Legal

Data Processing Addendum

Version 1.0. Last updated 9 August 2026.

This Data Processing Addendum, or “DPA”, forms part of the agreement between SQUAREZONE SOFTWARE PUBLISHING LLC-FZ, operating Swarmhit from Dubai, United Arab Emirates, referred to as “Company”, and the Customer using the Services.

This DPA applies where Company processes Customer Personal Data on behalf of Customer as a processor, service provider, or subprocessor. It does not apply where Company acts as an independent controller, including for Account management, billing, security, abuse prevention, product analytics, support, or certain professional discovery and enrichment data described in the Privacy Policy.

1. Definitions

“Applicable Data Protection Law” means data protection and privacy laws applicable to the processing of Customer Personal Data, including, where applicable, the UAE Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data, the EU General Data Protection Regulation 2016/679, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws.

“Customer Personal Data” means personal data contained in Customer Content and processed by Company on Customer’s behalf through the Services.

“Data Subject”, “Controller”, “Processor”, “Processing”, and “Personal Data” have the meanings given by Applicable Data Protection Law.

“Subprocessor” means a third party appointed by Company to process Customer Personal Data on Customer’s behalf.

“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Company. It does not include unsuccessful attempts that do not compromise Customer Personal Data.

2. Roles and scope

Customer is the Controller of Customer Personal Data. If Customer processes personal data for another controller, Customer is a Processor and appoints Company as its Subprocessor.

Company will process Customer Personal Data only to provide, secure, maintain, and support the Services, comply with documented Customer instructions, and comply with applicable law.

The agreement, Customer’s configuration and use of the Services, API calls, support requests, and other written instructions are Customer’s documented instructions.

Customer is responsible for the lawfulness of Customer Personal Data, its instructions, notices, legal bases, recipient selection, outreach content, opt-outs, and use of results.

3. Processing instructions

Company will not process Customer Personal Data for purposes incompatible with Customer’s documented instructions unless required by law. If law requires other processing, Company will inform Customer before processing unless prohibited.

If Company reasonably believes an instruction violates Applicable Data Protection Law, Company may suspend the affected processing and notify Customer. The parties will cooperate in good faith to resolve the issue.

4. Confidentiality and personnel

Company will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as necessary for their duties.

5. Security measures

Company will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage. The measures are described in Annex II.

Customer acknowledges that security measures evolve and may be updated, provided updates do not materially reduce the overall protection of Customer Personal Data during a paid term.

6. Subprocessors

Customer gives Company general written authorization to appoint Subprocessors. Company will require each Subprocessor to protect Customer Personal Data through written terms that are materially consistent with the obligations applicable to Company under this DPA.

A current list of material Subprocessors will be made available on request at contact@swarmhit.com or through a designated Swarmhit page. Company will provide reasonable notice of a new material Subprocessor where required by Applicable Data Protection Law.

Customer may object to a new Subprocessor on reasonable, documented data protection grounds within 15 days after notice. The parties will attempt to resolve the objection. If no reasonable solution is available, either party may terminate the affected Services, and Company will refund prepaid fees for the unused portion of the terminated Services.

Company remains responsible for each Subprocessor’s performance of its data protection obligations to the extent required by Applicable Data Protection Law.

7. Data Subject requests

Taking into account the nature of processing, Company will provide reasonable assistance to Customer through available functionality or support so Customer can respond to Data Subject requests.

If Company receives a request relating to Customer Personal Data, Company will direct the requester to Customer or notify Customer, unless Company is legally required to respond directly. Customer is responsible for responding to requests.

8. Security Incidents

Company will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notification will include available information reasonably necessary for Customer to meet legal obligations.

Company will take reasonable steps to contain, investigate, and mitigate the Security Incident and will provide reasonable cooperation. Notification is not an admission of fault or liability.

9. Assistance and compliance

Taking into account the nature of processing and information available to Company, Company will provide reasonable assistance with Customer’s obligations concerning security, breach notifications, data protection impact assessments, prior consultations, and demonstrations of compliance.

Additional assistance beyond standard Services may be subject to reasonable fees where the request is not caused by Company’s breach.

10. Audits

Company will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant independent reports or questionnaires where available.

If that information is insufficient, Customer may request an audit no more than once per year, unless required by a regulator or following a material Security Incident. Audits must be conducted on reasonable prior notice, during normal business hours, by an independent auditor bound by confidentiality, and without unreasonable disruption or access to other customers’ data.

Customer bears audit costs unless the audit identifies a material breach by Company.

11. Return and deletion

Upon termination of the affected Services, Company will delete or return Customer Personal Data at Customer’s choice where supported by the Services. Unless law requires retention, active copies will be deleted within 90 days after termination, and backup copies will be deleted or rendered inaccessible through normal backup cycles.

Company may retain data required by law or necessary to establish, exercise, or defend legal claims, subject to continued protection and limited processing.

12. International transfers

Customer authorizes Company and its Subprocessors to process Customer Personal Data in countries where they operate, subject to lawful transfer safeguards.

