Data Processing Agreement
Last Updated: August 23, 2026
1. Purpose and Scope
This Data Processing Agreement ("DPA") governs the processing of personal data that PWLL UG (haftungsbeschränkt) ("pipe0", "we", "us") carries out on behalf of a customer ("Customer", "you") in providing the pipe0 platform, API, Sheets, MCP server, and related services (the "Service").
This DPA forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement"). By accepting the Agreement you accept this DPA. No signature is required and none is exchanged: this DPA takes effect for you when you accept the Agreement or first use the Service, whichever is earlier.
Requesting a signed copy. You do not need a signed copy for this DPA to apply to you, and most customers never ask for one. If your procurement or compliance process requires an executed document on file, email legal@pipe0.com with your legal entity name and registered address, and we will return a countersigned PDF of this version, normally within five business days. If you need to negotiate particular terms, or to put your own DPA template in place instead of this one, write to the same address and we will work through it with you. Neither request delays your use of the Service — this DPA governs it in the meantime.
Where this DPA conflicts with the Agreement on a question of data protection, this DPA prevails. On every other question the Agreement prevails.
Each version of this DPA stays available at its own dated URL. The address pipe0.com/resources/legal/dpa always resolves to the current version, and is the address to cite. Section 16.2 describes how versions change.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "Data Protection Law" means the GDPR together with any national law implementing or supplementing it that applies to a party and, where applicable, the UK GDPR and the Swiss Federal Act on Data Protection.
"Controller", "processor", "sub-processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" carry the meanings given to them in Article 4 GDPR. We do not restate them here.
"Customer Personal Data" means personal data that you submit to the Service, or that the Service produces on your instruction, and that pipe0 processes on your behalf under this DPA. It does not include the data described in section 3.3.
"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
"Pipe", "search", "sheet", "connection" and "provider" carry the meanings given to them in the pipe0 documentation.
3. Roles of the Parties
3.1. You are the controller. In respect of Customer Personal Data you act as controller, or as processor on behalf of your own customers. You determine the purposes and means of the processing: which records you submit, which pipes and searches you run against them, which providers those pipes call, and what you do with the results.
3.2. pipe0 is your processor. In respect of Customer Personal Data pipe0 acts as processor and processes it only on your documented instructions, as described in section 5.
pipe0 does not operate a contact database of its own. Each pipe and search routes your request to a named third-party provider, identified per entry in the pipe catalog. pipe0 selects and integrates those providers and, for managed connections, holds the account with them — but it is your choice of pipe that determines which provider receives your data and for what purpose.
3.3. pipe0 is a controller for its own account data. pipe0 acts as an independent controller, not as your processor, for the account, billing, authentication, usage-metadata and abuse-prevention data it processes in order to operate and secure the Service. That processing is governed by the Privacy Policy and falls outside this DPA. The parties are not joint controllers.
4. Description of the Processing
Annex I sets out the subject matter and duration of the processing, its nature and purpose, the categories of personal data and of data subjects, and the retention applied, as required by Article 28(3) GDPR. Annex I also serves as Annex I.B to the SCCs where those apply under section 10.
5. Instructions
5.1. pipe0 processes Customer Personal Data only on your documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, pipe0 informs you before processing unless that law prohibits it on important grounds of public interest.
5.2. Your documented instructions consist of this DPA, the Agreement, and your own configuration of the Service: the records you submit, the pipes and searches you run, the connections you select, the schedules and agents you configure, and any further written instruction you give. Running a pipe is an instruction to transmit that pipe's declared input fields to that pipe's provider.
5.3. pipe0 informs you if, in its opinion, an instruction infringes Data Protection Law. pipe0 may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
5.4. pipe0 does not use Customer Personal Data for its own purposes, does not sell it, and does not use it to train AI models. Section 9.4 covers the AI providers pipe0 engages.
6. Your Obligations
6.1. You warrant that you have a lawful basis under Article 6 GDPR for the processing you instruct, including for enriching records with data obtained from providers, and that you have given data subjects any notice Data Protection Law requires. This includes, where applicable, notice under Article 14 GDPR that their data was obtained from a source other than themselves.
6.2. You are responsible for the lawfulness of the records you submit and for limiting them to what is adequate, relevant and necessary for your purpose. You are equally responsible for what you do with the output: section 15 sets out the purposes for which output data may be used, the fact that pipe0 does not verify it, and how responsibility between us is allocated.
