1. Parties and roles
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Controller”) and the operator of SignalScout athttps://scout.nuits.net (“Processor”) for the Service described in theTerms of Service.
Where the Controller uploads personal data in lead lists or related inputs, the Controller determines the purposes and means of processing. The Processor processes that data only to provide the Service (research runs, metering, support, security).
Payments are handled by Polar as Merchant of Record. Polar acts as an independent controller/MoR for checkout, tax, and receipts, not as a subprocessor of lead-list content under this DPA.
2. Subject matter and duration
- Subject matter: hosting and processing of customer-provided inputs and account data needed to run personalize and battlecard research, to re-check watchlist accounts on a weekly schedule, to deliver the results to destinations the Controller connects, and to meter credits.
- Duration: for the term of the Controller’s use of the Service, and until deletion under the Privacy Policy or Controller instruction.
- Nature: storage, transmission, automated research orchestration, scheduled re-checking, delivery to Controller-nominated destinations, logging, and deletion.
- Purpose: provide the Service under the Terms.
3. Types of personal data and data subjects
As determined by the Controller, which may include:
- Business contact details in lead lists (names, titles, company, domain, notes).
- Account user email and authentication metadata for the Controller’s users of SignalScout.
- Run history and credit ledger tied to the Controller’s account.
- Research records produced by weekly checks on watchlist accounts: a summary, source URL, publication date, and drafted copy. These may name an individual, because an event such as a leadership change names a person.
- Delivery configuration and logs: the destinations the Controller connects, what was sent to each, and whether it arrived.
Data subjects are typically business contacts and the Controller’s own personnel. The Controller is responsible for lawful basis and notices to data subjects for outreach and list sources.
Research performed for one Controller is stored against that Controller’s account only. The Processor does not pool watchlist research into a shared company database, and one Controller’s research is never used to answer another Controller’s check.
4. Processor obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller (use of the Service and support requests), including this DPA and the Terms.
- Ensure persons authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational measures (HTTPS, access controls, session security, least-privilege secrets, optional error monitoring).
- Encrypt access tokens and signing secrets for Controller-connected destinations at rest, and never include them in a data export.
- Assist the Controller, where reasonably possible, with data subject requests, DPIAs, and breach notifications, taking into account the nature of processing.
- Delete or return personal data on termination according to the Privacy Policy and in-product delete/export tools, except where retention is required by law. Deletion covers the watchlist, signal records, check log, delivery configuration and history, and the stored transcripts of the research agents.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
Retention
The Processor enforces the schedule published in thePrivacy Policy by an automated daily sweep. Two figures are material to this DPA. Signal wording is kept for a period the Controller sets, from 30 to 400 days, defaulting to 180. Separately, a content-free fingerprint of each signal is kept for the life of the watch so a later check does not report the same event twice; the fingerprint records that a page was seen, never what it said.
5. Subprocessors
The Controller authorizes the Processor to engage subprocessors listed in thePrivacy Policy (currently including Cloudflare, Resend, OpenRouter and routed model providers, Exa, Firecrawl, optionally Sentry, and, where the Controller connects them, Slack and HubSpot). The Processor will impose data-protection obligations no less protective than those in this DPA. Material changes to subprocessors will be reflected in the Privacy Policy; continued use of the Service after update constitutes acceptance for standard plans. Enterprise customers may request written notice by emailing support.
A webhook endpoint the Controller configures is not a subprocessor of the Processor. It is a destination the Controller chooses and operates, and personal data reaching it is an onward transfer at the Controller’s instruction.
6. International transfers
Processing may occur in the United States and other regions where subprocessors operate. Where GDPR/UK GDPR requires a transfer mechanism, the parties rely on the subprocessors’ applicable SCCs or equivalent safeguards, and on the Controller’s configuration of the Service.
7. Security incidents
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, and will provide information reasonably available to assist the Controller’s own notification duties.
8. Controller obligations
- Ensure a lawful basis for personal data uploaded to the Service.
- Not upload special-category data or data of children unless explicitly agreed in writing.
- Remain responsible for outreach legality (CAN-SPAM, CASL, ePrivacy, GDPR) when sending messages generated with the Service. The Processor does not transmit messages to researched individuals.
- Be entitled to connect each delivery destination it nominates, including authority to install an application in a Slack workspace, ownership of a webhook endpoint, and authority to write to a CRM account.
- Set a retention period for signal wording appropriate to its own obligations, and keep the watchlist limited to accounts it has a lawful basis to research.
- Use export/delete tools or contact support for data subject requests that require Processor assistance.
9. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms. If there is a conflict between this DPA and the Terms regarding personal data processing, this DPA controls for that subject.
10. Contact
Privacy and DPA requests:support@scout.nuits.net. Update this page with the Processor’s registered legal name and postal address before enterprise execution.