Data Processing Addendum · Effective September 11, 2026

How we process data for customers.

This addendum is part of the Terms of Service for every customer whose use of Petrichor involves personal data protected by the GDPR, UK GDPR, Swiss FADP or US state privacy laws. It sets out our obligations as your processor and lists every subprocessor we use.

01

Parties and roles

This Data Processing Addendum ("DPA") is between the customer identified in the Petrichor account ("Customer") and BluBubl Limited ("Petrichor"). It forms part of the Terms of Service and applies automatically; no signature is needed. Customers who need a countersigned copy for their records can request one at alex@trypetrichor.com.

The parties act in the following roles:

DataCustomerPetrichor
Customer Data: contacts, CRM records, documents and lists the Customer uploads or connects; messages sent and received through the Customer's connected accounts; workspace contentControllerProcessor
Petrichor Lead Data: business-contact records Petrichor sources from public sources and licensed providers and makes available in the productController for the copies it selects, exports and contactsIndependent controller for the underlying index (see the Privacy Policy)
Account data about the Customer's own usersn/aController

Where the CCPA/CPRA applies, Petrichor is a service provider for Customer Data, will not sell or share it, will not retain, use or disclose it outside the direct business relationship except as permitted, and will notify the Customer if it can no longer meet its obligations.

02

Details of processing

ItemDescription
Subject matterProvision of the Petrichor service: lead discovery and enrichment, outreach drafting and sending from the Customer's connected accounts, reply handling, CRM sync and learning from outcomes.
DurationThe term of the Customer's account, plus the export and deletion period in the Terms.
Nature and purposeHosting, storage, analysis with machine-learning models, transmission to connected platforms, and reporting, all to carry out the Customer's go-to-market work on its instructions.
Types of personal dataBusiness contact data: names, job titles, employers, business email addresses and phone numbers, professional profile URLs, work locations, message content and metadata, CRM fields the Customer chooses to sync. No special-category data is permitted.
Data subjectsThe Customer's prospects, leads, customers and CRM contacts; the Customer's own users.
03

Petrichor's obligations as processor

  • Instructions. Process Customer Data only on the Customer's documented instructions, which are the Terms, this DPA, and the settings and actions the Customer takes in the product. Petrichor will inform the Customer if an instruction appears to infringe data-protection law.
  • Confidentiality. Ensure that staff with access to Customer Data are bound by confidentiality and receive appropriate training. Staff access inside a Customer workspace occurs only with the Customer's permission and is logged.
  • Security. Implement the technical and organisational measures in Security measures and keep them under review.
  • Subprocessors. Engage subprocessors only under the conditions in Subprocessors.
  • Assistance. Help the Customer respond to data-subject requests, and provide reasonable assistance with security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to Petrichor.
  • Data-subject requests. Forward to the Customer without undue delay any request Petrichor receives that relates to Customer Data, and not respond to it except on the Customer's instruction or where the law requires. Petrichor honours opt-outs and objections directly across the platform, since suppression protects the data subject regardless of which controller receives the request.
  • Deletion and return. At the end of the service, delete or return Customer Data at the Customer's choice within the period stated in the Terms, unless the law requires retention. The Customer can export leads and workspace data from the product at any time.
  • Audit. Make available the information necessary to demonstrate compliance with this DPA, in the first instance through documentation and written answers. Where a Customer reasonably requires more, Petrichor will allow an audit once per year, on 30 days' notice, at the Customer's cost, conducted so as not to disrupt the service or expose other customers' data.
04

Customer's obligations

  • Have a lawful basis for every category of personal data the Customer uploads, connects or instructs Petrichor to contact, and provide any notices the law requires.
  • Give instructions that comply with data-protection law and the terms of connected platforms.
  • Honour opt-outs and data-subject rights for its campaigns and not re-import suppressed contacts.
  • Not upload special-category data, data about children, or financial account data.
  • Configure autonomy, budgets and team permissions appropriately and keep credentials secure.
05

Security measures

Petrichor maintains the following measures, appropriate to the risk of processing business-contact data:

  • Encryption in transit (TLS) for all connections to and between services.
  • Authenticated encryption at rest for connected-account credentials and secrets, with keys held separately from the database and versioned for rotation.
  • Passwords stored only as salted bcrypt hashes; single sign-on via Google available.
  • Role-based access inside workspaces (admin, team lead, member) with per-member spend allowances.
  • Production access limited to named staff over authenticated connections; staff sessions inside a Customer account are explicit, permissioned and logged.
  • Provider-level rate limits and pacing for outreach to protect connected accounts.
  • Spend governors, budgets and pause controls that bound what the agent may do.
  • Health monitoring, incident tracking and daily automated evaluations of agent behaviour.
  • Segregated tenancy at the data layer keyed by team, with regular backups.
06

Personal data breaches

Petrichor will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available. Petrichor will cooperate with the Customer's own notifications to authorities and data subjects.

