Data Processing Agreement
Data Processing Agreement.
Last updated: 2 July 2026
Need a signed copy (including the full text of the SCCs, UK Addendum, and Sub-Processors)? Please reach out to help@1close.ai.
This 1Close AI Data Processing Agreement and its Annexes ("DPA") is incorporated into and forms part of the 1Close AI Customer Terms of Service between you and us (the "Agreement"). This DPA reflects the parties' agreement with respect to (i) the Processing of Customer Personal Data by us as a Processor on your behalf, and (ii) the Processing of Controller Personal Data by each party as a Controller in connection with our enrichment products and your use of the 1Close AI tracking code.
In case of any conflict or inconsistency with other terms included in the Agreement, this DPA will take precedence to the extent of such conflict or inconsistency.
The Controller-to-Processor terms apply solely to the extent that 1Close AI is a Processor of Customer Personal Data in connection with the Subscription Services.
We update these terms from time to time. If you have an active 1Close AI subscription, we will let you know when we do through an in-app notice (or via email if you have subscribed to receive email notifications via the link in our General Terms).
The term of this DPA will follow the term of the Agreement. Terms not otherwise defined in this DPA will have the meaning as set forth in the Agreement.
1. Definitions and interpretation
The following definitions and rules of interpretation apply in this DPA.
1.1 Definitions
Controller: means an entity that alone or jointly with others determines the purposes and means of Processing of Personal Data. For purposes of this DPA, a Controller includes a "business" as such term is defined by the CCPA/CPRA, or a similar designation under Data Protection Legislation.
Customer Personal Data: means any Personal Data that Supplier Processes as a Processor on behalf of Customer, as more particularly described in Annex A of this DPA.
Data Protection Legislation: means all data protection and privacy laws and regulations enacted in Europe and applicable (in whole or in part) to the respective Party's processing of Personal Data including (as applicable) (i) EU Regulation 2016/679 (General Data Protection Regulation) ("EU GDPR"); (ii) EU e-Privacy Directive (Directive 2002/58/EC); (iii) any national data protection laws made under or pursuant to (i) or (ii); and (iv) in respect of the UK, the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any other laws in force in the UK applicable to the processing of Personal Data (together, "UK Data Protection Law"); (v) the US Data Protection Legislation; and (vi) the Swiss Federal Data Protection Act and its implementing regulations ("Swiss DPA"); in each case as may be amended, superseded or replaced from time to time.
EEA: the European Economic Area.
Europe: for the purposes of this DPA, the European Economic Area and/or its member states ("EEA"), the United Kingdom ("UK") and/or Switzerland.
Permitted Affiliate: means any Affiliate of Customer which: (i) is subject to Data Protection Legislation and the Controller with respect to the Personal Data; and (ii) is permitted to use the Services pursuant to the Agreement, but has not signed its own Order with Supplier and is not a "Customer" as defined under the Agreement.
Personal Data: means all information relating to an identified or identifiable natural person or consumer ("Data Subject"), including any data or information that is deemed "personal data", "personally identifiable information" and/or "personal information" under Data Protection Legislation.
Processing, processes, processed, process: means any operation or set of operations which is performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, destruction, or creating information from, Personal Data.
Processor: means an entity that Processes Personal Data on behalf of, and in accordance with the instructions of, a Controller. For purposes of this DPA, a Processor includes a "service provider" as such term is defined by the CCPA/CPRA, or any similar or analogous designation under Data Protection Legislation.
Restricted Transfer: means a transfer (directly or via onward transfer) of Personal Data that is subject to Data Protection Legislation to a country outside Europe which is not subject to an adequacy determination by the European Commission, United Kingdom or Swiss authorities (as applicable).
Security Incident: means any actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data processed by Supplier and/or its Subprocessors.
Standard Contractual Clauses: means the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
Subprocessor: means any third party appointed by Supplier to process Customer Personal Data in connection with the provision of Services. Subprocessors may include Supplier Affiliates but shall exclude Supplier employees, contractors and consultants.
