Data Processing Agreement

Last updated: April 2026

Incorporated into the Terms of Service by reference.

Agenturo is GDPR-compliant. This Data Processing Agreement ("DPA") formalises the controller/processor relationship required by Article 28 of the General Data Protection Regulation (EU) 2016/679. By enabling lead capture on your agent, you (the Controller) and Agenturo (the Processor) enter into this DPA automatically — no separate signature is required.

1. Definitions

  • "Controller" means the Agenturo user who has enabled lead capture on their agent and is responsible for determining the purposes and means of processing visitor lead data.
  • "Processor" means Agenturo, which processes personal data on behalf of the Controller.
  • "Personal Data" means any data submitted via the lead capture form: visitor name, email address, phone number, company name, and message.
  • "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.
  • "GDPR" means the General Data Protection Regulation (EU) 2016/679.
  • "Sub-processor" means any third party engaged by Agenturo to process Personal Data on the Controller's behalf. See Sub-processors.

2. Subject Matter and Duration

Agenturo processes lead Personal Data solely to provide the lead capture feature — storing submissions, notifying the Controller by email, and displaying leads in the admin panel. Processing continues for as long as the Controller's account is active and lead capture is enabled, or until earlier deletion or termination.

3. Nature and Purpose of Processing

  • Collecting and storing lead form submissions on behalf of the Controller.
  • Sending new-lead notification emails to the Controller.
  • Displaying leads in the Controller's admin panel.
  • Applying retention rules: leads are stored for 90 days by default (extendable to 1 year at the Controller's election), then permanently deleted.

Agenturo does not use lead Personal Data for its own purposes, marketing, or profiling.

4. Types of Personal Data and Data Subjects

Categories of data: name, email address, phone number (optional), company name (optional), free-text message.

Data subjects: visitors to the Controller's agent page who voluntarily submit a lead capture form.

5. Controller Obligations

  • Establish and document a lawful basis for collecting visitor lead data (e.g., consent under Art. 6(1)(a) GDPR).
  • Provide visitors with a privacy notice that includes the Controller's identity, the purpose of data collection, and their rights.
  • Ensure the lead capture consent text displayed to visitors accurately describes how their data will be used.
  • Not use collected lead data for spam, unsolicited marketing beyond what visitors were informed of, or sale to third parties.
  • Promptly notify Agenturo at privacy@agenturo.app if a data subject exercises a right (access, erasure, portability) relating to lead data, so Agenturo can assist.
  • Comply with all applicable privacy laws in the Controller's jurisdiction.

6. Processor Obligations (Agenturo)

Agenturo commits to the following under Article 28 GDPR:

  • Process only on documented instructions: Agenturo processes lead Personal Data only as described in this DPA and the Terms of Service. If Agenturo is required by law to process data beyond these instructions, it will notify the Controller unless prohibited by law.
  • Confidentiality: Agenturo ensures that persons authorised to process Personal Data are bound by confidentiality obligations.
  • Security: Agenturo implements appropriate technical and organisational measures including encryption at rest (AES-256), encryption in transit (TLS 1.3), access controls, and rate limiting. See the Privacy Policy §8 for details.
  • Sub-processors: Agenturo engages the sub-processors listed at agenturo.app/subprocessors. Agenturo will provide 14 days' notice before adding new sub-processors that process lead data, giving the Controller the opportunity to object.
  • Assist with rights requests: Agenturo will assist the Controller in responding to data subject rights requests (access, erasure, portability, restriction, objection) within 30 days of receiving a request at privacy@agenturo.app.
  • Deletion on termination: Upon termination of the Controller's account or deletion of their agent, Agenturo will permanently delete all associated lead Personal Data. The Controller may also delete leads individually via the admin panel at any time.
  • Audit cooperation: Agenturo will make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR upon reasonable written request to privacy@agenturo.app.
  • Breach notification: In the event of a personal data breach affecting lead data, Agenturo will notify the Controller without undue delay (and within 72 hours where feasible) so the Controller can meet their own notification obligations.

7. International Data Transfers

Lead Personal Data is stored in the United States (Neon PostgreSQL). Transfer is made on the basis of Neon's Standard Contractual Clauses (SCCs) under Article 46 GDPR. See the sub-processors list for each provider's transfer mechanism.

8. Liability

Each party is responsible for its own compliance with applicable data protection law. Agenturo's liability under this DPA is subject to the limitations set out in the Terms of Service §13.

9. Governing Law

This DPA is governed by the same law as the Terms of Service. GDPR obligations apply regardless of governing jurisdiction where EU/EEA data subjects are involved.

10. How to Accept

No separate signature is required. By enabling lead capture on your agent (via the admin panel), you confirm that you have read and accepted this DPA, which is incorporated into the Terms of Service by reference.

For DPA-related questions or to request a countersigned copy, email privacy@agenturo.app.

Contact

privacy@agenturo.app · Privacy Policy · Sub-processors · Terms of Service