Skip to content
Switching tools? We’ll help you move.See how
GrowthxAI Outreach

Data Processing Agreement

Last updated: 23 September 2026. Effective from the same date.

This Data Processing Agreement ("DPA") is between the customer named on the workspace ("you", the "Customer") and ResourcePlan Solution Private Limited ("GrowthxAI", "we", "us"). It forms part of the Terms of Service (the "Terms") and governs how we process personal data on your behalf when you use GrowthxAI Outreach (the "Service"). It is written to meet Article 28 of the GDPR and the UK GDPR, the processor requirements of India's Digital Personal Data Protection Act, 2023, and the service-provider requirements of United States state privacy laws.

At a glance

A plain-English summary. The agreement itself starts at section 1, and where they differ the agreement wins.

Who is who
You are the controller of the data in your workspace. We are your processor.
What we do with it
Only what is needed to run the product for you. No selling, no advertising, no AI training.
Where it lives
United States / Europe. Transfers are covered by SCCs, the UK Addendum and the DPF.
Sub-processors
Listed in Annex 3. 30 days' notice of any change, and you can object.
If something goes wrong
We tell you without undue delay, and within 72 hours of confirming a breach.
When you leave
30 days to export, deletion from live systems within 90 days after that, backups within a further 35.
Audits
Once a year on request: written answers and evidence first, an inspection if that is not enough.
Signing
Applies automatically under the Terms. Ask for a countersigned copy any time.

1. What this agreement covers and when it applies

  • Acceptance. By accepting the Terms, creating a workspace or using the Service, you accept this DPA on behalf of the organisation you represent. No separate signature is needed. If you want a countersigned copy for your records, see section 18.
  • What it covers. This DPA applies to the personal data in your workspace that we process on your behalf: the leads you import or collect, the messages sent and received through your senders, and the session data and mailbox tokens of the accounts you connect ("Customer Data"). It applies whether you use the Service through the app at app.growthxai.com, the API, the Chrome extension or the Claude connector.
  • What it does not cover. Personal data we hold as a controller, such as your account, billing, support and usage data and the details of the people you invite to your workspace, is covered by our Privacy Policy, not by this DPA.
  • Order of precedence. If this DPA conflicts with the Terms, this DPA prevails for the matters it covers. If the Standard Contractual Clauses in section 13 conflict with this DPA, the Clauses prevail. A signed order form or written agreement between us that expressly changes this DPA prevails over it for the matters it covers.
  • Duration. This DPA lasts for as long as we process Customer Data for you, including the export and deletion periods in section 14, whether or not the Terms have ended.

2. Definitions

"Personal data", "controller", "processor", "data subject", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. Under the DPDP Act, "controller" includes a data fiduciary and "processor" includes a data processor. Under US state privacy laws, "controller" includes a business and "processor" includes a service provider or contractor. In addition:

  • "Data Protection Laws" means every law that applies to the processing of Customer Data under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, the DPDP Act and applicable US state privacy laws.
  • "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission in Decision (EU) 2021/914, and the "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
  • "Sub-processor" means a third party we engage to process Customer Data on our behalf.
  • "Sender" means a LinkedIn account or mailbox connected to your workspace.
  • "Workspace Owner" means the person with the Owner role in your workspace, who is our contact for notices under this DPA.

3. Roles of the parties

  • You are the controller. You decide whose data goes into your workspace, whom to contact, what to say and when to stop. We do not choose your leads, write to them on our own initiative or use Customer Data for anything of our own.
  • We are the processor. We process Customer Data only to provide, secure and support the Service for you, as described in Annex 1 and as you instruct us through the Service.
  • Agencies and their clients. If you run outreach for clients, you may act as a processor for your client (who is then the controller) and we act as your sub-processor. In that case you confirm that your agreement with your client allows you to appoint us on the terms of this DPA, that you have your client's authorisation for the sub-processors in Annex 3, and that you will pass on any instructions or objections from your client. Your obligations to us under this DPA do not change.
  • Each of us complies with the law. Each party will comply with the Data Protection Laws that apply to it in its role.

