GoWarm
  • Home
  • GoWarm CRM
  • GoWarm Work
  • Pricing
  • GoWarm Insights
  • Book a Demo
Legal

Data Processing Addendum

Last updated: 1 June 2026

This Data Processing Addendum (“DPA”) forms part of the Master Subscription Agreement between DeepConnect Technologies Inc. (“DeepConnect”) and the customer that accepts it (“Customer”) (the “Agreement”) and governs DeepConnect’s processing of Personal Data on Customer’s behalf in connection with the SaaS Service. It applies to the extent DeepConnect processes Personal Data that is subject to Data Protection Laws. Capitalized terms not defined here have the meaning given in the Agreement.

1.Definitions

“Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and applicable U.S. state privacy laws. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data contained within Customer Content, Contacts and Accounts that DeepConnect processes on Customer’s behalf. “Sub-processor” means a third party engaged by DeepConnect to process Customer Personal Data. “Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission Implementing Decision (EU) 2021/914.

2.Roles and Scope of Processing

As between the parties, Customer is the Controller and DeepConnect is the Processor of Customer Personal Data, except where DeepConnect acts as an independent Controller as described in its Privacy Policy (for example, with respect to Usage Data and account administration). DeepConnect will process Customer Personal Data only as a Processor on behalf of Customer. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex A.

3.Customer Instructions

DeepConnect will process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA, and Customer’s configuration and use of the SaaS Service, unless required to do otherwise by applicable law (in which case DeepConnect will, where legally permitted, inform Customer of that requirement before processing). Customer instructs DeepConnect to process Customer Personal Data as necessary to provide, secure, and support the SaaS Service. Customer is responsible for ensuring its instructions comply with Data Protection Laws and that it has a lawful basis for the processing.

4.Confidentiality

DeepConnect will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and have received appropriate training on their responsibilities. Access to Customer Personal Data is limited to personnel who require access to perform the Agreement.

5.Security

DeepConnect will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. A description of these measures is set out in Annex B. DeepConnect may update its security measures from time to time provided the updates do not materially reduce the overall level of protection.

6.Sub-processors

Customer provides general authorization for DeepConnect to engage Sub-processors to process Customer Personal Data, subject to this Section. DeepConnect maintains a current list of Sub-processors at the location identified in Annex C. DeepConnect will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for each Sub-processor’s performance. DeepConnect will give Customer reasonable prior notice of any intended addition or replacement of a Sub-processor (for example, by updating the list or by email), and Customer may object on reasonable data-protection grounds within the notice period. If the parties cannot resolve the objection, Customer may terminate the affected portion of the SaaS Service as its sole remedy.

7.Data Subject Rights

Taking into account the nature of the processing, DeepConnect will provide reasonable assistance, including by appropriate technical and organizational measures, to enable Customer to respond to requests from Data Subjects to exercise their rights under Data Protection Laws. If DeepConnect receives such a request directly relating to Customer Personal Data, it will, where legally permitted, promptly forward the request to Customer and will not respond directly except on Customer’s instructions or as required by law.

8.Personal Data Breach Notification

DeepConnect will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include the information reasonably available to DeepConnect to help Customer meet its own breach-notification obligations, and DeepConnect will take reasonable steps to mitigate and remediate the breach. DeepConnect’s notification is not an acknowledgment of fault or liability.

9.Data Protection Impact Assessments

Taking into account the nature of processing and information available to DeepConnect, DeepConnect will provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Data Protection Laws in relation to the SaaS Service.

10.Return and Deletion

Upon expiration or termination of the Agreement, DeepConnect will, at Customer’s choice, delete or return Customer Personal Data in accordance with the data-export and deletion provisions of the Agreement, and delete existing copies unless retention is required by applicable law. Customer may export Customer Content, Contacts and Accounts during the applicable data export period described in the Agreement.

11.Audits

DeepConnect will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, in accordance with the audit provisions of the Agreement. To the extent available, DeepConnect may satisfy audit requests by providing third-party certifications or audit reports (such as SOC 2 or ISO 27001).

12.International Transfers

Customer authorizes DeepConnect to transfer Customer Personal Data outside the country of origin, including to the United States and India, as necessary to provide the SaaS Service. Where such transfers are subject to the GDPR or UK GDPR and are made to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum) are incorporated into this DPA by reference and apply to such transfers, with DeepConnect acting as “data importer” and Customer as “data exporter,” and with the relevant modules and annexes completed by reference to Annexes A and B.

13.Liability and Precedence

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. Except as expressly modified here, the Agreement remains in full force and effect.

14.Term

This DPA takes effect when Customer accepts the Agreement and continues until DeepConnect has ceased all processing of Customer Personal Data and deleted or returned it in accordance with Section 10.

Annex A

Details of Processing

Subject matterProvision of the GoWarmCRM sales execution platform and related services under the Agreement.
DurationFor the term of the Agreement, plus the data-export and deletion periods described in the Agreement.
Nature and purposeHosting, storage, transmission, display, organization, and analysis of Customer Personal Data to provide sales prospecting, sequencing, diagnostics, and related functionality, including integrations the Customer enables.
Types of Personal DataIdentifiers and contact details (name, business email, phone, address), professional information (job title, employer, LinkedIn URL), commercial and activity information, and communications content submitted through the SaaS Service.
Categories of Data SubjectsCustomer’s authorized users, and Customer’s contacts, prospects, leads, and other business individuals (Contacts and Accounts) that Customer chooses to process in the SaaS Service.
Special categoriesNone intended. Customer must not submit special-category data or data relating to children except as expressly permitted under the Agreement.
Annex B

Technical and Organizational Measures

DeepConnect maintains a security program that includes, at a minimum, the following measures, which may be updated provided the overall level of protection is not materially reduced:

  • Access control: role-based access, unique credentials, least-privilege provisioning, and prompt revocation of access on personnel changes.
  • Authentication: enforced strong authentication for administrative access and support for multi-factor authentication.
  • Encryption: encryption of Customer Personal Data in transit (TLS) and at rest using industry-standard algorithms.
  • Network and application security: firewalls, segmentation, secure software development practices, and regular vulnerability scanning and penetration testing of internet-facing applications.
  • Logging and monitoring: audit logging of administrative and security-relevant events and monitoring for anomalous activity.
  • Resilience: backups, disaster-recovery procedures, and measures to restore availability after an incident.
  • Vendor management: security assessment of Sub-processors and contractual flow-down of data-protection obligations.
  • Incident response: a documented process for detecting, responding to, and notifying Customer of Personal Data Breaches.
Annex C

Sub-processors

DeepConnect engages Sub-processors to provide hosting, infrastructure, communications, and analytics in support of the SaaS Service. A current list of Sub-processors, including the processing each performs, is available on request and at DeepConnect’s sub-processors page. DeepConnect will provide notice of changes to this list as described in Section 6 of this DPA.

Questions about this DPA may be directed to info@deepconnecttech.com or DeepConnect Technologies Inc., 8 The Green STE A, Dover, Kent, DE 19901.