Supervisory Authority: means any regulatory, supervisory, governmental, state agency, Attorney General or other competent authority with jurisdiction or oversight over compliance with Data Protection Legislation.
UK Addendum: means the International Data Transfer Addendum to the Standard Contractual Clauses (version B1.0) issued by Information Commissioners Office under S.119(A) of the UK Data Protection Act 2018, as it is revised under Section 18 therein; as may be amended, superseded or replaced from time to time.
US Data Protection Legislation: means all privacy laws and regulations applicable in the United States, including the California Consumer Privacy Act (the "CCPA"), as amended by the California Privacy Rights Act ("CPRA") when effective, as well as any regulations and guidance that may be issued thereunder; and, where applicable, the Virginia Consumer Data Protection Act ("CDPA"), the Colorado Privacy Act ("CPA"), the Utah Consumer Privacy Act ("UCPA"), and the Connecticut Data Privacy Act ("CTDPA"); in each case as may be amended or superseded from time to time.
2. Scope and applicability
The Parties agree that in connection with the Services, the Customer is the Controller of the Customer Personal Data and Supplier shall Process Customer Personal Data as a Processor on behalf of Customer, except where Supplier acts as a Controller Processing Customer Personal Data in accordance with the legitimate business purposes identified in Section 4. Each Party shall process Customer Personal Data under this Agreement in accordance with and as permitted by the Agreement and Data Protection Legislation. Each Party will reasonably cooperate with the other in any activities contemplated by this DPA and to help enable each Party to comply with its respective obligations under Data Protection Legislation.
3. Processor terms
3.1 Customer responsibilities
Customer is responsible for the accuracy, quality and legality of the Customer Personal Data. Customer warrants and represents to Supplier that it has provided notice and obtained all consents, permissions and rights necessary for Supplier and its Subprocessors to lawfully process Customer Personal Data for the purposes contemplated by the Agreement (including this DPA). Should the Customer provide Customer Personal Data to the Supplier that was not requested by the Supplier, the Customer shall indemnify and hold harmless the Supplier from and against any data protection breach of said Customer Personal Data.
3.2 Processing instructions
Customer as Controller instructs Supplier to Process Customer Personal Data as a Processor for the purposes described below:
- Provide and update the Services as configured and used by Customer and its Authorised Users, including to make ongoing product improvements and personalise the Services;
- Operate enrichment products within the Subscription Services as configured and used by Customer on Customer's instruction;
- Secure and real-time monitor the Services (including but not limited to resolving issues, bugs and errors); and
- Provide Customer support, including applying knowledge gained from individual customer support requests to benefit all Supplier customers but only to the extent such knowledge is anonymised.
The Parties agree that the Agreement, along with Customer's configuration of any settings or options in the Services and any other documented instruction provided by Customer and acknowledged by Supplier as constituting instructions for purposes of this DPA, set out the Customer's complete and final instructions to Supplier in relation to the Processing of Customer Personal Data (including for the purposes of Standard Contractual Clauses). If Supplier believes that an instruction violates Data Protection Legislation, Supplier shall promptly inform Customer, unless the relevant applicable law prohibits this, and request that Customer withdraw, amend, or confirm the instruction. Pending the decision on the withdrawal, amendment, or confirmation of the instruction, Supplier shall be entitled to suspend the implementation of the instruction. Customer acknowledges that it is Customer's responsibility to ensure its instructions comply with Data Protection Legislation.
4. Controller terms
4.1 Purposes
Supplier may Process certain Customer Personal Data as an independent Controller solely when the Processing is strictly necessary and proportionate, and if the Processing is for one of the following purposes:
Directly identifiable data (such as name and email address, and all Customer Personal Data directly connected to such directly identifiable data) may be Processed for: (i) billing, account, and Customer relationship management (marketing communications to procurement, sales, and other Customer personnel that request such communication), and related Customer correspondence (e.g., necessary updates); (ii) securing the Services (including but not limited to detect, prevent, and investigate fraud, spam, or unlawful use of the Services); or (iii) complying with legal obligations under applicable laws, including responding to Data Subject Requests for Personal Data Processed by Supplier as a Controller (for example website data), tax requirements, and disputes.
