legal

Data Processing Addendum

Effective 6 August 2026  .  Last updated 6 August 2026

The short version, which is not the legal version but is honest: when you type someone else's name into Warmline, that is their personal data and you are the one responsible for it. We are your processor. We use it only to write your line, we do not keep it, and we do not use it for anything of our own. This document says that in the language a data protection officer, a procurement team or a regulator will want to see, and it is automatically in force for anyone who uses Warmline for business purposes. You do not have to sign anything.

1. Scope and how this becomes binding

This Data Processing Addendum ("DPA") forms part of the Terms of Service between data according to me, operator of Warmline at warmline.dataaccordingtome.com ("Processor", "we", "us"), and the person or organisation using the Service ("Controller", "you").

It applies automatically, without signature, whenever you use Warmline to process personal data relating to an identified or identifiable living individual and you are subject to the GDPR, the UK GDPR, the Swiss FADP, the CCPA as amended, or another data protection law that requires a written processor agreement.

If your organisation requires a countersigned copy, email amy@dataaccordingtome.com with your entity name and address and we will execute this DPA in that form. The terms will not change.

2. Definitions

"Data Protection Law" means all laws applicable to the processing under this DPA, including Regulation (EU) 2016/679 (GDPR), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the CCPA as amended by the CPRA.

"Personal Data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.

"Customer Personal Data" means personal data contained in Input you submit to the Service, principally the prospect name, company or newsletter, the researched detail and the outreach reason.

"SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.

"Service" has the meaning given in the Terms of Service.

3. Roles of the parties

Getting the roles right is the whole point of this document, so here they are in plain terms.

4. Annex I: details of the processing

ItemDetail
Subject matterGeneration of a two to four sentence outreach opening line from Input supplied by the Controller
DurationThe duration of the individual request. Processing ends when the response is returned.
Nature of processingTransmission, transient in-memory storage, prompt construction, disclosure to the AI sub-processor for text generation, receipt and return of the generated text. No storage, no profiling, no enrichment, no analytics.
PurposeProviding the Service to the Controller, and nothing else
Categories of data subjectsIndividuals the Controller intends to contact ("prospects"), who may be professional contacts, hiring managers, founders, investors, editors, clients or similar
Categories of personal dataName (capped at 80 characters); company or newsletter name (capped at 120); one free-text researched detail (capped at 600); the Controller's stated outreach reason (capped at 400). Any further personal data is present only because the Controller chose to type it in.
Special category dataNone permitted. The Controller is contractually prohibited from submitting special category data under Art. 9 GDPR, criminal offence data under Art. 10, government identifiers, financial account data, health data, biometric data, precise geolocation, or any data relating to a child.
FrequencyContinuous, on demand, initiated by the Controller
Retention by ProcessorNone. Customer Personal Data is not written to any database, file or persistent log under our control. It exists only for the lifetime of the HTTP request.
Retention by sub-processorsThe AI sub-processor retains inputs for a short period for trust and safety purposes under its own commercial terms, and does not use business API inputs or outputs for model training. The hosting sub-processor retains standard request metadata in server logs, typically for about 30 days.
Competent supervisory authorityDetermined under Clause 13 SCCs by reference to the Controller's establishment or its EU representative

5. Our obligations as processor

We will:

6. Your obligations as controller

You warrant and undertake that:

7. Annex II: technical and organisational security measures

We implement the following measures. They are stated as commitments, not aspirations, and we will not materially reduce them during the term.

AreaMeasure
Data minimisation by designCustomer Personal Data is never written to a database. The most effective control against unauthorised access to stored data is not storing it, and that is the architecture.
Field limitsEvery input field is length-capped server-side before any onward transmission, which bounds both cost and the volume of any single disclosure.
Encryption in transitTLS on all connections, from the browser to our endpoints and from our endpoints to every sub-processor.
Encryption at restApplied by our hosting and key-value sub-processors to the limited data they hold (rate-limit keys, counters, subscriber emails, submitted notes).
Credential handlingAPI keys and storage tokens live only in server-side environment variables. They are never present in client-side code, which is why generation is proxied through our own endpoint rather than called from the page.
Access controlAdministrative access to the hosting and storage consoles is limited to the operator, protected by strong unique credentials and multi-factor authentication.
Abuse and availability controlsServer-side per-IP and global daily rate limits, enforced where a client cannot bypass them, protecting against automated extraction and denial of service.
Input sanitisationSubmitted notes are stripped of markup on receipt and escaped again on render. User-submitted content is held in a pending queue and is not displayed publicly without manual review.
Logging disciplineError logging records status codes and a truncated provider message. Prospect fields are not deliberately written to logs.
Retention limitsRate-limit keys carry a 48-hour expiry set at creation, so IP-linked records self-delete without manual intervention.
Sub-processor diligenceSub-processors are selected on the basis of published security posture, recognised certifications and contractual data protection terms, including no-training commitments for AI processing.
Incident responseA documented route for detection, assessment and notification, with the timelines in section 11.
Data minimisation by designThe controls above are architectural rather than procedural. Customer Personal Data is never written to a database, so there is no store to breach, and no retention policy that can be applied inconsistently.

8. Annex III: sub-processors

You give us general written authorisation to engage the sub-processors below, and to appoint replacements or additions subject to the notice and objection rights in this section.

