Contents
- Definitions
- Scope & Roles
- Processing on Instructions
- Confidentiality of Personnel
- Security Measures
- Sub-processors
- Assistance to Customer
- Personal Data Breach
- International Transfers
- Audits & Information
- Return & Deletion
- US State Privacy Law Terms
- India DPDP Act Terms
- Liability & Order of Precedence
- Annex 1 — Processing Details
- Annex 2 — Security Measures
- Annex 3 — Approved Sub-processors
1. Definitions
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU GDPR (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), other US state privacy laws, and India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
- "Personal Data" means any information relating to an identified or identifiable natural person that Processor processes on behalf of Customer under the Agreement (a subset of Customer Data).
- "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given in the GDPR; equivalent terms in other Data Protection Laws (e.g., "Data Fiduciary"/"Data Processor" under the DPDP Act; "Business"/"Service Provider" under the CCPA) are read accordingly.
- "SCCs" means the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914); "UK Addendum" means the ICO's International Data Transfer Addendum to the SCCs.
- "Customer" means the customer entity that is party to the Agreement; "Processor" means BuyerIntentSystem.
2. Scope & Roles
2.1 This DPA applies to Processing of Personal Data by Processor on behalf of Customer in connection with the Services described in the Agreement.
2.2 Customer is the Controller (or, where Customer itself acts as a processor for a third party, Customer warrants it has authority to appoint Processor as sub-processor). BuyerIntentSystem is the Processor. Annex 1 sets out the subject matter, duration, nature, purposes of Processing, categories of Data Subjects, and types of Personal Data.
2.3 Each party will comply with its own obligations under Data Protection Laws. Customer warrants that it has a lawful basis for the Processing, has provided all required notices to Data Subjects, and that its instructions will comply with Data Protection Laws.
3. Processing on Instructions (GDPR Art. 28(3)(a))
Processor will Process Personal Data only on Customer's documented instructions — including the Agreement, this DPA, and Customer's configuration and use of the Services — unless required otherwise by law to which Processor is subject; in that case, Processor will inform Customer of the legal requirement before Processing (unless the law prohibits it). Processor will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality of Personnel (Art. 28(3)(b))
Processor ensures that all persons authorized to Process Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate data-protection training. Access is limited to personnel who need it to perform the Services.
5. Security Measures (Art. 28(3)(c), Art. 32)
Processor implements and maintains technical and organizational measures appropriate to the risk, as described in Annex 2 and the Security Overview. Processor may update these measures provided the updates do not materially reduce overall protection.
6. Sub-processors (Art. 28(2), 28(4))
6.1 Customer grants general written authorization for Processor to engage the sub-processors listed in Annex 3.
6.2 Processor will give Customer at least fourteen (14) days' prior notice (by email or by updating the published sub-processor list with a notification mechanism) of any intended addition or replacement. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.
6.3 Processor will impose data-protection obligations on each sub-processor that are no less protective than this DPA and remains fully liable for its sub-processors' performance.
7. Assistance to Customer (Art. 28(3)(e)–(f))
Taking into account the nature of the Processing, Processor will:
- Assist Customer by appropriate technical and organizational measures in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If a Data Subject contacts Processor directly, Processor will forward the request to Customer without undue delay and will not respond substantively except on Customer's instruction or as required by law;
- Assist Customer with security, breach notification, data protection impact assessments, and prior consultations with Supervisory Authorities (Arts. 32–36), considering the information available to Processor;
- Charge reasonable fees for assistance that is materially beyond what the Services include, where permitted by law.
8. Personal Data Breach
Processor will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will describe, to the extent known: the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, measures taken or proposed, and a contact point. Processor will cooperate with Customer's reasonable investigation and remediation. Processor's notification is not an acknowledgment of fault or liability.
9. International Transfers
9.1 Processor will not transfer Personal Data protected by the EU/UK GDPR outside the EEA/UK except: (a) to a country with an adequacy decision; (b) under the SCCs (Module Two: controller-to-processor, or Module Three: processor-to-processor, as applicable), which are incorporated by reference into this DPA with Customer as data exporter and Processor as data importer; or (c) under another valid transfer mechanism.
9.2 For UK transfers, the UK Addendum applies to the SCCs; for Swiss transfers, the SCCs are adapted as required by the FDPIC.
9.3 For the SCCs: Clause 7 (docking) is included; Clause 9(a) Option 2 (general authorization, fourteen (14) days' notice); Clause 11 optional language is not included; Clause 17: law of Ireland; Clause 18: courts of Ireland. Annexes I–III of the SCCs are populated by Annexes 1–3 of this DPA.
9.4 For Personal Data governed by the DPDP Act, Processor will not transfer Personal Data to any country restricted by notification of the Indian Central Government.
10. Audits & Information (Art. 28(3)(h))
Processor will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant certifications, assessments, and this DPA's Annexes. Customer (or an independent auditor bound by confidentiality) may audit Processor's compliance no more than once per 12-month period, on at least thirty (30) days' notice, during business hours, without disrupting operations, subject to confidentiality obligations. Where a written response or existing report reasonably satisfies the request, that will fulfill the audit right. Customer bears the costs of audits unless the audit reveals material non-compliance.