Anonymised and/or aggregated data (Supplier will anonymise and/or aggregate as much as possible and pseudonymised and/or aggregated data will not be Processed on a per-Customer level), for: (i) improving and optimising the performance and core functionalities of the Services; (ii) internal reporting, financial reporting, revenue planning, capacity planning, and forecast modelling (including product strategy and statistical analysis purposes for Supplier's global benchmarks); and (iii) receiving and using Feedback for Supplier's service improvement.
Supplier shall only Process Customer Personal Data for the purposes specified in this DPA; provided, however, that Supplier may Process Customer Personal Data for "further" or "compatible" purposes (within the meaning of Articles 5(1)(b) and 6(4) EU and UK GDPR) or seek consent from Data Subjects for new types of Processing, where permitted by Data Protection Legislation.
4.2 Compliance with law
Each Party shall be individually and separately responsible for complying with the obligations that apply to it as a Controller under Data Protection Legislation and neither Party shall be responsible for the other Party's compliance with Data Protection Legislation. In particular, each Party shall be individually responsible for ensuring that its Processing of Personal Data is lawful, fair and transparent, and shall make available to Data Subjects a privacy notice that fulfils the requirements of Data Protection Legislation.
5. Supplier's personnel
Supplier shall ensure that its personnel that is authorised to process Customer Personal Data is subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
6. Security
The Supplier shall implement and maintain appropriate technical and organizational security measures as required by Data Protection Legislation to protect the Customer Personal Data from Security Incidents and to preserve the security and confidentiality of the Customer Personal Data, including those set out in Annex B to this DPA ("Security Measures"). Customer acknowledges that the Security Measures are subject to technical progress and development and that Supplier may update or modify its Security Measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by Customer.
7. Security incident
Upon becoming aware of a Security Incident affecting Customer Personal Data, Supplier shall notify Customer without undue delay and shall provide Customer with timely information as it becomes known or as is reasonably requested by Customer to allow it to meet any obligations to report or inform supervisory authorities, Data Subjects and other entities of such Security Incident under Data Protection Legislation. Supplier shall take appropriate and reasonable steps to contain, investigate and mitigate the Security Incident.
8. Law enforcement requests
If a law enforcement agency sends Supplier a demand for Customer Personal Data (for example, through a subpoena or court order), Supplier will attempt to redirect the law enforcement agency to request that Customer Personal Data directly from Customer. As part of this effort, Supplier may provide Customer's basic contact information to the law enforcement agency. If compelled to disclose Customer Personal Data to a law enforcement agency, then Supplier will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless Supplier is legally prohibited from doing so.
9. International transfers
9.1 Processing locations
Customer acknowledges and agrees that Supplier may transfer and process Personal Data to and in the United States and other locations in which Supplier, its affiliates or its Subprocessors maintain Processing operations, as more particularly described in Annex C. Supplier shall at all times ensure such transfers are made in compliance with the requirements of Data Protection Legislation.
9.2 Application of Standard Contractual Clauses
Where a transfer of Personal Data from Customer (as a "data exporter") to Supplier (as a "data importer") under this DPA is a Restricted Transfer and Data Protection Legislation requires that appropriate safeguards are put in place, such transfers shall be subject to the Standard Contractual Clauses, which shall be deemed incorporated into and form part of the DPA, as follows:
EEA Restricted Transfers (Processors): In relation to Restricted Transfers of Customer Personal Data protected by the EU GDPR, the Standard Contractual Clauses shall apply, completed as follows:
- Module Two (Controller to Processor) will apply;
- in Clause 7, the optional docking clause will apply;
- in Clause 9, Option 2 will apply, and the time period for prior notice of Subprocessor changes shall be 10 days;
- in Clause 11, the optional language will not apply;
- in Clause 17, Option 1 will apply, and the Standard Contractual Clauses will be governed by Irish law;
- in Clause 18(b), disputes shall be resolved before the courts of Ireland;
- Annex I of the Standard Contractual Clauses shall be deemed completed with the information set out in Annex A to this DPA (as applicable to the Restricted Transfer in question);
- Annex II of the Standard Contractual Clauses shall be deemed completed with the information set out in Annex B to this DPA (as applicable to the Restricted Transfer in question).
