Data Processing Agreement
The Article 28 GDPR agreement governing personal data that Qualify AI processes on your behalf.
| Processor | Saltvision BV, Waregemsesteenweg 157a, 9770 Kruisem, Belgium — trading as Qualify AI (the “Processor”, “we”, “us”) |
| Enterprise & VAT number | BE 0786.771.552 — Crossroads Bank for Enterprises (KBO/BCE), Belgium |
| Contact | sales@qualifyai.eu · +32 56 62 51 95 Waregemsesteenweg 157a, 9770 Kruisem, Belgium |
| Controller | The Customer organisation that holds a subscription to the Service (the “Controller”, “you”) |
| Version | 1.2 |
| Effective date | 1 August 2026 |
| Forms part of | The Terms & Conditions of Service, Section 10.2 |
| Related documents | Sub-processor list · Privacy Policy |
Contact: sales@qualifyai.eu · +32 56 62 51 95 · Waregemsesteenweg 157a, 9770 Kruisem, Belgium
1. Scope and roles
This Data Processing Agreement (“DPA”) governs the processing of personal data by the Processor on behalf of the Controller in connection with the Qualify AI platform (the “Service”), as described in the Terms & Conditions.
The parties agree that, in respect of Customer Personal Data, the Controller is the data controller and the Processor is a data processor within the meaning of the GDPR. The Controller determines the purposes and means of the processing — in particular which prospects are contacted, on what basis, and with what message. Individuals the Controller invites to use the Service act under the Controller’s authority.
Where the Processor processes personal data for its own purposes — account administration, billing, security, and improvement of the Service in aggregated form — it acts as a controller and its Privacy Policy applies. That processing is outside the scope of this DPA.
2. Definitions
- GDPR — Regulation (EU) 2016/679, together with any national law implementing or supplementing it, including the Belgian Act of 30 July 2018.
- Customer Personal Data — personal data within Customer Data, as defined in the Terms, that the Processor processes on the Controller’s behalf. Annex 1 describes it.
- Data Subject, Processing, Personal Data Breach, Supervisory Authority — as defined in Article 4 GDPR.
- Sub-processor — a third party engaged by the Processor to process Customer Personal Data.
- SCCs — the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
3. Processing on documented instructions
The Processor will process Customer Personal Data only on the Controller’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, the Processor will inform the Controller before processing, unless that law prohibits it on important grounds of public interest.
The Controller’s instructions are given by: this DPA and the Terms; the configuration, campaign settings and Business Brief the Controller enters into the Service; the actions the Controller and its users take through the dashboard and interfaces; and any further written instruction the parties agree.
The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law. The Processor is not obliged to carry out an instruction it reasonably considers unlawful, and may suspend the affected processing until the instruction is withdrawn or amended.
The Processor will not sell Customer Personal Data, will not use it for its own marketing, and will not use it to train artificial-intelligence models except where the Controller has explicitly opted in as described in Section 13.1 of the Terms.
4. Controller obligations
The Controller warrants that:
- it has a valid lawful basis under Article 6 GDPR for the processing it instructs, including for each contact it initiates through the Service, and has documented any legitimate-interest assessment it relies on;
- it has provided the information required by Articles 13 and 14 GDPR to the individuals whose data it processes, or that an exemption applies;
- its instructions comply with data protection law and with the e-privacy and marketing rules of every market it addresses;
- it has the right to upload any recipient list it supplies to the Service; and
- it will not instruct processing of special categories of personal data under Article 9 GDPR, or of data relating to criminal convictions, through the Service.
5. Confidentiality
The Processor ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to provide the Service or to comply with law.
6. Security
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. Those measures are described in Annex 2.
The Processor may update the measures over time, provided the level of protection is not reduced. The Controller is responsible for the security of the elements within its own control, including account credentials, user access rights, and the email account it connects to the Service.
7. Sub-processors
The Controller gives the Processor a general written authorisation to engage Sub-processors, subject to this Section.
The Sub-processors engaged at the effective date of this DPA are published at qualifyai.eu/sub-processors, which forms Annex 3 to this DPA and is incorporated by reference.
Before a new Sub-processor begins processing Customer Personal Data, the Processor will update that page and give notice. The Controller may object on reasonable data-protection grounds within thirty (30) days of the notice. The parties will discuss the objection in good faith; if no workable alternative can be found, the Controller may terminate the affected part of the Service without penalty, and the Processor will refund any prepaid fees covering the unused remainder of the term. To receive change notices by email, write to sales@qualifyai.eu.
The Processor imposes on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-processor’s obligations.
8. International transfers
The Processor is established in Belgium and processes Customer Personal Data within the European Economic Area, except where a Sub-processor listed in Annex 3 is located outside it.
