Data Processing Agreement
Last Updated: October 8, 2026
This version applies to new customers from October 8, 2026. For customers who accepted an earlier version, it takes effect on November 7, 2026, under section 16.2 of that version; until then the earlier version continues to apply.
1. Purpose and Scope
This Data Processing Agreement ("DPA") governs the processing of personal data that PWLL UG (haftungsbeschränkt) ("pipe0", "we", "us") carries out on behalf of a customer ("Customer", "you") in providing the pipe0 platform, API, Sheets, MCP server, and related services (the "Service").
This DPA forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement"). By accepting the Agreement you accept this DPA. No signature is required and none is exchanged: this DPA takes effect for you when you accept the Agreement or first use the Service, whichever is earlier.
Requesting a signed copy. You do not need a signed copy for this DPA to apply to you. If your procurement or compliance process requires an executed document on file, email legal@pipe0.com with your legal entity name and registered address, and we will return a countersigned PDF of this version. If you need to negotiate particular terms, write to the same address. Terms agreed individually and in writing take precedence over this DPA to the extent they differ. Neither request delays your use of the Service — this DPA governs it in the meantime.
Where this DPA conflicts with the Agreement on a question of data protection, this DPA prevails. On every other question the Agreement prevails.
Each version of this DPA stays available at its own dated URL. The address pipe0.com/resources/legal/dpa always resolves to the current version, and is the address to cite. Section 16.2 describes how versions change.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "Data Protection Law" means the GDPR together with any national law implementing or supplementing it that applies to a party and, where applicable, the UK GDPR, the Swiss Federal Act on Data Protection, and the US state privacy laws referred to in section 10A.
"Controller", "processor", "sub-processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" carry the meanings given to them in Article 4 GDPR. We do not restate them here.
"Customer Personal Data" means personal data that you submit to the Service, or that the Service stores or transmits on your instruction, and that pipe0 processes on your behalf under this DPA. It includes Source Data once delivered to you. It does not include the data described in section 3.4.
"Data Source" means a third-party provider that returns data from a dataset it compiles and maintains itself, for example a contact, company, or profile database. Data Sources are named in the pipe catalog and listed in Annex IV.
"Source Data" means the data a Data Source returns in response to a pipe or search you run.
"Processing Service" means a third-party provider that processes the inputs you send only to return a result to you and does not add them to a dataset of its own, for example email and phone validation, web search, and AI model inference.
"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
"Pipe", "search", "sheet", "connection" and "provider" carry the meanings given to them in the pipe0 documentation.
3. Roles of the Parties
3.1. You are the controller. In respect of Customer Personal Data you act as controller, or as processor on behalf of your own customers. You determine the purposes and means of the processing: which records you submit, which pipes and searches you run against them, which providers those pipes call, and what you do with the results.
3.2. pipe0 is your processor. In respect of Customer Personal Data pipe0 acts as processor and processes it only on your documented instructions, as described in section 5. This covers receiving your inputs, transmitting them to the providers you select, receiving and delivering the results, and storing them in your workspace.
3.3. Data Sources are independent controllers. pipe0 does not operate a contact database of its own, and the Service is not one. A Data Source compiles and maintains its own dataset and decides for itself how that dataset is collected, kept and disclosed. When you run a pipe or search that calls a Data Source:
- the Data Source discloses Source Data from its own dataset as an independent controller, under its own terms and privacy notice;
- you receive Source Data as an independent controller, with pipe0 retrieving and delivering it on your instruction as your processor; and
- the Data Source receives the input fields of that pipe as an independent controller under its own terms. Some Data Sources state in their terms that they retain such inputs or use them to maintain their datasets.
A Data Source is not pipe0's sub-processor and does not act on pipe0's behalf or on yours. pipe0, the Data Source and you are not joint controllers.
3.4. pipe0 is a controller for its own account data. pipe0 acts as an independent controller, not as your processor, for the account, billing, authentication, usage-metadata and abuse-prevention data it processes in order to operate and secure the Service. That processing is governed by the Privacy Policy and falls outside this DPA.
