overwise.
How it works Compare Pricing FAQ
EN · DE
Sign in Start trial
How it works Compare Pricing FAQ
Sign in Start trial
EN · DE
DPA

Data Processing Addendum

Effective May 2026

Draft notice. This document is a placeholder. Counsel-reviewed copy will replace it before launch. Email tobias@overwise.com for the current binding agreement.
On this page
  1. 1. Definitions
  2. 2. Subject matter & duration
  3. 3. Data subject categories & data types
  4. 4. Security measures
  5. 5. Sub-processors
  6. 6. International transfers
  7. 7. Audit rights
  8. 8. Acceptance

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person processed by Overwise on behalf of the Customer.

"Processing" includes collection, storage, retrieval, transmission, and deletion.

"Sub-processor" means a third party Overwise engages to process Personal Data (see Section 5).

2. Subject matter & duration

This DPA governs Overwise's processing of Personal Data on your behalf as part of providing the service described at overwise.com. It applies for the duration of your subscription and survives termination for the data-retention windows specified in the Privacy Policy.

3. Data subject categories & data types

Data subjects: the prospects/leads you target via Overwise, plus your own team members with Overwise accounts.

Personal Data types: name, business email, business phone, public LinkedIn profile, public Instagram handle, company affiliation, role, public-source enrichment signals (hiring page, recent funding, tech stack), and outreach correspondence (drafts, sent messages, replies).

4. Security measures

Encryption at rest (AES-256) for all stored Personal Data. TLS 1.3 for all data in transit. OAuth-based authentication (no password storage). EU-Central data residency (Frankfurt). Access logs retained 90 days. Full security architecture is documented at /security.

5. Sub-processors

The current sub-processor list:

  • Anthropic (LLM drafting + classification)
  • OpenAI (embeddings for voice extraction)
  • MongoDB Atlas (storage)
  • Stripe (billing)
  • Postmark (transactional email)
  • Apify (lead-discovery scraping)

We will provide 30 days' written notice before adding or replacing a sub-processor. You may object to material changes; if we can't accommodate, you may terminate without penalty.

6. International transfers

Personal Data is primarily stored in the EU (Frankfurt). Some sub-processors are based in the US (Anthropic, OpenAI, Stripe, Postmark). For these transfers, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework where applicable. Copies of executed SCCs available on request.

7. Audit rights

You may audit our compliance with this DPA, no more than once per year and with 30 days' written notice. We'll provide reasonable cooperation, including access to relevant SOC 2 reports (when available — currently in progress, target Q4 2026) or equivalent third-party audit summaries.

8. Acceptance

This DPA is automatically incorporated into the agreement of any Founder Team plan customer. Starter and Growth plan customers may request DPA execution by emailing tobias@overwise.com; we respond within 5 business days.

overwise.

The AI sales agent for B2B SaaS founders. Find leads, run outbound, your way.

Product

  • How it works
  • Compare
  • Pricing
  • FAQ

Company

  • About
  • Blog
  • Changelog
  • Contact

Legal

  • Privacy
  • Terms
  • DPA
  • Security
© 2026 Overwise. All rights reserved. Last updated · May 2026