1. Definitions
In this DPA:
- Authorised User means any individual you permit to access your incorporated.today account who can initiate Contact Enrichment.
- Contact Enrichment Feature means the on-demand retrieval of third-party business contact information (emails, telephone numbers, and related professional attributes) for UK company officers and accounts signatories via the Service, including passthrough delivery and optional Saved Contact storage.
- Enrichment Personal Data means personal data relating to identifiable individuals returned by an enrichment Sub-processor in response to your documented instruction, including names, job titles or roles (where returned), business email addresses, telephone numbers, and employer or company context.
- Passthrough Processing means retrieval, transient server-side handling, and delivery of Enrichment Personal Data to your active browser session without automatic persistence in Processor's application database.
- Saved Contact Data means Enrichment Personal Data you instruct Processor to store by clicking Save in the Inspector Contacts tab, held in encrypted form in Postgres together with associated metadata (company number, company name, person name, normalised name key, role, save timestamp, and data provider source).
- Service means the incorporated.today platform operated by Processor (trading as inc:tdy, incorporated:today and incorporated.today).
- Sub-processor has the meaning in Article 28 UK GDPR and includes the entities listed in Section 10.
- UK GDPR means the UK General Data Protection Regulation as retained in UK law, together with the Data Protection Act 2018.
2. Parties
Processor: fernandes.media limited (trading as inc:tdy, incorporated:today and incorporated.today), company number 17256342, registered office 66 Dulverton Road, Leicester, LE3 0SA, England. Contact: info@incorporated.today. ICO registration: not currently registered.
Controller: The organisation or individual that holds a paid incorporated.today account with access to the Contact Enrichment Feature (Pro or Executive tier) and that accepts this DPA. Where you subscribe on behalf of an organisation, you represent that you have authority to bind that organisation.
3. Formation, acceptance & precedence
This DPA forms part of your subscription to the Service and is incorporated into our Terms of service by reference. It applies when you accept version 2026-06-18 or later at checkout, during legal onboarding, or by continuing to use the Contact Enrichment Feature after we publish a material update and require re-acceptance.
Acceptance is recorded on your user account (dpa_accepted_at, dpa_version). The Contact Enrichment Feature is blocked until legal onboarding is complete, including current Terms, Privacy, Cookie policy, and this DPA.
If there is a conflict between this DPA and the Terms regarding the processing of Enrichment Personal Data or Saved Contact Data, this DPA prevails. Account data, billing, platform security logs, Companies House registry cache, encrypted company notes, watchlist, contacted flags, and search indexing are governed by our Privacy policy and Terms, not this DPA.
4. Scope
This DPA applies only to processing of Enrichment Personal Data and Saved Contact Data under the Contact Enrichment Feature.
In scope:
- each explicit click of Get contact details on an officer or signatory (Passthrough Processing);
- transient in-memory handling of async enrichment jobs in your browser session and on Processor's API layer pending delivery;
- each explicit click of Save on a completed enrichment result (Saved Contact Data);
- export, deletion, and account-level purge of Saved Contact Data on your instruction or account termination.
Out of scope (Processor acts as an independent controller or under separate lawful bases — see Privacy policy):
- user account, authentication, and subscription metadata;
- encrypted private company notes, contacted flags, watchlists, and saved searches;
- Companies House registry data, officer/signatory names from statutory filings cache, and Typesense search index documents;
- Brandfetch domain/logo lookup (separate pass-through, not enrichment);
- enrichment credit metering and billing metadata (no contact payloads).
5. Controller and processor roles
- You (Controller) determine whether and why to obtain Enrichment Personal Data, your lawful basis under Article 6 UK GDPR, and all downstream use (including outbound sales, marketing, research, CRM import, and retention outside the Service).
- Processor processes Enrichment Personal Data only on your documented instructions as set out in Section 6, and implements the technical measures in Annexes A and B.
- Each Authorised User's click actions constitute your instructions. You are responsible for Authorised Users' compliance with this DPA and Section 8.
