Data Processing Agreement (DPA)
Last updated: 8 October 2026
Draft: this text is currently under legal review and may still change.
This English version is a convenience translation. The German version is legally binding.
This Data Processing Agreement (“DPA”) governs the processing of personal data by airrange software GmbH, Sperberweg 7, 82152 Krailling, Germany (“ListPlus”, “processor”) on behalf of the customer (“Customer”, “controller”) when using ListPlus. It supplements the ListPlus Terms of Service (listplus.ai/terms, “Terms”) and becomes part of the contract when the user agreement is concluded, without the need for a separate signature. A signed copy is available on request (support@listplus.ai).
§ 1 Subject matter and definitions
(1) This DPA covers the processing of personal data that ListPlus carries out on behalf of the Customer when providing the Service under the Terms (“Customer Data”). Nature, purpose, categories of data and data subjects are set out in Annex 1.
(2) Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given in Art. 4 GDPR.
(3) “Retrieval Tools” are the features of the Service with which the Customer queries data from external data providers or publicly available sources, in particular enrichment, person and segment search, email verification, LinkedIn imports, AI research and signal lookups, including via the Agent API.
§ 2 Roles of the parties
(1) ListPlus as processor. The Customer is the controller and appoints ListPlus as processor for
- data the Customer uploads, imports, creates, synchronises from connected systems or forwards to the Inbox;
- data the Customer queries with the Retrieval Tools: ListPlus runs each search, enrichment or research only at the Customer's request and within the scope the Customer sets, transmits the necessary search key to the respective data provider and makes the result available to that Customer only;
- data the Customer sends to destinations of its choice via pipelines, exports, the Agent API or connected systems.
The Customer decides whether, about which persons, with which tools and for what purpose data is processed. It is responsible for complying with the obligations data protection law imposes on controllers.
(2) ListPlus as controller. ListPlus processes the following on its own responsibility and not on behalf of the Customer:
- account, contract, billing, support and usage data of the Customer's users;
- data required for operation, security, prevention of abuse and fraud, credit billing and compliance with legal obligations;
- aggregated or anonymised usage statistics for improving the Service that do not allow conclusions about individual data subjects in Customer Data;
- the cross-customer company cache (§ 13(3) of the Terms), to the extent it exceptionally contains personal data;
The ListPlus Privacy Policy (listplus.ai/privacy) applies to this processing.
(3) Data providers. External data providers are themselves responsible for their own databases. ListPlus owns no contact database and does not pass data from a database of its own to the Customer. Data providers and sources are listed in Annex 3, Part B; on a lookup they receive only the search key. Whether they are sub-processors (§ 7) in that respect or independent recipients to which the Customer transfers on its own legal basis is being clarified with our lawyers; until then the information and objection rights of § 7 apply to them accordingly.
§ 3 Instructions
(1) ListPlus processes Customer Data only on documented instructions from the Customer, unless required to do so by Union or Member State law; in that case ListPlus informs the Customer of that legal requirement before processing, unless that law prohibits it.
(2) The Customer's instructions are set out in full in the Terms, this DPA, the workspace policy and the Customer's operation of the Service. Every action triggered by the Customer or its users — such as an import, a search, an enrichment, a Watchlist alert, an AI research run with the search description written and the sources chosen by the Customer, a pipeline or an export — counts as a documented instruction to the extent defined by that action. The same applies to actions the Customer triggers via the Agent API or an AI system it connects. With the workspace policy (Terms § 3(4)) the Customer instructs ListPlus not to use certain features, data providers or sources for its workspace; ListPlus enforces this instruction technically.
(3) The Customer gives further instructions in text form to support@listplus.ai. ListPlus may refuse instructions that go beyond the agreed scope of services or carry them out for reasonable remuneration.
(4) ListPlus informs the Customer without delay if, in its opinion, an instruction infringes data protection law, and may suspend carrying it out until the Customer confirms or changes it.
§ 4 Customer obligations
The Customer ensures that
- there is a legal basis for every processing it initiates, in particular for querying data with the Retrieval Tools and for its later use;
- it informs data subjects under Art. 13 and 14 GDPR, honours objections and responds to data subject requests;
- advertising by email, phone or other channels only takes place within the legal requirements, in particular Section 7 of the German Act Against Unfair Competition (UWG);
- no special categories of personal data (Art. 9 GDPR) and no data relating to criminal convictions (Art. 10 GDPR) are processed;
- it is entitled to provide the Customer Data to ListPlus for processing.
