Parties and roles
This Data Processing Addendum ("DPA") is between the customer identified in the Petrichor account ("Customer") and BluBubl Limited ("Petrichor"). It forms part of the Terms of Service and applies automatically; no signature is needed. Customers who need a countersigned copy for their records can request one at alex@trypetrichor.com.
The parties act in the following roles:
| Data | Customer | Petrichor |
|---|---|---|
| Customer Data: contacts, CRM records, documents and lists the Customer uploads or connects; messages sent and received through the Customer's connected accounts; workspace content | Controller | Processor |
| Petrichor Lead Data: business-contact records Petrichor sources from public sources and licensed providers and makes available in the product | Controller for the copies it selects, exports and contacts | Independent controller for the underlying index (see the Privacy Policy) |
| Account data about the Customer's own users | n/a | Controller |
Where the CCPA/CPRA applies, Petrichor is a service provider for Customer Data, will not sell or share it, will not retain, use or disclose it outside the direct business relationship except as permitted, and will notify the Customer if it can no longer meet its obligations.
Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Petrichor service: lead discovery and enrichment, outreach drafting and sending from the Customer's connected accounts, reply handling, CRM sync and learning from outcomes. |
| Duration | The term of the Customer's account, plus the export and deletion period in the Terms. |
| Nature and purpose | Hosting, storage, analysis with machine-learning models, transmission to connected platforms, and reporting, all to carry out the Customer's go-to-market work on its instructions. |
| Types of personal data | Business contact data: names, job titles, employers, business email addresses and phone numbers, professional profile URLs, work locations, message content and metadata, CRM fields the Customer chooses to sync. No special-category data is permitted. |
| Data subjects | The Customer's prospects, leads, customers and CRM contacts; the Customer's own users. |
Petrichor's obligations as processor
- Instructions. Process Customer Data only on the Customer's documented instructions, which are the Terms, this DPA, and the settings and actions the Customer takes in the product. Petrichor will inform the Customer if an instruction appears to infringe data-protection law.
- Confidentiality. Ensure that staff with access to Customer Data are bound by confidentiality and receive appropriate training. Staff access inside a Customer workspace occurs only with the Customer's permission and is logged.
- Security. Implement the technical and organisational measures in Security measures and keep them under review.
- Subprocessors. Engage subprocessors only under the conditions in Subprocessors.
- Assistance. Help the Customer respond to data-subject requests, and provide reasonable assistance with security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to Petrichor.
- Data-subject requests. Forward to the Customer without undue delay any request Petrichor receives that relates to Customer Data, and not respond to it except on the Customer's instruction or where the law requires. Petrichor honours opt-outs and objections directly across the platform, since suppression protects the data subject regardless of which controller receives the request.
- Deletion and return. At the end of the service, delete or return Customer Data at the Customer's choice within the period stated in the Terms, unless the law requires retention. The Customer can export leads and workspace data from the product at any time.
- Audit. Make available the information necessary to demonstrate compliance with this DPA, in the first instance through documentation and written answers. Where a Customer reasonably requires more, Petrichor will allow an audit once per year, on 30 days' notice, at the Customer's cost, conducted so as not to disrupt the service or expose other customers' data.
Customer's obligations
- Have a lawful basis for every category of personal data the Customer uploads, connects or instructs Petrichor to contact, and provide any notices the law requires.
- Give instructions that comply with data-protection law and the terms of connected platforms.
- Honour opt-outs and data-subject rights for its campaigns and not re-import suppressed contacts.
- Not upload special-category data, data about children, or financial account data.
- Configure autonomy, budgets and team permissions appropriately and keep credentials secure.
Security measures
Petrichor maintains the following measures, appropriate to the risk of processing business-contact data:
- Encryption in transit (TLS) for all connections to and between services.
- Authenticated encryption at rest for connected-account credentials and secrets, with keys held separately from the database and versioned for rotation.
- Passwords stored only as salted bcrypt hashes; single sign-on via Google available.
- Role-based access inside workspaces (admin, team lead, member) with per-member spend allowances.
- Production access limited to named staff over authenticated connections; staff sessions inside a Customer account are explicit, permissioned and logged.
- Provider-level rate limits and pacing for outreach to protect connected accounts.
- Spend governors, budgets and pause controls that bound what the agent may do.
- Health monitoring, incident tracking and daily automated evaluations of agent behaviour.
- Segregated tenancy at the data layer keyed by team, with regular backups.
Personal data breaches
Petrichor will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available. Petrichor will cooperate with the Customer's own notifications to authorities and data subjects.