EEA Restricted Transfers (Controller): In relation to Restricted Transfers of Customer Personal Data protected by the EU GDPR, the Standard Contractual Clauses shall apply, completed as follows:
- Module One (Controller to Controller) will apply;
- in Clause 7, the optional docking clause will apply;
- in Clause 11, the optional language will not apply;
- in Clause 17, Option 1 will apply, and the Standard Contractual Clauses will be governed by Irish law;
- in Clause 18(b), disputes shall be resolved before the courts of Ireland;
- Annex I of the Standard Contractual Clauses shall be deemed completed with the information set out in Annex A to this DPA (as applicable to the Restricted Transfer in question); and
- Annex II of the Standard Contractual Clauses shall be deemed completed with the information set out in Annex B to this DPA.
UK Transfers: In relation to transfers of Customer Personal Data that are protected by UK Data Protection Law, the Standard Contractual Clauses:
- shall apply as completed in accordance with the paragraphs above; and
- shall be deemed amended as specified by the UK Addendum, which shall be deemed executed by the Parties and incorporated into and form an integral part of this DPA.
Any conflict between the terms of the Standard Contractual Clauses and the UK Addendum shall be resolved in accordance with Section 10 and Section 11 of the UK Addendum. In addition, tables 1 to 3 in Part 1 of the UK Addendum shall be completed respectively with the information set out in Annexes A and B of this DPA and table 4 in Part 1 shall be deemed completed by selecting "neither party".
9.3 Conflicts
It is not the intention of either Party to contradict or restrict any of the provisions set forth in the Standard Contractual Clauses and, accordingly, if and to the extent the Standard Contractual Clauses conflict with any provision of the DPA, the Standard Contractual Clauses shall prevail to the extent of such conflict.
9.4 Alternative transfer arrangements
To the extent the Supplier adopts an alternative recognised lawful mechanism for the transfer of Personal Data not described in this DPA ("Alternative Transfer Mechanism"), the Alternative Transfer Mechanism shall apply instead of any applicable transfer mechanism described in this DPA (but only to the extent such Alternative Transfer Mechanism complies with Data Protection Legislation and extends to the territories to which Personal Data is transferred).
10. Complaints, data subject requests and third-party rights
The Supplier must, at no additional cost to the Customer, take such technical and organisational measures as may be appropriate, and promptly provide such information to the Customer as the Customer may reasonably require, to enable the Customer to comply with:
- the rights of Data Subjects under the Data Protection Legislation, including, but not limited to, subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data; and
- information or assessment notices served on the Customer by the Commissioner (or other relevant regulator) under the Data Protection Legislation.
Supplier will promptly notify Customer if Supplier receives any such request related to the processing of Customer Personal Data under the Agreement. Supplier will not respond to such complaints, inquiries and/or requests except on the documented instructions of Customer, unless legally compelled to do so. Supplier will provide Customer with reasonable cooperation, assistance and information to assist Customer in responding to such requests.