6. Documented instructions
You instruct Processor to:
- enable the Contact Enrichment Feature for Pro and Executive subscriptions with valid DPA acceptance;
- upon each Get contact details action, query enabled licensed enrichment Sub-processors (sync waterfall and/or async BetterContact path) and deliver results to your active session via HTTPS;
- operate Passthrough Processing as the default — no automatic write of emails or telephone numbers to Postgres or Typesense;
- hold incomplete async jobs in transient server and client session state only until completion, failure, or session end;
- upon each Save, encrypt and store Saved Contact Data in Postgres, scoped strictly to your user account, with metadata for audit (save timestamp, provider source, optional provider request identifier);
- upon your delete action, hard-delete the relevant Saved Contact Data row;
- upon export request, deliver a structured export of your Saved Contact Data;
- upon account deletion, permanently delete all Saved Contact Data associated with your account.
You do not instruct Processor to send marketing communications on your behalf. Processor will not use Enrichment Personal Data for its own marketing or to build independent commercial contact databases.
Processor may refuse, suspend, or limit processing where an instruction would infringe UK GDPR, PECR, applicable sanctions, or our acceptable use rules, or where required by law or a competent authority.
7. Processing schedule (Article 28)
| Item | Passthrough Processing | Saved Contact Data |
|---|---|---|
| Subject matter | On-demand B2B contact enrichment lookups | Optional encrypted storage of enrichment results you save |
| Duration | While you hold Pro/Executive access with valid DPA acceptance | Until you delete the contact, export and delete, or your account is deleted |
| Nature | API query; transient server handling; HTTPS delivery to client session; optional async polling | AES-256-GCM encryption at rest; per-user row isolation; upsert by user, company, and normalised person name |
| Purpose | Assist your B2B prospecting and company research as you direct | Allow you to retain selected enrichment results within the Service for ongoing research |
| Data subjects | Directors, officers, employees, signatories, and related business individuals | Same |
| Categories of personal data | Names, roles/titles, business emails, phone numbers, employer/company context | Same fields, plus save metadata and provider source |
| Retention by Processor | Zero retention after session ends (except non-contact billing/ownership metadata — see Annex A) | Encrypted storage until delete or account termination |
| Special categories | None intentionally processed | None intentionally processed |
8. Controller obligations
You represent, warrant, and undertake that:
- you have determined and can demonstrate a valid lawful basis under Article 6 UK GDPR before obtaining or using Enrichment Personal Data, including documented legitimate interest assessments where you rely on legitimate interests;
- you will comply with PECR and screen against TPS/CTPS (and equivalent rules) before unsolicited telephone or electronic marketing contact;
- you will provide Article 13/14 fair processing information to data subjects where required — Processor cannot do this on your behalf for passthrough results displayed only in your session;
- clicking Save is your instruction to retain that data subject's contact details; you remain Controller for any use of Saved Contact Data after storage;
- you accept sole responsibility for accuracy verification, outbound communications, CRM imports, exports, copies taken outside the Service, and retention in systems you control;
- Authorised Users act on your behalf; their actions bind you as instructions under this DPA;
- you will not use enrichment for spam, harassment, unlawful surveillance, discrimination, fraud, or resale of contact lists in violation of law, upstream provider terms, or our Terms;
- you will notify Processor promptly if you become aware that an instruction infringes data protection law.
9. Processor obligations
Processor shall:
- process Enrichment Personal Data and Saved Contact Data only on your documented instructions (Section 6), unless required by UK or EU law applicable to Processor (in which case Processor shall inform you unless prohibited);
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures per Annex B and Article 32 UK GDPR;
- engage Sub-processors only in accordance with Section 10;
- taking into account the nature of processing, assist you with reasonable measures to respond to data subject requests relating to Saved Contact Data (export and deletion via the Service; passthrough results are not stored by Processor after session end);
- assist you with security, breach notification, and DPIA obligations as reasonably requested, limited to information Processor actually holds;
- at your choice, delete or return Saved Contact Data on termination of services, except where UK law requires retention;
- make available information necessary to demonstrate compliance and allow audits as set out in Section 14;
- notify you without undue delay after becoming aware of a personal data breach affecting Saved Contact Data or the transmission of Enrichment Personal Data through Processor's systems (Section 12).