11. Return & Deletion (Art. 28(3)(g))
Upon termination or expiry of the Services, Processor will, at Customer's choice, return Personal Data in a commonly used format and/or delete it (including copies) within thirty (30) days, unless retention is required by law — in which case Processor will isolate and protect the retained data and Process it only as required by that law. Deletion from backups occurs in the ordinary backup rotation cycle, not exceeding ninety (90) days.
12. US State Privacy Law Terms (CCPA/CPRA & similar)
Where the CCPA or similar US state laws apply, Processor acts as Customer's "service provider"/"processor," and:
- Processor will not sell or share Personal Data (as defined by the CCPA);
- Processor will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship with Customer, including not combining it with data from other sources except as permitted for service providers;
- Processor certifies that it understands and will comply with these restrictions;
- Processor will notify Customer if it can no longer meet its obligations, and Customer may take reasonable steps to stop and remediate unauthorized use;
- Processor grants Customer the rights to assess and remediate required by Cal. Civ. Code §1798.100(d)(5).
13. India DPDP Act Terms
Where the DPDP Act applies, Customer is the "Data Fiduciary" and Processor is a "Data Processor" engaged under a valid contract per Section 8(2) of the DPDP Act. Processor will: process Personal Data only per this DPA; implement reasonable security safeguards; notify Customer of any breach without undue delay so Customer can meet its notification duties to the Data Protection Board of India and affected Data Principals; and delete Personal Data as described in Section 11 when the purpose is served, unless retention is required by law.
14. Liability & Order of Precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws do not permit such limitation. In case of conflict: (1) the SCCs prevail over (2) this DPA, which prevails over (3) the Agreement, with respect to the Processing of Personal Data.
Annex 1 — Details of Processing
| Subject matter | Provision of the Serious Buyer System™ — lead-intake, lead-scoring, and related setup and consulting services. |
|---|---|
| Duration | The term of the Agreement plus the deletion period in Section 11. |
| Nature & purpose | Collection, structuring, storage, scoring/analysis, and display of lead data submitted by or for Customer, to help Customer prioritize serious buyers; related support and troubleshooting. |
| Categories of Data Subjects | Customer's leads, prospects, and clients (e.g., prospective property buyers); Customer's personnel who use the Services. |
| Types of Personal Data | Name, email, phone; property-search criteria (budget, timeline, financing status, location preferences); questionnaire responses; lead scores and notes; communication metadata. No special-category/sensitive data is intended to be processed — Customer agrees not to submit it. |
| Frequency | Continuous, for the duration of the Services. |
| Competent Supervisory Authority (SCCs Annex I.C) | The supervisory authority of the EU Member State in which the Customer (data exporter) is established |
Annex 2 — Technical & Organizational Security Measures
- Access control: unique accounts, strong passwords, multi-factor authentication on administrative and provider accounts; least-privilege, role-based access; access revoked promptly on role change or departure.
- Encryption: TLS 1.2+ for data in transit; encryption at rest via hosting/storage providers.
- Infrastructure: reputable cloud providers with industry certifications (e.g., ISO 27001, SOC 2) — see Annex 3; logical tenant/customer data separation.
- Data minimization: only fields required for lead scoring are collected; no sensitive-category data requested.
- Backups & availability: provider-managed backups; documented recovery procedures.
- Endpoint & organizational security: device encryption and screen locks; confidentiality agreements with all personnel and contractors; security and privacy awareness training.
- Vendor management: due diligence and data-protection terms with all sub-processors.
- Incident response: documented process for detecting, escalating, containing, and notifying breaches (Section 8).
- Logging & monitoring: administrative access and material system events logged where supported.
Further detail: Security Overview.
Annex 3 — Approved Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud / Vercel | Application & data hosting | United States / Global |
| Google Workspace (Google LLC) | Business email & documents | United States / Global |
| CRM and form tools (as configured for the engagement) | Lead intake & management | United States / Global |
| Calendly LLC | Appointment booking | United States / Global |
| Stripe, Inc. / Razorpay Software Pvt. Ltd. | Payment processing (Customer billing data) | United States / Global |
| Google Analytics (Google LLC) | Website analytics (Company site only) | United States / Global |
The current list is maintained in this Annex 3 and updated from time to time. To subscribe to change notifications, email buyerintentsystem@gmail.com.
Execution
This DPA is deemed executed by the parties upon execution of the Agreement or Customer's acceptance of the Terms of Service, whichever occurs first. Where a signed copy is required:
| Customer (Controller / Data Exporter) | BuyerIntentSystem (Processor / Data Importer) |
|---|---|
| Name: ______________________ Title: ______________________ Date: ______________________ Signature: ______________________ |
Name: ______________________ Title: ______________________ Date: ______________________ Signature: ______________________ |