3.5. No pooling. pipe0 does not add Customer Personal Data or Source Data to any dataset of its own, does not combine one customer's results with another's, and does not reuse one customer's results to answer another customer's request.
4. Description of the Processing
Annex I sets out the subject matter and duration of the processing, its nature and purpose, the categories of personal data and of data subjects, and the retention applied, as required by Article 28(3) GDPR. Annex I also serves as Annex I.B to the SCCs where those apply under section 10.
5. Instructions
5.1. pipe0 processes Customer Personal Data only on your documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, pipe0 informs you before processing unless that law prohibits it on important grounds of public interest.
5.2. Your documented instructions consist of this DPA, the Agreement, and your own configuration of the Service: the records you submit, the pipes and searches you run, the connections you select, the schedules and agents you configure, and any further written instruction you give. Running a pipe or search is an instruction to transmit its declared input fields to the provider it calls and to deliver that provider's results to you. An agent, script or integration that uses your credentials gives instructions on your behalf.
5.3. pipe0 informs you if, in its opinion, an instruction infringes Data Protection Law. pipe0 may suspend the affected processing until the instruction is confirmed, amended or withdrawn. pipe0 is not obliged to review your instructions for lawfulness.
5.4. pipe0 does not use Customer Personal Data for its own purposes, does not sell it, and does not use it to train AI models. Section 9.4 covers the AI providers pipe0 engages.
6. Your Obligations
6.1. Lawful basis and notice. You are responsible for having a lawful basis under Article 6 GDPR for the processing you instruct and for the use you make of Source Data, and for giving data subjects any notice Data Protection Law requires. This includes, where applicable, notice under Article 14 GDPR that their data was obtained from a source other than themselves, in which you may name the Data Source and pipe0 as the means of retrieval. Receiving Source Data through the Service does not supply you with a lawful basis for using it, and you may not rely on any statement by pipe0 or a Data Source as a substitute for your own assessment.
6.2. Your own due diligence. You are responsible for the due diligence your Data Protection Law expects of a party that obtains personal data from a third party, proportionate to your use. pipe0 supports it by publishing the Data Sources in Annex IV and the pipe catalog, and by passing on documentation as described in section 9.6.
6.3. What you submit and what you do with it. You are responsible for the lawfulness of the records you submit and for limiting them to what is adequate, relevant and necessary for your purpose. You are equally responsible for what you do with the output: section 15 sets out the purposes for which output data may be used, the fact that pipe0 does not verify it, and how responsibility between us is allocated.
6.4. Objections and deletion. You must honour objections and erasure requests from data subjects, and must stop using and delete a data subject's Source Data within 30 days after pipe0 or a Data Source tells you that the data subject has objected or that the data must be removed.
6.5. Special categories of data. The Service is built for business contact data and is not designed to process special categories of personal data within the meaning of Article 9 GDPR. You must not instruct pipe0 to process such data, and you must not use the Service's filters to select individuals on the basis of a special category.
You should be aware that profile data returned by providers is free text in places and can incidentally reveal a special category: a person's languages, the societies listed in their education history, the free-text summary on their profile, or their profile photograph. pipe0 does not classify or filter this content. Where you retain such fields you are responsible for handling them lawfully, and you should consider excluding them from the output fields you request.
6.6. Profiling and monitoring. Some pipes derive career-event signals about individuals, and stream enrolment places an individual on a watch list so that later changes about them are reported to you. This may be profiling within the meaning of Article 4(4) GDPR and may, depending on your purpose and its scale, require a data protection impact assessment under Article 35 GDPR. That assessment is your responsibility as controller; pipe0 assists under section 11.
6.7. You must notify pipe0 without undue delay of any personal data breach affecting the Service that you become aware of.
7. Confidentiality
pipe0 ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it in order to provide the Service.
8. Security
8.1. pipe0 implements appropriate technical and organisational measures under Article 32 GDPR. The measures in place are described in Annex II.
8.2. Annex II describes those measures as they stand on the date of this version. pipe0 may change them provided the level of security is not reduced.
