← Back to site
Legal

Data Processing Agreement

Version: 1.0  ·  Effective date: July 17, 2026

What this is: This Data Processing Agreement ("DPA") applies when BuyerIntentSystem processes personal data on behalf of a customer as part of the Serious Buyer System™ services — typically your leads' and clients' data. It is incorporated into our Terms of Service and any signed Client Services Agreement (together, the "Agreement").

Contents

  1. Definitions
  2. Scope & Roles
  3. Processing on Instructions
  4. Confidentiality of Personnel
  5. Security Measures
  6. Sub-processors
  7. Assistance to Customer
  8. Personal Data Breach
  9. International Transfers
  10. Audits & Information
  11. Return & Deletion
  12. US State Privacy Law Terms
  13. India DPDP Act Terms
  14. Liability & Order of Precedence
  15. Annex 1 — Processing Details
  16. Annex 2 — Security Measures
  17. Annex 3 — Approved Sub-processors

1. Definitions

2. Scope & Roles

2.1 This DPA applies to Processing of Personal Data by Processor on behalf of Customer in connection with the Services described in the Agreement.

2.2 Customer is the Controller (or, where Customer itself acts as a processor for a third party, Customer warrants it has authority to appoint Processor as sub-processor). BuyerIntentSystem is the Processor. Annex 1 sets out the subject matter, duration, nature, purposes of Processing, categories of Data Subjects, and types of Personal Data.

2.3 Each party will comply with its own obligations under Data Protection Laws. Customer warrants that it has a lawful basis for the Processing, has provided all required notices to Data Subjects, and that its instructions will comply with Data Protection Laws.

3. Processing on Instructions (GDPR Art. 28(3)(a))

Processor will Process Personal Data only on Customer's documented instructions — including the Agreement, this DPA, and Customer's configuration and use of the Services — unless required otherwise by law to which Processor is subject; in that case, Processor will inform Customer of the legal requirement before Processing (unless the law prohibits it). Processor will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality of Personnel (Art. 28(3)(b))

Processor ensures that all persons authorized to Process Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate data-protection training. Access is limited to personnel who need it to perform the Services.

5. Security Measures (Art. 28(3)(c), Art. 32)

Processor implements and maintains technical and organizational measures appropriate to the risk, as described in Annex 2 and the Security Overview. Processor may update these measures provided the updates do not materially reduce overall protection.

6. Sub-processors (Art. 28(2), 28(4))

6.1 Customer grants general written authorization for Processor to engage the sub-processors listed in Annex 3.

6.2 Processor will give Customer at least fourteen (14) days' prior notice (by email or by updating the published sub-processor list with a notification mechanism) of any intended addition or replacement. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.

6.3 Processor will impose data-protection obligations on each sub-processor that are no less protective than this DPA and remains fully liable for its sub-processors' performance.

7. Assistance to Customer (Art. 28(3)(e)–(f))

Taking into account the nature of the Processing, Processor will:

8. Personal Data Breach

Processor will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will describe, to the extent known: the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, measures taken or proposed, and a contact point. Processor will cooperate with Customer's reasonable investigation and remediation. Processor's notification is not an acknowledgment of fault or liability.

9. International Transfers

9.1 Processor will not transfer Personal Data protected by the EU/UK GDPR outside the EEA/UK except: (a) to a country with an adequacy decision; (b) under the SCCs (Module Two: controller-to-processor, or Module Three: processor-to-processor, as applicable), which are incorporated by reference into this DPA with Customer as data exporter and Processor as data importer; or (c) under another valid transfer mechanism.

9.2 For UK transfers, the UK Addendum applies to the SCCs; for Swiss transfers, the SCCs are adapted as required by the FDPIC.

9.3 For the SCCs: Clause 7 (docking) is included; Clause 9(a) Option 2 (general authorization, fourteen (14) days' notice); Clause 11 optional language is not included; Clause 17: law of Ireland; Clause 18: courts of Ireland. Annexes I–III of the SCCs are populated by Annexes 1–3 of this DPA.

