Data Processing Agreement

Version 1.0  ·  Effective Date: June 18, 2026

1. Introduction

This Data Processing Agreement ("DPA") is entered into between:

This DPA supplements the iLeadX Terms of Service and Privacy Policy and governs the processing of Personal Data by iLeadX on behalf of the Controller in connection with the Platform. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters.

This DPA is designed to comply with the requirements of Article 28 of the General Data Protection Regulation (GDPR) and equivalent provisions in other applicable data protection laws, including the CCPA/CPRA (California), LGPD (Brazil), PIPEDA (Canada), and NDPR (Nigeria).

2. Definitions

3. Scope & Duration

3.1 Scope

This DPA applies to all processing of Personal Data by iLeadX in the course of providing the Platform to the Controller under the Enterprise plan or a separately executed subscription agreement.

3.2 Duration

This DPA shall remain in effect for the duration of the Controller's subscription to the Platform. Upon termination or expiration of the subscription, this DPA shall automatically terminate, subject to Section 10 (Data Retention & Deletion).

4. Nature, Purpose & Categories of Processing

4.1 Nature of Processing

iLeadX processes Personal Data to provide the lead-generation, enrichment, AI scoring, and data export services described in the Terms of Service.

4.2 Purpose of Processing

4.3 Categories of Data Subjects

4.4 Categories of Personal Data

CategoryExamples
Business Contact InformationBusiness email addresses, business phone numbers, job titles, company names
Public Professional ProfilesLinkedIn profiles, professional social media accounts
Business MetadataCompany address, industry, ratings, reviews, technology stack
User Account DataController employee names, email addresses, login credentials (hashed)
AI-Generated InsightsLead scores, urgency assessments, pitch angles, pain point analyses

5. Obligations of the Processor

iLeadX agrees to:

  1. Process only on documented instructions: Process Personal Data only in accordance with the Controller's documented instructions, including those set forth in the Terms of Service and this DPA, unless required to do so by applicable law.
  2. Confidentiality: Ensure that all persons authorized to process Personal Data are bound by appropriate confidentiality obligations.
  3. Security measures: Implement and maintain appropriate technical and organizational measures to protect Personal Data as described in Section 7 of this DPA.
  4. Sub-processing: Not engage any Sub-Processor without the Controller's prior general written authorization, as described in Section 6 of this DPA.
  5. Data Subject rights: Assist the Controller in responding to Data Subject requests as described in Section 8 of this DPA.
  6. Breach notification: Notify the Controller without undue delay upon becoming aware of a Data Breach as described in Section 9 of this DPA.
  7. Data Protection Impact Assessments: Provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities.
  8. Deletion or return: At the Controller's election, delete or return all Personal Data upon termination of the Platform subscription as described in Section 10 of this DPA.
  9. Audit rights: Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 11 of this DPA.

6. Sub-Processors

6.1 Authorized Sub-Processors

The Controller authorizes iLeadX to engage the following Sub-Processors for the purposes described below:

Sub-ProcessorPurposeData ProcessedLocation
PaystackPayment processingTransaction data, emailNigeria
StripePayment processing (alternative)Transaction data, emailUnited States
NowPaymentsCryptocurrency payment processingTransaction data, wallet addressesEstonia
Google (OAuth)User authenticationEmail, name, profile pictureUnited States
Google Sheets APILead export (user-initiated)Lead Data selected for exportUnited States
Ollama (Local)AI scoring and enrichmentLead Data for analysisSelf-hosted (Controller's region)
SMTP ServiceTransactional emailsEmail address, email contentConfigured by Controller

6.2 Changes to Sub-Processors

iLeadX shall notify the Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 14 days in advance. The Controller may object to such changes within 7 days of notification. If the Controller objects and iLeadX cannot accommodate the objection, the Controller may terminate the subscription without penalty.

6.3 Sub-Processor Obligations

iLeadX shall impose on all Sub-Processors data protection obligations substantially similar to those set forth in this DPA. iLeadX shall remain fully liable to the Controller for the performance of any Sub-Processor's obligations.