Where Customer Personal Data protected by the GDPR is transferred to Company in a country without an applicable adequacy decision, the European Commission Standard Contractual Clauses adopted by Decision 2021/914 are incorporated by reference as follows:

  • Module Two applies where Customer is a Controller and Company is a Processor;
  • Module Three applies where Customer is a Processor and Company is a Subprocessor;
  • Clause 7, the docking clause, applies;
  • Clause 9 uses Option 2, general written authorization, with the notice period in Section 6;
  • the optional language in Clause 11 does not apply;
  • Clause 17 is governed by the law of Ireland;
  • the courts of Ireland are selected under Clause 18(b);
  • Annex I and Annex II of this DPA complete the relevant annexes to the Standard Contractual Clauses.

For UK Restricted Transfers, the UK International Data Transfer Addendum issued by the UK Information Commissioner’s Office is incorporated and completed using the information in this DPA. The selected exporter may terminate the Addendum as permitted by its mandatory provisions.

For transfers subject to Swiss data protection law, references in the Standard Contractual Clauses to the GDPR and EU institutions will be interpreted to include the corresponding Swiss law and authority where required, and Swiss Data Subjects may enforce applicable rights in Switzerland.

If a transfer mechanism is invalidated, the parties will cooperate to implement a lawful replacement.

13. United States privacy terms

Where Company processes personal information subject to United States state privacy law on behalf of Customer, Company acts as a service provider or processor and will:

  • process the information only for the limited and specified purposes in the agreement;
  • not sell or share Customer Personal Data or retain, use, or disclose it outside the direct business relationship except as permitted by law;
  • not combine Customer Personal Data with personal information received from another person or collected from Company’s own interaction with an individual, except as permitted by law;
  • provide the same level of privacy protection required by applicable law;
  • notify Customer if Company determines it can no longer meet an applicable obligation;
  • allow Customer to take reasonable steps to stop and remediate unauthorized use.

14. Liability and precedence

The liability limits in the Terms of Service or applicable Order Form apply to this DPA. If there is a conflict, this DPA prevails for processing of Customer Personal Data. The Standard Contractual Clauses prevail where they expressly require a different result.

15. Contact

Questions concerning this DPA may be sent to contact@swarmhit.com.

Annex I: Details of processing

A. Parties

Data exporter: Customer identified in the applicable Account or Order Form.

Data importer: SQUAREZONE SOFTWARE PUBLISHING LLC-FZ, operating Swarmhit from Dubai, United Arab Emirates.

B. Subject matter and duration

Subject matter: Processing Customer Personal Data to provide Swarmhit’s SaaS platform, outreach tools, APIs, infrastructure, integrations, inbox, analytics, support, and related features.

Duration: The subscription or service term, plus the limited retention period described in this DPA.

C. Nature and purpose

Hosting, organizing, enriching, segmenting, transmitting, sequencing, displaying, retrieving, analyzing, securing, supporting, deleting, and otherwise processing Customer Personal Data according to Customer’s configuration and instructions.

D. Data Subjects

  • Customer’s Authorized Users and Connected Account holders;
  • prospects, professional contacts, campaign recipients, and message participants;
  • Customer’s clients, employees, contractors, and organization members;
  • individuals whose data is submitted through Customer applications, APIs, agents, or white-label services.

E. Categories of Personal Data

  • names, professional emails, profile URLs, employers, job titles, locations, and business contact details;
  • profile, connection, invitation, message, reply, campaign, inbox, and engagement data;
  • tags, notes, segmentation, prompts, workflow instructions, and Customer-defined fields;
  • Connected Account identifiers, authentication or session tokens, and connection status;
  • device, API, webhook, log, diagnostic, and security data related to use of the Services.

F. Sensitive data

The Services are not intended for special-category or highly sensitive data. Customer must not submit such data unless expressly supported, necessary, lawful, and subject to appropriate safeguards.

G. Frequency

Continuous or as initiated by Customer during the service term.

H. Supervisory authority

The competent supervisory authority is determined under Clause 13 of the Standard Contractual Clauses based on the relevant Data Exporter and Data Subjects.

Annex II: Technical and organizational measures

Company maintains measures appropriate to the nature and risk of processing, including where applicable:

  • role-based access controls and least-privilege access;
  • authentication controls and protection of administrative access;
  • encryption of data in transit and encryption at rest where appropriate;
  • segregation of Customer environments and logical access boundaries;
  • logging, monitoring, alerting, and audit trails for relevant systems;
  • secure software development, code review, dependency management, and vulnerability remediation processes;
  • backup, recovery, business continuity, and incident response procedures;
  • controls for API keys, tokens, credentials, and secrets;
  • personnel confidentiality obligations and security awareness;
  • Subprocessor due diligence and written data protection obligations;
  • data retention, deletion, and access-review processes;
  • periodic review and improvement of security measures.

Stop building the execution layer.
Start shipping outreach.

Get an API key in minutes, or launch your first campaign in the app. Same engine either way.