1. Definitions
- Data Protection Laws means all laws applicable to the processing of Personal Data under the Agreement, including the GDPR (EU 2016/679), UK GDPR and Data Protection Act 2018, the Swiss FADP, and the CCPA/CPRA, each as amended.
- Personal Data means personal data or personal information (as defined in applicable Data Protection Laws) contained in Customer Data that Coldbean processes on Customer's behalf.
- Processing, Controller, Processor, Data Subject, Supervisory Authority, and Personal Data Breach have the meanings given in the GDPR.
- SCCs means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
- UK Addendum means the UK ICO's International Data Transfer Addendum to the SCCs.
- Subprocessor means a third party engaged by Coldbean to process Personal Data on Customer's behalf.
2. Roles and Scope
2.1 Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Coldbean is the Processor of Personal Data. Each party will comply with its obligations under Data Protection Laws.
2.2 Where Customer is itself a Processor, Customer warrants that its instructions to Coldbean are consistent with the instructions of the ultimate Controller, and Coldbean is engaged as a subprocessor.
2.3 This DPA does not apply to personal data for which Coldbean is an independent controller (e.g., Customer's account and billing data), which is governed by the Coldbean Privacy Policy.
3. Processing Instructions
3.1 Coldbean will process Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required by law to do otherwise (in which case Coldbean will inform Customer of the legal requirement before processing, unless prohibited by law).
3.2 Customer's instructions consist of: (i) the Agreement and this DPA; (ii) Customer's configuration and use of the Service; and (iii) other written instructions agreed by the parties. Coldbean will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to conduct legal review for Customer).
3.3 Details of processing (subject matter, duration, nature, purpose, data categories, data subject categories) are set out in Annex 1.
4. Confidentiality
Coldbean ensures that persons authorized to process Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate data-protection training.
5. Security
5.1 Coldbean implements and maintains appropriate technical and organizational measures ("TOMs") designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing. The current TOMs are described in Annex 2 and at coldbean.ai/security.
5.2 Coldbean may update the TOMs from time to time, provided updates do not materially reduce the overall level of protection.
5.3 Customer is responsible for securing its own credentials, endpoints, connected third-party accounts, and its configuration of the Service (including access permissions it grants to its Users).
6. Subprocessors
6.1 Customer provides general authorization for Coldbean to engage Subprocessors. The current list is set out in Annex 3 and maintained at coldbean.ai/dpa (or provided on request to tim@coldbean.ai).
6.2 Coldbean will provide at least 15 days' notice of new Subprocessors (via the list page, email, or in-product notice). Customer may object on reasonable data-protection grounds within that period; the parties will discuss in good faith, and if no resolution is reached, Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees.
6.3 Coldbean will impose data-protection obligations on Subprocessors that are materially no less protective than this DPA and remains liable for its Subprocessors' performance.
7. Data Subject Rights
Taking into account the nature of processing, Coldbean will assist Customer through appropriate technical and organizational measures (including in-product export, correction, and deletion tools) in fulfilling Customer's obligation to respond to Data Subject requests. If a Data Subject contacts Coldbean directly regarding Personal Data processed for Customer, Coldbean will promptly forward the request to Customer and will not respond substantively except as required by law.
8. Personal Data Breach
Coldbean will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data. The notification will describe, to the extent known: the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. Coldbean will provide reasonable cooperation and timely updates as information becomes available. Coldbean's notification is not an acknowledgment of fault or liability.
9. Assistance
Taking into account the nature of processing and information available to it, Coldbean will provide reasonable assistance to Customer with: (i) security of processing (Art. 32 GDPR); (ii) breach notifications to Supervisory Authorities and Data Subjects (Arts. 33–34); (iii) data protection impact assessments (Art. 35); and (iv) prior consultations (Art. 36). Coldbean may charge reasonable fees for assistance materially exceeding standard Service functionality.
10. Audits
10.1 Coldbean will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to security questionnaires and summaries of third-party audits or penetration tests, where available.
10.2 Where Data Protection Laws grant Customer an audit right that cannot be satisfied by the above, Customer (or an independent auditor bound by confidentiality, not a Coldbean competitor) may audit Coldbean's compliance once per 12-month period, on at least 30 days' notice, during business hours, in a manner that does not disrupt Coldbean's operations or compromise other customers' data. Each party bears its own costs.
11. International Transfers
11.1 Customer authorizes Coldbean to transfer Personal Data internationally as necessary to provide the Service, subject to this Section.
11.2 For transfers of Personal Data from the EEA to countries without an adequacy decision, the SCCs are incorporated by reference, with: Module Two (Controller → Processor) applying where Customer is a Controller and Module Three (Processor → Processor) where Customer is a Processor; Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 15 days' notice); Clause 11 optional language excluded; Clause 17: law of Ireland; Clause 18: courts of Ireland; Annexes I–III populated by Annexes 1–3 of this DPA.
11.3 For UK transfers, the UK Addendum applies with Table entries populated by this DPA; for Swiss transfers, the SCCs apply as adapted for the FADP (references to the GDPR read as the FADP; competent authority: FDPIC).