7. Security Measures

iLeadX shall implement and maintain the following technical and organizational measures to protect Personal Data:

7.1 Technical Measures

MeasureDescription
Encryption in TransitTLS 1.3 for all data transmitted between the Platform and Users
Password HashingArgon2 algorithm with per-password salting
AuthenticationJWT-based access tokens with refresh token rotation
Two-Factor AuthenticationTOTP-based 2FA (mandatory for admin accounts, optional for users)
Access ControlsRole-based access (user, admin, super_admin) with least-privilege principle
Audit LoggingComprehensive logging of administrative actions with immutable records
Rate LimitingAPI rate limiting to prevent abuse and brute-force attacks
Session ManagementPer-device session tracking with IP logging and remote revocation

7.2 Organizational Measures

8. Data Subject Rights

iLeadX shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection laws, including:

If iLeadX receives a Data Subject request directly, it shall promptly forward the request to the Controller and shall not respond to the request except at the Controller's documented instruction.

9. Data Breach Notification

9.1 Notification Obligation

iLeadX shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Data Breach affecting Personal Data.

9.2 Notification Content

The notification shall, to the extent reasonably available:

9.3 Coordination

iLeadX shall cooperate with the Controller and take such reasonable steps as the Controller directs to assist in the investigation, mitigation, and remediation of any Data Breach.

10. Data Retention & Deletion

10.1 Retention During Subscription

Personal Data shall be retained for the duration of the Controller's subscription to the Platform, unless earlier deletion is requested by the Controller.

10.2 Deletion Upon Termination

Within 30 days of termination or expiration of the subscription, iLeadX shall, at the Controller's election:

  1. Return a complete copy of all Personal Data in a structured, commonly used, machine-readable format; or
  2. Delete all Personal Data from iLeadX's systems.

Thereafter, iLeadX shall delete all existing copies of Personal Data, except where retention is required by applicable law. iLeadX shall certify the completion of deletion to the Controller in writing upon request.

10.3 Surviving Data

Shared business data (company names, addresses, ratings) that has been stripped of Controller-specific enrichment data may be retained in anonymized form for Platform improvement purposes.

11. Audit Rights

11.1 Information Provision

iLeadX shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.

11.2 On-Site Audits

The Controller may, no more than once per calendar year and upon 30 days' written notice, conduct an on-site audit of iLeadX's data processing facilities during normal business hours. The Controller shall bear all costs of such audit. The Controller shall use a mutually agreed-upon independent third-party auditor for any on-site audit.

11.3 Alternative Compliance Evidence

In lieu of an on-site audit, iLeadX may provide the Controller with a summary of a recent third-party audit report or certification (such as a SOC 2 Type II report, once available) demonstrating compliance with this DPA.

12. International Data Transfers

12.1 Transfer Mechanisms

Where Personal Data is transferred from the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions to a country not deemed to provide an adequate level of protection, iLeadX shall ensure appropriate safeguards are in place, including:

12.2 Data Residency

Enterprise Controllers may request specific data residency accommodations. iLeadX will make commercially reasonable efforts to accommodate such requests, subject to technical feasibility and mutual agreement.

13. Liability

Each party's liability under this DPA shall be subject to the limitations and exclusions set forth in the Terms of Service. Nothing in this DPA shall limit either party's liability for: (a) breach of its confidentiality obligations; (b) intentional misconduct or gross negligence; or (c) any liability that cannot be limited or excluded under applicable law.

14. Governing Law

This DPA shall be governed by the laws specified in the Terms of Service. For data processing activities subject to GDPR, the laws of the relevant EU Member State shall also apply to the extent required by GDPR.

15. Execution

This DPA is incorporated by reference into the Terms of Service and becomes effective upon the Controller's subscription to the iLeadX Enterprise plan or execution of a separate Order Form referencing this DPA. No separate signature is required for this DPA to take effect.

For the Processor (iLeadX):

iLeadX — a subsidiary of Wako Digital Hub Ltd
Email: [email protected]
Subject: "DPA — Enterprise Agreement"

For the Controller:

As set forth in the applicable Enterprise Order Form or subscription agreement.

© 2026 iLeadX — a subsidiary of Wako Digital Hub Ltd. All rights reserved.

← Back to iLeadX