TC
TheCombain

Data Processing Agreement (DPA)

This Data Processing Agreement is entered into between TheCombain (operated by Metaoro sp. z o. o.) and the Customer, in accordance with Article 28 of the GDPR.

1. Roles and Responsibilities

TheCombain acts as a Data Processor. The Customer acts as a Data Controller. TheCombain processes personal data only on documented instructions from the Customer.

2. Data Categories

  • Business contact data (professional email, business phone, company role)
  • Customer account data (email, name, billing information)
  • Usage data (API calls, credit transactions)

3. Data Sources

All lead data is sourced from publicly accessible business websites. Data is collected using automated web scraping tools that respect robots.txt directives where feasible.

4. Security Measures

  • Encryption in transit (TLS 1.3)
  • Encrypted at rest (PostgreSQL encryption)
  • Access control with role-based permissions
  • Audit logging of all administrative actions
  • Regular security audits and penetration testing

5. Sub-processors

  • Stripe (payment processing)
  • DeepSeek (AI processing)
  • Hetzner (server hosting, EU)

6. Data Breach Notification

TheCombain will notify the Customer of any personal data breach within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR.

7. Data Deletion

Upon termination, TheCombain will delete all Customer data within 30 days, except where retention is required by law.

8. Contact

Data Protection Officer: dpo@thecombain.com