11. Subprocessors
Customer provides a general prior authorisation for Supplier to engage Subprocessors to process Customer Personal Data on Customer's behalf. The Subprocessors currently engaged by Supplier are set out in Annex C of this DPA (or at https://1close.ai/privacy Section 9, as may be updated from time to time) ("Subprocessor List"). Supplier shall notify Customer if it makes any changes to its Subprocessor List at least ten (10) calendar days prior to any such change in accordance with the mechanism used by Supplier. Customer may object in writing to Supplier's appointment of a new Subprocessor on reasonable grounds relating to data protection by notifying Supplier promptly in writing within ten (10) calendar days of receipt of any Supplier's notice and the Parties shall discuss Customer concerns in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, Supplier will, at its sole discretion, either (i) not appoint the Subprocessor; or (ii) permit Customer to suspend or terminate the affected Services in accordance with the termination provisions in the Agreement without liability to either Party (but without prejudice to any fees incurred by Customer prior to suspension or termination). Supplier will enter into a written agreement with each Subprocessor imposing data protection obligations no less protective of Customer Personal Data than those set out in this DPA, to the extent applicable to the nature of the services provided by such Subprocessor. Supplier will remain responsible for any acts or omissions of its Subprocessors that cause Supplier to breach any of its obligations under this DPA.
12. Permitted affiliates
When a Permitted Affiliate becomes a party to the DPA, then such Permitted Affiliate shall be entitled to exercise its rights and remedies available under this DPA to the extent required under Data Protection Legislation. However, if Data Protection Legislation requires the Permitted Affiliate to directly exercise a right or remedy against Supplier directly by itself, the Parties agree that to the extent permitted under law: (i) only the Customer that is the contracting entity to the Agreement shall exercise any such right or seek any such remedy on behalf of the Permitted Affiliate; and (ii) the Customer that is the contracting party to the DPA shall exercise any such rights under this DPA in a combined manner for all of its Permitted Affiliates together, instead of doing so separately for each Permitted Affiliate. The Customer that is the contracting entity is responsible for coordinating all communication with Supplier under the DPA and be entitled to make and receive any communication related to this DPA on behalf of its Permitted Affiliates.
13. Sale and use restrictions
For the purposes of US Data Protection Legislation (to the extent applicable), Supplier shall not (a) sell Customer Personal Data, as the term "sell" is defined by US Data Protection Legislation, (b) share Customer Personal Data, as the term "share" is defined by the CPRA, (c) disclose or transfer Customer Personal Data to a Subprocessor or any other parties that would constitute "selling" as the term is defined by US Data Protection Legislation or "sharing" as the term is defined by the CPRA, and (d) unless otherwise permitted by US Data Protection Legislation, retain, use, disclose, or otherwise Process the Customer Personal Data for any purposes other than the business purposes described in this DPA.
14. Data return and destruction
Customer may, by written notice to Supplier, require Supplier within 30 (thirty) days of the date of cessation of any Services involving the Processing of Customer Data to enable Customer to download all copies of Customer Personal Data in the control or possession of Supplier and Subprocessors. Supplier may retain some or all Customer Personal Data and Customer Data to the extent required by Applicable Laws or to the extent the Customer Personal Data or Customer Data is archived on back-up systems and provided that Supplier continues protecting such Customer Personal Data and Customer Data in accordance with the Agreement and only processes such Customer Personal Data and Customer Data as necessary for the purposes specified in Applicable Laws requiring its storage and for no other purpose. All other Customer Data shall be deleted or anonymised within 30 (thirty) days of the termination or expiry of this Agreement in accordance with Supplier's data destruction policies. Provided, however, that nothing contained herein shall preclude Supplier from using anonymised data obtained from Personal Data and Customer Data for the purpose of data compilation, research and product improvement including to develop, train, refine and improve its artificial intelligence and machine learning models, scoring algorithms, features and methodologies, statistical analyses, and Customer acknowledges that notwithstanding the termination of this Agreement, non-attributable irrevocably anonymised aggregated data will persist in Supplier's global benchmarks and scoring models.
15. Data retention
Retention periods for Customer Personal Data are as set out in the Supplier's Global Privacy Policy (Section 11 — Data retention) and the Data Return and Destruction clause (Section 14) of this DPA. Customer Personal Data processed on behalf of Customer as Processor is retained for the duration of the Agreement and deleted or returned per Section 14 unless Applicable Law requires longer retention.