8.3. pipe0 does not currently hold a SOC 2 or ISO 27001 certification and makes no representation that it does.
9. Sub-processors and Data Sources
9.1. General authorisation. You give pipe0 general written authorisation, within the meaning of Article 28(2) GDPR, to engage sub-processors subject to this section.
9.2. Platform sub-processors. pipe0 engages the sub-processors listed in Annex III to host, deliver and secure the Service. They may process Customer Personal Data for every customer.
9.3. Processing Services, on managed connections. Where you run a pipe or search that calls a Processing Service on a managed connection, pipe0 supplies the credentials and the Processing Service acts as pipe0's sub-processor. Each is engaged only for the pipes and searches you actually run, and is named in Annex IV and in the pipe catalog entry for the pipe that calls it, together with the fields that pipe transmits.
9.4. AI providers. AI pipes, message drafting, row filtering, report generation and the pipe0 agent transmit the inputs you configure to the AI providers listed in Annex III. Their agreements with pipe0 prohibit them from training their models on that data.
9.5. Custom connections. Where you supply your own API key or OAuth grant for a provider, you contract with that provider directly and it processes your data under your agreement with it rather than pipe0's. pipe0's role is limited to transmitting the data on your instruction and storing the credential. Where a pipe calls several providers, pipe0 uses your custom connection for each provider you have configured one for and its own managed connection for the rest.
9.6. Data Sources. Data Sources are not sub-processors (section 3.3), and sections 9.7 to 9.9 do not apply to them. pipe0 selects Data Sources with reasonable care, reviews their published terms and privacy documentation before making them available, and may withdraw a Data Source at any time, including where it has doubts about the Data Source's compliance. On request, pipe0 provides you with the documentation a Data Source makes available about its sourcing and lawful basis, to the extent pipe0 holds it and may share it. pipe0 does not warrant that documentation, and section 15.1 applies to all Source Data.
9.7. Changes. pipe0 gives you at least 30 days' notice before a new platform sub-processor begins processing Customer Personal Data, by updating Annex III and notifying you by email or in the Service. Processing Services and Data Sources added to the catalog are published in the catalog and Annex IV, and receive data only when you first run a pipe that calls one.
9.8. Objection. You may object to a new platform sub-processor on reasonable data-protection grounds within 30 days of notice. The parties will discuss the objection in good faith. If it cannot be resolved, you may terminate the affected part of the Service without penalty for the remainder of the term. You object to a Processing Service or Data Source by not running the pipes that call it.
9.9. Flow-down. pipe0 engages each sub-processor under a written agreement imposing data protection obligations as required by Article 28(4) GDPR, and is liable to you for its sub-processors' performance of those obligations to the extent Article 28(4) GDPR requires, subject to section 15.
10. International Transfers
10.1. pipe0 is established in Germany. Customer Personal Data is processed within the European Economic Area except where a sub-processor is established or operates outside it, or where a provider you instruct pipe0 to call is.
10.2. Several of the sub-processors in Annex III, and many of the providers in Annex IV, are established in the United States or other third countries. Where pipe0 transfers Customer Personal Data to a sub-processor in a third country, it does so on the basis of an adequacy decision, including the EU–US Data Privacy Framework where the recipient's certification covers the transfer, and otherwise on the basis of the SCCs together with any supplementary measures the transfer requires under Chapter V GDPR. Where you instruct pipe0 to transmit inputs to a Data Source in a third country, the transfer is made on your instruction, and the Data Source's own transfer terms apply to its processing.
10.3. SCCs. Where the SCCs are the transfer mechanism between you and pipe0, in particular where you are established outside the EEA, they are incorporated into this DPA by reference and take effect on your acceptance of the Agreement with no separate signature. Module Two (controller to processor) applies where you act as controller, and Module Three (processor to processor) where you act as processor for your own customers. Annex I to this DPA serves as Annex I.B to the SCCs, Annex II serves as Annex II, and Annex III together with Annex IV is the list under Clause 9. Clause 9 operates under Option 2, general written authorisation, with the notice period in section 9.7. Clause 17 is governed by the law of Germany and Clause 18(b) designates the courts of Berlin. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies in addition, with the information in this DPA completing its tables.