4. Details of the processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.

5. Our obligations as your processor

We will:

  • Follow your instructions. Process Customer Data only on your documented instructions, including any transfer to a third country, unless the law we are subject to requires otherwise. In that case we will tell you before processing, unless the law forbids it on important grounds of public interest. Your instructions are the Terms, this DPA, the settings and actions you take in the Service (for example importing leads, scheduling a sequence, connecting a sender, switching on an AI step, exporting or deleting data) and any further written instructions you give us that are consistent with the Terms.
  • Tell you if an instruction is unlawful. If we believe an instruction breaches Data Protection Laws, we will tell you promptly. We may then pause the processing concerned until the instruction is changed or confirmed.
  • Keep it confidential. Make sure everyone we authorise to process Customer Data is bound by a duty of confidentiality, whether by contract or by law, and has access only to the extent their role needs it.
  • Not use it for ourselves. Not sell Customer Data, share it for advertising, combine it with data from other customers to build profiles or lists, or use it to train AI or machine-learning models. We may produce aggregated statistics that do not identify any person or customer, for example to size our infrastructure or report on the health of the Service as a whole.
  • Keep records. Maintain the records of processing that Article 30(2) of the GDPR requires, and make them available to you or a supervisory authority on request.
  • Point you to the right document. Meet the security, breach, assistance, sub-processor, transfer, audit and deletion obligations set out in sections 7 to 14.

6. Your obligations as controller

You are responsible for:

  • A lawful basis. Having a lawful basis to process every lead's personal data and to send them messages, and giving the notices the law requires. This includes the marketing rules that apply to you and to the people you contact, which may include the ePrivacy rules, PECR, CAN-SPAM and CASL.
  • The data you bring. The accuracy, quality and legality of Customer Data, and having the right to upload the lead lists you use.
  • Your instructions. Making sure your instructions to us comply with Data Protection Laws, and not instructing us to process special categories of personal data, data about children, or data whose processing would be unlawful in your hands.
  • Your senders. Having the permission of the owner of every sender you connect, as the Acceptable Use Policy requires.
  • Requests from the people you contact. Answering access, deletion and opt-out requests from data subjects, with our help under section 10.
  • Your team's access. Setting roles and client scopes appropriately, protecting logins and API keys, and removing people who no longer need access.

7. Sub-processors

  • General authorisation. You authorise us to engage the sub-processors listed in Annex 3, and, subject to this section, further sub-processors. The current list is also kept on our Security & trust page.
  • Notice of changes. Before we add or replace a sub-processor that will process Customer Data, we will give Workspace Owners at least 30 days' notice by email or in the Service, naming the sub-processor and what it will do. Where a change is needed urgently to keep the Service secure or running, we will notify you as soon as we can and explain why.
  • Your right to object. You may object in writing to privacy@growthxai.com within the notice period on reasonable grounds relating to data protection. We will then work with you in good faith to find a solution, such as a configuration change or an alternative provider. If we cannot, either of us may terminate the affected part of the Service, or the Terms as a whole if that part is essential, and we will refund the unused part of any prepaid period.
  • Same obligations, our responsibility. We will put each sub-processor under a written contract with data protection obligations that are no less protective than those in this DPA, and we remain fully responsible to you for each sub-processor's performance.
  • Your own AI provider is not our sub-processor. If you add your own Gemini, Anthropic or OpenAI key, that provider processes AI requests under your own agreement with them, and you are responsible for that relationship. See section 15.
  • The platforms you connect (LinkedIn, Google, Microsoft and other mailbox providers) receive the messages and actions you schedule as independent controllers under their own terms. They are not our sub-processors.

8. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, we will implement and maintain appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The measures we maintain today are described in Annex 2 and on the Security & trust page. We may update them from time to time, but not in a way that materially lowers the overall level of protection during the term.

You are responsible for the security of the parts you control: your team's logins, the roles and client scopes you set, your API keys, the devices your senders log in from, and the settings you choose in the Service.

9. Personal data breaches

  • Notice. If we become aware of a personal data breach affecting Customer Data, we will notify the Workspace Owner without undue delay, and in any case within 72 hours of confirming the breach, at the email address on the account.
  • What we tell you. As far as we know it at the time, and updated as we learn more: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point for more information.
  • Help with your obligations. We will give you the information you reasonably need to notify your supervisory authority and the data subjects, where the law requires you to. Whether and how you notify is your decision as controller.
  • Not an admission. Notifying you of a breach is not an admission of fault or liability by us.
  • Reporting to us. If you believe Customer Data has been compromised on your side, for example a leaked API key or a compromised login, tell us at once at security@growthxai.com so we can help contain it.

