Legal · DPA
Data Processing Agreement.
This is a template Data Processing Agreement describing the terms under which CogniLead processes personal data as your processor when you run outbound campaigns through it. It is a draft for review — not a signable contract, and not legal advice (see the disclaimer above) — until CogniLead GmbH completes incorporation. Have your Data Protection Officer and legal counsel review it before relying on it in production.
1. Overview
This DPA supplements the CogniLead Terms of Service and applies whenever CogniLead processes personal data on your behalf as part of running outbound campaigns on leads you supply. It does not apply to CogniLead's processing of your own account and billing data, which is a separate controller relationship covered by the Privacy Policy. For the broader GDPR posture this DPA sits under, see /legal/gdpr.
2. Parties and roles
- Controller: the customer — you decide who is contacted, what is sent, and why.
- Processor: CogniLead (operated by Medishift; CogniLead GmbH is in formation) — processes the recipient data you supply solely to run the campaigns you configure.
3. Processing purpose & scope
Processing under this DPA is limited to:
- Recipient contact data you submit via the dashboard or the
/api/v1/leadsAPI (name, email address, company, role, and any additional fields you choose to send). - Campaign content you author or generate through CogniLead's AI content scaffolding.
- Delivery, bounce, reply, suppression, and unsubscribe events produced by running your campaigns.
CogniLead does not source, enrich, or sell recipient data itself — you supply the leads; CogniLead runs the send. Processing does not extend to consumer or newsletter email, only B2B cold-adjacent outbound.
4. Processing on instructions
CogniLead processes personal data only on your documented instructions — as expressed through your campaign configuration, API calls, and dashboard actions — except where required to do otherwise by law, in which case CogniLead will inform you before processing unless that law prohibits it.
5. Sub-processors
You authorize CogniLead to engage the following sub-processors, consistent with the current Privacy Policy and GDPR page:
| Sub-processor | Function |
|---|---|
| Supabase | Authentication, multi-tenant Postgres database, Row Level Security |
| Amazon SES | Outbound and transactional email delivery; bounce/complaint notifications |
| Cloudflare | Application hosting and edge network |
| Stripe | Billing |
| phi-cloud | LLM inference for outbound personalization and content scaffolding |
CogniLead will give reasonable notice before adding or replacing a sub-processor that will process your data, and remains liable for each sub-processor's performance of its data-protection obligations.
6. Assistance with data subject rights
CogniLead will provide reasonable assistance to help you respond to data subject requests (access, rectification, erasure, objection) concerning the campaign data it processes on your behalf. In practice this means: erasure and access requests against campaign data are actioned through your dashboard or a support ticket, and objection requests are handled automatically and immediately by the suppression mechanism described in GDPR §5 — no manual intervention is required for a recipient's unsubscribe to take effect.
7. Security measures
CogniLead implements the technical and organizational measures described in full at /legal/security, including TLS 1.3 in transit, AES-256 at rest, Postgres Row Level Security keyed by tenant, MFA on the dashboard, and daily encrypted backups with a 30-day retention window.
8. Breach notification
CogniLead will notify you of a confirmed personal-data breach without undue delay and no later than 48 hours after discovery, by email to the address on your account and a banner in the dashboard — matching the commitment in Security §12. The notification will describe the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed.
9. Data residency & transfers
Primary tenant data is hosted in the EU (Supabase, eu-west-1). Where data must cross a border to reach a sub-processor listed above, CogniLead relies on appropriate safeguards such as Standard Contractual Clauses. Re-region of an existing tenant is available as a controlled operation via a service ticket.
10. Audit rights
You may request evidence of CogniLead's compliance with this DPA (such as the current security posture at /legal/security). CogniLead is not yet SOC 2 certified; the compliance roadmap is published at Security §10. A right to a more formal audit, and its mechanics, is a term for negotiation once the contracting entity is registered — see the disclaimer above.
11. Deletion on termination
On termination of your account, CogniLead will delete or return the personal data processed on your behalf, subject to the retention schedule in the Privacy Policy — a 30-day grace window for recovery before hard deletion, with suppression and unsubscribe entries retained indefinitely so a recipient who opted out is never re-contacted even after your account is deleted. Financial records are retained for 7 years as required by Swiss accounting and tax law, independent of account deletion.
12. Liability
Liability terms under this DPA follow the liability provisions of the underlying Terms of Service, once the contracting entity is registered and this template becomes executable. Nothing in this template narrows either party's statutory obligations under applicable data-protection law.