Subprocessors
The Customer authorises Petrichor to engage the subprocessors below. Petrichor imposes data-protection obligations on each that are no less protective than this DPA, and remains liable for their performance. Entries marked customer-directed are engaged only when the Customer connects that service to its own workspace.
Petrichor will publish changes to this list on this page and notify account admins by email at least 30 days before a new subprocessor processes Customer Data. A Customer that objects on reasonable data-protection grounds may raise the objection at alex@trypetrichor.com; if the parties cannot resolve it, the Customer may terminate the affected service with a pro-rata refund of prepaid fees.
Infrastructure, models and data providers
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| DigitalOcean, LLC | Cloud hosting, application servers and databases | All service data | United States (New York) |
| OpenAI, LLC | Large language models that draft, classify and plan | Chat content, workspace context, prospect records passed for scoring and drafting | United States |
| DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) | Large language models for bulk classification and drafting | Chat content, workspace context, prospect records passed for scoring and drafting | China |
| OpenRouter, Inc. | Routing layer for third-party language models | Prompts and model outputs routed through it | United States |
| Google LLC | Sign in with Google (identity only) | Google account email, name and profile identifier at sign-in | United States |
| Stripe, Inc. | Subscription billing and payment processing | Billing name, email, payment method (held by Stripe), invoices | United States |
| Resend, Inc. | Transactional email (for example demo-request notifications) | Recipient email address and message content | United States |
| Exa Labs, Inc. | Web search and company or person discovery | Search queries, company and public-profile results | United States |
| Apollo.io | B2B contact and company data | Business contact records (name, title, employer, business email, LinkedIn URL) | United States |
| HarvestAPI | Public professional-profile and job-posting data | Public profile fields, employer, tenure, public posts | See provider |
| FullEnrich | Business contact enrichment (email and phone) | Name, employer, LinkedIn URL; returns business email or phone | France |
| LeadMagic | Business contact enrichment and email validation | Name, employer, LinkedIn URL; returns business email or phone | United States |
| Leads Friday | Business email enrichment | Name, employer, LinkedIn URL; returns business email | See provider |
| Hunter.io | Business email discovery and verification | Name and company domain; returns business email | France |
| Up2Data | Company and relationship data for warm-introduction paths | Company identifiers and public professional relationships | See provider |
| BuiltWith Pty Ltd | Technology-stack signals about companies | Company domains | Australia |
| Twilio, Inc. | Phone number format and carrier lookups | Business phone numbers returned by enrichment | United States |
Customer-directed integrations
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Unipile | Connecting your email and LinkedIn accounts so the agent can send and read on your behalf | Mailbox and LinkedIn messages, contacts and account credentials for accounts you connect | France |
| HeyReach | LinkedIn outreach automation for accounts you connect | LinkedIn account session, campaign contacts and messages | Lithuania |
| Instantly.ai | Email sending infrastructure for mailboxes you connect | Campaign recipients, message content, delivery and reply events | United States |
| HubSpot, Inc. | CRM sync and deduplication for a CRM you connect | CRM contacts, companies and deal records you authorise us to read or write | United States |
| Nango | Secure connection broker for third-party integrations you authorise | OAuth tokens and API responses for the integrations you connect | France (EU hosting) |
Public data sources that are read but do not act on our behalf (company websites, public job boards such as Greenhouse and Ashby, regulatory filings, public professional profiles) are not subprocessors and are not listed.
International transfers
BluBubl Limited is established in the United States and hosts the service there. Where Customer Data protected by EU, UK or Swiss law is transferred to Petrichor or onward to a subprocessor in a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) and, for onward transfers, Module Three, which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and the Swiss amendments where applicable. Petrichor selects the options as follows: Clause 7 docking clause included; Clause 9 option 2 (general authorisation) with the notice period above; Clause 11 optional language not included; Clause 13 supervisory authority of the Customer's establishment; Clause 17 law of Ireland; Clause 18 courts of Ireland. Annex I is completed by Details of processing, Annex II by Security measures, and Annex III by Subprocessors.
Where a subprocessor is certified under the EU-US Data Privacy Framework, Petrichor may rely on that certification instead. Petrichor will assess the laws of destination countries and apply supplementary measures where needed, and will inform the Customer if it can no longer comply with the transfer terms.
Liability, precedence and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing limits liability to data subjects under the Standard Contractual Clauses. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms with respect to the processing of personal data. This DPA lasts as long as Petrichor processes Customer Data.

