Data processing addendum
Last updated September 28, 2026
This addendum forms part of the Terms of service between you (the controller) and CloudGens (the processor) whenever OmniLead processes personal data on your behalf.
1. Scope and roles
This DPA applies to personal data in Customer Data, such as contacts you import, notes, emails and pipeline records (“Customer Personal Data”). You are the controller and CloudGens is the processor. It does not cover the OmniLead database of public professional information, for which we are an independent controller as described in our Privacy policy.
2. Instructions
We process Customer Personal Data only on your documented instructions, which are the Terms, this DPA and your use of the product's features, unless the law requires otherwise. We'll tell you if we believe an instruction breaks data protection law.
3. Details of processing
- Subject matter and duration: providing OmniLead for the term of your subscription plus the deletion period below.
- Nature and purpose: hosting, storage, search, verification, sending and receiving email, CRM features and support.
- Data subjects: your prospects, customers, investors, partners and research contacts, and your users.
- Categories of data: names, work contact details, job titles, organisations, message content and activity history. You must not upload special-category data.
4. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality obligations.
5. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- Workspace isolation enforced by Postgres row-level security on every tenant table.
- Encryption in transit (TLS) and at rest; mailbox credentials and OAuth tokens encrypted with AES-256-GCM using versioned keys.
- Least-privilege access for staff, audit logging of reveals, exports, billing, mailbox and member changes, and deletions.
- Rate limiting, input validation on every endpoint, and security headers.
- Backups and a tested restore process through our hosting provider.
More detail is on our security page.
6. Sub-processors
You authorise the sub-processors on our sub-processors page. We impose data protection terms on each that are at least as protective as this DPA and remain responsible for them. We'll give at least 30 days' notice of a new sub-processor by updating that page and emailing account owners. You may object on reasonable data protection grounds; if we can't resolve it, you may terminate the affected service and receive a refund of prepaid fees for it.
7. Assistance and data subject rights
OmniLead includes tools to find, export, correct and delete records and to suppress addresses. Where you can't use them, we'll help you respond to data subject requests and with data protection impact assessments and consultations with authorities, taking into account the nature of the processing.
8. Personal data breaches
We'll notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information you reasonably need to meet your obligations.
9. International transfers
Where Customer Personal Data is transferred outside the EEA, UK or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses (Module 2, controller to processor; and Module 3 where applicable) and the UK Addendum are incorporated by reference.
10. Audits
We'll make available the information reasonably necessary to demonstrate compliance with this DPA. You may audit once a year on 30 days' notice, at your cost, in a way that doesn't disrupt the service or compromise other customers' data.
11. Return and deletion
You can export Customer Data at any time. After your subscription ends we delete Customer Personal Data within 30 days, and from backups on their normal rotation, unless the law requires us to keep it.
12. CCPA terms
For the CCPA, we act as your service provider. We won't sell or share Customer Personal Data, retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing OmniLead, or combine it with other data except as the CCPA permits.
To sign a countersigned copy, email privacy@omni.cloudgens.net.