Data Processing Agreement

Last updated: September 15, 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Orygo AI Srl ("OrygoAI", "Processor") and the Customer ("Controller") and applies where OrygoAI processes personal data on the Customer's behalf in connection with Listmap. It is intended to meet Article 28 of Regulation (EU) 2016/679 ("GDPR"). If there is a conflict between this DPA and the Terms on the subject of personal data processed as a processor, this DPA prevails.

1. Roles

For personal data of third parties that the Customer stores in lists, prompts, imported files, chat transcripts, and enrichment results (including professional emails, phone numbers, names, job titles, and LinkedIn URLs), the Customer is the controller and OrygoAI is the processor.

For account registration, authentication, billing, support, and website cookies about the Customer's own users, OrygoAI is an independent controller as described in the Privacy Policy. That processing is outside the scope of this DPA.

2. Subject matter, duration, nature, and purpose

OrygoAI processes Customer personal data to provide Listmap: building and storing GTM lists, searching and enriching company and people records, running AI chat and column jobs, exporting lists, and storing chat history for the Customer's workspace. Processing lasts for the term of the Agreement and any short retention period needed to erase or return the data afterwards.

Categories of data subjects typically include the Customer's team members (as users of the workspace) and third-party business contacts the Customer chooses to research, import, or enrich. Categories of data typically include identifiers and professional contact details. The Customer must not instruct OrygoAI to process special-category data or data relating to children.

3. Instructions

OrygoAI processes Customer personal data only on documented instructions from the Customer, including the Terms, this DPA, and actions the Customer takes in the product (creating lists, running enrichment, exporting, deleting). OrygoAI will inform the Customer if, in its opinion, an instruction infringes GDPR, unless prohibited by law.

Obtaining a contact through Listmap does not constitute consent to contact that person. The Customer is solely responsible for its legal basis (including legitimate interest assessments and ePrivacy / marketing rules) for collecting, enriching, sharing, and using contact data.

4. Confidentiality and security

Persons authorized to process Customer personal data are under an appropriate confidentiality obligation. OrygoAI implements technical and organisational measures appropriate to the risk, including: access control and organisation-scoped tenancy; session authentication; transport encryption to the application; least-privilege production access; logging; and deletion of list rows rather than indefinite hiding.

No measure is perfect. The Customer remains responsible for deciding what personal data to put in lists, and for using least-privilege access within its own team.

5. Sub-processors

The Customer authorises OrygoAI to engage the sub-processors listed on the Sub-processors page (Annex B) to provide the Services, including authentication, hosting, payments, transactional email, enrichment, local-business search, and AI model inference. OrygoAI will impose data-protection obligations on sub-processors that are no less protective than those in this DPA, to the extent applicable to the service they provide.

OrygoAI will keep the sub-processor list current. Material additions will be reflected on that page. The Customer may object to a new sub-processor on reasonable GDPR grounds by writing to davide@listmap.ai within 14 days of the list being updated. If the parties cannot accommodate the objection, the Customer may stop using the affected feature or terminate the Services.

6. International transfers

Some sub-processors are located outside the EEA (including in the United States). Where a transfer of Customer personal data is not covered by an adequacy decision, OrygoAI relies on a valid transfer mechanism, typically the EU Standard Contractual Clauses, and any supplementary measures the sub-processor offers (such as data processing addenda). Details are in each sub-processor's own terms.

7. Assistance

Taking into account the nature of the processing, OrygoAI will assist the Customer, through appropriate technical and organisational measures, with responding to data-subject requests under GDPR Chapter III, and with the Customer's obligations on security, breach notification, data-protection impact assessments, and prior consultation, insofar as they relate to Listmap. The product allows the Customer to access, export, correct, and delete list rows in its own workspace. Requests that cannot be fulfilled in-product can be sent to davide@listmap.ai.

OrygoAI will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal-data breach affecting Customer personal data processed under this DPA, providing the information reasonably available at that time.

8. Deletion and return

During the subscription the Customer can export lists (CSV/XLSX), delete rows and lists, and — if they are the organization owner — delete the workspace from the Account page. Workspace deletion erases lists, chats, member accounts, and credits from production databases. Research documents the UI hides, and any leftover soft-deleted rows from older product versions, are hard-deleted after 30 days.

After the Agreement ends, OrygoAI will delete Customer personal data from production systems within 30 days of a written request to davide@listmap.ai, except where Union or Member State law requires storage (for example fiscal records of the Customer's own payments). Backups age out on the backup cycle.

9. Audits

OrygoAI will make available information reasonably necessary to demonstrate compliance with this DPA. If that information is not sufficient, the Customer may request, no more than once per 12 months except after a confirmed breach, a remote audit on 30 days' notice, during business hours, without disrupting the service, and subject to confidentiality. OrygoAI may satisfy an audit request with a current independent security report or equivalent summary where available.

10. Liability

Liability arising out of this DPA is subject to the limitations in the Terms, except to the extent those limitations are prohibited by mandatory data-protection law.

Annex A — processing details

  • Subject matter: hosting and processing of GTM lists, chat, and enrichment jobs.
  • Duration: term of the Agreement plus the deletion period in Section 8.
  • Nature: collection, storage, organisation, retrieval, enrichment via third-party providers, disclosure via Customer-initiated exports, erasure.
  • Purpose: providing Listmap as instructed by the Customer.
  • Data subjects: Customer users; business contacts the Customer researches or imports.
  • Personal data: names, professional emails, phone numbers, job titles, company affiliation, locations, LinkedIn URLs, and other fields the Customer adds to a list or pastes into chat.

Annex B — sub-processors

The current list is published at the Sub-processors page and is incorporated by reference. Questions: davide@listmap.ai.