1.Purpose and Scope
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the service agreement between the client ("Controller") and AutomateYourOutreach.com, operated by G1 Equity Ltd. or G1 Group International LLC as applicable ("Processor"), as described in Section 1 of our Privacy Policy. It reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR") and applies wherever the Processor processes personal data of prospects on the Controller's behalf in connection with LinkedIn outreach campaigns.
This DPA governs only the Processor's processing of prospect data as processor. It does not apply to the Processor's own processing of the Controller's account, billing, and correspondence data, which is addressed as controller-to-controller processing under Section 2 of the Privacy Policy.
2.Definitions
- "Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Sub-processor" have the meanings given in Article 4 GDPR.
- "Prospect Data" means personal data of individuals contacted through LinkedIn outreach campaigns run by the Processor on the Controller's instructions.
- "Services" means the done-for-you LinkedIn outreach services provided under the service agreement between the Parties.
3.Subject Matter and Duration
The subject matter of this DPA is the processing of Prospect Data by the Processor for the purpose of delivering the Services. This DPA takes effect on the date the Controller begins using the Services and remains in force for as long as the Processor processes Prospect Data on the Controller's behalf, including any period necessary to complete deletion or return of data under Section 14.
4.Nature and Purpose of Processing
The Processor processes Prospect Data to identify, contact, and manage outreach conversations with prospects matching the ideal customer profile ("ICP") supplied by the Controller, including sending connection requests, messages, and follow-ups, and recording replies and engagement status, all on the Controller's LinkedIn account or an account authorized by the Controller.
5.Categories of Data Subjects and Data
| Category | Details |
|---|---|
| Data subjects | Individuals identified on LinkedIn as matching the Controller's ICP ("prospects") |
| Personal data processed | Publicly available LinkedIn profile information (name, job title, employer, profile URL), connection status, message and reply content, and engagement timestamps |
| Special categories (Art. 9) | Not intentionally collected or targeted |
6.Controller's Instructions
The Processor will process Prospect Data only on the Controller's documented instructions, including those given through the ICP, campaign brief, and kickoff call, unless required to do otherwise by EU or member state law, in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
The Processor will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
7.Confidentiality
The Processor ensures that any person authorized to process Prospect Data, including its own personnel, has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and processes Prospect Data strictly on a need-to-know basis to perform the Services.
8.Technical and Organizational Measures
The Processor implements the technical and organizational measures described in Section 10 of our Privacy Policy, appropriate to the risk, in accordance with Article 32 GDPR, including encryption of data in transit, restricted access to personal data, secure handling of LinkedIn credentials, and regular review of processing activities and vendor security practices. The Controller acknowledges having reviewed these measures and considers them appropriate to the risk presented by the processing described in this DPA.
9.Sub-processors
The Controller grants the Processor general authorization to engage the categories of sub-processors listed in Section 7 of our Privacy Policy (hosting and infrastructure providers, payment processors, email and communication tools, and analytics providers), each bound by a written agreement imposing data protection obligations equivalent to those set out in this DPA.
The Processor will inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable grounds relating to data protection within a reasonable period. The Processor remains fully liable to the Controller for the performance of any sub-processor's obligations.
10.Assistance With Data Subject Rights
Taking into account the nature of the processing, the Processor assists the Controller, insofar as reasonably possible, in responding to requests from data subjects seeking to exercise their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, and objection). Where the Processor receives a request directly from a prospect, it will forward that request to the Controller without undue delay, as described in Section 12 of our Privacy Policy, and will not respond to the request itself except to acknowledge receipt and redirect the data subject.
11.Assistance With Articles 32–36
The Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to the Processor. In particular, the Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Prospect Data, and will provide reasonably requested information to support the Controller's own notification obligations under Articles 33 and 34.
12.International Transfers
Any transfer of Prospect Data to a country outside the EU/EEA is carried out only under the safeguards described in Section 8 of our Privacy Policy, including adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, or the European Commission's Standard Contractual Clauses. A copy of the applicable Standard Contractual Clauses is available to the Controller on request.
13.Audits and Inspections
The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Audits are subject to reasonable advance notice (at least 14 days, unless a regulator requires shorter notice), are limited to once every 12 months absent a specific compliance concern or incident, and are conducted in a manner that does not unreasonably disrupt the Processor's operations or other clients' confidentiality.
14.Deletion or Return of Data
At the Controller's choice, the Processor deletes or returns all Prospect Data to the Controller after the end of the provision of Services, and deletes existing copies unless EU or member state law requires storage of the personal data, consistent with Section 9 of our Privacy Policy.
15.Liability
Each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the underlying service agreement between the Parties, except where such limitations are not permitted under applicable mandatory law, including Article 82 GDPR.
16.Term and Termination
This DPA remains in effect for as long as the Processor processes Prospect Data on behalf of the Controller under the service agreement, and terminates automatically upon completion of deletion or return of all Prospect Data under Section 14, or upon termination of the underlying service agreement, whichever is later.
17.Governing Law
This DPA is governed by the same governing law and jurisdiction provisions as the underlying service agreement between the Parties, without prejudice to any data subject's rights under applicable data protection law.
18.Contact
Questions about this DPA, or requests for a countersigned copy, an up-to-date sub-processor list, or a copy of the applicable Standard Contractual Clauses, can be directed to our data protection contact below.
G1 Equity Ltd. — EU / international clients
Email: info@g-1.group
Registered address: Efesou 9, 5280 Paralimni, Cyprus
G1 Group International LLC — US-based clients
Email: info@g-1.group
Registered address: 30 N Gould St Ste N, Sheridan, WY 82801, USA