Where Customer Personal Data is transferred outside the EEA, the transfer is made under an adequacy decision of the European Commission or, in its absence, under the SCCs, together with any supplementary measures required following the judgment in Schrems II (Case C-311/18). Where the SCCs apply between the Processor and a Sub-processor, Module Three (processor to sub-processor) applies. The Controller authorises the Processor to enter into such clauses with Sub-processors on the Controller’s behalf.
The transfer mechanism applying to each Sub-processor is stated in Annex 3. The Processor will make available a copy of the relevant safeguards on request, redacted for commercial confidentiality where necessary.
9. Assistance with data subject rights
Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR.
The Service provides the Controller with functions to search, view, export, correct, suppress and delete prospect records directly, which will in most cases allow the Controller to respond without our involvement. Where it does not, we will provide reasonable additional assistance.
If a Data Subject contacts the Processor directly regarding data processed on the Controller’s behalf, the Processor will not respond substantively, will refer the Data Subject to the Controller, and will inform the Controller without undue delay.
10. Assistance with security, breach and impact assessments
Taking into account the nature of processing and the information available to it, the Processor will assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR — security of processing, notification of personal data breaches to the Supervisory Authority and to Data Subjects, data protection impact assessments, and prior consultation.
11. Personal data breach
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, so far as known at the time: the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for further information. Where the information cannot be provided at once, it will be provided in phases without undue further delay.
The Processor will not notify a Supervisory Authority or Data Subjects on the Controller’s behalf unless the Controller instructs it to, or the law requires the Processor to do so in its own right.
12. Deletion and return of data
On termination or expiry of the subscription, the Processor will, at the Controller’s choice, delete or return Customer Personal Data. The Controller may export its data through the Service at any time before termination.
Unless the Controller requests return within thirty (30) days of termination, the Processor will delete Customer Personal Data from active systems within that period, and from backups within ninety (90) days, at which point backup copies expire on their normal rotation.
The Processor may retain Customer Personal Data where Union or Member State law requires it, and will retain suppression records — the addresses of individuals who have unsubscribed, objected or been suppressed — for as long as necessary to keep honouring those opt-outs, since deleting them would cause those individuals to be contacted again. Suppression records are limited to what is necessary for that purpose and are not used for any other.
13. Audit and demonstration of compliance
The Processor will make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Controller or another auditor it mandates.
In practice, the Processor will satisfy this obligation in the first instance by providing this DPA, Annex 2, the Sub-processor list, and written responses to a reasonable security questionnaire. Where that is genuinely insufficient for the Controller to meet its own obligations, or where a Supervisory Authority requires it, the Controller may conduct an on-site audit, subject to: at least thirty (30) days’ written notice; no more than once in any twelve-month period, except following a Personal Data Breach or where a Supervisory Authority requires it; conduct during normal business hours and in a manner that does not disrupt the Service or compromise other customers’ confidentiality; the auditor being bound by confidentiality and not being a competitor of the Processor; and the Controller bearing its own and the Processor’s reasonable costs.
14. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions set out in Section 19 of the Terms & Conditions. Nothing in this DPA limits liability that cannot be limited under mandatory law, including liability to Data Subjects under Article 82 GDPR.
15. Duration
This DPA takes effect when the Controller accepts the Terms and continues for as long as the Processor processes Customer Personal Data on the Controller’s behalf. The obligations in Sections 5, 8, 12 and 14 survive termination for as long as the Processor holds any Customer Personal Data.
16. Order of precedence, changes and governing law
In the event of a conflict on data-protection matters, this DPA prevails over the Terms & Conditions and over any order. Where the SCCs apply and conflict with this DPA, the SCCs prevail.
The Processor may update this DPA where necessary to reflect a change in law, in the Service, or in Sub-processors, provided the change does not reduce the level of protection. Material changes will be notified in accordance with Section 22 of the Terms.
This DPA is governed by Belgian law, and disputes are subject to the jurisdiction set out in Section 23 of the Terms, without prejudice to the mandatory jurisdiction rules of the GDPR.
Annex 1 — Details of the processing
Subject matter
The provision of the Qualify AI B2B outreach automation platform to the Controller, as described in the Terms & Conditions.
Duration
The term of the Controller’s subscription, plus the deletion periods set out in Section 12.
Nature and purpose of the processing
Collection, organisation, storage, retrieval, consultation, use, transmission, restriction and erasure of business contact data, for the purposes of: identifying prospects matching the Controller’s Ideal Customer Profile; scoring and prioritising them; generating and storing outreach and follow-up content; transmitting approved messages through the email account the Controller connects; recording engagement and replies; analysing replies; and presenting pipeline reporting to the Controller.