6.3. Special categories of data. The Service is built for business contact data and is not designed to process special categories of personal data within the meaning of Article 9 GDPR. You must not instruct pipe0 to process such data, and you must not use the Service's filters to select individuals on the basis of a special category.
You should be aware that profile data returned by providers is free text in places and can incidentally reveal a special category: a person's languages, the societies listed in their education history, the free-text summary on their profile, or their profile photograph. pipe0 does not classify or filter this content. Where you retain such fields you are responsible for handling them lawfully, and you should consider excluding them from the output fields you request.
6.4. Profiling and monitoring. Some pipes derive career-event signals about individuals, and stream enrolment places an individual on a watch list so that later changes about them are reported to you. This is profiling within the meaning of Article 4(4) GDPR and may, depending on your purpose and its scale, require a data protection impact assessment under Article 35 GDPR. That assessment is your responsibility as controller; pipe0 assists under section 11.
6.5. You must notify pipe0 without undue delay of any personal data breach affecting the Service that you become aware of.
7. Confidentiality
pipe0 ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it in order to provide the Service.
8. Security
8.1. pipe0 implements appropriate technical and organisational measures under Article 32 GDPR. The measures in place are described in Annex II.
8.2. Annex II describes those measures as they stand on the date of this version. pipe0 may change them provided the level of security is not reduced.
8.3. pipe0 does not currently hold a SOC 2 or ISO 27001 certification and makes no representation that it does.
9. Sub-processors
9.1. General authorisation. You give pipe0 general written authorisation, within the meaning of Article 28(2) GDPR, to engage sub-processors subject to this section.
9.2. Platform sub-processors. pipe0 engages the sub-processors listed in Annex III to host, deliver and secure the Service. They may process Customer Personal Data for every customer.
9.3. Provider sub-processors, on managed connections. Where you run a pipe or search on a managed connection, pipe0 supplies the provider credentials and holds the account with that provider. Those providers act as pipe0's sub-processors. Each is engaged only for the pipes and searches you actually run, and each is named in the pipe catalog entry for the pipe that calls it, together with the fields that pipe transmits. The catalog is the authoritative list.
9.4. AI providers. AI pipes, message drafting, row filtering, report generation and the pipe0 agent transmit the inputs you configure to the AI providers listed in Annex III. Their agreements with pipe0 prohibit them from training their models on that data.
9.5. Custom connections are not pipe0 sub-processors. Where you supply your own API key or OAuth grant for a provider, you contract with that provider directly and it processes your data under your agreement with it rather than pipe0's. pipe0's role is limited to transmitting the data on your instruction and storing the credential. Where a pipe calls several providers, pipe0 uses your custom connection for each provider you have configured one for and its own managed connection for the rest, so sections 9.3 and 9.5 can both apply within a single run.
9.6. Changes. pipe0 gives you at least 30 days' notice before a new platform sub-processor begins processing Customer Personal Data, by updating Annex III and notifying you by email or in the Service. Providers added to the catalog are published in the catalog itself and begin processing only when you first run a pipe that calls one.
9.7. Objection. You may object to a new platform sub-processor on reasonable data-protection grounds within 30 days of notice. The parties will discuss the objection in good faith. If it cannot be resolved, you may terminate the affected part of the Service without penalty for the remainder of the term.
9.8. Flow-down and liability. pipe0 imposes on each sub-processor data protection obligations that are in substance no less protective than those in this DPA, and remains fully liable to you for its sub-processors' performance.
10. International Transfers
10.1. pipe0 is established in Germany. Customer Personal Data is processed within the European Economic Area except where a sub-processor is established or operates outside it, or where a provider you instruct pipe0 to call is.
10.2. Several of the sub-processors in Annex III, and many of the providers in the pipe catalog, are established in the United States or process data there. Where pipe0 transfers Customer Personal Data to such a recipient it does so on the basis of that recipient's certification under the EU–US Data Privacy Framework where the certification covers the transfer, and otherwise on the basis of the SCCs together with any supplementary measures the transfer requires under Chapter V GDPR.