16. Records and audits
Upon Customer's written request, Supplier shall, no more than annually and on reasonable notice, provide Customer (on a confidential basis) written responses to all reasonable written requests for information made by Customer related to its Processing of Customer Personal Data (including responses to information security and audit questionnaires that are strictly necessary to confirm Supplier's compliance with this DPA), in accordance with Data Protection Legislation.
17. Miscellaneous
Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect.
This DPA shall be deemed a part of and incorporated into the Agreement so that references in the Agreement to "Agreement" shall be interpreted to include this DPA.
Customer acknowledges that Supplier may disclose this DPA (including the Standard Contractual Clauses and UK Addendum) and any relevant privacy provisions in the Agreement to European data protection authority, the US Department of Commerce, the Federal Trade Commission, or any other US or European judicial or regulatory body upon their request.
Notwithstanding anything to the contrary in the Agreement, Supplier may periodically make modifications to this DPA as may be required to comply with Data Protection Legislation.
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by the Standard Contractual Clauses, the UK Addendum or Data Protection Legislation.
Annex A — Standard Contractual Clauses particulars
As agreed between the Parties:
The Supplier shall comply with any further written instructions with respect to processing by the Customer. Any such further instructions shall be incorporated into this Annex A.
| Details | |
|---|---|
| Data Exporter | |
| Name | The entity identified as the Customer in the Agreement |
| Address | The Customer's address as identified in the Agreement |
| Contact | The Customer's contact details, as set out in the Order Form and/or as set out in the Customer's 1Close AI account |
| Activities | See Annex A.1 and A.2 below |
| Role | Controller |
| Data Importer | |
| Name | The entity identified as the Supplier in the Agreement (1Close AI Limited) |
| Address | 66 Paul Street, London, England, EC2A 4NE |
| Contact | George Tritton-Price, Director |
| Activities | See Annex A.1 and A.2 below |
| Role | Processor and Controller |
The Parties' execution of this DPA shall constitute execution of the Standard Contractual Clauses by both Parties.
Annex A.1 — Description of processing/transfer (Processor)
| Field | Detail |
|---|---|
| Categories of Data Subjects | Employees, contractors, vendors, business partners or other individuals whose Personal Data is provided to Supplier under the Agreement |
| Frequency of transfer | One-off, otherwise continuous |
| Nature and purposes | The provision of the Services and enrichment products as described in the Agreement and initiated by the Customer from time to time; see Section 3.2 of this DPA |
| Subject matter | Customer Personal Data |
| Categories of Personal Data | Identification and contact information (name, employer, job title, email, phone, physical business address); access/authorisation data (username and password); user profile data including performance trends, strengths and weaknesses and recurring patterns; biometric data (facial images and voice recordings uploaded by the user) |
| Retention period | See Section 15 of this DPA and Privacy Policy Section 11 |
| Sensitive data | Customer Personal Data may include biometric data (voice recordings and related call artefacts) as described above |
For transfers to (sub-)processors: subject matter, nature and duration in line with the information above.
Annex A.2 — Description of processing/transfer (Controller)
| Field | Detail |
|---|---|
| Categories of Data Subjects | Employees, contractors, business partners or other individuals whose Personal Data is provided to Supplier under the Agreement |
| Categories of Personal Data | Identification and contact information; access/authorisation data; usage data (feedback, service performance, utilisation of the Services) |
| Sensitive data | Supplier does not collect or Process special category or sensitive data as part of its controller role |
| Frequency | One-off, otherwise continuous when using the Services |
| Subject matter | Customer Personal Data |
| Nature of processing | The purposes contemplated below |
| Purposes | (a) review and ensure proper working of the Services and enrichment products; (b) maintain and improve the Services and Supplier's business (including data compilation, statistical analysis, benchmarking, research and product improvement, including to develop, train, refine and improve AI/ML models, scoring algorithms, features and methodologies for Supplier's benchmarks); (c) detect, prevent, and investigate fraud, spam, or unlawful use; (d) comply with legal obligations; (e) marketing purposes |
Annex A.3 — Competent supervisory authority
The data exporter's competent supervisory authority will be determined in accordance with Data Protection Legislation.
