-Connect maintains appropriate organizational and technical security measures (including access controls, monitoring and logging, vulnerability and breach detection, incident response, and encryption of Customer Personal Data in transit and at rest), including the measures set out in Schedule C, which apply as Annex II of the SCCs. We-Connect will notify Customer of any Personal Data Breach without undue delay and in any event within 48 hours of becoming aware. Where a breach results from We-Connect's negligence or a material failure to comply with this DPA, We-Connect bears the costs of investigating and remediating it and will reasonably reimburse Customer for legally required notification and remediation costs.
6.Audit
We-Connect cooperates with a Supervisory Authority audit of its processing facilities. On request, We-Connect provides written responses to a reasonable security questionnaire together with the Schedule C measures. If that does not, in Customer's reasonable judgment, sufficiently confirm compliance, Customer or an agreed accredited third-party auditor may audit We-Connect during business hours with reasonable advance notice, subject to confidentiality, at Customer's cost, no more than once annually, with scope and timing agreed in advance.
7.Data transfers
For transfers of EU Personal Data to We-Connect in a jurisdiction that is not the EU, the EEA, or a European Commission-approved adequate country, the parties use Module 2 of the EU SCCs (Controller to Processor), incorporated by reference, with disputes governed by the law of the Member State in which the data exporter is established. If We-Connect cannot comply, EU Personal Data is processed exclusively within an EU member state, and any movement to a non-EU country requires Customer's prior written consent. For transfers of UK Personal Data to a jurisdiction that is not the UK or a UK-adequate country, the EU SCCs apply as amended by the UK International Data Transfer Addendum, which is deemed executed and incorporated. Schedule A and Schedule C apply as Annex I and Annex II respectively.
8.Data return and deletion
On termination of the processing services or upon Customer's reasonable request, We-Connect will, and will cause its Subprocessors to, at Customer's choice, return or securely destroy all Customer Personal Data and copies, unless Data Protection Requirements prevent this, in which case We-Connect preserves its confidentiality and processes it only as required by law. Unless Customer requests earlier return or deletion, and except where retention is legally required, We-Connect permanently deletes all Customer Personal Data within 90 days of termination. We-Connect may continue to process Customer Personal Data only where it has been aggregated and de-identified so that it does not identify any individual or customer, and does not use it to train generalized AI models.
9.Third-party data processors
Where We-Connect, on Customer's instructions, transfers Customer Personal Data to third-party processors the Customer has connected (for example the Customer's own CRM), Customer is responsible for entering into its own contractual arrangements with those third parties, and they are not Subprocessors of We-Connect.
10.Term
This DPA remains in effect for as long as We-Connect processes Personal Data on behalf of Customer or until the We-Connect Contract terminates and all Personal Data has been returned or deleted in accordance with Section 8.
11.Governing law, jurisdiction, and venue
Notwithstanding anything in the Agreement to the contrary, this DPA is governed by the laws of the Member State in which the data exporter is established. Where a dispute arises regarding the processing of UK Personal Data, that dispute is governed by the laws of England and Wales.
Schedule A: Description of the transfer
Categories of data subjects: Prospects and business contacts of the Customer, whose personal data the Customer collects from LinkedIn through its connected account(s), imports (for example via CSV), or syncs from its connected CRM.
Categories of Personal Data: depending on the Customer's input, first and last name, LinkedIn profile URL and image, headline, summary, current job title and company, industry, location, skills, work experience history, email address and phone number where visible, connection and engagement status, tags and lead status assigned by the Customer, and the content of messages sent and received through campaigns.
Sensitive data: None intended. The Customer agrees not to submit special categories of personal data to the platform.
Nature and purpose: collection, organization, structuring, use, storage, combination, and making available on We-Connect properties in order to provide, support, and improve the services, provide customer support, fulfill We-Connect's obligations, and comply with applicable law.
Retention: for the term of the services specified on the ordering document and in accordance with Section 8.