10.3. SCCs. Where the SCCs are the transfer mechanism between you and pipe0, in particular where you are established outside the EEA, they are incorporated into this DPA by reference and take effect on your acceptance of the Agreement with no separate signature. Module Two (controller to processor) applies where you act as controller, and Module Three (processor to processor) where you act as processor for your own customers. Annex I to this DPA serves as Annex I.B to the SCCs, Annex II serves as Annex II, and Annex III together with the pipe catalog is the list under Clause 9. Clause 9 operates under Option 2, general written authorisation, with the notice period in section 9.6. Clause 17 is governed by the law of Germany and Clause 18(b) designates the courts of Berlin.
10.4. pipe0 notifies you if it becomes subject to a legally binding request from a public authority for disclosure of Customer Personal Data, unless it is prohibited from doing so.
11. Assistance
11.1. Data subject rights. Taking into account the nature of the processing, pipe0 assists you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR. Sheets exposes the search, export and deletion operations needed to locate and act on an individual's records directly. Where a request reaches pipe0 rather than you, pipe0 does not respond to it on the merits; it refers the data subject to you and informs you without undue delay.
11.2. Articles 32 to 36. pipe0 assists you in ensuring compliance with the obligations in Articles 32 to 36 GDPR — security of processing, breach notification, data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to pipe0.
11.3. pipe0 makes available to you the information necessary to demonstrate compliance with Article 28 GDPR.
12. Personal Data Breach
12.1. pipe0 notifies you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
12.2. The notification describes, to the extent known, the nature of the breach and where possible the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, pipe0 provides it in phases without undue further delay.
12.3. pipe0 cooperates with you and takes reasonable steps to assist your investigation and any notification you must make under Articles 33 or 34 GDPR. A notification under this section is not an admission of fault or liability.
13. Deletion and Return
13.1. Data you delete. You can delete rows, columns, sheets and connections at any time through the Service.
13.2. How deletion works in Sheets. You should understand this before relying on it. Every change to a sheet is recorded as an effect in an append-only history, and a destructive change seals the previous version of the sheet so that it can be restored. Deleting a row therefore removes it from the current version of the sheet, but does not by itself erase it from the sealed earlier versions. Where you need a record erased rather than removed from the current version — to satisfy an erasure request under Article 17 GDPR, for example — contact privacy@pipe0.com and pipe0 carries out the erasure across sheet versions and backups.
13.3. API runs. Records of asynchronous pipe and search runs, including the records you submitted and the results produced, are retained for 21 days from creation and are then deleted automatically. Synchronous runs are not stored.
13.4. End of the Agreement. At your choice, pipe0 deletes or returns all Customer Personal Data at the end of the provision of the Service and deletes existing copies, unless Union or Member State law requires it to store the data. Absent a contrary instruction from you, pipe0 deletes Customer Personal Data within 30 days of termination of your account. Export what you need before you terminate; sheet export works at any size the sheet supports.
13.5. Backups are retained on a rolling cycle and expire on that cycle. Data in an expired backup is not restored to production.
14. Audit
14.1. pipe0 makes available to you the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by you or by an auditor you mandate.
14.2. In the first instance pipe0 responds to a written security questionnaire, no more than once in any twelve-month period, within a reasonable period and in any event within 30 days.
14.3. Where a questionnaire does not resolve the matter, or following a personal data breach affecting your data, you may conduct an on-site audit no more than once in any twelve-month period, on 30 days' written notice, during business hours, subject to confidentiality undertakings and without unreasonably disrupting pipe0's operations. pipe0 may object to an auditor that is a competitor. You bear the cost of an audit you initiate unless it reveals a material non-compliance.
14.4. A supervisory authority exercising its own powers is not subject to the limits in this section.
15. Allocation of Responsibility and Liability
15.1. The Service returns third-party data, and pipe0 does not verify it. Output data is obtained from the providers named in the pipe catalog and from public sources. pipe0 does not check it, and does not warrant that it is accurate, current, complete, or lawfully obtained by the provider, or that any particular record may lawfully be used for any particular purpose. You are responsible for verifying output data before you rely on it, and for deciding whether and how to contact any individual it identifies.
15.2. Permitted purpose. You may use Customer Personal Data and output data only to initiate or manage a business relationship relevant to the individual's professional role. You must not use the Service or its output:
- to make or support a decision about an individual's eligibility for credit, insurance, housing, employment, or any comparable benefit, or for any purpose that would make the output a consumer report or its equivalent under applicable law;
- to direct consumer-oriented offers or purely personal communications at an individual;
- to produce a decision based solely on automated processing that produces legal effects concerning an individual or similarly significantly affects them within the meaning of Article 22 GDPR, unless you have your own lawful basis for it;
- to re-identify an individual from anonymised data, or to profile or monitor an individual for a purpose unrelated to a business relationship;
- to resell or redistribute raw output data as a data product; or
- in breach of any law governing unsolicited communication, including the ePrivacy Directive as implemented in the recipient's country, the German Act Against Unfair Competition (UWG), the US CAN-SPAM Act, and the US Telephone Consumer Protection Act.