11.4 If Coldbean adopts an alternative valid transfer mechanism (e.g., an adequacy framework certification), that mechanism may apply in place of the SCCs to the extent lawful.
12. CCPA/CPRA Terms
To the extent Personal Data includes personal information of California residents processed on Customer's behalf, Coldbean acts as Customer's "service provider." Coldbean will not: sell or share the personal information; retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA; or combine it with personal information from other sources except as permitted. Coldbean certifies that it understands and will comply with these restrictions, will notify Customer if it can no longer meet its obligations, and grants Customer the right to take reasonable steps to remediate unauthorized use.
13. Return and Deletion
Upon termination or expiry of the Service, Coldbean will, at Customer's election exercised within 30 days, return Personal Data via export tools or delete it. Absent an election, Coldbean will delete or de-identify Personal Data within 90 days of termination, except: (i) backups, which expire on their normal cycle (up to 35 additional days) and are protected until deletion; and (ii) data Coldbean must retain under applicable law, which remains subject to this DPA's protections.
14. Liability and Order of Precedence
14.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where prohibited by Data Protection Laws. Nothing in this Section limits a Data Subject's rights under the SCCs.
14.2 In case of conflict, the order of precedence is: (1) the SCCs/UK Addendum, (2) this DPA, (3) the Agreement.
15. Term
This DPA is effective for as long as Coldbean processes Personal Data on Customer's behalf.
Annex 1 — Description of Processing
Data exporter
Customer (controller or processor), a business user of the Coldbean Service.
Data importer
Xquare Labs LLC (Coldbean), provider of mailbox management and sales pipeline software (processor).
Subject matter
Provision of the Coldbean Service under the Agreement.
Duration
The subscription term plus the deletion period in Section 13.
Nature and purpose
Hosting, storage, transmission, organization, analysis, display, and deletion of Customer Data to provide mailbox management, deliverability, and sales pipeline / dealflow functionality; support; security; and service improvement as permitted by the Agreement.
Categories of Data Subjects
- Customer's Users (employees, contractors).
- Customer's prospects, leads, contacts, and their representatives.
- Correspondents of connected mailboxes.
Categories of Personal Data
- Identification and contact data (names, email addresses, phone numbers, job titles, company).
- Business communications (email content and metadata from connected mailboxes, where features require).
- Commercial data (deal records, pipeline stage, notes, interaction history).
- Technical data (IP addresses, identifiers, usage logs of Users).
Special categories
None intended. Customer agrees not to submit special-category data or data of children.
Frequency
Continuous, for the subscription term.
Retention
Per Section 13.
Competent Supervisory Authority (SCCs)
The authority of the EU member state in which the data exporter is established, or as determined under Clause 13 of the SCCs; for Ireland-governed clauses, the Irish Data Protection Commission where applicable.
Annex 2 — Technical and Organizational Measures
- Encryption: TLS 1.2+ in transit; AES-256 (or equivalent) at rest; encrypted storage of OAuth tokens and secrets with restricted key access.
- Access control: Role-based access, least privilege, MFA for administrative access, unique accounts, prompt deprovisioning on role change or departure.
- Network security: Firewalling, WAF and rate limiting at the edge, network segmentation, VPN-restricted internal administration.
- Application security: Secure development practices, code review, dependency and vulnerability scanning, periodic penetration testing.
- Logging and monitoring: Centralized logging of administrative and data-access events, alerting on anomalous activity, log retention for investigation.
- Availability and resilience: Redundant infrastructure with reputable cloud providers, automated backups, tested restore procedures, capacity monitoring.
- Incident response: Documented incident-response plan, defined severity levels, breach-notification workflow supporting the 72-hour commitment in Section 8.
- Personnel: Confidentiality obligations, security awareness training, background screening where lawful.
- Vendor management: Due diligence and contractual safeguards for Subprocessors; periodic review.
- Data minimization and separation: Logical tenant separation; production data excluded from development environments except where strictly necessary and protected.
- Physical security: Provided by cloud data-center providers maintaining industry certifications (e.g., ISO 27001, SOC 2).
Annex 3 — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloud hosting provider(s) (e.g., AWS / GCP / equivalent) | Infrastructure, storage, compute | USA / EU |
| Cloudflare | CDN, DNS, WAF, edge security | Global |
| Stripe | Payment processing | USA |
| Google LLC | Workspace APIs for connected accounts (as configured by Customer) | Global |
| Microsoft Corporation | Microsoft 365 / Graph APIs for connected accounts (as configured by Customer) | Global |
| Transactional email provider | Service notifications | USA / EU |
| Analytics and error-monitoring provider(s) | Product analytics, diagnostics | USA / EU |
| Support tooling provider | Customer support | USA / EU |
The authoritative, current list — including specific vendor names — is maintained at coldbean.ai/dpa and provided on request. Replace the generic entries above with your actual vendors before publishing.
This DPA forms part of our Terms of Service. See also our Privacy Policy and Security practices.