10.4. pipe0 notifies you if it becomes subject to a legally binding request from a public authority for disclosure of Customer Personal Data, unless it is prohibited from doing so.
10A. US State Privacy Laws
Where the California Consumer Privacy Act or a comparable US state privacy law applies to Customer Personal Data, pipe0 acts as your service provider or processor within the meaning of that law, and processes Customer Personal Data only for the business purpose of providing the Service as described in Annex I. pipe0 does not sell or share Customer Personal Data, as those terms are defined in that law; does not retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship between you and pipe0; does not combine it with personal information it receives from or on behalf of another person, except as that law permits; complies with the obligations that law imposes on service providers and provides the same level of privacy protection it requires; notifies you if it determines it can no longer meet those obligations; and permits you, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use.
11. Assistance
11.1. Data subject rights. Taking into account the nature of the processing, pipe0 assists you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR. Sheets exposes the search, export and deletion operations needed to locate and act on an individual's records directly. Where a request concerning Customer Personal Data reaches pipe0 rather than you, pipe0 does not respond to it on the merits; it refers the data subject to you, and to the Data Source where the request concerns that Data Source's dataset.
11.2. Articles 32 to 36. pipe0 assists you in ensuring compliance with the obligations in Articles 32 to 36 GDPR — security of processing, breach notification, data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to pipe0.
11.3. pipe0 makes available to you the information necessary to demonstrate compliance with Article 28 GDPR.
11.4. Assistance beyond what Data Protection Law requires of a processor, including completing bespoke questionnaires or attestations, is provided at pipe0's discretion and may be charged at reasonable rates.
12. Personal Data Breach
12.1. pipe0 notifies you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data in pipe0's systems or those of its sub-processors.
12.2. The notification describes, to the extent known, the nature of the breach and where possible the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, pipe0 provides it in phases without undue further delay.
12.3. pipe0 cooperates with you and takes reasonable steps to assist your investigation and any notification you must make under Articles 33 or 34 GDPR. A notification under this section is not an admission of fault or liability.
12.4. An incident in a Data Source's own systems or dataset is not a breach under this section. pipe0 has no obligation to monitor Data Sources for such incidents.
13. Deletion and Return
13.1. Data you delete. You can delete rows, columns, sheets and connections at any time through the Service.
13.2. How deletion works in Sheets. Every change to a sheet is recorded as an effect in an append-only history, and a destructive change seals the previous version of the sheet so that it can be restored. Deleting a row therefore removes it from the current version of the sheet, but does not by itself erase it from the sealed earlier versions. Where you need a record erased rather than removed from the current version — to satisfy an erasure request under Article 17 GDPR, for example — contact privacy@pipe0.com and pipe0 erases it from all sheet versions. Copies in backups are not edited; they expire on the backup cycle described in section 13.5.
13.3. API runs. Every pipe and search run is stored as a run record, whether you start it synchronously or asynchronously. A run record includes the records you submitted, the results produced, and a per-provider log of the inputs sent and outcomes returned. Run records remain retrievable by their run ID and are deleted automatically once 21 days have passed since creation, at the latest within 24 hours after that.
13.4. End of the Agreement. At your choice, pipe0 deletes or returns all Customer Personal Data at the end of the provision of the Service and deletes existing copies, unless Union or Member State law requires it to store the data. Absent a contrary instruction from you, pipe0 deletes Customer Personal Data within 30 days of termination of your account. Export what you need before you terminate; sheet export works at any size the sheet supports.
13.5. Backups are retained on a rolling cycle and expire on that cycle. Data in an expired backup is not restored to production, and data erased under section 13.2 is not restored from a backup into production.
14. Audit
14.1. pipe0 makes available to you the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by you or by an auditor you mandate.
14.2. In the first instance pipe0 responds to a written security questionnaire, no more than once in any twelve-month period, within a reasonable period and in any event within 30 days.