15.3. Your indemnity. You indemnify pipe0 and hold it harmless against all third-party claims, supervisory authority proceedings, fines, damages, losses and reasonable costs including legal fees, arising out of or in connection with:
- your breach of section 5, 6 or 15;
- processing you instruct for which you have no lawful basis, or for which you have not given a notice that Data Protection Law requires;
- an instruction that infringes Data Protection Law where pipe0 has informed you under section 5.3 and you have confirmed the instruction;
- your use of output data for a purpose that section 15.2 prohibits; or
- a claim by a data subject, or an act of a supervisory authority, that is attributable to your acts or omissions as controller rather than to pipe0's breach of its own obligations under this DPA.
This indemnity is not subject to any cap on liability in the Agreement. It does not apply to the extent the claim results from pipe0's own breach of this DPA, its gross negligence, or its intentional misconduct.
pipe0 notifies you of a claim covered by this indemnity without undue delay, gives you the conduct of its defence if you ask for it, and does not settle it in a way that admits liability on your part without your consent, which you may not unreasonably withhold. You may not settle a claim in a way that admits fault by pipe0, imposes an obligation on it, or affects its relationship with a supervisory authority, without pipe0's consent. pipe0 may participate in the defence at its own cost.
15.4. Recourse between the parties. Article 82(5) GDPR applies between us: where one party has paid compensation in full for damage caused by processing, it may claim back from the other the share of that compensation corresponding to the other's part of the responsibility. As between the parties, responsibility for determining the purposes of the processing, for the lawful basis relied on, and for the use made of output data rests with you.
15.5. pipe0's liability. pipe0's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, and this DPA creates no separate or additional cap. pipe0 is not liable for any consequence of output data being inaccurate, incomplete or out of date.
15.6. What this section does not limit. Nothing in this DPA excludes or limits liability for intent or gross negligence, for injury to life, body or health, or under the German Product Liability Act (Produkthaftungsgesetz). Where a party negligently breaches a material contractual obligation, its liability is limited to the foreseeable damage typical of this type of contract. Nothing in this DPA affects a data subject's right to compensation under Article 82 GDPR, or the liability regime in Clause 12 of the SCCs where those apply under section 10.3.
16. Term, Changes and Governing Law
16.1. This DPA takes effect when you accept the Agreement and continues for as long as pipe0 processes Customer Personal Data. Sections 7, 12, 13, 15 and 16 survive its termination.
16.2. pipe0 may issue a new version of this DPA where a change in Data Protection Law, in the Service, or in its sub-processors requires one. Each version is published at its own dated URL and earlier versions stay available. pipe0 notifies you at least 30 days before a new version takes effect, unless a change in law requires it sooner. Continued use of the Service after that date constitutes acceptance.
16.3. This DPA is governed by the law of Germany. The courts of Berlin have exclusive jurisdiction, without prejudice to Clause 18 of the SCCs where those apply.
16.4. If a provision of this DPA is found to be unenforceable, the remaining provisions remain in full force and effect.
17. Contact
To request a countersigned copy of this DPA, to negotiate particular terms, or to propose your own DPA template, email legal@pipe0.com.
For questions about how we process personal data, to exercise a data subject right, or for an erasure request under section 13.2, email privacy@pipe0.com.
PWLL UG (haftungsbeschränkt)
Quitzowstrasse 118
10559 Berlin, Germany
Annex I — Details of the Processing
Subject matter. Provision of the pipe0 platform, API, Sheets, MCP server and integrations, as described in the Agreement.
Duration. The term of the Agreement, plus the retention periods in section 13.
Nature of the processing. Receipt and transmission of records; enrichment of records by routing declared input fields to third-party providers and returning their output; search against third-party datasets and the public web; validation of email addresses and phone numbers; AI-assisted generation, classification, filtering and summarisation; storage in sheets; export; and transmission to systems you connect.