The Customer informs ListPlus without delay if it detects errors or irregularities in the processing.
§ 5 Confidentiality
ListPlus ensures that all persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Only persons who need access to provide the Service, support or fix incidents are given access to Customer Data.
§ 6 Technical and organisational measures
(1) ListPlus takes the technical and organisational measures described in Annex 2 under Art. 32 GDPR to ensure a level of security appropriate to the risk.
(2) The measures are subject to technical progress. ListPlus may replace them with equivalent or better measures; the level of security must not fall below the agreed level.
§ 7 Sub-processors
(1) The Customer gives ListPlus general authorisation to engage sub-processors. The sub-processors engaged when the contract is concluded are listed in Annex 3 and are deemed approved.
(2) ListPlus informs the Customer in text form at least 30 days before engaging a new or replacing an existing sub-processor (e.g. by email or by updating Annex 3 with notice by email). The Customer may object to the change within this period in text form for a valid data protection reason. If the parties cannot agree, the Customer may terminate the user agreement with effect from the date the sub-processor is engaged. [TO CHECK: special rule for the short-notice replacement of a data provider that fails or discontinues its service.]
(3) ListPlus contractually binds each sub-processor to data protection obligations that substantially correspond to those in this DPA. ListPlus is liable to the Customer for the sub-processor's compliance with these obligations under Art. 28(4) GDPR.
(4) Ancillary services ListPlus uses from third parties without those third parties having access to Customer Data (e.g. telecommunications, payment processing for ListPlus itself) are not sub-processing within the meaning of this DPA.
§ 8 Transfers to third countries
Customer Data is processed outside the EU/EEA only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision (e.g. the EU-U.S. Data Privacy Framework) or the EU Standard Contractual Clauses (Module 3, processor to processor) that ListPlus concludes with the respective sub-processor. The Service is hosted in the EU region Frankfurt; the sub-processors concerned and the respective safeguard are listed in Annex 3.
§ 9 Assisting the Customer
(1) ListPlus assists the Customer with appropriate technical and organisational measures in responding to data subject requests. The Service enables the Customer to view, export, correct and delete Customer Data itself; the workspace's Block List flags records of people who are not to be contacted. If a data subject objects to ListPlus, ListPlus enters their identifier as a hash into a cross-customer suppression list so that they are no longer retrieved from data providers, recorded as a research hit or monitored through the Service; records the Customer already holds are unaffected and are for the Customer to handle.
(2) If a data subject contacts ListPlus directly, ListPlus forwards the request to the Customer without delay where the Customer can be identified, and does not answer it itself unless the Customer instructs it to or the law requires it.
(3) Taking into account the nature of processing and the information available, ListPlus assists the Customer in complying with the obligations under Art. 32 to 36 GDPR (security, notifications, data protection impact assessment, prior consultation).
(4) ListPlus may charge reasonable fees based on effort for assistance that goes beyond the features of the Service and is not caused by a breach by ListPlus.
§ 10 Personal data breaches
ListPlus notifies the Customer of a breach affecting Customer Data without undue delay after becoming aware of it, where possible within 48 hours. The notification contains, as far as known, the information under Art. 33(3) GDPR; missing information is provided later. ListPlus takes the necessary measures to secure the data and mitigate possible adverse effects without delay. Notifying supervisory authorities and data subjects is the Customer's responsibility.
§ 11 Deletion and return
(1) During the term of the contract, the Customer can export and delete Customer Data itself at any time. Certain data is deleted automatically after the periods stated in the Privacy Policy (section 11).
(2) After the user agreement ends and the account is deleted, ListPlus deletes the Customer Data unless there is a legal obligation to retain it. Copies in backups at the hosting provider are overwritten at the end of the backup cycle [TO CHECK: backup periods, currently up to 30 days].
(3) Data is returned through the Service's export feature before deletion.
§ 12 Evidence and audits
(1) On request, ListPlus provides the Customer with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. Up-to-date self-assessments, the description of measures in Annex 2 and certificates and audit reports of sub-processors (e.g. the hosting provider's ISO 27001 or SOC 2) will normally suffice as evidence.