14.3. Where a questionnaire does not resolve the matter, or following a personal data breach affecting your data, you may conduct an on-site audit no more than once in any twelve-month period, on 30 days' written notice, during business hours, subject to confidentiality undertakings and without unreasonably disrupting pipe0's operations. pipe0 may object to an auditor that is a competitor. You bear the cost of an audit you initiate unless it reveals a material non-compliance.
14.4. A supervisory authority exercising its own powers is not subject to the limits in this section.
15. Allocation of Responsibility and Liability
15.1. The Service returns third-party data, and pipe0 does not verify it. Source Data is obtained by Data Sources and is delivered to you as the Data Source returns it. pipe0 does not compile it, check it, or select which records a Data Source returns. pipe0 does not warrant that Source Data is accurate, current, complete, or lawfully collected or disclosed by the Data Source, or that any particular record may lawfully be used for any particular purpose. You are responsible for verifying output data before you rely on it, and for deciding whether and how to contact any individual it identifies. As between the parties, the collection of Source Data is the responsibility of the Data Source, and its use is yours.
15.2. Permitted purpose. You may use Customer Personal Data and output data only for your own internal business purposes, to initiate or manage a business relationship relevant to the individual's professional role. You must not use the Service or its output:
- to make or support a decision about an individual's eligibility for credit, insurance, housing, employment, or any comparable benefit, or for any purpose that would make the output a consumer report or its equivalent under applicable law;
- to direct consumer-oriented offers or purely personal communications at an individual;
- to produce a decision based solely on automated processing that produces legal effects concerning an individual or similarly significantly affects them within the meaning of Article 22 GDPR, unless you have your own lawful basis for it;
- to re-identify an individual from anonymised data, or to profile or monitor an individual for a purpose unrelated to a business relationship;
- to sell, license, or otherwise make output data available to third parties, other than service providers acting on your behalf, or to build or supplement a database, list, or enrichment service offered to others;
- in breach of a use restriction that a Data Source publishes and that the pipe catalog or the Service brings to your attention; or
- in breach of any law governing unsolicited communication, including the ePrivacy Directive as implemented in the recipient's country, the German Act Against Unfair Competition (UWG), the UK Privacy and Electronic Communications Regulations, the US CAN-SPAM Act, the US Telephone Consumer Protection Act, and Canada's Anti-Spam Legislation.
15.3. Your indemnity. You indemnify pipe0 against third-party claims, supervisory authority proceedings, fines, damages, losses and reasonable costs including legal fees, to the extent they arise from a matter for which you are responsible under this DPA, namely:
- your breach of section 5, 6 or 15;
- processing you instruct for which you have no lawful basis, or for which you have not given a notice that Data Protection Law requires;
- an instruction that infringes Data Protection Law where pipe0 has informed you under section 5.3 and you have confirmed the instruction;
- your use of output data, including any communication you send; or
- a claim by a data subject, or an act of a supervisory authority, that is attributable to your acts or omissions as controller rather than to pipe0's breach of its own obligations under this DPA.
This indemnity does not apply to the extent the claim results from pipe0's own breach of this DPA. Where pipe0 contributed to the loss, the indemnity is reduced in proportion to pipe0's share of responsibility. pipe0 notifies you of a claim covered by this indemnity without undue delay, gives you the conduct of its defence if you ask for it, and does not settle it in a way that admits liability on your part without your consent, which you may not unreasonably withhold. You may not settle a claim in a way that admits fault by pipe0, imposes an obligation on it, or affects its relationship with a supervisory authority, without pipe0's consent. pipe0 may participate in the defence at its own cost.
15.4. Recourse between the parties. Article 82(5) GDPR applies between us: where one party has paid compensation in full for damage caused by processing, it may claim back from the other the share of that compensation corresponding to the other's part of the responsibility. As between the parties, responsibility for determining the purposes of the processing, for the lawful basis relied on, for notice to data subjects, and for the use made of output data rests with you.