Subprocessors
- Amazon Web Services, Inc. (Cloud server provider)
- Cloudflare, Inc. (Content delivery network)
- The Constant Company, LLC, d/b/a Vultr (Cloud server provider)
- Google LLC (Email and document hosting, AI processing)
- OpenAI OpCo, LLC (AI processing)
- Anthropic, PBC (AI processing)
- Intercom, Inc. (Chat and help center)
- Mailjet SAS (Transactional emails)
- The Rocket Science Group, LLC, d/b/a Mailchimp Mandrill (Transactional emails)
- Atlassian, Inc. (Collaboration tools)
- Slack Technologies, LLC (Collaboration tool)
- HubSpot, Inc. (CRM)
- Stripe, Inc. (Payment processing)
- ZoomInfo Technologies LLC (Data enrichment)
- NeverBounce, a ZoomInfo company (Email verification)
- Hunter Web Services, Inc. (Email verification and enrichment)
- Oxylabs, UAB (Network proxy services)
- Bright Data Ltd (Network proxy services)
Schedule B: CCPA / CPRA addendum
This Addendum amends the DPA with respect to We-Connect's processing of Customer Personal Data of California Consumers under the CCPA/CPRA. For those purposes, We-Connect acts as a Service Provider. Customer does not sell Customer Personal Data to We-Connect, because We-Connect uses Customer Personal Data only for the purposes specified in the DPA. We-Connect certifies that it has read and understands this Addendum and will abide by it, including by avoiding any action that would cause either party to be deemed to have sold or shared Personal Data or Personal Information under the CCPA/CPRA.
Schedule C: Technical and organizational measures
This Schedule is Annex II to the SCCs and sets out the technical and organizational measures We-Connect maintains to protect Customer Personal Data.
1. General security measures
We-Connect complies with industry-standard security measures across personnel, facilities, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, and incident response, and with applicable data-privacy and security laws, regulations, and standards.
2. Information security program
We-Connect maintains an information security program designed to preserve the confidentiality, integrity, and availability of its systems and data, including the measures below.
- Secure software development: review and testing of applications, products, and services for common vulnerabilities, a defense-in-depth strategy, periodic penetration testing and security assessment, and defined baseline configurations and patching requirements.
- Human-resources security: background checks, acknowledgment of security policies, and onboarding and termination controls for employees and third parties.
- Data classification and protection: classification of data containing personal data, encryption requirements, rules for transmission and removable media, and access governance.
- Network security: safe network practices and defined service levels for internal and external network services.
- Physical and environmental security: protection of areas containing sensitive information and of critical information services.
- Business continuity and disaster recovery: data-center resiliency and disaster-recovery procedures for business-critical data and functions.
3. Access control
Access to facilities, applications, systems, network devices, and operating systems is limited to personnel with a business need, is removed when no longer required, and is reviewed periodically.
4. Risk assessments
We-Connect follows a documented risk-management procedure and secure software-development lifecycle, performs regular risk assessments of its products and infrastructure, conducts application and infrastructure testing for each new product and periodic reassessments, and uses a combination of manual penetration testing and automated tools together with peer code review.
5. Third-party risk assessments
We-Connect conducts security due diligence on third-party service providers, reviewing the scope and sensitivity of data processed, the purpose of the work, the provider's organizational and technical measures, storage limitations, and data-deletion procedures.
6. Supplementary measures
- Customer Personal Data is transferred across public networks to We-Connect's data centers in the United States and stored on secured servers behind a firewall.
- All Customer Personal Data is encrypted in transit across public networks where supported; certain highly confidential data is also encrypted at rest, using industry-tested, accepted cryptographic standards.
- Data is replicated across data centers in a secure environment.
- Application logic with appropriate authorization protects tenant data; access requests are reviewed; server and database access logs are retained for auditing.
- Servers are monitored by standard and proprietary network-monitoring tools.
- Corporate systems and databases are password protected, with dual-factor authentication for VPN access.
- Customer and member passwords are hashed and salted and stored in a separate, secure database.
- Keys to the payment-card database are rotated regularly.
- Active, automated monitoring of critical access logs and anomaly detection.
Security contact: privacy@we-connect.io.
Contact
Questions about this agreement should be sent to privacy@we-connect.io.
Back to top

