Data Processing Agreement
Effective 1 October 2026. This Data Processing Agreement ("DPA") forms part of the Terms of Service between The Hashtag Crew ("we", "us", the "Processor") and the customer that has accepted them ("you", the "Controller") for the use of NectarScout (the "Service"). It applies whenever we process Customer Personal Data for you. If this DPA and the Terms conflict on data protection, this DPA wins.
A countersigned copy is available on request from hello@nectarscout.com.
1. Definitions
- Data Protection Laws means every law on personal data that applies to the processing, including the EU General Data Protection Regulation 2016/679 (GDPR), the GDPR as it forms part of UK law and the UK Data Protection Act 2018 (UK GDPR), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws, Canada's PIPEDA, Australia's Privacy Act 1988, New Zealand's Privacy Act 2020, South Africa's POPIA, India's Digital Personal Data Protection Act 2023, and the UAE Personal Data Protection Law.
- Customer Personal Data means personal data that we process for you while providing the Service.
- Controller, processor, data subject, personal data breach, processing and supervisory authority have the meanings given in the GDPR. "Controller" includes a "business" and "processor" includes a "service provider" under the CCPA, and the equivalent terms in the other Data Protection Laws.
- Sub-processor means a third party we engage that processes Customer Personal Data.
- SCCs means the standard contractual clauses approved by the European Commission in Decision 2021/914. UK Addendum means the International Data Transfer Addendum issued by the UK Information Commissioner.
2. Roles
You are the controller of Customer Personal Data and we are your processor. Where you are yourself a processor for your own client, we are your sub-processor, and you confirm that your client has authorised our appointment.
For a small amount of data we act as an independent controller: our records about you as a customer, data we need to secure the Service and prevent abuse, and the do-not-contact records we keep so that opt-outs are honoured. Our Privacy Policy covers that data.
3. Your instructions
We will process Customer Personal Data only on your documented instructions, unless the law requires otherwise (in which case we will tell you first, unless the law forbids it). Your instructions are this DPA, the Terms, and the way you configure and use the Service. We will tell you if we believe an instruction breaks Data Protection Laws.
You are responsible for:
- having a lawful basis for the processing, and giving data subjects any notice the law requires;
- the accuracy of the data you put into the Service and of the instructions you give;
- complying with the laws on electronic marketing, telephone calls and call recording in each country where you contact people (see our Acceptable Use Policy).
4. Details of the processing
- Subject matter: providing the Service: finding and researching businesses, analysing websites, generating website previews, drafting and sending email, logging calls, managing a sales pipeline, and creating proposals and invoices.
- Duration: the term of your subscription, plus the deletion period in section 11.
- Nature and purpose: collection, storage, organisation, analysis (including by AI models), retrieval, transmission and deletion, so that you can find and communicate with businesses.
- Data subjects: owners, staff and contacts of the businesses you research or contact; people who reply to you or contact you through a feature of the Service; your own team members.
- Categories of data: names, job titles, work email addresses, work phone numbers, business addresses, website content and images, email messages and their metadata, call times, durations and recording references, notes and files you add, and contact details a visitor chooses to leave.
- Special category data: none is required by the Service. You must not deliberately put special category data (such as health, religion or political opinions) or data about children into the Service.
5. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law.
6. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data, including:
- encryption of data in transit (TLS) and of stored secrets such as mailbox passwords and API keys (AES-256-GCM);
- one-way hashing of user passwords (scrypt);
- separation of each customer's data by account, and role-based access inside a team;
- secure, HTTP-only, expiring session cookies;
- hosting on Oracle Cloud Infrastructure, whose storage is encrypted at rest;
- nightly backups, each checked for integrity before it is kept;
- access to production limited to personnel who need it;
- logging of significant actions taken in each workspace.
We may update these measures, provided we do not reduce the overall level of protection.
7. Sub-processors
You give us general authorisation to engage Sub-processors. Our current Sub-processors are listed at nectarscout.com/legal/subprocessors.
- We will impose on each Sub-processor data protection obligations that protect Customer Personal Data to the standard of this DPA, and we remain responsible for their performance.
- We will update the list at least 30 days before a new Sub-processor starts processing Customer Personal Data, and tell you by email or in the Service.
- You may object on reasonable data protection grounds within those 30 days. We will then work with you in good faith to find a solution. If we cannot, either of us may end the affected part of the Service, and we will refund any prepaid fees for the period after it ends.
8. Helping you with data subject requests
Taking into account the nature of the processing, we will help you respond to requests from data subjects exercising their rights. If we receive a request directly that relates to your data, we will pass it to you without undue delay and will not respond ourselves except to confirm it has been passed on, unless you ask us to or the law requires it.
9. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as we know them, what happened, the data and people affected, the likely consequences, and what we are doing about it. We will give you further information as it becomes available and reasonably help you meet your own obligations to notify regulators and individuals.
10. Help with assessments
We will give you reasonable help with data protection impact assessments and prior consultations with supervisory authorities, where these relate to the Service and you cannot get the information elsewhere.
11. Deletion or return at the end
When your subscription ends, you may export your data by asking us at hello@nectarscout.com within 30 days. We will then delete Customer Personal Data within 90 days of the end of your subscription, unless the law requires us to keep it. Data in backups is deleted within a further 60 days, and is not used in the meantime.
12. Audits
We will make available the information reasonably needed to show that we comply with this DPA, including written answers to security questionnaires. If that is not enough, or a supervisory authority requires it, you may audit our compliance, at your own cost, no more than once a year, with at least 30 days' notice, during business hours, and under a duty of confidentiality. An audit must not access other customers' data.
13. International transfers
Customer Personal Data is processed in the United States and in the other countries listed on the Sub-processors page.
- From the EU or EEA: the SCCs, Module 2 (controller to processor) and, where you are a processor, Module 3 (processor to processor), are incorporated into this DPA. For the SCCs: clause 7 (docking) applies; clause 9 option 2 (general authorisation) applies, with the notice period in section 7 above; the optional wording in clause 11 does not apply; clauses 17 and 18 are governed by and subject to the courts of Ireland; and Annexes I and II are completed by sections 4 and 6 of this DPA.
- From the United Kingdom: the UK Addendum is incorporated, completed with the information in this DPA, and either party may end it as allowed by its section 19.
- From Switzerland: the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
- From other countries: we will use the transfer mechanism, if any, that the applicable law requires.
14. US state law terms
Where the CCPA or a similar US state law applies, we act as your service provider or processor, and we will not:
- sell or share Customer Personal Data;
- keep, use or disclose it for any purpose other than providing the Service, or outside our direct business relationship with you;
- combine it with personal data we receive from anyone else, except as those laws allow.
We will comply with those laws and tell you if we can no longer meet them. We certify that we understand these restrictions.
15. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where the law does not allow them to apply.
16. General
This DPA lasts as long as we process Customer Personal Data for you. If any part of it is found to be invalid, the rest continues. It is governed by the same law as the Terms, except where the SCCs or the UK Addendum require otherwise.