This Data Processing Agreement (“DPA”) forms part of every Agreement between DigitalHeroes.global OÜ and a Client under the Client Terms of Service. It applies automatically whenever the Agency processes personal data on the Client’s behalf. It meets the requirements of Article 28 of the GDPR.
1.1 The Client is the controller, and DigitalHeroes.global OÜ, registry code 14650687, Sepapaja 6, Tallinn 15551, Estonia (the “Agency”) is the processor, of the personal data described in Annex 1 (“Client Personal Data”). Where the Client itself acts as a processor for its own customers, the Agency acts as its sub-processor, and the Client confirms that its controller has authorised this.
1.2 For clients subject to Singapore’s Personal Data Protection Act 2012, the Agency acts as a “data intermediary” and this DPA sets out the terms of that processing. For clients subject to the UK GDPR, references to the GDPR include the UK GDPR.
1.3 Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given in the GDPR. Other capitalised terms have the meaning given in the Client Terms of Service.
2.1 The Agency processes Client Personal Data only on the Client’s documented instructions, including those in the Agreement, the Order and written messages from the Client’s authorised contacts, unless EU or Member State law requires otherwise. In that case, the Agency informs the Client before processing, unless the law prohibits this.
2.2 The Agency informs the Client if, in its opinion, an instruction breaches data protection law. The Agency may suspend that instruction until the Client confirms or changes it.
2.3 The Client is responsible for the lawfulness of its instructions and of the personal data it provides or collects through the Services, including having a lawful basis, providing privacy information to data subjects, and obtaining any consents required for direct marketing and tracking.
3.1 The Agency ensures that everyone authorised to process Client Personal Data (employees, freelancers and subcontractors) is bound by confidentiality obligations and only has access to the data they need for their tasks.
4.1 The Agency implements appropriate technical and organisational measures to protect Client Personal Data, taking into account the state of the art, costs, and the nature and risks of the processing. The current measures are described in Annex 2. The Agency may update them as long as the overall level of protection is not reduced.
4.2 The Client is responsible for the security of its own systems and accounts, including access it grants, password policies and two-factor authentication on accounts it owns.
5.1 The Client gives the Agency general authorisation to use sub-processors. The Agency provides the current list of its sub-processors to the Client on request (see Annex 3).
5.2 The Agency informs the Client by email of any intended addition or replacement of a sub-processor at least fourteen (14) days in advance. The Client may object on reasonable data protection grounds within that period. If the parties cannot find a solution, the Client may terminate the affected Services without penalty as its sole remedy.
5.3 The Agency imposes data protection obligations on each sub-processor that are substantially the same as those in this DPA, and remains responsible to the Client for their performance.
5.4 Tools and platforms that the Client has chosen and contracted itself (for example its own CRM, email platform, ad accounts or website host) are not sub-processors of the Agency. When the Agency works inside those tools, it does so under the Client’s own contract with that provider.
6.1 The Agency’s team members, freelancers and sub-processors may be located outside the European Economic Area, including in countries that do not have an adequacy decision from the European Commission.
6.2 The Agency transfers Client Personal Data outside the EEA only where a valid transfer mechanism under Chapter V of the GDPR is in place, such as an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified) or the Standard Contractual Clauses adopted by the European Commission, together with any supplementary measures required. The Client authorises such transfers.
6.3 Where the Client is established in the UK or Singapore, transfers are made in line with the UK GDPR (including the UK International Data Transfer Addendum where needed) or the Singapore PDPA transfer rules respectively.
7.1 Taking into account the nature of the processing, the Agency assists the Client by appropriate technical and organisational measures in responding to requests from data subjects. If the Agency receives such a request directly, it forwards it to the Client without undue delay and does not respond itself unless instructed.
7.2 The Agency provides reasonable assistance with data protection impact assessments, prior consultations with supervisory authorities and security obligations, as far as these relate to the Agency’s processing.
7.3 Assistance that goes beyond what is reasonable, or is needed because of the Client’s own actions, may be charged at the Agency’s hourly rate.
8.1 The Agency notifies the Client without undue delay, and where possible within forty-eight (48) hours, after becoming aware of a personal data breach affecting Client Personal Data. The notice includes the information the Agency has at that moment, and more information follows as it becomes available.
8.2 The Agency takes reasonable steps to contain the breach and supports the Client in meeting its own notification duties. The Client decides whether and how to notify authorities and data subjects.
9.1 When the Services end, the Agency deletes or returns, at the Client’s choice, all Client Personal Data within thirty (30) days, and deletes existing copies, unless EU or Member State law requires storage. If the Client makes no choice within that period, the Agency may delete the data. Data in backups is deleted in the normal backup cycle and kept protected until then.
10.1 The Agency makes available to the Client the information reasonably necessary to demonstrate compliance with this DPA, primarily through written answers, documentation and available certifications of its sub-processors.
10.2 If that information is not sufficient, the Client may audit the Agency’s compliance once per year, with at least thirty (30) days’ written notice, during normal business hours, without disrupting the Agency’s operations and subject to confidentiality. The Client bears the costs of the audit, including the Agency’s reasonable time. Audits by a supervisory authority are always allowed.
11.1 Each party’s liability under this DPA is subject to the limitations in the Client Terms of Service, to the extent permitted by law. Nothing limits either party’s liability towards data subjects under Article 82 GDPR.
11.2 This DPA applies for as long as the Agency processes Client Personal Data. If this DPA conflicts with the Client Terms of Service on a data protection matter, this DPA prevails.
Item | Description |
Subject matter and purpose | Performing the Services under the Agreement: paid advertising, marketing automation and CRM, email and messaging campaigns, SEO and AI search, website design and development, analytics and reporting. |
Nature of processing | Collection through forms and integrations, storage, organisation, segmentation, enrichment, matching for advertising audiences, sending communications, analysis, reporting, transfer between the Client’s tools, deletion. |
Categories of data subjects | The Client’s customers, prospects and leads, newsletter subscribers, website visitors, social media users who engage with the Client, the Client’s staff and business contacts. |
Categories of personal data | Contact data (name, email, phone, address, company, job title), CRM data (pipeline stage, notes, tags, interaction history), communication content and preferences, consent records, online identifiers (cookie IDs, IP address, device data, click IDs), order and transaction data where connected, and any other data the Client chooses to process through the Services. |
Special category data | Not intended. The Client must not provide special category data (such as health data) or data about children without prior written agreement with the Agency. |
Duration | For the term of the Agreement plus the deletion period in section 9. |
The Agency uses sub-processors in the following categories: CRM and marketing automation platforms; workflow automation and hosting; email, file storage and collaboration; project management and meeting tools; reporting dashboards; AI assistants used with business settings; lead data enrichment; and the Agency’s own team members and freelancers. The full list, with each sub-processor’s name, purpose and location, is provided to the Client on request by email to team@digitalheroes.global.