07

Subprocessors

The Customer authorises Petrichor to engage the subprocessors below. Petrichor imposes data-protection obligations on each that are no less protective than this DPA, and remains liable for their performance. Entries marked customer-directed are engaged only when the Customer connects that service to its own workspace.

Petrichor will publish changes to this list on this page and notify account admins by email at least 30 days before a new subprocessor processes Customer Data. A Customer that objects on reasonable data-protection grounds may raise the objection at alex@trypetrichor.com; if the parties cannot resolve it, the Customer may terminate the affected service with a pro-rata refund of prepaid fees.

Infrastructure, models and data providers

SubprocessorPurposeData processedLocation
DigitalOcean, LLCCloud hosting, application servers and databasesAll service dataUnited States (New York)
OpenAI, LLCLarge language models that draft, classify and planChat content, workspace context, prospect records passed for scoring and draftingUnited States
DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.)Large language models for bulk classification and draftingChat content, workspace context, prospect records passed for scoring and draftingChina
OpenRouter, Inc.Routing layer for third-party language modelsPrompts and model outputs routed through itUnited States
Google LLCSign in with Google (identity only)Google account email, name and profile identifier at sign-inUnited States
Stripe, Inc.Subscription billing and payment processingBilling name, email, payment method (held by Stripe), invoicesUnited States
Resend, Inc.Transactional email (for example demo-request notifications)Recipient email address and message contentUnited States
Exa Labs, Inc.Web search and company or person discoverySearch queries, company and public-profile resultsUnited States
Apollo.ioB2B contact and company dataBusiness contact records (name, title, employer, business email, LinkedIn URL)United States
HarvestAPIPublic professional-profile and job-posting dataPublic profile fields, employer, tenure, public postsSee provider
FullEnrichBusiness contact enrichment (email and phone)Name, employer, LinkedIn URL; returns business email or phoneFrance
LeadMagicBusiness contact enrichment and email validationName, employer, LinkedIn URL; returns business email or phoneUnited States
Leads FridayBusiness email enrichmentName, employer, LinkedIn URL; returns business emailSee provider
Hunter.ioBusiness email discovery and verificationName and company domain; returns business emailFrance
Up2DataCompany and relationship data for warm-introduction pathsCompany identifiers and public professional relationshipsSee provider
BuiltWith Pty LtdTechnology-stack signals about companiesCompany domainsAustralia
Twilio, Inc.Phone number format and carrier lookupsBusiness phone numbers returned by enrichmentUnited States

Customer-directed integrations

SubprocessorPurposeData processedLocation
UnipileConnecting your email and LinkedIn accounts so the agent can send and read on your behalfMailbox and LinkedIn messages, contacts and account credentials for accounts you connectFrance
HeyReachLinkedIn outreach automation for accounts you connectLinkedIn account session, campaign contacts and messagesLithuania
Instantly.aiEmail sending infrastructure for mailboxes you connectCampaign recipients, message content, delivery and reply eventsUnited States
HubSpot, Inc.CRM sync and deduplication for a CRM you connectCRM contacts, companies and deal records you authorise us to read or writeUnited States
NangoSecure connection broker for third-party integrations you authoriseOAuth tokens and API responses for the integrations you connectFrance (EU hosting)

Public data sources that are read but do not act on our behalf (company websites, public job boards such as Greenhouse and Ashby, regulatory filings, public professional profiles) are not subprocessors and are not listed.

08

International transfers

BluBubl Limited is established in the United States and hosts the service there. Where Customer Data protected by EU, UK or Swiss law is transferred to Petrichor or onward to a subprocessor in a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) and, for onward transfers, Module Three, which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and the Swiss amendments where applicable. Petrichor selects the options as follows: Clause 7 docking clause included; Clause 9 option 2 (general authorisation) with the notice period above; Clause 11 optional language not included; Clause 13 supervisory authority of the Customer's establishment; Clause 17 law of Ireland; Clause 18 courts of Ireland. Annex I is completed by Details of processing, Annex II by Security measures, and Annex III by Subprocessors.

Where a subprocessor is certified under the EU-US Data Privacy Framework, Petrichor may rely on that certification instead. Petrichor will assess the laws of destination countries and apply supplementary measures where needed, and will inform the Customer if it can no longer comply with the transfer terms.

09

Liability, precedence and term

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing limits liability to data subjects under the Standard Contractual Clauses. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms with respect to the processing of personal data. This DPA lasts as long as Petrichor processes Customer Data.