9.4 For Personal Data governed by the DPDP Act, Processor will not transfer Personal Data to any country restricted by notification of the Indian Central Government.

10. Audits & Information (Art. 28(3)(h))

Processor will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant certifications, assessments, and this DPA's Annexes. Customer (or an independent auditor bound by confidentiality) may audit Processor's compliance no more than once per 12-month period, on at least thirty (30) days' notice, during business hours, without disrupting operations, subject to confidentiality obligations. Where a written response or existing report reasonably satisfies the request, that will fulfill the audit right. Customer bears the costs of audits unless the audit reveals material non-compliance.

11. Return & Deletion (Art. 28(3)(g))

Upon termination or expiry of the Services, Processor will, at Customer's choice, return Personal Data in a commonly used format and/or delete it (including copies) within thirty (30) days, unless retention is required by law — in which case Processor will isolate and protect the retained data and Process it only as required by that law. Deletion from backups occurs in the ordinary backup rotation cycle, not exceeding ninety (90) days.

12. US State Privacy Law Terms (CCPA/CPRA & similar)

Where the CCPA or similar US state laws apply, Processor acts as Customer's "service provider"/"processor," and:

13. India DPDP Act Terms

Where the DPDP Act applies, Customer is the "Data Fiduciary" and Processor is a "Data Processor" engaged under a valid contract per Section 8(2) of the DPDP Act. Processor will: process Personal Data only per this DPA; implement reasonable security safeguards; notify Customer of any breach without undue delay so Customer can meet its notification duties to the Data Protection Board of India and affected Data Principals; and delete Personal Data as described in Section 11 when the purpose is served, unless retention is required by law.

14. Liability & Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws do not permit such limitation. In case of conflict: (1) the SCCs prevail over (2) this DPA, which prevails over (3) the Agreement, with respect to the Processing of Personal Data.

Annex 1 — Details of Processing

Subject matterProvision of the Serious Buyer System™ — lead-intake, lead-scoring, and related setup and consulting services.
DurationThe term of the Agreement plus the deletion period in Section 11.
Nature & purposeCollection, structuring, storage, scoring/analysis, and display of lead data submitted by or for Customer, to help Customer prioritize serious buyers; related support and troubleshooting.
Categories of Data SubjectsCustomer's leads, prospects, and clients (e.g., prospective property buyers); Customer's personnel who use the Services.
Types of Personal DataName, email, phone; property-search criteria (budget, timeline, financing status, location preferences); questionnaire responses; lead scores and notes; communication metadata. No special-category/sensitive data is intended to be processed — Customer agrees not to submit it.
FrequencyContinuous, for the duration of the Services.
Competent Supervisory Authority (SCCs Annex I.C)The supervisory authority of the EU Member State in which the Customer (data exporter) is established

Annex 2 — Technical & Organizational Security Measures

Further detail: Security Overview.

Annex 3 — Approved Sub-processors

Sub-processorPurposeLocation
Google Cloud / VercelApplication & data hostingUnited States / Global
Google Workspace (Google LLC)Business email & documentsUnited States / Global
CRM and form tools (as configured for the engagement)Lead intake & managementUnited States / Global
Calendly LLCAppointment bookingUnited States / Global
Stripe, Inc. / Razorpay Software Pvt. Ltd.Payment processing (Customer billing data)United States / Global
Google Analytics (Google LLC)Website analytics (Company site only)United States / Global

The current list is maintained in this Annex 3 and updated from time to time. To subscribe to change notifications, email buyerintentsystem@gmail.com.

Execution

This DPA is deemed executed by the parties upon execution of the Agreement or Customer's acceptance of the Terms of Service, whichever occurs first. Where a signed copy is required:

Customer (Controller / Data Exporter)BuyerIntentSystem (Processor / Data Importer)
Name: ______________________
Title: ______________________
Date: ______________________
Signature: ______________________
Name: ______________________
Title: ______________________
Date: ______________________
Signature: ______________________
Disclaimer: This document is a template prepared for BuyerIntentSystem and does not constitute legal advice. Have a qualified attorney review it before use, particularly the SCC elections in Section 9.3 and the Annexes.