10. Sub-processors
You provide general written authorisation for Processor to engage the Sub-processors below. Processor remains liable to you for Sub-processor performance.
| Sub-processor | Processing activity | Personal data handled |
|---|---|---|
| BetterContact (or successor API provider) | Async contact enrichment API | Query parameters and returned contact fields; may process outside the UK |
| People Data Labs | Sync contact enrichment API (when enabled) | Query parameters and returned contact fields; may process outside the UK |
| Apollo.io | Sync contact enrichment API (when enabled) | Query parameters and returned contact fields; may process outside the UK |
| Vercel Inc. | Serverless application hosting and API execution | Transient request/response handling in memory; TLS termination |
| Neon (Postgres) | Managed relational database | Saved Contact Data (encrypted payloads + metadata); async job ownership records (request identifier and user identifier only); enrichment billing idempotency records — not contact payloads |
| IONOS VPS (self-hosted) | Search ingest infrastructure | Companies House company documents only — no enrichment contact fields indexed |
Processor may add or replace Sub-processors by updating this page and, where material, notifying you by email or in-product notice. You may object on reasonable grounds relating to data protection within 14 days of notice. If we cannot reasonably accommodate an objection, you may terminate the Contact Enrichment Feature portion of your subscription without penalty for that feature (other Terms apply to the remainder of the Service).
Enabled enrichment providers are configured administratively; only providers with valid API credentials are invoked. Default technical order is People Data Labs → Apollo → BetterContact (async), subject to feature flags.
11. International transfers
Enrichment Sub-processors may process data in the United States or other countries outside the UK. Where Processor or a Sub-processor transfers personal data outside the UK, Processor will ensure appropriate safeguards under UK GDPR Chapter V (including UK International Data Transfer Agreement addendum and/or UK Addendum to EU Standard Contractual Clauses, and supplementary measures where required).
You acknowledge that upstream enrichment APIs are outside Processor's direct control and may involve transfers you must factor into your own compliance programme as Controller.
12. Personal data breaches
Processor shall notify you without undue delay, and in any event within 72 hours of becoming aware, where feasible, of a personal data breach affecting:
- Saved Contact Data stored in Postgres;
- the integrity or confidentiality of Enrichment Personal Data in transit through Processor's API layer; or
- unauthorised access to systems used exclusively for enrichment.
Notification shall include, to the extent known: nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed. Passthrough-only sessions that did not result in Saved Contact Data generally limit Processor's stored exposure to non-contact metadata.
You remain responsible for notifying the ICO and data subjects where you are required to do so as Controller.
13. Data subject rights
Passthrough results: Because Processor does not retain Enrichment Personal Data after your browser session ends (unless you Save), erasure or access requests relating to contact details shown only in passthrough mode must be directed to you as Controller, or to the relevant enrichment Sub-processor holding the upstream source record. Processor will redirect third-party requests received directly to you where appropriate.
Saved Contact Data: Processor will assist by providing export (Export all in the Inspector Contacts tab) and per-contact deletion tools. Account deletion triggers bulk purge. Processor will respond to your written instructions to assist with data subject requests within a reasonable time, limited to Saved Contact Data Processor holds.
14. Deletion, return & termination
On termination of your subscription or revocation of enrichment access, Processor will delete Saved Contact Data within 30 days, except where retention is required by law or for established legal claims (in which case data is isolated and protected until deletion is permitted).
Passthrough results are not returned or archived by Processor at termination. You are responsible for exporting Saved Contact Data before account closure if you need a copy.
Sections 8, 11, 15, and 16 survive termination for claims arising during the term.