(2) The Customer may carry out further audits, including inspections, at most once per calendar year after giving reasonable notice (at least 30 days) during normal business hours, itself or through an auditor bound to confidentiality who does not compete with ListPlus, unless a supervisory authority requires more or there is a specific reason. Each party bears its own costs.
§ 13 Liability
Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the Terms (§ 14 of the Terms) and the indemnification under § 15 of the Terms apply. As a processor, ListPlus is only liable for damage caused where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the Customer's lawful instructions.
§ 14 Term and final provisions
(1) This DPA applies for the term of the user agreement and beyond for as long as ListPlus processes Customer Data.
(2) In the event of conflicts between this DPA and the Terms, this DPA prevails in matters of data protection.
(3) ListPlus may change this DPA under the procedure in § 16 of the Terms, in particular to adapt it to changes in the law or in sub-processors. § 7 takes precedence for sub-processors.
(4) The laws of the Federal Republic of Germany apply. To the extent permitted by law, the place of jurisdiction is the registered office of airrange software GmbH.
(5) Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.
Annex 1: Subject matter and scope of processing
Nature and purpose of processing
Storing, checking, cleaning, enriching, searching, researching, transmitting and exporting contact and company lists as part of the Service under the Terms, including querying external data providers and publicly available sources with the Retrieval Tools and processing by AI models to the extent described in the Privacy Policy (section 12).
Categories of data subjects
- business contacts, prospects, customers and other persons in the Customer's lists;
- persons whose data the Customer queries with the Retrieval Tools, including persons the Customer has monitored on the Watchlist and persons recorded in AI research as authors of, commenters on or reactors to public posts;
- senders of, and persons named in, forwarded content (Inbox); persons who fill in a form of the Customer or whose data a system sends to a list's webhook;
- correspondents the Customer captures through the Outlook add-in;
- the Customer's employees, to the extent they are contained in Customer Data.
Categories of personal data
- name, job title and seniority, company;
- business email address and its deliverability status, business phone and, where applicable, mobile number;
- LinkedIn profile URL, location, publicly visible profile information (e.g. career history, past employers), public posts, comments and reactions; in AI research the source, evidence and a fit estimate;
- content of forwarded emails and attachments (Inbox);
- other data the Customer adds to its lists (no data under Art. 9 and 10 GDPR).
Duration
For the term of the user agreement; deletion under § 11.
Annex 2: Technical and organisational measures
- Hosting and location: application, file storage and working memory (Redis) in the EU region Frankfurt. The hosting provider Vercel is certified under ISO 27001:2022 and has a SOC 2 Type 2 report; ListPlus itself holds no certification of its own.
- Encryption: transmission encrypted only (TLS), including between the application and the database and to every service provider; file storage encrypted at the hosting provider [TO CHECK: confirm encryption at rest for Redis Cloud]; access keys stored by the Customer are stored encrypted.
- Sign-in control: sign-in by one-time email code or via Google; sessions via signed tokens (30 days); no shared accounts.
- Access control: access to lists only for the respective account, invited workspace members and people it is explicitly shared with; every interface checks authorisation on the server. Database and API keys are used on the server only.
- Separation: Customer Data is stored separately per workspace. Results about people are not shared between customers; only company data without personal reference is stored across customers (30 days).
- Data minimisation in retrievals: only the search key needed for the query is transmitted to data providers, never the rest of the list.
- Data minimisation in AI: AI processing on the server only; the extract needed for the task is sent to AI providers — for checks only unique values, for text columns, the Inbox, the webhook check and dictation the respective text or record (Privacy Policy, section 12); requests to OpenAI with the “do not store” setting, to the judgement model without storage at the provider. The Customer can switch AI features off per workspace.
- Transfer control: external access points (Agent API, data endpoints, Inbox address, list webhooks) are protected by secret, revocable keys; incoming webhooks verify signatures or shared secrets; which service providers receive data the Customer controls through the workspace policy.
- Availability: the lists live permanently in the hosting provider's file storage and are loaded from there; the database is replicated and writes a journal, there is currently no separate backup of the database [TO CHECK: retention of the file storage]. Rate limits against abuse.
- Deletion: deletion of lists, workspaces and the account by the Customer with immediate effect (self-service); automatic deletion periods for the Inbox, shared links, research runs, caches and pipeline history (Privacy Policy, section 17).
