Pipelizo
Legal · DPA

Data Processing Addendum

Last updated: May 1, 2026

01

Purpose

This Data Processing Addendum ("DPA") forms part of the Pipelizo Terms of Service and sets out the terms under which Pipelizo, Inc. processes personal data on behalf of its customers. It is designed to satisfy GDPR Art. 28, UK-GDPR, and CCPA service-provider requirements.

02

Roles

For personal data within customer workspaces, the customer is the controller and Pipelizo is the processor. For account and marketing data, Pipelizo is the controller.

03

Scope of processing

Pipelizo processes customer data only on documented instructions from the customer, for the purpose of providing the service as described in the Terms.

Categories of data subjects: customer's employees, prospects, contacts, customers. Categories of data: name, email, phone, company, job title, communication history, deal metadata, and any custom fields the customer chooses to create.

04

Sub-processors

A current list of authorized sub-processors is maintained at pipelizo.com/sub-processors. The customer hereby provides general authorization for these sub-processors.

Pipelizo will give 30 days' notice before adding any new sub-processor; the customer may object by terminating the affected portion of the service.

05

International transfers

Where data is transferred outside the EEA/UK, Pipelizo relies on EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, supplemented by appropriate technical safeguards (encryption, pseudonymization, access controls).

06

Security

Pipelizo implements technical and organizational measures as documented in our Security overview, which form part of this DPA by reference.

07

Data subject rights

Pipelizo will, taking into account the nature of processing, assist the customer in fulfilling data subject access, rectification, erasure, restriction, and portability requests — at no additional charge.

08

Breach notification

Pipelizo will notify the customer without undue delay (target: within 48 hours) of becoming aware of a personal data breach. Notifications include the nature of the breach, affected data, likely consequences, and remediation steps.

09

Audit & deletion

The customer may, at most once per year, request reasonable audit information about Pipelizo's compliance — typically satisfied by sharing our SOC 2 Type II report.

On termination, Pipelizo will delete or return all customer data within 30 days, except where retention is required by law.

10

Execution

This DPA is automatically incorporated into your Pipelizo Terms. If a signed DPA is required for your records, email support@pipelizo.com — we counter-sign within 48 hours.

Questions about this policy?

Reach out to our legal team — we reply within 2 business days.

Contact legal →
Ready when you are

Move your pipeline
like it's 2026.

Spin up a workspace in 90 seconds. Import your contacts in two clicks. Close your first deal in Pipelizo by Friday.

  • 20-min call
  • Weekend migration
  • Real operators
  • SOC 2 Type II
Onboarding · Day 1
3 of 4 steps complete
On track
Connect inbox
Import contacts (1,284)
Build first pipeline
4 Invite your team