10. Helping with requests from data subjects

  • Tools first. The Service lets you find a person by name, email or profile URL, view and export everything held about them, correct their record, block them so nobody in your workspace contacts them again, and delete them. Use these to answer most requests yourself.
  • Requests that reach us. If a data subject contacts us about data in your workspace, we will not answer on your behalf. We will forward the request to you without undue delay and tell the person that you are the controller, unless the law requires us to act ourselves.
  • Further help. Where you cannot fulfil a request with the tools in the Service, we will give you reasonable assistance, taking into account the nature of the processing. We may charge a reasonable fee for assistance that goes well beyond what the Service provides.

11. Impact assessments and consultation

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with any data protection impact assessment and any prior consultation with a supervisory authority that Data Protection Laws require of you in relation to the Service. The information on this page, the Security & trust page and the Annexes are intended to answer most of what an assessment needs.

12. Audits and information

  • Information on request. We will make available the information reasonably necessary to demonstrate our compliance with this DPA, including written answers to your security questionnaire and the certifications and audit reports of our hosting providers, on a confidential basis.
  • Audits. You, or an independent auditor you appoint who is not our competitor and who is bound by confidentiality, may audit our compliance with this DPA once in any 12-month period, on at least 30 days' written notice, during business hours, at your cost and with minimal disruption to our operations. We will first answer in writing and with documentary evidence. An on-site or remote inspection follows only where that evidence is not enough to demonstrate compliance, or where a supervisory authority requires it.
  • After a breach. The once-a-year limit does not apply to an audit that follows a personal data breach affecting your Customer Data.
  • What we don't have yet. We do not currently hold SOC 2 or ISO 27001 certification. We say so rather than imply otherwise; the measures in Annex 2 are what we can evidence today.

13. International transfers

We are based in India. Your workspace data is hosted in the United States / Europe, and the sub-processors in Annex 3 process it in the regions stated there. Our staff may access Customer Data from India to support and operate the Service.

Where Customer Data protected by the GDPR, the UK GDPR or the Swiss FADP is transferred to a country that does not provide an adequate level of protection, the transfer is covered by one of the following, in this order of preference:

  • a decision that the destination country provides adequate protection (GDPR Article 45);
  • for providers certified under the EU-US Data Privacy Framework, its UK Extension or the Swiss-US DPF, that certification;
  • otherwise, the Standard Contractual Clauses, which are incorporated into this DPA by reference as follows.
  • Modules. Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you act as a processor for your clients.
  • Options. Clause 7 (docking) is included. Under Clause 9, Option 2 (general authorisation) applies with the notice period in section 7. The optional language in Clause 11 is not included. Under Clause 13, the supervisory authority of the EU member state where you are established (or where your representative is established) is competent. Under Clause 17, the Clauses are governed by the law of Ireland; under Clause 18, disputes are resolved by the courts of Ireland.
  • Annexes. Annex I of the SCCs is completed with the details in Annex 1 and the parties' details on this page; Annex II with Annex 2; and Annex III with Annex 3.
  • UK transfers. The UK Addendum applies to transfers from the United Kingdom, with Tables 1 to 3 completed with the information above and, in Table 4, either party able to end the Addendum as set out in section 19 of it.
  • Swiss transfers. For transfers from Switzerland, references in the SCCs to the GDPR are read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner is the competent authority and Swiss law governs, and "member state" includes Switzerland so that Swiss data subjects can enforce their rights in Switzerland.

Where Customer Data protected by the DPDP Act is transferred outside India, we do so in line with that Act and any restrictions notified by the Indian government. If a transfer mechanism we rely on is invalidated, we will work with you in good faith to put a replacement in place promptly.

14. Return and deletion of Customer Data

  • During the term. Owners and Managers can export leads, messages, actions and the audit log as CSV at any time, and can delete leads, senders and workspace data from within the Service. Disabling a sender with "Purge stored secrets" removes its stored session data or mailbox tokens.
  • When the Terms end. Your workspace stays readable for 30 days so you can export your data. We then delete Customer Data from our live systems within 90 days of the end of that period, and from backups in the ordinary course of their rotation, within a further 35 days. Stored sender session data and mailbox tokens are removed when the workspace is deleted at the latest.
  • Earlier on request. If you ask us to delete your workspace before the export period ends, we will do so, and the timings above run from your request.
  • Exceptions. We may keep Customer Data to the extent the law requires, or as needed to establish or defend legal claims, in which case we will keep it confidential and process it only for those purposes. We will confirm deletion in writing on request.