15.5. pipe0's liability. pipe0's liability under or in connection with this DPA, including under section 9.9, is subject to the limitations of liability in the Agreement, and this DPA creates no separate or additional liability. pipe0 is not liable for any consequence of Source Data being inaccurate, incomplete, out of date, or unlawfully collected by a Data Source, except where pipe0 itself acted with intent or gross negligence.
15.6. What this section does not limit. Nothing in this DPA excludes or limits liability for intent or gross negligence, for injury to life, body or health, or under the German Product Liability Act (Produkthaftungsgesetz). Nothing in this DPA affects a data subject's right to compensation under Article 82 GDPR, or the liability regime in Clause 12 of the SCCs where those apply under section 10.3.
16. Term, Changes and Governing Law
16.1. This DPA takes effect when you accept the Agreement and continues for as long as pipe0 processes Customer Personal Data. Sections 7, 12, 13, 15 and 16 survive its termination.
16.2. pipe0 may issue a new version of this DPA where a change in Data Protection Law, in the Service, in its sub-processors or Data Sources, or in its providers' terms requires one. Each version is published at its own dated URL and earlier versions stay available. pipe0 notifies you at least 30 days before a new version takes effect, unless a change in law requires it sooner. If you object in writing before that date, either party may terminate the Agreement with effect from it; otherwise the new version applies from that date.
16.3. This DPA is governed by the law of Germany. The courts of Berlin have exclusive jurisdiction, without prejudice to Clause 18 of the SCCs where those apply.
16.4. If a provision of this DPA is found to be unenforceable, the remaining provisions remain in full force and effect.
17. Contact
To request a countersigned copy of this DPA, or to negotiate particular terms, email legal@pipe0.com.
For questions about how we process personal data, to exercise a data subject right, or for an erasure request under section 13.2, email privacy@pipe0.com.
PWLL UG (haftungsbeschränkt)
Quitzowstrasse 118
10559 Berlin, Germany
Annex I — Details of the Processing
Subject matter. Provision of the pipe0 platform, API, Sheets, MCP server and integrations, as described in the Agreement.
Duration. The term of the Agreement, plus the retention periods in section 13.
Nature of the processing. Receipt and transmission of records; retrieval of results by routing declared input fields to the third-party providers you select and delivering their output; validation of email addresses and phone numbers; AI-assisted generation, classification, filtering and summarisation; storage in sheets; export; and transmission to systems you connect.
Purpose. Business-to-business prospecting, lead and account research, list building, data validation and enrichment, CRM hygiene, and outbound communication, in each case as you configure it.
Categories of data subjects. Business contacts and prospects; employees, officers and representatives of the companies you research; authors of public professional and social content; your own personnel who use the Service; and, where you enrol individuals in a stream, the individuals you monitor.
Categories of personal data. Which of these are processed depends entirely on the pipes and searches you run.
| Category | Examples of fields |
|---|---|
| Identity | Name, first name, last name, addressee name |
| Business contact | Work email, email validity and deliverability status, landline, phone |
| Personal contact | Personal email, alternate personal emails, mobile number |
| Employment | Job title, job description, seniority, profile headline, company name, company domain |
| Online profiles | Professional profile URL, developer profile URL, company profile URL, X username and user ID, Slack user ID, avatar URL |
| Location | Address lines, city, state, country, postcode, location hint |
| Technical | IP address |
| Profile content | Free-text profile summary, education history, employment history, languages, skills, certifications, profile photograph |
| Public posts | Post text and post lists from professional and social sources, follower counts |
| Derived and inferred | Career-event signals such as joined company, left company, promotion, changed role, work anniversary and graduated; estimated salary; signal counts |
| Connected systems | Records matched in your Slack, Gmail, Google Calendar, HubSpot, Salesforce, Attio, PostgreSQL or Databricks instance |
Special categories of data. None are requested by pipe0 or classified by it, and section 6.5 prohibits you from instructing their processing. Free-text profile fields may incidentally contain data from which a special category could be inferred.
Frequency of the processing. Continuous, on your instruction: per API call, per sheet run, and on any schedule you configure.