Purpose. Business-to-business prospecting, lead and account research, list building, data validation and enrichment, CRM hygiene, and outbound communication, in each case as you configure it.
Categories of data subjects. Business contacts and prospects; employees, officers and representatives of the companies you research; authors of public professional and social content; your own personnel who use the Service; and, where you enrol individuals in a stream, the individuals you monitor.
Categories of personal data. Which of these are processed depends entirely on the pipes and searches you run.
| Category | Examples of fields |
|---|---|
| Identity | Name, first name, last name, addressee name |
| Business contact | Work email, email validity and deliverability status, landline, phone |
| Personal contact | Personal email, alternate personal emails, mobile number |
| Employment | Job title, job description, seniority, profile headline, company name, company domain |
| Online profiles | Professional profile URL, developer profile URL, company profile URL, X username and user ID, Slack user ID, avatar URL |
| Location | Address lines, city, state, country, postcode, location hint |
| Technical | IP address |
| Profile content | Free-text profile summary, education history, employment history, languages, skills, certifications, profile photograph |
| Public posts | Post text and post lists from professional and social sources, follower counts |
| Derived and inferred | Career-event signals such as joined company, left company, promotion, changed role, work anniversary and graduated; estimated salary; signal counts |
| Connected systems | Records matched in your Slack, Gmail, Google Calendar, HubSpot, Salesforce, Attio, PostgreSQL or Databricks instance |
Special categories of data. None are requested by pipe0 or classified by it, and section 6.3 prohibits you from instructing their processing. Free-text profile fields may incidentally contain data from which a special category could be inferred.
Frequency of the processing. Continuous, on your instruction: per API call, per sheet run, and on any schedule you configure.
Retention. Asynchronous run records, 21 days from creation. Synchronous runs, not stored. Sheet data, for the lifetime of the sheet, subject to section 13. Connection credentials, until you delete the connection or your account.
Transfers to sub-processors. As described in section 9 and Annex III, for the duration and purpose set out above.
Annex II — Technical and Organisational Measures
These are the measures in place as at the date of this version.
Encryption in transit. Traffic to and from the Service, and between the Service and its providers, uses TLS.
Encryption of credentials at rest. Connection credentials, meaning provider API keys and OAuth tokens, are held in Vault, pipe0's secure storage layer, encrypted at rest with AES-256-GCM. Secrets referenced in templated fields are resolved server-side at execution and are never returned in a response.
Access control and authentication. API access uses organisation-scoped API keys managed by organisation administrators. Browser contexts use a separate public key that authorises no data access, so a page can offer autocomplete without exposing an API key. The MCP server accepts OAuth only; API keys do not authenticate against it. Access to production systems is granted on a least-privilege basis.
Separation and isolation. Data is separated by organisation. Sandbox runs mock providers and never reach a provider, a connected system, or your CRM.
Integrity. Every run records the sheet version it validated against and is refused if the sheet has moved on, so concurrent edits cannot corrupt a result. Every change to a sheet is recorded in an append-only history identifying what changed, when, and which person, schedule or agent triggered it.
Recoverability. A destructive change seals the previous sheet version, so a sheet can be restored to an earlier point. Backups are taken on a rolling cycle.
Confirmation gating. Agent tools that spend credits or mutate data require confirmation on first use.
Personnel. Persons with access to Customer Personal Data are bound by confidentiality obligations.
Sub-processor measures. Sub-processors are engaged under agreements imposing data protection obligations no less protective in substance than those in this DPA.
Annex III — Sub-processors
Platform sub-processors
| Sub-processor | Purpose | Established |
|---|---|---|
| Cloudflare, Inc. | Content delivery, security, and webhook resolution | United States |
| Vercel Inc. | Hosting and deployment | United States |
| Hetzner Online GmbH | Infrastructure and storage | Germany |
| Anthropic, PBC | AI model inference | United States |
| OpenAI, LLC | AI model inference | United States |
| Google LLC | AI model inference | United States |
"Established" identifies where the entity is incorporated. It is not a statement about where processing takes place: several of these sub-processors operate facilities in more than one region.
Provider sub-processors
Providers called on a managed connection act as pipe0's sub-processors under section 9.3. Each is named in the pipe catalog entry for the pipe or search that calls it, together with the input fields that pipe transmits. The catalog is the authoritative and current list, and it changes as pipes are added and retired.
Providers called on a custom connection are not pipe0 sub-processors. See section 9.5.