15. AI features

  • With our key. When you use an AI step (reply tagging, drafts, AI-written lines, routing), the lead and message text that step needs is sent to the AI provider named in Annex 3 under our agreement with them, which does not permit them to train on it. The provider is our sub-processor and this DPA applies.
  • With your own key. If you add your own Gemini, Anthropic or OpenAI key, the same text is sent to that provider under your own agreement with them. They are then your processor, not ours, and you are responsible for the terms you have accepted with them.
  • Human approval. AI-written lines are shown to you and sent only after a person in your workspace approves them. AI features never send anything on their own.
  • No training, no profiling. We do not use Customer Data to train or fine-tune any AI model, and the Service makes no decision about a data subject that produces legal or similarly significant effects for them.

16. United States state privacy laws

Where the CCPA or another US state privacy law applies to Customer Data, we act as your service provider or processor and this section applies in addition to the rest of this DPA. We will not:

  • sell or share Customer Data, in the sense those words have under the CCPA;
  • retain, use or disclose Customer Data for any purpose other than the business purposes set out in this DPA and the Terms, or outside our direct business relationship with you;
  • combine Customer Data with personal data we receive from anyone else, except as those laws permit a service provider to do.

We will comply with the obligations that apply to service providers and give the same level of protection those laws require. We will tell you if we can no longer meet these obligations, and you may take reasonable steps to stop and remedy unauthorised use of Customer Data. We certify that we understand and will comply with these restrictions.

17. Liability, changes and governing law

  • Liability. Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms, except where Data Protection Laws or the SCCs do not allow them to be limited.
  • Changes. We may update this DPA to reflect changes in the law, in our providers or in the Service. The new version applies from the "Last updated" date at the top. For changes that reduce your rights or our obligations we will notify Workspace Owners at least 30 days in advance by email or in the Service. If you do not accept a change, you may terminate the Terms before it takes effect and we will refund the unused part of any prepaid period.
  • Governing law. This DPA is governed by the laws of India and the courts at Jaipur, Rajasthan, India have exclusive jurisdiction, as set out in the Terms, except that the SCCs and the UK Addendum are governed by the law and courts stated in section 13, and nothing in this section limits a data subject's rights under Data Protection Laws.
  • Severability. If any part of this DPA is found invalid, the rest continues in force and the invalid part is replaced by a valid one that comes as close as possible to its intent.

18. Getting a signed copy, and contact

This DPA applies automatically, so most customers do not need to do anything. If your organisation's process needs a countersigned document, email privacy@growthxai.com from the Workspace Owner's address with your legal entity name and address, and we will return a signed PDF of this DPA. We do not negotiate changes to this DPA on self-serve plans. If your organisation must use its own template, tell us what you need and we will look at it.

DPA and privacy questions: privacy@growthxai.com
Security incidents: security@growthxai.com
General support: hello@growthxai.com
Post: ResourcePlan Solution Private Limited, CIN U62013RJ2023PTC090277, 45-46, Shiv Marg, Guru Jhambeshwar Nagar A, Block E, Vaishali Nagar, Jaipur, Rajasthan 302021, India

Annex 1: Details of the processing

Subject matterThe personal data in your workspace that we process to provide the Service.
DurationThe term of the Terms, plus the export and deletion periods in section 14.
Nature of the processingCollection (importing leads from files, CRMs, LinkedIn searches and post engagement, and enrichment you switch on), storage, organisation, retrieval, use, transmission (sending the connection requests, messages and emails you schedule and receiving replies), analysis by AI steps you switch on, display in the inbox and reports, export, erasure.
PurposeRunning the LinkedIn and email outreach you configure, keeping each lead's record and timeline, managing replies, keeping your senders within safe limits, reporting on results, and supporting you. Nothing else.
Types of personal data
  • Leads and contacts: name, job title, company, location, LinkedIn profile URL and public profile data, email address, phone number where you add it, custom fields, tags, stage and notes you record.
  • Messages: the content and metadata of connection requests, LinkedIn messages and emails sent and received through your senders, and each lead's timeline.
  • Sender data: the name, profile URL and email address of each connected account, its encrypted LinkedIn session data or mailbox OAuth tokens or IMAP/SMTP details, proxy country, limits and health.
  • Client data (agencies): client names, contacts and the leads and senders assigned to them.
  • Activity data: planned and executed actions, replies and their AI tags, tasks, and the workspace audit log.
Special categories of personal data are not intended to be processed and you must not upload them.
Categories of data subjectsThe leads and contacts you import or collect and the people you correspond with; the owners of the senders you connect; your team members and contractors; your clients' staff and, where you act for clients, your clients' leads.
FrequencyContinuous, for as long as the workspace is active.
RetentionAs set out in section 14.
Transfers to sub-processorsAs set out in Annex 3, for the purposes stated there and for the duration of the processing.