Categories of Data Subjects
- Prospects — employees, officers and representatives of the businesses the Controller targets
- Recipients on lists the Controller uploads to the Service
- Individuals who reply to the Controller’s outreach
- The Controller’s own Authorised Users, in relation to their activity within the Service
Categories of personal data
- Identity and role — first and last name, job title, seniority
- Business contact details — business email address and, where available, professional profile links and business telephone
- Employer information — company name, industry, size, location, website
- Content — outreach messages generated, edited and sent; inbound replies and their metadata; notes and dispositions recorded by the Controller
- Engagement data — message opens, link clicks, reply and unsubscribe events, with associated timestamps and, where tracking is enabled, the recipient’s IP address and user agent at the moment of opening
- Derived data — AI-generated qualification scores, reasoning, sentiment and intent classifications
- Suppression data — email addresses of individuals who have opted out or been suppressed
- User account data — for the Controller’s Authorised Users: name, business email, role and activity logs
Special categories of personal data
None. The Service is not intended for, and the Controller must not instruct, processing of special categories of personal data under Article 9 GDPR or data relating to criminal convictions.
Frequency of the processing
Continuous, for the duration of the subscription.
Annex 2 — Technical and organisational measures
The Processor maintains the measures below in accordance with Article 32 GDPR. They may be updated over time provided the level of protection is not reduced.
Access control and authentication
- Individual named accounts; shared logins are not permitted for administrative access.
- Role-based permissions separating platform administrators from customer administrators and their users.
- Administrative access to production systems is limited to the smallest practicable number of named personnel.
- Credentials for third-party services are held in the credential stores of the relevant platforms rather than in application source code.
- Access rights are reviewed when a person’s role changes and revoked promptly when it ends.
Tenant separation
- The platform is multi-tenant. Every record carries a tenant identifier and application queries are scoped to the requesting tenant, so one customer cannot read or modify another customer’s data.
- Outreach is dispatched through the individual email account each customer connects, so sending identity is separated per tenant.
Encryption
- All traffic between users, the platform and its service providers is encrypted in transit using TLS.
- Data at rest is encrypted by the underlying hosting and workflow platforms using their standard storage-level encryption.
Resilience and backup
- The application database is backed up by the hosting provider on its standard schedule, with point-in-time restore available within the provider’s retention window.
- Backups inherit the storage-level encryption of the hosting platform.
Logging and monitoring
- Significant actions within the platform — approvals, rejections, sends, configuration changes and administrative actions — are recorded in an activity log with actor and timestamp.
- Automated pipeline failures raise alerts to the operations contact.
- Acceptance of the Terms is recorded with document version and timestamp.
Data minimisation and purpose limitation
- Only business contact data necessary for B2B outreach is collected; the Service does not seek personal contact details or special-category data.
- Customer Personal Data is not used for the Processor’s own marketing and is not sold.
- Customer Personal Data, prompts and Business Briefs are not used to train AI models unless the Controller opts in; the Processor’s AI provider is engaged under commercial API terms under which inputs are not used for model training.
Outreach safeguards
- A platform-level suppression list prevents contact with addresses that have unsubscribed, objected or been suppressed, applied before every send.
- An unsubscribe mechanism is included in outgoing messages and cannot be disabled by the Controller.
- Daily sending caps and a graduated warm-up schedule limit volume per connected mailbox.
- Open-tracking can be suppressed by recipient jurisdiction, and fails closed — suppressing the pixel — where the recipient’s country cannot be determined.
Organisational measures
- Personnel with access to Customer Personal Data are bound by confidentiality obligations.
- Sub-processors are assessed before engagement and bound by written data-protection terms.
- A documented procedure governs the identification, assessment and notification of personal data breaches, including the 48-hour notification commitment in Section 11.
- Deletion and return of Customer Personal Data follow the timetable in Section 12.
Annex 3 — Sub-processors
The current list of Sub-processors, with the purpose, categories of data, location and transfer mechanism for each, is maintained at qualifyai.eu/sub-processors and forms part of this DPA. Changes are notified in accordance with Section 7.
Qualify AI — Data Processing Agreement, version 1.2. Change in 1.2: the Processor is confirmed as Saltvision BV, with its registered office and its enterprise and VAT number stated in full, and the “provider details pending” notice removed; no substantive term has changed. Change in 1.1: the Processor’s legal name, registered office and enterprise number were shown as pending confirmation; no substantive term changed. Incorporated into the Terms & Conditions of Service at Section 10.2. For a countersigned copy, contact sales@qualifyai.eu.
