Date of last modification: 12 mars 2026
This Data Processing Agreement (“DPA“) forms part of and is incorporated into the Terms of Service, Order Form or other written or electronic agreement between Leedflow Technology AB, company registration number 559491-1660 (“Processor” or “Leedflow“), and the customer entity that has entered into the Agreement with Leedflow (“Controller” or “Customer“).
This DPA applies where Leedflow Processes Personal Data on behalf of Customer in connection with the Services.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
For purposes of this DPA:
The parties acknowledge and agree that:
Customer is responsible for:
Leedflow will Process Personal Data for the limited and specified purpose of providing the Services to Customer under the Agreement.
The subject matter, duration, nature and purpose of the Processing, the categories of Personal Data and the categories of Data Subjects are described in Appendix 1.
Leedflow shall:
Customer instructs Leedflow to Process Personal Data as necessary to:
Leedflow shall ensure that persons authorized to Process Personal Data:
Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing, and the risks to the rights and freedoms of natural persons, Leedflow shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk.
These measures include, where appropriate:
A general description of Leedflow’s current technical and organizational security measures is set out in Appendix 2.
Customer provides general authorization for Leedflow to engage Subprocessors.
Leedflow shall:
Leedflow will inform Customer of material changes to Subprocessors.
Taking into account the nature of the Processing, Leedflow shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligations to respond to requests for exercising Data Subject rights.
Leedflow shall also assist Customer in ensuring compliance with obligations relating to:
Leedflow shall notify Customer without undue delay after becoming aware of a Personal Data Breach.
Such notification shall include, where available:
Leedflow may transfer Personal Data outside the EEA where necessary to provide the Services.
Such transfers shall be carried out in accordance with Applicable Data Protection Law using appropriate safeguards, including Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful mechanisms.
Upon termination of the Services, Leedflow shall delete or return all Personal Data to Customer, unless retention is required by applicable law.
Liability arising from this DPA shall be subject to the limitations of liability set out in the Agreement.
This DPA is governed by Swedish law.
Purpose: Provision of the Services (lead generation, enrichment, outreach)
Data subjects: Users, employees, business contacts
Data types: Name, business email, job title, company data, usage data
Duration: For the duration of the Agreement
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Google Cloud Platform | Cloud hosting, database | All platform data | EU |
| Unipile | LinkedIn integration | Profile data, messages | France |
| Nylas | Email infrastructure | Email data | Ireland |
| Stripe | Payments | Billing data | EU |
| Google OAuth | Authentication | Email, profile data | EU |