Data Processing Agreement
Version of
This agreement applies whenever a customer uses CampaignStack to process personal data it controls. It is part of the terms of service and needs no signature to apply. A countersigned copy, or a copy naming your entity, is sent on request to privacy@campaignstack.io.
1. Parties and roles
The customer (the business holding the CampaignStack account) is the controller of the customer data below. CampaignStack, the operator named on the invoice, is the processor. For the shared professional database CampaignStack is a controller in its own right; that processing is described in the privacy policy and is outside this agreement.
2. What is processed
| Subject matter | Running outbound campaigns on LinkedIn and email on the customer's behalf. |
| Duration | The life of the customer account, plus the retention periods in the privacy policy. |
| Nature and purpose | Storing, enriching, scoring and contacting business contacts; drafting messages; recording replies, meetings and outcomes; reporting. |
| Categories of data | Business contact details (name, title, employer, work email, LinkedIn URL), professional events, message content exchanged with the customer's connected accounts, tags, notes, campaign membership and results. Connected-account credentials as described on the security page. |
| Data subjects | Business contacts the customer imports or attaches to its workspace; the customer's own users; the holders of connected LinkedIn and Google accounts. |
| Special categories | None are requested, and the customer agrees not to import any. |
3. Instructions
CampaignStack processes customer data only on the customer's documented instructions: the terms, this agreement, and what the customer configures in the product (campaigns, workflows, review settings, exclusions, integrations, API and MCP calls). If CampaignStack believes an instruction breaks data-protection law, it tells the customer before acting on it.
4. Confidentiality
People with access to customer data are bound by confidentiality. Access is limited to what operating and supporting the Service requires, and every access path is role-gated inside the product.
5. Security
The technical and organisational measures are those described on the security page at the time of processing: TLS in transit, AES-256-GCM for stored keys and credentials, encrypted browser profiles, no LinkedIn session in any database, per-account isolation of proxies and profiles, role-based access, logging stripped to technical fields. That page is updated when the measures change, and a change that lowers protection is notified under section 12.
6. Subprocessors
The customer authorises the subprocessors listed on the security page, in these categories:
- Hosting, database and backend functions
- The automation server that runs browser sessions
- Residential proxies that carry LinkedIn traffic
- Transactional email delivery
- AI model providers, as listed with what each receives
- Error tracking, product analytics and technical logs
- Payment processing
CampaignStack tells registered customers by email at least 14 days before adding or replacing a subprocessor that will handle customer data. A customer that objects on reasonable data-protection grounds may terminate the affected workspace before the change applies and is refunded the unused part of the period. Each subprocessor is bound by written terms at least as protective as this agreement, and CampaignStack stays responsible for their performance.
7. Transfers
Customer data is stored on infrastructure in the United States and the European Union, as stated per vendor on the security page. Transfers outside the EEA and the UK rest on the European Commission's standard contractual clauses or the vendor's EU-US Data Privacy Framework certification, as stated in each vendor's agreement. The security page names the model providers that receive personal data and where they are hosted, including the one hosted in China that runs the browser agents; a customer that does not accept that provider should not use the features that depend on browser agents, and can ask which ones do.
8. Assisting the customer
CampaignStack helps the customer answer data-subject requests about customer data: export of a person's record, correction, deletion and objection are available in the product, and the suppression register honours an objection across every sending path. Requests that reach CampaignStack directly and concern customer data are forwarded to the customer within five working days. CampaignStack assists with impact assessments and consultations with a supervisory authority to the extent the information is with CampaignStack.
9. Breach notification
CampaignStack notifies the customer without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting customer data, with what is known at that time and updates as the picture changes. The incident runbook is an internal document; the security page describes the stop levers, what is and is not backed up, and how to reach us.
10. Deletion and return
At the end of the contract, or when the customer deletes a workspace or the account, customer data is deleted subject to the retention periods in the privacy policy (90 days after the deletion for a workspace's leads, lists, imports and conversations), and connected browser profiles are destroyed. Before that, the customer can export lead lists as CSV and workflows as JSON from the product. Data in the shared professional database that the customer did not supply is not customer data and is not deleted on the customer's behalf.
11. Audit
CampaignStack answers a written security questionnaire once a year and makes available the documentation that shows compliance with this agreement. An on-site or remote audit is available once a year, on 30 days' notice, at the customer's cost, during business hours, limited to what a supervisory authority could require, and never reaching another customer's data. There is no SOC 2 report or external penetration test to share yet; the security page says so.
12. Changes
This agreement changes only by a new version published here, notified to registered customers at least 14 days before it applies, and never to lower the protection of customer data without the customer's agreement.
13. Liability and precedence
Liability under this agreement follows section 12 of the terms of service. Where this agreement and the terms conflict on the processing of personal data, this agreement wins.