Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA”) forms part of the agreement between GROWKINS (“Processor”) and the client (“Controller”) where GROWKINS processes personal data on behalf of the Controller in connection with the services provided.

This DPA is intended to support compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable privacy legislation where relevant.

1. Purpose

The purpose of this Agreement is to define the responsibilities of both parties regarding the processing of personal data while GROWKINS delivers its services.

This DPA applies whenever GROWKINS processes personal data on behalf of a client.

2. Definitions

For the purposes of this Agreement:

Controller means the organization that determines the purposes and means of processing personal data.

Processor means GROWKINS, which processes personal data on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person.

Processing includes collecting, storing, organizing, accessing, using, transferring, or deleting personal data.

Data Subject means the individual whose personal data is processed.

3. Scope of Processing

GROWKINS processes personal data solely for the purpose of delivering the agreed services, which may include:

  • Lead Generation
  • Appointment Setting
  • SDR as a Service
  • Outbound Sales
  • Cold Email Outreach
  • LinkedIn Outreach
  • Account-Based Marketing
  • CRM Management
  • Campaign Reporting

Processing activities are limited to those necessary to perform contractual obligations.

4. Categories of Personal Data

  • Depending on the services provided, GROWKINS may process business-related personal data including:

    • Name
    • Business Email Address
    • Job Title
    • Company Name
    • Business Phone Number
    • LinkedIn Profile Information
    • Company Information
    • Communication History
    • CRM Records
    • Campaign Activity Data

    GROWKINS does not intentionally collect special categories of personal data unless expressly agreed in writing and permitted by applicable law.

5. Categories of Data Subjects

Personal data processed under this Agreement may relate to:

  • Business Executives
  • Decision Makers
  • Sales Leaders
  • Marketing Leaders
  • Procurement Teams
  • Existing Customers
  • Prospective Customers
  • Employees of Client Organizations

6. Processor Obligations

GROWKINS agrees to:

  • Process personal data only on documented instructions from the Controller.
  • Process data solely for the agreed business purposes.
  • Maintain appropriate technical and organizational security measures.
  • Ensure personnel handling personal data are subject to confidentiality obligations.
  • Assist the Controller, where reasonably possible, in meeting applicable data protection obligations.
  • Notify the Controller without undue delay after becoming aware of a confirmed personal data breach affecting processed data.

7. Controller Obligations

The Controller is responsible for:

  • Ensuring a lawful basis for processing personal data.
  • Providing appropriate privacy notices where required.
  • Obtaining any necessary consents.
  • Ensuring the accuracy of provided data.
  • Complying with applicable data protection laws.

The Controller remains responsible for determining the purposes and legal basis of processing.

8. Security Measures

GROWKINS may engage trusted third-party service providers to support service delivery, including providers of:

  • Cloud Infrastructure
  • CRM Systems
  • Sales Engagement Platforms
  • Analytics Services
  • Communication Tools
  • Project Management Software
  • Data Storage
  • Security Services

GROWKINS remains responsible for ensuring that subprocessors are contractually required to provide appropriate data protection safeguards.

9. Subprocessors

GROWKINS may engage trusted third-party service providers to support service delivery, including providers of:

  • Cloud Infrastructure
  • CRM Systems
  • Sales Engagement Platforms
  • Analytics Services
  • Communication Tools
  • Project Management Software
  • Data Storage
  • Security Services

GROWKINS remains responsible for ensuring that subprocessors are contractually required to provide appropriate data protection safeguards.

10. International Data Transfers

Where personal data is transferred internationally, GROWKINS will implement appropriate safeguards as required by applicable law, including contractual protections where appropriate.

11. Data Subject Rights

Where applicable, GROWKINS will reasonably assist the Controller in responding to requests relating to:

  • Access
  • Rectification
  • Erasure
  • Restriction of Processing
  • Data Portability
  • Objection to Processing

GROWKINS will promptly notify the Controller if it receives a request directly from a data subject concerning data processed on the Controller’s behalf, unless prohibited by law.

12. Data Breach Notification

If GROWKINS becomes aware of a confirmed personal data breach affecting personal data processed under this Agreement, GROWKINS will notify the Controller without undue delay and provide available information reasonably necessary to support the Controller’s response obligations.

13. Data Retention & Deletion

GROWKINS retains personal data only for as long as necessary to:

  • Deliver contracted services
  • Meet legal obligations
  • Resolve disputes
  • Enforce contractual rights

Upon termination of services and subject to legal or contractual retention requirements, GROWKINS will delete or return personal data as agreed with the Controller.

14. Confidentiality

GROWKINS will ensure that employees, contractors, and authorized personnel with access to personal data are bound by appropriate confidentiality obligations.

Access to personal data is limited to individuals who require it to perform their duties.

15. Audits & Information

Where reasonably required and subject to appropriate confidentiality protections, GROWKINS will provide information necessary to demonstrate compliance with this Agreement.

Any audits shall be conducted at mutually agreed times in a manner that minimizes disruption to business operations.

16. Liability

Each party remains responsible for its own compliance with applicable data protection laws.

Liability relating to data processing is governed by the applicable service agreement unless otherwise required by law.

17. Term & Termination

This DPA remains in effect for as long as GROWKINS processes personal data on behalf of the Controller under the applicable service agreement.

Termination of the underlying agreement automatically terminates this DPA, except for obligations that survive by law or by their nature.

18. Contact

Questions regarding this Data Processing Agreement or GROWKINS’ data processing practices may be directed through the contact information provided on our Contact page.

Our Commitment

GROWKINS is committed to processing personal data responsibly, securely, and transparently.

We recognize that trust is essential to every business relationship and continually work to maintain high standards of privacy, information security, and regulatory compliance while delivering exceptional revenue growth services.