Data Processing Agreement
Effective date: 2 September 2026
1. Scope, Roles & Acceptance
This Data Processing Agreement (“DPA”) is between Folup LLC, a limited liability company formed in Florida, United States, trading as folup (“folup,” “we,” “us”), and the customer using the Service (“you”). It gives effect to Article 28(3) of the GDPR and its UK equivalent.
You do not need to sign this. It forms part of our Terms of Service and applies automatically whenever we process personal data on your behalf. If your organisation needs a countersigned copy for its records, e-mail hello@folup.ai and we will provide one.
What this DPA covers. Processing where you are the controller and we are your processor — the candidate records you import, the outreach content you create, and the mailbox metadata we handle to send your messages and detect replies.
What it does not cover. Two things sit outside it, because we are the controller for both and this DPA would be the wrong instrument:
- Your own account, billing, and usage data. That is governed by our Privacy Policy.
- Business e-mail addresses that folup itself locates or verifies. We are the controller of those records, as Section 2 of the Privacy Policy explains, and Section 8 of the Terms of Service sets out the licence on which you may use them.
2. What We Process, and Why
Article 28(3) requires this to be set out specifically rather than in general terms.
- Subject matter. Providing the folup Service to you.
- Duration. For as long as your account is active, plus the 30-day export window described in Section 12.
- Nature and purpose. Storing candidate records; drafting outreach at your request; sending it from your connected mailbox; reading message headers to detect replies; and showing you reporting on your own activity.
- Categories of data subject. Candidates and professional contacts you import, and the individual users of your folup account.
- Categories of personal data. Names, business e-mail addresses, employers, job titles, public professional profile links, the content of outreach you write, and message metadata (thread and message identifiers, headers, reply timestamps). Not the contents of your mailbox: the permissions we hold cannot return message bodies.
- Special-category data. None. The Terms of Service prohibit importing it and the Service is not built to handle it.
3. Our Obligations as Processor
We will:
- process personal data only on your documented instructions, which include your configuration and use of the Service, and not for our own purposes;
- tell you if we believe an instruction breaches data-protection law, and not simply carry it out;
- never use your candidate data to build a shared database, enrich another customer’s account, or train any artificial-intelligence or machine-learning model;
- implement the security measures in Section 6;
- impose equivalent obligations on any sub-processor, and remain responsible to you for their performance;
- assist you in responding to data subject requests, as set out in Section 9;
- assist you with your obligations under Articles 32 to 36, including data protection impact assessments and consultation with a supervisory authority, so far as the information is available to us;
- return or delete personal data as set out in Section 12.
4. Your Obligations as Controller
You warrant that you have a lawful basis for the personal data you import and for contacting the people it concerns, that you have given any notice the law requires, and that your instructions to us will not put us in breach. Section 8 of the Terms of Service covers this in more detail. You remain responsible for the accuracy of the data you provide and for deciding how long you need it.
5. Confidentiality
We treat your personal data as confidential. Anyone we authorise to process it is bound by a duty of confidentiality that survives the end of their engagement, and we grant access only where it is needed to run the Service or to support you.
6. Security Measures
Taking into account the state of the art, the cost of implementation, and the risks involved, we maintain measures appropriate under Article 32. In practice:
- personal data is encrypted in transit using TLS, and encrypted at rest;
- mailbox connection tokens are encrypted at rest;
- access to production data is limited to what is needed to operate the Service;
- we request the narrowest mailbox permissions that will do the job, which is why we cannot read your message contents at all;
- we keep the ability to restore availability and access to personal data after an incident.
We may change these measures as the Service develops, but not in a way that materially reduces the protection given to personal data.
7. Sub-processors
You give general authorisation for us to engage sub-processors on the terms in Section 3. Those that may process personal data on your behalf today are:
- Vercel — application and website hosting (United States).
- Anthropic — the model behind AI drafting, contractually barred from training on data we send it (United States).
Two others touch data but not as your processor: Stripe handles our billing relationship with you, where we are the controller; and Sanity serves our blog and receives no personal data at all. We also use specialist business contact-data providers for the e-mail lookup described in Section 1, where we act as controller rather than as your processor. We will identify any of these by name on request — e-mail us and we will tell you.
Changes. We will update this list before adding or replacing a sub-processor that handles personal data, and e-mail customers on paid plans. If you reasonably object on data-protection grounds within 30 days, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the Service and we will refund the unused portion of any prepaid fees.
8. International Transfers
We operate from the United States and the sub-processors above process data there. Where you transfer personal data from the EEA, the UK, or Switzerland to us, the European Commission’s Standard Contractual Clauses for controller-to-processor transfers (Module Two) are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where UK data is involved.
For those clauses: you are the data exporter and we are the data importer; the docking clause applies; Section 7 lists the authorised sub-processors; Section 2 supplies the description of processing; and Section 6 supplies the technical and organisational measures. Where this DPA and those clauses conflict, the clauses prevail.
9. Data Subject Requests
The Service lets you access, correct, export, and delete candidate records yourself, which will usually be the fastest route. Where you need more, we will help you respond within the statutory deadline at no charge.
If a data subject contacts us directly about data you control, we will not respond substantively on your behalf. We will tell them that you are the controller, identify you, and pass the request to you promptly — and we will delete our own copy where we hold one as controller. Section 12 of the Privacy Policy explains this from the candidate’s side.
10. Personal Data Breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you. Our notice will describe the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed — and where we do not have all of that at first, we will send what we have and follow up rather than waiting.
We will not notify a supervisory authority or any data subject on your behalf unless you ask us to or the law requires it of us directly.
11. Audits & Information
On request we will give you the information you reasonably need to demonstrate compliance with this DPA. Where that is not enough to satisfy an obligation you have under Article 28(3)(h), you may audit us, or appoint an independent auditor to do so, once in any twelve-month period on 30 days’ written notice — more often if a supervisory authority requires it or following a breach. Audits happen during business hours, must not disrupt the Service, and are subject to confidentiality.
12. Return and Deletion of Data
You can export your data at any time from your account. After your account closes, it remains available for export for 30 days, after which we permanently delete it from our production systems.
You may ask us in writing to delete it sooner and we will, unless the law requires us to keep it — in which case we will tell you which data and why, and keep processing it only for that purpose. Suppression records are the one deliberate exception: where someone has asked never to be contacted again, we keep the minimum needed to honour that indefinitely, because deleting it would undo the suppression.
13. Liability, Precedence & Term
This DPA takes effect when you begin using the Service and continues for as long as we process personal data on your behalf. Sections 5, 6, 10, and 12 survive its end.
Each party’s liability under this DPA is subject to the limitation of liability in Section 12 of the Terms of Service, except where that limitation is not permitted by data-protection law.
Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of personal-data processing. Where it conflicts with the Standard Contractual Clauses, those clauses prevail. This DPA is governed by the law stated in Section 15 of the Terms of Service, except where data-protection law requires otherwise.
14. Contact
Questions about this DPA, requests for a countersigned copy, or sub-processor enquiries: hello@folup.ai.