1. Parties, scope and precedence
This DPA is between the customer identified in the TargetWise account or order form and GDB HOLDINGS LIMITED, whose company details appear in the Terms. ‘Customer Personal Data’ means personal data processed by TargetWise solely on that customer’s behalf to supply the contracted service. The customer is controller, or a processor authorised by its controller; TargetWise is processor or subprocessor respectively.
Applicable Data Protection Law includes the UK GDPR and Data Protection Act 2018, EU GDPR where applicable, and other applicable privacy laws. Terms such as controller, processor and personal data breach have their meaning under that law. Account administration, billing, service security and independently determined professional-data activities are controller activities described in the Privacy Notice.
This DPA takes priority over conflicting processor provisions in the service agreement. Mandatory transfer clauses prevail over this DPA. The parties’ service-agreement liability provisions apply only to the extent consistent with applicable law and those clauses.
2. Processing schedule
The following schedule describes standard instructed processing. An order form may specify narrower fields, operations, jurisdictions or retention requirements. The customer must not send special-category or criminal-offence data unless a separate written agreement expressly permits it.
| Item | Description |
|---|---|
| Subject matter and purpose | Customer-requested business-data lookup, matching, enrichment, result delivery and related support |
| Duration | The service term and the limited period needed to return or delete Customer Personal Data under section 8 |
| Nature of processing | Receipt, validation, transmission, matching, retrieval, temporary storage, organisation, disclosure to the customer and deletion |
| Data subjects | Professionals and business representatives identified in customer queries, and customer personnel whose data is supplied for instructed support |
| Personal-data types | Names, business contact identifiers, professional profile URLs, employer and role details, work emails, business phones, company context and related query or support information |
| Frequency | On demand or as initiated by the customer’s authorised integrations |
| Customer instructions | The agreement, enabled account settings, authorised API or dashboard requests and additional lawful written instructions accepted within the service scope |
3. Instructions and confidentiality
TargetWise will process Customer Personal Data only on documented instructions, including instructions about international transfers, unless law requires otherwise. Where law requires processing outside instructions, we will inform the customer before processing unless legally prohibited. We will promptly inform the customer if, in our opinion, an instruction infringes Applicable Data Protection Law and may pause the affected operation while it is resolved.
We will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty. Access is limited to the service purpose. We will not sell Customer Personal Data processed under this DPA, combine it into an independently licensed customer-list database or use it to train a general-purpose model.
The customer is responsible for lawful instructions, necessary notices and permissions, data minimisation and the authority to appoint us. It remains responsible for processing it controls and for responding to individuals, subject to our assistance duties below.
4. Security and personal data breaches
Taking account of the nature, scope, context and purposes of processing and the risks to individuals, TargetWise will implement appropriate technical and organisational measures under applicable law. These include the controls in the security schedule below and proportionate arrangements to maintain confidentiality, integrity, availability and restoration capability, and to assess their effectiveness.
We will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notice will not wait for the completion of an investigation. We will provide available information about the nature of the breach, affected data and individuals where known, likely consequences, a contact point, and measures taken or proposed. Information may be provided in phases as it becomes available.
We will take reasonable steps to contain and remediate the incident and assist the customer with its assessment and notification obligations. A notification is not an admission of liability. The customer decides its regulator and individual notifications unless the law independently requires us to notify.
5. Individual rights and compliance assistance
Taking account of the nature of processing, we will assist the customer through appropriate technical and organisational measures with requests for access, correction, erasure, restriction, portability and objection. We will promptly notify the customer of a request relating to its Customer Personal Data and will not substantively respond on its behalf unless authorised or legally required.
Taking account of the processing and information available to us, we will assist with security obligations, breach notifications, data-protection impact assessments and prior regulator consultations. The parties will agree reasonable arrangements for exceptional assistance outside standard service support; a fee discussion will not excuse a mandatory obligation or delay time-critical incident information.
6. Subprocessors and changes
The customer gives general written authorisation for the relevant subprocessors identified in the published provider register. We will appoint subprocessors under written terms imposing substantially the same applicable data-protection obligations as this DPA, and remain responsible to the customer for their performance of those obligations.
We will give notice to the customer’s account contact at least 15 days before an intended addition or replacement that will process Customer Personal Data, identifying the provider and service. A page update alone does not replace that notice. The customer may object during that period on reasonable, documented data-protection grounds.
We will discuss a reasonable alternative or mitigation before the change takes effect for the affected processing. If the parties cannot resolve the objection, the customer may terminate the affected service and receive a proportionate refund of unused prepaid fees. An independent controller or data licensor is not a subprocessor merely because its data appears in a result; actual processing roles determine the applicable agreement.
7. International transfers and assurance
TargetWise will not make a restricted transfer of Customer Personal Data without a valid mechanism under Applicable Data Protection Law. Depending on the recipient and destination, this may be an applicable adequacy decision, the European Commission’s 2021 Standard Contractual Clauses, the UK Addendum or the UK International Data Transfer Agreement, together with required assessments and supplementary measures.
Where clauses are required, the parties must identify the actual exporter, importer and roles, select the appropriate module and complete the required annexes, options, processing details, security measures and subprocessor schedule before the restricted transfer. This web page does not claim that merely naming the clauses completes a transfer agreement. The relevant execution copy and safeguards are available through office@targetwise.ai.
We will make information necessary to demonstrate compliance available to the customer and allow and contribute to audits, including inspections, by the customer or its independent auditor. Evidence review is normally the first step. Audits must protect other customers’ information, use reasonable notice and avoid unnecessary disruption. An annual routine schedule may be agreed, but does not restrict audits required by a regulator, law or a substantiated compliance concern.
8. Return and deletion at the end of service
At the end of the relevant processing services, at the customer’s choice, we will return or delete Customer Personal Data and delete existing copies unless applicable law requires storage. The customer should communicate its choice before termination so a secure return can be arranged. In the absence of a return instruction, deletion is the default. We will confirm the handling on request.
Any copy that cannot immediately be removed from an isolated backup remains protected, is excluded from ordinary use and is deleted through the applicable backup replacement process. If restored for recovery, the deletion instruction must be reapplied. Lawfully retained copies are restricted to their legally required purpose; ordinary commercial convenience is not an exception to deletion.
Controller records retained independently for invoices, legal duties or a necessary suppression identifier are governed by the Privacy Notice. They do not extend our entitlement to retain Customer Personal Data processed solely on instructions.
9. Security schedule
The standard application uses the following technical controls. Infrastructure evidence, backup arrangements, review records and any additional requirements can be requested for a procurement review. A certification or exclusive data-residency commitment applies only where expressly evidenced and agreed.
| Control | Standard application measure |
|---|---|
| Access | WorkOS authentication, workspace ownership checks, authenticated dashboard and API requests |
| API credentials | Workspace-specific keys, one-time full-key display, stored keyed digests and revocation |
| Provider credentials | Secrets applied on the server to fixed provider connections, not exposed in customer responses |
| Saved results | AES-256-GCM encryption with user and workspace context; creator-only retrieval and a 30-day access window |
| Transmission and validation | Encrypted connections in production, accepted-input validation, request and response size limits and provider timeouts |
| Operational records | Request IDs and usage metadata support investigation without requiring routine retention of full API inputs or results |
Email office@targetwise.ai. For privacy requests, include only the details needed to identify the relevant record.