Data Processing Agreement
The terms on which Webdior Solutions Private Limited processes personal data on behalf of customers, meeting the requirements of Article 28 of the GDPR and UK GDPR. It forms part of the Terms of Service and applies automatically; no signature is needed.
Last updated 15 September 2026
Contents
1. Scope and parties
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer") and Webdior Solutions Private Limited ("Outiy") for the Outiy service ("Service"). It applies whenever Outiy processes Customer Personal Data on the Customer’s behalf.
"Customer Personal Data" means personal data in Customer Data, as defined in the Terms of Service. It does not include personal data for which Outiy is an independent controller, such as account and billing data or the Outiy business contact index, which our Privacy Policy covers.
Terms such as "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Data Protection Law" means all laws that apply to the processing, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, US state privacy laws, the Australian Privacy Act 1988 and India’s Digital Personal Data Protection Act 2023.
2. Roles and instructions
- The Customer is the controller of Customer Personal Data, or a processor acting for its own customer. Outiy is the Customer’s processor, or sub-processor.
- Outiy processes Customer Personal Data only on the Customer’s documented instructions. The agreement, this DPA and the Customer’s use and configuration of the Service are the Customer’s complete instructions. Outiy will tell the Customer if it believes an instruction breaks Data Protection Law, unless the law prohibits this.
- Outiy may process Customer Personal Data otherwise only where the law requires it, and will tell the Customer before doing so unless that law prohibits it.
- The Customer is responsible for the lawfulness of its instructions, for having a lawful basis for the processing, and for giving data subjects any notices required.
3. Confidentiality of personnel
Outiy ensures that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality, receives appropriate training, and has access only to the extent their role requires. Staff access to a customer’s workspace for support requires a recorded reason, is time-limited, is read-only by default, and appears in the Customer’s audit log.
4. Security
Outiy implements the technical and organisational measures in Annex 2, which are designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Outiy may update these measures, provided the overall level of protection is not reduced.
5. Sub-processors
- The Customer gives Outiy general authorisation to engage sub-processors. The current list is at outiy.com/legal/subprocessors.
- Outiy will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible to the Customer for their performance.
- Outiy will give at least 30 days’ notice before adding or replacing a sub-processor, by updating that page and notifying customers who have subscribed to updates there or in the product.
- The Customer may object on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.
6. Assistance to the Customer
- The Service includes tools for the Customer to access, correct, export, delete and suppress Customer Personal Data. Where the Customer cannot use those tools to respond to a data subject request, Outiy will provide reasonable assistance.
- If Outiy receives a request from a data subject about Customer Personal Data, it will direct them to the Customer and will not respond itself, except to confirm the request has been forwarded or where the law requires.
- Outiy will provide reasonable information and assistance for the Customer’s data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing.
7. Personal data breaches
- Outiy will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
- The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases.
- Outiy will take reasonable steps to contain, investigate and mitigate the breach, and will cooperate with the Customer’s notification obligations.
- Notifying a breach is not an admission of fault by Outiy.
8. Return and deletion
When the agreement ends, the Customer may export Customer Personal Data for 30 days. After that, Outiy will delete Customer Personal Data from live systems within a further 30 days, and it will expire from backups within 35 days, unless the law requires Outiy to keep it. Hashed addresses on suppression lists are kept so that opt-outs continue to be honoured.
9. Audits
- Outiy will make available the information reasonably necessary to demonstrate compliance with this DPA, including responses to security questionnaires and summaries of independent security testing.
- Where that information is not sufficient, or a supervisory authority requires it, the Customer may audit Outiy’s compliance once in any 12-month period, on at least 30 days’ written notice, during business hours, at its own cost, in a way that does not disrupt the Service or compromise other customers’ data, and subject to confidentiality.
10. International transfers
Outiy is established in India and may process Customer Personal Data in the countries where it and its sub-processors operate. Where Data Protection Law restricts such a transfer, the parties agree that:
- EEA transfers are governed by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 ("SCCs"), which are incorporated by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. Clause 7 (docking) applies; under Clause 9, option 2 (general written authorisation) applies with the notice period in section 5; the option in Clause 11 does not apply; under Clauses 17 and 18, the SCCs are governed by the law of, and disputes resolved in the courts of, Ireland; Annex I is completed by Annex 1 below, and Annex II by Annex 2.
- UK transfers are governed by the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, incorporated by reference, with the tables completed by the information in this DPA. Either party may end the Addendum as set out in its section 19.
