Data Processing Addendum
Effective
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person processed by Overwise on behalf of the Customer.
"Processing" includes collection, storage, retrieval, transmission, and deletion.
"Sub-processor" means a third party Overwise engages to process Personal Data (see Section 5).
2. Subject matter & duration
This DPA governs Overwise's processing of Personal Data on your behalf as part of providing the service described at overwise.com. It applies for the duration of your subscription and survives termination for the data-retention windows specified in the Privacy Policy.
3. Data subject categories & data types
Data subjects: the prospects/leads you target via Overwise, plus your own team members with Overwise accounts.
Personal Data types: name, business email, business phone, public LinkedIn profile, public Instagram handle, company affiliation, role, public-source enrichment signals (hiring page, recent funding, tech stack), and outreach correspondence (drafts, sent messages, replies).
4. Security measures
Encryption at rest (AES-256) for all stored Personal Data. TLS 1.3 for all data in transit. OAuth-based authentication (no password storage). EU-Central data residency (Frankfurt). Access logs retained 90 days. Full security architecture is documented at /security.
5. Sub-processors
The current sub-processor list:
- Anthropic (LLM drafting + classification)
- OpenAI (embeddings for voice extraction)
- MongoDB Atlas (storage)
- Stripe (billing)
- Postmark (transactional email)
- Apify (lead-discovery scraping)
We will provide 30 days' written notice before adding or replacing a sub-processor. You may object to material changes; if we can't accommodate, you may terminate without penalty.
6. International transfers
Personal Data is primarily stored in the EU (Frankfurt). Some sub-processors are based in the US (Anthropic, OpenAI, Stripe, Postmark). For these transfers, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework where applicable. Copies of executed SCCs available on request.
7. Audit rights
You may audit our compliance with this DPA, no more than once per year and with 30 days' written notice. We'll provide reasonable cooperation, including access to relevant SOC 2 reports (when available — currently in progress, target Q4 2026) or equivalent third-party audit summaries.
8. Acceptance
This DPA is automatically incorporated into the agreement of any Founder Team plan customer. Starter and Growth plan customers may request DPA execution by emailing tobias@overwise.com; we respond within 5 business days.