Data Processing Addendum
When we run outbound for you, you are the controller of the contact data and we are your processor. This is the agreement that says so.
Last updated: 22 August 2026
Roles
You (the client) determine whose data is processed and why — you are the controller. Vestanam Solutions Private Limited processes that data only on your documented instructions — we are the processor. Every external client signs this addendum before their account goes live, and the platform enforces that gate: an external account with no DPA recorded cannot activate an offering, cannot run the funnel, and cannot send. It is a switch in the software, not a note in a checklist.
This page summarises the addendum so you can read it before you talk to us. The signed document is what governs.
Scope of processing
- Subject matter: discovery, enrichment, verification, scoring and message drafting for B2B outreach.
- Data subjects: employees of prospective business customers, in their professional capacity.
- Data types: name, job title, employer, business email, business phone where published, public professional profile links, and company information. No special-category data, and no consumer data.
- Sources: publicly accessible ones — company websites, public search results, public professional profiles. We do not buy contact lists.
- Duration: the term of the service agreement.
Our commitments
- Process only on your instructions, and tell you if an instruction looks unlawful.
- Keep each account’s data isolated from every other account — enforced by row-level security in the database, so a query that forgets to filter returns nothing rather than another client’s data.
- Bind our personnel and sub-processors to confidentiality.
- Apply appropriate technical and organisational measures, including encryption in transit, least-privilege access, and address verification before any send.
- Assist you with data-subject requests, and notify you of a personal-data breach without undue delay and within 72 hours of becoming aware of it.
- Delete or return the data on termination, at your choice.
- Make available the information needed to demonstrate compliance.
- Honour opt-outs automatically and permanently. An opt-out is recorded against your account and that person is never contacted again through the platform.
Sub-processors
These are the third parties that may process personal data on your behalf today. We notify clients before adding to this list, so you have the chance to object before a new provider sees any data.
- Hetzner Online GmbH — hosting and database storage. Germany.
- OpenAI — extracting company details from public pages, and summarising a company. United States.
- Anthropic — drafting the first message. United States.
- Groq — fallback provider for the above. United States.
- Exa Labs — public web and professional-profile search. United States.
- MillionVerifier — confirming that an email address exists before anything is sent to it.
- Telegram — internal operational notifications to our team, which include lead names.
Content sent to the AI providers above is submitted under API terms that exclude its use for model training.
International transfers
Data is stored in Germany. Processing by the providers listed above may involve transfers to the United States, made under the recipient’s standard contractual clauses together with the supplementary measures described in the addendum. Where you are an Indian entity, transfers are made in accordance with the Digital Personal Data Protection Act, 2023.
Audit
You may ask us to demonstrate compliance with this addendum once a year, or after a breach, on reasonable notice — normally satisfied by written answers and evidence rather than an on-site visit.
Getting a copy
The executable DPA is provided during onboarding and signed before processing begins. To request it in advance, email privacy@loopwyn.com.