- Organisation: commitment to confidentiality; access to production data only where needed for operation and support [TO CHECK: describe logging of administrative access].
Annex 3: Sub-processors
Part A: Sub-processors
These providers process customer data on our behalf under Art. 28 GDPR. “Switch off” names the workspace policy switch with which the customer stops transfers to this provider for its workspace.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off |
|---|---|---|---|---|---|
| Vercel Inc. | Running the application, file storage for lists and imports, queues for background work, web analytics and speed insights, AI gateway (access to the model “Jev”) | All data of the application; connection data on every request (IP address, browser) | Covina, California, USA — Hosting, file storage and queues in the EU region Frankfurt | EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreement | no |
| Redis Ltd. (Redis Cloud) | The application's database: workspaces, lists, working data, caches | All data of the application | Seat: Mountain View, California, USA — Database in Frankfurt (AWS eu-central-1), transport TLS-encrypted — [TO CHECK: Confirm the data processing agreement and encryption at rest] | Processing in the EU; Standard Contractual Clauses for support access from third countries | no |
| Pusher Ltd. | Live status updates in the browser (import done, enrichment running, new hits) | Events about operations; for small changes the changed cell values | London, United Kingdom — [TO CHECK: Confirm the cluster location] | Adequacy decision for the United Kingdom | no |
| Pipedream, Inc. | Connections to CRM systems and spreadsheets (OAuth credentials, forwarding of calls); internal notifications about account, list and payment events | Records the customer exchanges with a connected system; from events the user id, e-mail address, list name and row count and a summary of the payment event (customer, e-mail, amount, plan) | San Francisco, California, USA — [being replaced] — [TO CHECK: The service is being discontinued; notifications move to n8n, the replacement for connections is open] | Standard Contractual Clauses | yes (connections) |
| Postmark (ActiveCampaign, LLC) | Receiving e-mails forwarded to the Inbox address @in.listplus.ai; sending workspace invitations and pipeline digest mails from notifications@listplus.ai | Forwarded e-mails in full (sender, subject, body, attachments); the invitee's address and the inviter's name; per digest entry name, position, company | Chicago, Illinois, USA — [TO CHECK: Sign the data processing agreement; shorten retention at the provider (default 45 days)] | Standard Contractual Clauses | yes (inboxEmail, pipelineEmail) |
| OpenAI | Language models for commands, checks, AI columns, column recognition on import, recognition of contacts in the Inbox, mapping of unknown webhook fields, AI research; transcription of dictations | The excerpt the task needs (section “AI processing” of the privacy policy); requests are not stored at the provider (store: false) and not used for training | OpenAI Ireland Ltd., Dublin, Ireland (contracting entity for the EU) / OpenAI, L.L.C., San Francisco, USA — [TO CHECK: Confirm the contracting entity (Ireland/USA) and the Data Processing Addendum] | EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the Data Processing Addendum | yes (ai) |
| Groq, Inc. | Fast language model for short single calls: understanding a search query, role resolution, list titles, short Inbox entries | The short text of the request (search description, signature line) | Mountain View, California, USA — [TO CHECK: Confirm the Data Processing Addendum and the no-training clause] | Standard Contractual Clauses | yes (ai) |
| TypeSafe AI (Modell „Jev“, über das AI Gateway von Vercel) | Judgement model: seniority of job titles, kind of a LinkedIn position, pre-check of Inbox entries and webhook records, judge columns | The values to judge (job titles, positions, up to 12 fields of a record); without storage at the provider (zero data retention) | Seat: to be confirmed — [TO CHECK: Confirm seat, contracting entity and safeguard] | Standard Contractual Clauses via Vercel | yes (ai) |
| Apify Technologies s.r.o. | Data collection platform: runs scrapers (“actors”) that read public pages — LinkedIn imports (Sales Navigator, employee lists, post reactions and comments, people search incl. by past employer), Crunchbase company pages, Reddit, X, Google Maps profiles, web traffic, contact details on websites | The search URL, company URL, post URL, company name or research query — never the customer's list | Prague, Czech Republic — [TO CHECK: Confirm the data processing agreement; third-party actors run on Apify's infrastructure] | Processing in the EU | yes (provider:apify) |
Part B: Data providers and sources