- Swiss transfers are governed by the SCCs as adapted for the Swiss Federal Act on Data Protection, with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.
Outiy has assessed the laws of the countries it transfers to and applies supplementary measures, including encryption in transit and at rest and resisting overbroad government access requests. Enterprise customers may choose EU hosting for workspace data.
11. US state privacy laws
Where US state privacy laws apply, Outiy acts as a "service provider" or "processor" and will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than performing the Service, or outside the direct business relationship with the Customer; or combine it with personal data from other sources except as those laws permit. Outiy will notify the Customer if it can no longer meet these obligations, and the Customer may take reasonable steps to stop unauthorised use.
12. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Law does not allow liability to data subjects to be limited. If this DPA conflicts with the Terms, this DPA applies; if it conflicts with the SCCs, the SCCs apply.
Annex 1 — Details of processing
| Data exporter | The Customer, as identified in its account, acting as controller or processor. |
| Data importer | Webdior Solutions Private Limited, New Delhi, India (full registered address to be confirmed). Contact: privacy@outiy.com. Acts as processor. |
| Subject matter and duration | Provision of the Service for the term of the agreement, plus the deletion period in section 8. |
| Nature and purpose | Hosting, storing, organising, enriching, verifying and searching leads; composing, translating and sending email from the Customer’s own mailboxes; detecting replies and bounces; reading connected calendars for meetings with leads; tracking email engagement where enabled; analytics; synchronising with the Customer’s chosen integrations; customer support. |
| Categories of data subjects | The Customer’s prospects, leads, customers and business contacts; recipients of the Customer’s emails; attendees of the Customer’s meetings; the Customer’s Users. |
| Categories of personal data | Name, job title, employer, work email address, telephone number, business location, public professional profile addresses, email content and replies, email engagement (opens, clicks, IP address, user agent), meeting details (title, time, attendee addresses), notes and custom fields the Customer adds, and User account identifiers. |
| Special categories | None intended. The Customer must not submit special category data or data about criminal convictions. |
| Frequency of transfer | Continuous, for the duration of the Service. |
| Retention | As set out in section 8 and in the Privacy Policy. |
| Competent supervisory authority | The supervisory authority determined under Clause 13 of the SCCs. Where Outiy has appointed an EU representative (to be confirmed), the authority of that representative's Member State. |
Annex 2 — Technical and organisational measures
| Area | Measures |
|---|---|
| Encryption | TLS 1.2+ for all traffic. Encryption at rest for databases, object storage and backups. Mailbox credentials, calendar tokens, integration secrets and inbound email bodies individually encrypted with AES-256-GCM envelope encryption; each value is bound to its record so a copied value cannot be decrypted. Master keys held in a hardware-backed key management service and rotatable. |
| Tenant isolation | PostgreSQL row-level security enforced and forced on every table holding customer data; the application connects with a role that cannot bypass it. Automated tests verify that one organisation cannot read or write another’s data. |
| Access control | Role-based access within each organisation, custom roles that cannot exceed their base role, two-factor authentication, SAML/OIDC single sign-on, SCIM provisioning, IP allowlists, and session management. |
| Staff access | Separate staff console showing only aggregate data. Account access requires a written reason, expires after 30 minutes, is read-only unless approved by a second staff member, and is recorded in the customer’s audit log. Least privilege and prompt removal of leavers. |
| Logging and monitoring | Audit logs of significant actions, exportable to the customer’s SIEM. Infrastructure monitoring and alerting. Security events reviewed. |
| Application security | Input validation on every request, output encoding, CSRF protection, rate limits, protection against server-side request forgery when fetching external pages, signed webhooks with replay protection, API keys stored only as hashes, dependency scanning and code review. |
| Data minimisation | Only replies and bounces to emails sent through the Service are downloaded from mailboxes; only meetings that include a lead are stored from calendars; remote images in replies are never loaded. |
| Availability and resilience | Managed, highly available database with point-in-time recovery; nightly cross-region backups kept for 35 days; recovery point objective of 15 minutes and recovery time objective of 4 hours. |
| Incident management | Documented incident response process, with customer notification as set out in section 7. |
| Vendor management | Sub-processors assessed before engagement and bound by written data protection terms. |
| Deletion | Customer-initiated deletion and suppression tools; automatic retention periods; organisation data purged within 30 days of deletion. |
Annex 3 — Sub-processors
See the Sub-processors page, which forms part of this Annex.