Data Processing Agreement
Customer-directed processing, data protection assistance and the relationship to your executed agreement.
Existing accepted agreements and customer rights continue. This publication does not make a material contractual change effective before any required notice and acceptance. Contact Defrost.
Roles and scope
This schedule describes processing performed by DEFROST LLC on a customer’s documented instructions under the applicable service agreement. The customer controls that processing and Defrost processes it for the customer. Each party remains responsible for processing for which it independently determines the purposes and means.
This proposed revision does not replace an executed DPA. The executed agreement controls its application, precedence, liability and signature requirements.
Processing details
Customer-directed processing includes sourcing and verifying professional contacts, researching business context, generating drafts, storing approvals, sending messages, handling replies and opt-outs, reporting, exporting and deleting records. Processing continues for the service period and the applicable return/deletion period.
Data subjects include workspace users, professional prospects and correspondents. Data includes names, business contact and employer details, source and verification records, research and citations, outreach instructions, message content, delivery/reply events, and limited suppression records. Domain registration also requires registrant contact information. Sensitive data and children’s information are not intended inputs.
Customer instructions
Defrost processes personal data on documented customer instructions, including instructions expressed through authorized product settings. The customer is responsible for the lawfulness, accuracy, and scope of those instructions and for providing required notices.
If an instruction appears to violate applicable data protection law, Defrost may pause the affected processing and request clarification. Any additional processing requires a lawful basis and documented authority.
Confidentiality and security
Access to customer personal data is limited to authorized personnel and service providers for their duties, subject to the confidentiality terms applicable to them. Defrost implements tenant-scoped authorization and authenticated encryption for supported stored credentials. The security summary describes the implemented controls and limits.
This schedule does not claim an independent audit, certification, completed penetration test, universal audit trail or verified recovery service level.
Rights assistance and incidents
Taking account of the nature of processing and information available, Defrost assists the customer with applicable individual-rights requests, security obligations, impact assessments and regulator inquiries under the governing agreement and applicable law. For a personal-data breach affecting customer data, Defrost notifies the customer without undue delay after becoming aware, and provides available information and subsequent updates needed to respond.
Use privacy@defrostmail.com for data-protection requests and support@defrostmail.com for urgent security reports. Any shorter timing already agreed remains applicable.
Sub-processors and transfers
Our provider information describes provider categories and how to obtain the service-specific schedule. Contact privacy@defrostmail.com for the identities, purposes, locations and relevant transfer information for the processors and sub-processors involved in your service. We provide the information required for customer oversight under applicable law and the governing agreement.
Appointment, contractual protections, change notice, objection and transfer safeguards remain governed by the executed agreement and applicable law. Any agreed advance notice, including a 30-day requirement, remains in force; asking for the schedule is not a substitute for a required proactive notice. The application database is in the United States.
Return and deletion
Contact privacy@defrostmail.com for return, export or deletion of covered personal data. Defrost assists with verified instructions at the end of covered services or as otherwise required by the governing agreement and law. Existing workspace export tools remain available.
We verify the requester’s authority, arrange an appropriate delivery method and explain the scope of the response and any lawful retention exception. Deletion covers applicable application records, with provider copies and backups handled separately. A limited suppression record prevents renewed unwanted outreach.
Existing accepted orders, terms and executed DPAs continue to govern the processing they cover. This page does not remove an agreed deletion period, export right, service level, notice, objection or acceptance requirement. Any material contractual change follows the applicable notice and acceptance process.
Audit and recovery evidence
Contact privacy@defrostmail.com for information supporting your contractual audit rights, security assessment, retention or recovery questions. We provide relevant available evidence with its scope and date, while protecting other customers and security-sensitive material. Appropriate confidentiality arrangements may apply to additional commercial or technical material; they do not replace or restrict a statutory access right.
A security summary does not create a certification or recovery service level. Previously agreed audit, deletion and recovery commitments remain applicable.
Term, liability, and contact
An executed DPA continues for the processing it covers. Its survival, signature, precedence, liability, audit and termination terms continue unchanged by this proposed schedule, including any previously agreed countersignature deadline.
DPA questions: privacy@defrostmail.com.