On a lookup these providers receive only the search key (e.g. e-mail address, domain, LinkedIn URL, name and company or search filters), never the rest of the list. They are controllers of their own data; ListPlus is the tool with which the customer queries them. Whether they count as sub-processors or as independent recipients for the search key is being clarified with our lawyers.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off |
|---|---|---|---|---|---|
| Prospeo | B2B contact database (segment search), verified business e-mail addresses and phone numbers, company profiles, job changes | Search filters or the search key: LinkedIn URL, name and company, domain | Prospeo SAS, Paris, France — [TO CHECK: Confirm the seat] | Processing in the EU | yes (provider:prospeo) |
| FullEnrich | Business e-mail address and phone number from name and company or LinkedIn URL (waterfall through 20+ sources) | Name and company, domain or LinkedIn URL | FullEnrich Corp., San Francisco, USA | Standard Contractual Clauses according to the provider's privacy policy | yes (provider:fullenrich) |
| CompanyEnrich | Company data from domain or company name (industry, size, location, website); workforce, decision makers, similar companies | Domain or company name; for person lookups name and company | Company in Turkey — Servers, databases and backups in Finland — [TO CHECK: Clarify the safeguard for access from Turkey] | Processing in the EU (Finland); Turkey without an adequacy decision | yes (provider:companyenrich) |
| HarvestAPI | Publicly visible LinkedIn data: profile, company, profile search, posts and reactions, open jobs; the basis of the Watchlist alerts | LinkedIn URL, name and company, post URL | Seat: to be confirmed — [TO CHECK: Confirm seat and safeguard] | To be confirmed | yes (provider:linkedin, alerts) |
| Enrich.so | Publicly visible LinkedIn profile data from a URL (fallback when HarvestAPI does not answer) | LinkedIn URL | Seat: to be confirmed — [TO CHECK: Confirm seat and safeguard] | To be confirmed | yes (provider:linkedin) |
| MillionVerifier | Checking whether an e-mail address is deliverable | The e-mail address | GBD Software as a Service Private Limited Company, Budapest, Hungary | Processing in the EU | yes (provider:millionverifier) |
| Serper (Google-Suche) | Google search results: LinkedIn profile URL for name and company, company website, news, web search of the AI research, confirmation of recognised contacts in the Inbox | The search term (e.g. name and company) | Serper, seat: to be confirmed — [TO CHECK: Confirm seat and safeguard] | To be confirmed | yes (provider:serper) |
| Hacker News (Suche über Algolia) | Public stories and comments on Hacker News including user names, for the AI research | Only the search term, never data from customer lists | Algolia, Inc., San Francisco, USA — public interface without an account | No contract; only the search term is transmitted | no |
| Öffentliche Quellen (über Apify gelesen) | Publicly visible pages a scraper reads at the customer's request; the platforms are not our contracting partners, the customer observes their terms | The URL or search called | LinkedIn, Crunchbase, Reddit, X, Google Maps, Similarweb, arbitrary websites | Not applicable (retrieval of public pages) | yes (provider:apify, source:reddit, source:twitter, source:linkedin, source:people, source:sources) |
Part C: Recipients chosen by the customer
Systems the customer transfers data to because it connects or names them itself. The customer is the controller of that transfer; they are listed for completeness.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off |
|---|---|---|---|---|---|
| Verbundene Systeme des Kunden | Import from and export to systems the customer connects; pipeline targets | The records the customer transfers | HubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, lemlist (via Pipedream); Instantly, Smartlead, Attio, Close, Slack (with the customer's key) | The customer is the controller of this transfer | yes (connections) |
| Eigener Webhook-Endpunkt des Kunden | Pipeline target “endpoint” | The records the customer transfers | Named by the customer | The customer is the controller of this transfer | no |
| Die eigene KI des Kunden (Agent-API, MCP, Recherche-Link) | Reading and writing lists and research through an AI system the customer connects | What the connection exposes (columns, sublists, actions) | Chosen by the customer, e.g. ChatGPT, Claude, own agents | The customer is the controller of this transfer | yes (agentApi) |
Open points per provider are marked [TO CHECK] in the table; the current version of this annex is published at listplus.ai/en/subprocessors. Not in this annex: providers that process only the users' account, contract and billing data (privacy policy, section 15).