Annex B — Technical and organisational security measures
Description of the technical and organisational measures implemented by the Supplier to ensure an appropriate level of security.
| Type of measure | Description |
|---|---|
| Pseudonymisation and encryption | Employee laptops encrypted (AES-256 full disk). HTTPS on all web login interfaces. OAuth integration tokens encrypted at column level via pgcrypto (PostgreSQL). |
| Confidentiality, integrity, availability | Multi-tenant isolation. Access controls based on least privilege. |
| Restore availability | Automated daily backups with 7-day point-in-time recovery. Documented incident response plan. |
| Testing and evaluation | Annual penetration tests. Security incident management policies and procedures. |
| User identification and authorisation | Google OAuth and magic-link authentication via Supabase Auth. No password storage. Service-role keys server-only; public client uses anon key with Row-Level Security as the trust boundary. |
| Data in transmission | TLS 1.3 on customer-facing endpoints. HSTS headers. Webhook payloads verified with HMAC-SHA256. |
| Data at rest | AES-256 encryption at rest via Supabase/AWS. OAuth tokens encrypted at column level. Customer data isolation via authenticated company_id filtering on every server-side query, with Row-Level Security on customer-scoped tables. |
| Physical security | Cloud-only operation; no on-premise data processing. |
| Event logging | Audit logs for database access events. |
| System configuration | Infrastructure managed as code (Git, branch protection). Environment variables in Vercel with role-restricted access. Pull-request review and documented change-management policy. |
| IT security governance | Single-operator management with documented escalation chain per Incident Response Plan. |
| Certification | Sub-processors hold SOC 2 Type II where applicable (Supabase, Vercel, Anthropic, OpenAI, Zoom, Google). AWS infrastructure underlying Supabase and Vercel: SOC 2 Type II + ISO 27001. Anthropic and OpenAI confirm via commercial API terms that customer data is not used for model training. Direct SOC 2 Type I for 1Close AI Limited on roadmap. |
| Data minimisation | Only data required for service provision is collected. No third-party tracking cookies. |
| Data quality | Validation tests including backup verification. Privacy rights process per Privacy Policy. Application-level deduplication and integrity checks. |
| Limited retention | Documented retention policy (Privacy Policy Section 11). |
| Accountability | Privacy assessments required for new product/service involving Personal Data. |
| Portability and erasure | Privacy rights process per Privacy Policy. |
Annex C — Subprocessor list
Aligned with Global Privacy Policy Section 9 as of 18 June 2026. The Privacy Policy is the live sub-processor register for product-led customers; this annex mirrors it for contractual purposes.
| Name | Role | Processing activities | Location |
|---|---|---|---|
| Supabase, Inc. | Data Controller and Data Processor | Database hosting, data storage and retrieval | European Union West Region |
| Anthropic, PBC | Data Controller and Data Processor | AI model inference, natural language processing, content generation | United States |
| OpenAI, LLC | Data Controller and Data Processor | AI model inference (fallback), text embeddings, voice synthesis | United States |
| Zoom Video Communications, Inc. | Data Controller and Data Processor | Call recording, video conferencing, transcript generation | United States |
| Vercel Inc. | Data Controller and Data Processor | Application hosting, content delivery, serverless function execution | European Union (Dublin Region) |
| HighLevel, Inc. | Data Controller | Customer Relationship Management | United States |
| Slack Technologies, LLC (Salesforce, Inc.) | Data Controller and Data Processor | Workspace messaging, notifications, inbound chat identity resolution | United States |
| Google LLC (Gmail) | Data Controller and Data Processor | Email read and send, message synchronisation with deal records | European Union |
| Google LLC (Google Calendar) | Data Controller and Data Processor | Calendar synchronisation, meeting metadata and attendee information | European Union |