Retention. Run records, synchronous and asynchronous alike: 21 days from creation, then deleted within 24 hours. Sheet data, for the lifetime of the sheet, subject to section 13. Agent conversations and execution logs, for the lifetime of your account unless you ask privacy@pipe0.com to delete them earlier. Connection credentials, until you delete the connection or your account.
Transfers to sub-processors. As described in section 9 and Annexes III and IV, for the duration and purpose set out above.
Annex II — Technical and Organisational Measures
These are the measures in place as at the date of this version.
Encryption in transit. Traffic to and from the Service, and between the Service and its providers, uses TLS.
Encryption of credentials at rest. Connection credentials, meaning provider API keys and OAuth tokens, are held in Vault, pipe0's secure storage layer, encrypted at rest with AES-256-GCM. Secrets referenced in templated fields are resolved server-side at execution and are never returned in a response.
Access control and authentication. API access uses organisation-scoped API keys managed by organisation administrators. Browser contexts use a separate public key that authorises no data access, so a page can offer autocomplete without exposing an API key. The MCP server accepts OAuth only; API keys do not authenticate against it. Access to production systems is granted on a least-privilege basis.
Separation and isolation. Data is separated by organisation, and results are not shared or reused across organisations (section 3.5). Sandbox runs mock providers and never reach a provider, a connected system, or your CRM.
Integrity. Every run records the sheet version it validated against and is refused if the sheet has moved on, so concurrent edits cannot corrupt a result. Every change to a sheet is recorded in an append-only history identifying what changed, when, and which person, schedule or agent triggered it.
Recoverability. A destructive change seals the previous sheet version, so a sheet can be restored to an earlier point. Backups are taken on a rolling cycle.
Confirmation gating. Agent tools that spend credits or mutate data require confirmation on first use.
Personnel. Persons with access to Customer Personal Data are bound by confidentiality obligations.
Annex III — Platform Sub-processors
| Sub-processor | Purpose | Established |
|---|---|---|
| Cloudflare, Inc. | Content delivery, security, and webhook resolution | United States |
| Vercel Inc. | Hosting and deployment | United States |
| Hetzner Online GmbH | Infrastructure and storage | Germany |
| Anthropic, PBC | AI model inference | United States |
| OpenAI, LLC | AI model inference | United States |
| Google LLC | AI model inference | United States |
"Established" identifies where the entity is incorporated. It is not a statement about where processing takes place: several of these sub-processors operate facilities in more than one region.
Annex IV — Providers Reachable on Managed Connections
The pipe catalog is the authoritative list of which provider each pipe and search calls and which fields it transmits. This annex records each provider's role under this DPA and where it is established, as at the date of this version. Providers called on a custom connection are governed by section 9.5 instead.
Data Sources (independent controllers, section 3.3)
| Data Source | Entity | Established |
|---|---|---|
| Amplemarket | Tagis, Inc. | United States |
| Aviato | Bachmanity, Inc. | United States |
| BuiltWith | BuiltWith Pty Ltd | Australia |
| CompanyEnrich | STDİO Bilişim Ltd. Şti. | Türkiye |
| Crustdata | Crustdata Technologies Inc. | United States |
| Findymail | Peanuts SaaS Studio | France |
| Forager | Forager.ai, LLC | United States |
| Hunter | Hunter Web Services, Inc. | United States |
| Icypeas | Icypeas | France |
| LeadMagic | Lead Magic Corp. | United States |
| MixRank | Online Media Group, Inc. | United States |
| Prospeo | Defastra Tech Inc. | Canada |
| Surfe | Surfe Growster SAS | France |
| Wiza | Wiza, Inc. | United States |
| X | X Corp. | United States |
Processing Services (sub-processors, section 9.3)
| Processing Service | Entity | Purpose | Established |
|---|---|---|---|
| MillionVerifier | GBD Software as a Service Kft. | Email validation | Hungary |
| ZeroBounce | Hertza L.L.C. | Email validation | United States |
| Parallel | Parallel Web Systems Inc. | Web search and extraction | United States |
| Perplexity | Perplexity AI, Inc. | Web search with AI | United States |
| Google Gemini API | Google LLC | AI model inference | United States |