Data Processing Agreement

Last updated: 17 August 2026

This DPA is provided for LeadsBullseye customers who require one (for example under GDPR Art. 28). Where a negotiated agreement is required, it should be countersigned.

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Himo Tech (“Processor”, “we”) and the customer (“Controller”, “you”). It applies where we process personal data on your behalf in providing LeadsBullseye.

1. Roles

For the business-listing (lead) data you collect and the account content you submit, you are the Controller and we are the Processor. For our own account/billing records we act as an independent Controller (see the Privacy Policy).

2. Scope and instructions

We process personal data only to provide the Service and on your documented instructions (which include your configuration and use of the Service), unless required by law to do otherwise. This includes the on-demand contact enrichment feature: it executes only when you invoke it for a specific saved lead, which constitutes your documented instruction for that lead — we do not run it on our own initiative.

3. Subject matter, duration, nature and purpose

  • Subject matter: provision of the LeadsBullseye lead-generation and AI-qualification service.
  • Duration: the term of your subscription plus any legally required retention.
  • Nature/purpose: searching, qualifying, storing and displaying business-listing data and generating outreach content on your behalf.
  • Categories of data subjects: business owners and business contacts appearing in public listings; your authorized users.
  • Categories of personal data: business names, addresses, business phone numbers, website/profile status; publicly listed business contact data (email, phone, role-holder name, social/web link) retrieved via the on-demand contact enrichment feature at your instruction, each recorded with its source URL and a quoted excerpt from that source; user account details.

4. Confidentiality

Personnel authorized to process personal data are bound by confidentiality obligations.

5. Security

We implement appropriate technical and organizational measures, including encryption in transit, row-level tenant isolation, AES-256-GCM encryption of any API keys you supply, least-privilege access controls, and logging.

6. Subprocessors

You authorize us to engage the subprocessors below. We impose data-protection terms on them no less protective than this DPA and remain responsible for their performance. We will give notice of intended changes and allow you to object.

SubprocessorPurposeLocation
SupabaseAuthentication, database, hosting of application dataEU / US regions
HeyCatchProduct analytics — page and feature usage, and account identifiers of signed-in users. Only for visitors who accept analytics cookies; see our Cookie PolicyUnited States
StripeSubscription billing and paymentsUS / global
Google (Maps Platform & Gemini API)Business-listing data and AI qualification/generation, including on-demand contact enrichment via the Gemini API with Google Search groundingUS / global
Cloud hosting providerApplication server hostingAs configured at deployment

7. International transfers

Where we transfer EU/UK personal data outside the EEA/UK, we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism.

8. Assistance

Taking into account the nature of processing, we will assist you with data-subject requests, security, breach notification, and data-protection impact assessments, as required by applicable law.

9. Breach notification

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with information reasonably available to us.

10. Deletion and return

On termination, we will delete or return personal data processed on your behalf, except where retention is required by law. You may also delete leads and account data from within the Service.

11. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits consistent with confidentiality and security constraints.

To request a countersigned DPA or ask questions: hmounir@himo-tech.ca · Himo Tech