Sub-processorFunctionData processedLocation
Vercel Inc.Hosting, edge network and serverless function executionAll request data in transit, including Customer Personal Data; request metadata in server logsUnited States
Anthropic PBCAI text generationThe generation prompt containing Customer Personal DataUnited States
Upstash Inc. (Redis / Vercel KV)Rate limiting, counters, subscriber list, pending notesVisitor IP-derived keys, counters, subscriber emails, notes. No Customer Personal Data.United States

Notice and objection. We will give you at least thirty (30) days' notice before adding or replacing a sub-processor, by updating this page and, if you have given us an email address, by email. If you have a reasonable objection on data protection grounds, tell us within that period. We will work in good faith to address it. If we cannot, you may stop using the Service and, if you are on a paid plan, receive a pro-rata refund of prepaid fees for the unused period as your sole remedy.

9. International transfers and the Standard Contractual Clauses

Customer Personal Data is processed in the United States. Where the transfer is from the EEA, the UK or Switzerland to a country without an adequacy decision, the following applies.

If the SCCs are invalidated, replaced or amended, the parties will implement the successor mechanism without undue delay, and this DPA is deemed amended accordingly.

Government access requests. If we receive a legally binding request from a public authority for Customer Personal Data, we will notify you unless prohibited by law, challenge the request where there are reasonable grounds to consider it unlawful, and disclose only the minimum permissible. Given that we retain no Customer Personal Data, in practice there is nothing for us to produce in response to such a request.

10. Assistance with data subject requests

Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

The honest practical position: because we do not retain Customer Personal Data, we hold nothing to search, export, correct or delete on your behalf. A request from a prospect for access or erasure is answered from your own records. If a prospect contacts us directly, we will not respond to them on the substance. We will tell them we are a processor holding no data about them, direct them to the controller, and notify you promptly if we can identify you.

We do not charge for this assistance.

11. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed to address it and to mitigate adverse effects; and a contact point for further information. Where the full picture is not yet available, we will provide information in phases as it becomes available.

We will cooperate with you and take the reasonable steps you direct to assist in your investigation and in your own notifications to supervisory authorities and data subjects. Our notification is not an acknowledgement of fault or liability.

12. Assistance with DPIAs and prior consultation

We will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that relates to your use of the Service, taking account of the nature of the processing and the information available to us. Sections 4, 7 and 8 of this DPA are drafted to give you most of what a DPIA needs without a separate request.

13. Audits and information rights

We will make available all information reasonably necessary to demonstrate compliance with Art. 28 GDPR, including this DPA, our security measures in section 7, and the sub-processor list in section 8.

Where that information is not sufficient for your reasonable compliance needs, you may request an audit no more than once in any twelve month period, on at least thirty days' written notice, during business hours, subject to confidentiality obligations, and conducted so as not to disrupt the Service. You bear your own costs and our reasonable costs. You may request an additional audit following a confirmed personal data breach affecting Customer Personal Data or where a supervisory authority requires it.

Audits do not extend to the systems of sub-processors, for which we will instead provide such information about their security posture and certifications as we are permitted to share.

14. Deletion and return of data

At your choice, on termination of the Service or on your request, we will delete or return all Customer Personal Data and delete existing copies, unless retention is required by a law applicable to us.

Because Customer Personal Data is not persisted, deletion is effectively complete at the end of each request and no separate deletion step is required. If you request written confirmation of this, we will provide it within thirty days.

Deletion of visitor data we hold as controller (your email address, notes, rate-limit keys) is handled under the Privacy Policy.

15. California, and other US state laws

Where the CCPA as amended applies, we act as a "service provider" as defined in Cal. Civ. Code § 1798.140. We certify that we:

You may take reasonable and appropriate steps to ensure we use Customer Personal Data consistently with your CCPA obligations. Where Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or another US state comprehensive privacy law applies, we act as a "processor" or "service provider" under that law and undertake the equivalent obligations it imposes.

16. Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service, and any claim under this DPA counts towards the aggregate cap there. Nothing in this DPA limits any liability that cannot lawfully be limited, including a data subject's rights under Clause 12 of the SCCs or under Art. 82 GDPR.

Nothing in this section affects the rights of data subjects under the SCCs as third party beneficiaries.

17. Term, changes and order of precedence

This DPA takes effect when you first use the Service and continues for as long as we process Customer Personal Data on your behalf.

We may update this DPA to reflect changes in law, in sub-processors, or in the Service. Material changes take effect thirty days after we publish them here, or immediately where required by law. If a change materially reduces your protections and you object, you may stop using the Service.

Order of precedence. If there is a conflict, the SCCs prevail over this DPA, this DPA prevails over the Terms of Service, and the Terms of Service prevail over anything else, in each case only to the extent of the conflict and only in respect of the processing of Customer Personal Data.

If any provision is held invalid or unenforceable, it is severed and the remainder continues in force.

18. Contact

Privacy and data protection enquiries, DPA countersignature requests, sub-processor objections, audit requests and breach correspondence go to:

data according to me
Warmline
amy@dataaccordingtome.com
warmline.dataaccordingtome.com

Please put "DPA" in the subject line. We aim to respond within thirty days, and sooner where the law or an incident requires.