Annex 2: Technical and organisational measures

The measures below are those in place on the "Last updated" date. The Security & trust page is kept current between DPA revisions and says plainly what we do not yet have.

AreaMeasures
Encryption in transitThe app, the API, the Chrome extension and the Claude connector communicate over HTTPS (TLS). Connections to sub-processors are encrypted.
Encryption at rest and of secretsDatabases and backups are encrypted at rest by our hosting provider. LinkedIn session data, mailbox OAuth tokens and IMAP/SMTP credentials are additionally encrypted before storage. API keys are stored only as a hash. Customer-supplied AI keys are kept write-only.
Tenant isolationCustomer Data is separated by workspace, and within a workspace by client, using row-level security in the database. The same rules are enforced in the app, on the server, in the API and in the Claude connector.
Access control for your teamFour roles (Owner, Manager, Member, Client viewer) with client scoping. API keys act as the member who created them, never as Owner, and lose rights when that member does. Sign-in with Google or Microsoft is supported.
Credentials never sharedLinkedIn passwords are never given to us: the account owner logs in through a hosted page on their own device. Gmail and Outlook connect through OAuth. Disabling a sender with "Purge stored secrets" removes its stored session data.
Access by our staffAccess to production systems is limited to staff who need it to operate and support the Service, under confidentiality obligations, with individual accounts and multi-factor authentication on provider consoles. Access is removed when a role ends.
Logging and monitoringEvery change in a workspace, including exports, is recorded in an audit log that Owners and Managers can read and export. Application and infrastructure logs are retained for 12 months for security and troubleshooting.
Availability and backupsData is hosted with a provider that offers redundant storage and automated backups. Backups rotate on a 35-day cycle. Senders pause rather than lose state when a payment fails or a session expires.
Secure developmentChanges are reviewed and deployed through version control. Dependencies are kept up to date. Vulnerability reports are accepted at the security address and via /.well-known/security.txt.
Incident responseA documented process to detect, contain, assess and notify personal data breaches, with the notice commitment in section 9.
Sub-processor managementEach sub-processor is under a written data processing contract and is reviewed before engagement; the list and regions in Annex 3 are kept current.
Data minimisation and deletionThe Service stores only the fields needed to run outreach and the fields you add. Export and deletion tools are available in the Service, and the deletion periods in section 14 are applied when a workspace closes.
CertificationsNone held by us yet (no SOC 2 or ISO 27001). Our hosting and infrastructure providers hold their own certifications, which we can share on request.

Annex 3: Sub-processors

Authorised sub-processors as at 24 September 2026. The same list is on the Security & trust page. Changes follow section 7.

Sub-processorPurposeData involvedLocation
SupabaseDatabase, storage and back-end functionsAll workspace dataUnited States / Europe
StripePayments and billingBilling contact and payment detailsUnited States / Europe
ResendThe product's own emails to you and your team (not your outreach)Recipient email address, message contentUnited States / Europe
Google (Gemini)AI reply tagging, drafts, AI lines and routing, with our keyThe lead and message text the AI step needsUnited States / Europe
Proxy providersA dedicated proxy in the account owner's country for each LinkedIn senderLinkedIn traffic for that senderThe sender's own country

Not sub-processors: your own AI provider (if you add your own key), and the platforms you connect (LinkedIn, Google, Microsoft and other mailbox providers), which act as independent controllers. See sections 7 and 15.

Your next customers are already on LinkedIn.

Start booking meetings this week. Free for 14 days with up to 3 LinkedIn accounts, no card.

14 days free · 3 LinkedIn accounts · no card

  • Cancel any time in the billing portal
  • Nothing deleted if a payment fails
  • Teammates are free