15. Audit & compliance information
Processor shall make available on request reasonable information to demonstrate compliance with this DPA, including summaries of technical measures in Annexes A and B. Onsite audits may be conducted no more than once per twelve-month period (unless mandated by a supervisory authority or following a material breach), on at least 30 days' notice, during business hours, subject to confidentiality and security restrictions, and at your expense unless audit reveals material non-compliance by Processor.
16. Indemnity and liability
Indemnity. You shall indemnify and hold harmless Processor against claims, fines, penalties, damages, and reasonable legal costs arising from your (or an Authorised User's) use or misuse of Enrichment Personal Data or Saved Contact Data, failure to comply with PECR/TPS/CTPS, lack of lawful basis, outbound communications you initiate, instructions that infringe law, or breach of Section 8.
Cap. Processor's aggregate liability under this DPA is limited to the greater of £1,000 or fees paid by you for the Service in the twelve months before the claim, except where UK law prohibits exclusion (including fraud or death/personal injury from Processor's negligence).
Processor is not liable for upstream data accuracy, completeness, or your decisions made using enrichment results. Neither party excludes liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation.
17. Term
This DPA applies while you have Pro or Executive access to the Contact Enrichment Feature and a current dpa_version acceptance. Material changes require a new version acceptance via legal onboarding.
Annex A — Technical architecture
A.1 Passthrough path (default)
- Enrichment is returned only on authenticated requests with explicit fetch parameters; normal company profile loads never include vendor contact fields.
- Sync path (People Data Labs / Apollo): single request/response; results held in modal session state only; stripped before shared client cache refresh.
- Async path (BetterContact): POST submits job; client polls until complete; results appear in Inspector Contacts tab session RAM (contact-jobs-store); not written to Postgres unless Saved.
- Job ownership table stores provider request identifier and user identifier only — not contact payloads. Poll requests return 404 if the session user did not submit the job.
- Outcome-based credit metering records billing idempotency keys — not emails or phone numbers.
- No Typesense indexing of enrichment fields.
- Application logs and admin telemetry record company number and fetch metadata — not enrichment contact payloads.
- TLS for all client, API, and Sub-processor calls.
A.2 Optional Saved Contact path (explicit Save only)
- Save action in Inspector Contacts tab writes to saved_contacts (Postgres).
- Plaintext metadata: company number, company name, person name, normalised person name, role, save timestamp, provider source, optional provider request identifier.
- Contact fields (email, phone) encrypted AES-256-GCM; additional authenticated data binds ciphertext to user identifier, company number, and normalised person name; key version tracked for rotation.
- Unique constraint per user, company, and normalised person name (upsert on re-save).
- Strict per-user isolation on all API routes; session authentication required; email allowlist gate applies.
- Hard delete via card action, export endpoint, or account deletion purge.
- Company modal may load saved rows for the open company and map onto officers/signatories by normalised name — no cross-user visibility.
A.3 UI disclosure
Enrichment results are fetched on request and are not stored unless you click Save in the Inspector Contacts tab. Credit charges apply when contact details are returned (see Terms); misses are free.
Annex B — Security measures
| Measure | Implementation |
|---|---|
| Access control | Authenticated sessions; plan entitlements; legal onboarding gate; per-user saved contact isolation; async job ownership checks |
| Encryption in transit | TLS 1.2+ for browser, API, and Sub-processor connections |
| Encryption at rest (Saved Contact Data) | AES-256-GCM with per-row IV; AAD-bound ciphertext; key derived from application secret with versioned derivation string |
| Encryption at rest (company notes — out of DPA scope) | Separate AES-256-GCM scheme for CRM notes; documented in Privacy policy |
| Minimisation | No automatic persistence of passthrough enrichment; no contact fields in search index or routine logs |
| Availability | Hosted infrastructure with provider SLA; no guarantee of enrichment provider uptime |
| Incident response | Breach notification per Section 12; activity logging for security events |
| Personnel | Limited access to production systems; confidentiality obligations |
Legal notice. This document is provided for transparency and contractual clarity between B2B parties. It is not legal advice. Material reliance should be reviewed by qualified UK data protection counsel. Version 2026-06-18.