Data processing addendum
Where you use GTM for One to process personal data of people in the EU, UK or a comparable regime, this addendum applies and forms part of the terms.
Roles
For the business contact data you research and email, you are the controller and GTM for One is the processor. You decide who is contacted and why; we process on your instruction. For your own account data we are the controller, and the privacy policy covers it.
Scope of processing
- Subject matter: B2B prospecting and outreach.
- Duration: until you delete the data or stop using the service.
- Categories of data: name, job title, employer, business email address, public professional profile links, and company firmographics.
- Categories of data subject: employees, founders and decision-makers at businesses you target.
- No special categories. The service is not designed for, and must not be used for, data revealing health, beliefs, biometrics or comparable categories.
Our obligations
- Process only on your documented instruction, which the product itself expresses.
- Keep credentials confidential and encrypted. Mailbox passwords use AES-256-GCM at rest and are never returned to any browser.
- Assist you in responding to data subject requests within the statutory window.
- Notify you without undue delay of a personal data breach affecting your data.
- Delete your data on request, except the one-way hashes that enforce opt-outs.
- Make available what you reasonably need to demonstrate compliance.
Sub-processors
GTM for One calls third-party providers to do its work. Under a bring-your-own-key model these are your accounts under your contracts with them, and they act on your instruction as much as ours. Typically: an LLM gateway for research and drafting, search providers for company discovery, and email-finding providers for address resolution. Which ones are used is determined by the keys you connect, so you control the list.
International transfers
The service is operated from India, and providers may process data in other countries. Where required, transfers rely on Standard Contractual Clauses or an equivalent mechanism. You should confirm the transfer terms of each provider whose key you connect, since your contract with them governs.
Security
- Credentials and secrets encrypted at rest; secrets never sent to the browser.
- Suppression list stored as one-way hashes, so it cannot be reversed into a mailing list.
- Transport encryption for all provider calls and for SMTP and IMAP connections.
- Database access restricted to the application and the operator.
Your obligations
You warrant that you have a lawful basis for the outreach you send, that your use is limited to genuine B2B communication in line with the acceptable use policy, and that any list you import was obtained lawfully and may be used this way.