Version 2026-09-13 ยท MayeLeads Ltd
This Data Processing Agreement ("DPA") forms part of the Terms of Service between MayeLeads Ltd ("Processor", "we") and the customer organisation using ProspectRadar ("Controller", "you"). It is entered into under Article 28 of the UK GDPR and applies whenever we process personal data on your behalf.
Where this DPA conflicts with the Terms of Service, this DPA prevails in respect of the processing of personal data.
You are the controller of the personal data you place into, or generate through, ProspectRadar. You decide which employers to research, which individuals to contact, what to say to them, and on what lawful basis. We are your processor and act only on your documented instructions.
Your use of the Service, including the settings you choose, constitutes your documented instructions. We will tell you if, in our opinion, an instruction infringes UK GDPR.
We are an independent controller for a narrow, separate set of data: your own account and billing records, and service security logs. That processing is described in the Privacy Notice, not here.
| Subject matter | Business development from public job advertisements. For a recruitment business: identifying employers with open vacancies, identifying a relevant hiring contact, sending outreach, and recording responses. For a business selling products or services: identifying companies whose advertisements indicate work the product or service addresses, identifying a relevant decision-maker, sending outreach, and recording responses. Each workspace operates as one or the other, never both. |
|---|---|
| Duration | For as long as you hold an active workspace, plus the retention period in section 9. |
| Nature | Collection from public and licensed sources, enrichment, storage, organisation, automated analysis, transmission by email, and erasure. |
| Purpose | Solely to provide the Service to you. We do not use your data to market to your prospects, to build a shared contact database, or to train AI models. |
Data subjects
Personal data
No special category data is required by the Service. Article 9 data, criminal offence data and children's data are outside the scope of these instructions. If you place such data into free-text fields you do so as controller and outside our agreed instructions.
You warrant that:
You give general written authorisation for us to engage the sub-processors listed below. We will give you at least 30 days' notice before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve your objection you may terminate the affected part of the Service without penalty.
We impose on each sub-processor the same data protection obligations as are set out in this DPA, and we remain fully liable to you for their performance.
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| Anthropic | Analysing vacancy text, drafting outreach, classifying replies | Vacancy descriptions, contact name and title, reply content | US / EU |
| OpenAI | Same, when configured as the fallback AI provider | As above | US / EU |
| Google (Gmail API / Workspace) | Sending and receiving outreach, where you connect a Google mailbox | Full message content, sender and recipient addresses | Global |
| Your own SMTP/IMAP provider | Sending and receiving outreach, where you configure SMTP instead | Full message content, sender and recipient addresses | As determined by you |
| Hunter.io | Finding and verifying a work email address | Person name, employer name, employer domain | EU |
| Apollo.io | Finding a work email address, where enabled | Person name, employer name, employer domain | US |
| Serper (Google Search API) | Locating a company website and public professional profiles | Search queries containing person and employer names | US |
| Google Places API | Company identification and telephone lookup | Employer name and location | Global |
AI providers and training. We send prompts to the AI providers above under their business/API terms, which provide that inputs and outputs are not used to train their models. We do not enable any setting that would permit such training. We do not send candidate CVs to AI providers.
These services supply vacancy and company information to us; we do not send them personal data about your prospects, so they are not sub-processors of your data. They are listed for transparency: Adzuna, Reed, Companies House, postcodes.io, and the public job board APIs of Greenhouse, Lever, Workable and SmartRecruiters. Where you self-host, these calls originate from your own infrastructure.
Professional profiles. Where the Service identifies a likely decision-maker, it does so from public search-engine results (a name, a job title and a public profile link returned by the search API). The Service does not access, log in to, crawl or scrape LinkedIn or any other social network, and it never sends a message through them: any contact on such a network is composed and sent manually by a member of your staff, from their own account, using a message the Service merely drafts. Email addresses are derived from the employer's own domain and confirmed with its mail server, or supplied by the licensed providers above.
Where we host the Service for you, the database and application run on infrastructure we control, and the hosting provider is a sub-processor. Where you run your own instance, you are the host and no hosting sub-processor applies.
Taking into account the state of the art, the costs of implementation and the risks involved, we implement at least the following:
The Service provides the means for you to meet requests directly and without our involvement:
If a data subject contacts us directly about data we process on your behalf, we will not respond substantively but will forward the request to you without undue delay.
We will make available information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits or inspections conducted by you or an auditor you mandate. Audits shall be at your cost, on at least 30 days' written notice, no more than once in any 12-month period unless a personal data breach has occurred or a supervisory authority requires otherwise, and subject to confidentiality.
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, and will provide the information you need for your own notification obligations under Articles 33 and 34, including the nature of the breach, categories and approximate numbers affected, likely consequences and the measures taken. We will not notify a supervisory authority or data subjects on your behalf unless you instruct us to.
Some sub-processors in section 6 are located outside the UK. Where personal data is transferred outside the UK, the transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or under adequacy regulations where they apply, together with any supplementary measures required by a transfer risk assessment.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits either party's liability to a data subject or a supervisory authority, or excludes liability that cannot lawfully be excluded.
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Questions about this document? Contact kieranmayefx@gmail.com.