Data Processing Agreement
Version 2026-07-08 · Effective 2026-07-08
1. What this covers and why it exists
When you give Namari a lead list, you are handing us personal data about other people. Under laws like the GDPR and CCPA/CPRA, that makes you the controller (you decide why the data is used) and Namari the processor (we only act on your instructions). This agreement sets out the rules for that. It forms part of, and is governed by, our Terms of Service. If they conflict on data protection, this agreement wins.
2. Scope of processing
- Subject matter: contacting, qualifying, and following up on leads you provide, and booking meetings or closing sales on your behalf.
- Duration: for as long as your account is active, plus the deletion window in section 8.
- Categories of data subject: your prospects, leads, and customers.
- Categories of personal data: name, phone number, email address, company, and any notes, qualification answers, or call outcomes recorded during the service.
- Special category data: not requested and not permitted. Do not upload health, financial-account, biometric, or other sensitive data unless we have agreed to it in writing and put additional safeguards in place.
3. Your responsibilities as controller
You confirm that you have a lawful basis to collect the leads and to share them with us, that any required consents and notices are in place, and that contacting them complies with applicable law — including telemarketing and do-not-call rules such as the TCPA, and call-recording consent requirements in the relevant jurisdictions. Your instructions to us must be lawful.
4. Our obligations as processor
- Process personal data only on your documented instructions (your onboarding configuration, business rules, and support requests).
- Never sell, rent, or share the data, and never use it for our own purposes or to build our own marketing lists.
- Bind everyone with access — including agents — to confidentiality.
- Limit access to the agents and staff who need it to serve your account.
- Tell you if, in our opinion, an instruction would breach data protection law.
5. Security measures
- Encryption in transit; lead files held in private, access-controlled storage.
- Row-level access controls so a client’s data is only reachable by that client and their assigned team.
- No password sharing: access to your tools is granted by inviting our user, which you can revoke at any time. We do not store your credentials.
- Agent onboarding includes confidentiality and data-handling training.
- [ADD: MFA policy, device policy, background-check policy, and any certifications you obtain.]
6. Subprocessors
You authorize us to use the subprocessors below. We remain responsible for their performance, and we will give you at least [30] days’ notice before adding or replacing one, giving you a chance to object.
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel | Website and application hosting | United States / global edge |
| Supabase | Database, authentication, and lead-file storage | [SELECT YOUR REGION] |
| Stripe | Payment processing and card storage | United States / global |
| [EMAIL PROVIDER] | Transactional email (receipts, notifications) | [REGION] |
7. Data subject requests and breaches
If one of your leads contacts us to access, correct, or delete their data, we will not respond directly — we will refer them to you and assist you in responding, since the data is yours. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and within [72] hours, with the facts known at that time and the steps we are taking.
8. Deletion and return
On termination, or on your written request, we will delete or return your lead data and any copies within [30] days, except where we are legally required to retain it (for example, billing records needed for tax purposes). You can request deletion at any time from your portal or by contacting us.
9. Audits and international transfers
On reasonable notice and no more than once a year, we will provide the information needed to demonstrate compliance with this agreement. Where personal data is transferred outside its country of origin, we rely on Standard Contractual Clauses or another approved transfer mechanism.
10. Liability and contact
Liability under this agreement is subject to the limitations in our Terms of Service. Data protection contact: [PRIVACY CONTACT EMAIL], [NAMARI LEGAL ENTITY AND ADDRESS].
