This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between Rosebud Global Ltd (company number 16623472, trading as “Rosebud Solutions”, “we,” “us,” or “our”) and the customer that subscribes to the Service (“you,” the “Customer”). By subscribing, you agree to this DPA in respect of the personal data we process on your behalf.
This DPA reflects the requirements of Article 28 of the UK GDPR and applies where we process Contact Data as your processor. It does not govern data for which we are the controller, which is covered by our Privacy Policy.
For Contact Data, you are the Controller and we are your Processor. You are responsible for the lawfulness of the Contact Data and for having a valid lawful basis and any necessary consents. We process Contact Data only on your documented instructions, including as set out in this DPA, the Terms, and your configuration of the Service, unless required to do otherwise by law (in which case we will inform you unless legally prohibited).
Subject matter and duration. Provision of the Rosebud Solutions Service for the duration of your subscription and any agreed export period thereafter.
Nature and purpose. As Processor, and only to provide the Service on your instructions, we:
Categories of data subject. Your leads, inquirers, prospects and customers.
Categories of personal data. Contact identifiers, inquiry content and channel, qualification fields and status, appointment and engagement events, and — where you provide it — an expected or actual value. We do not enrich Contact Data with third-party or sourced data as part of the Service. No special category data is required by the Service; you should not submit special category data unless separately agreed.
You give general authorisation for us to engage Subprocessors to provide the Service, across these categories: hosting and database infrastructure; your CRM and calendar; messaging delivery (email, SMS, WhatsApp and Instagram); AI model providers; payment processing; security and bot detection; and product and website analytics. A named Subprocessor register — provider, purpose, data categories and processing region — is maintained and available to you on request.
We will impose data protection terms on each Subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give you 30 days’ prior written notice of any intended addition or replacement of a Subprocessor, during which you may reasonably object on data protection grounds.
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. If we receive such a request directly, we will refer the Data Subject to you and will not respond except on your instructions.
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Contact Data, and will provide information reasonably available to us to help you meet your notification obligations.
Where processing of Contact Data involves a transfer outside the United Kingdom, we will ensure an appropriate transfer mechanism is in place (such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), together with any supplementary measures required. [Transfer mechanisms and regions to be confirmed alongside the Subprocessor register.]
On termination or expiry of the Service, we will make Contact Data available to you for export for a period of 30 days, after which we will delete or anonymise Contact Data held within the Service, save where retention is required by law. Data already written into your own CRM is unaffected and remains under your control. Retention periods stated here must match those in the Terms and Privacy Policy.
We will make available to you information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality, and frequency limits to be set out in the final DPA.
This DPA supplements the Terms of Service. In the event of a conflict between this DPA and the Terms in respect of the processing of Contact Data, this DPA prevails. Liability under this DPA is subject to the limitations and exclusions set out in the Terms.
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Terms of Service.