Legal

Data Processing Addendum

Last updated: August 4, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Vantaire LLC, doing business as SalesWind (“SalesWind,” “we,” “us”), and the customer agreeing to those Terms (“Customer,” “you”). It applies where SalesWind processes personal data on your behalf. No signature is required: it takes effect automatically when you accept the Terms. If your procurement process needs a countersigned copy, email [email protected].

1. Scope, roles, and precedence

You are the controller (or “business”) for the personal data you upload to or generate in the Service about your prospects and their companies (“Customer Personal Data”). SalesWind is your processor (or “service provider”) for that data. This DPA does not apply to data for which SalesWind is itself the controller — your account, billing, and usage data — which is governed by the Privacy Policy.

If this DPA conflicts with the Terms of Service, this DPA controls for matters of personal data processing. If this DPA conflicts with the Standard Contractual Clauses referenced in Section 11, the Clauses control.

2. Definitions

“Data Protection Laws” means all privacy and data protection laws applicable to the processing under this DPA, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the California Consumer Privacy Act as amended (“CCPA”). “Controller,” “processor,” “data subject,” “personal data,” and “processing” have the meanings given in the GDPR; “business,” “service provider,” “sell,” and “share” have the meanings given in the CCPA. “Subprocessor” means a third party engaged by SalesWind to process Customer Personal Data.

3. Processing instructions

SalesWind will process Customer Personal Data only on your documented instructions, including regarding international transfers, unless required otherwise by law — in which case we will inform you before processing, unless that law prohibits it on important grounds of public interest. Your instructions consist of this DPA, the Terms, the Privacy Policy, and the actions you take in the Service (importing contacts, running research, generating and scheduling sequences, sending from a connected mailbox, enabling open tracking, exporting, and deleting).

You are responsible for the lawfulness of the personal data you provide and of the outreach you conduct, including having a lawful basis to contact your prospects, honouring opt-outs, and providing any required notices. You will not upload special categories of personal data or data about children. SalesWind will notify you if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

SalesWind ensures that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are granted access only on a need-to-know basis for operating, supporting, and securing the Service.

5. Security

SalesWind implements and maintains appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Current measures are described in Annex B. We may update them provided the level of protection is not materially reduced.

6. Subprocessors

You give general written authorisation for SalesWind to engage subprocessors. SalesWind imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable to you for their performance. Our current subprocessors are:

SubprocessorPurpose
RailwayApplication hosting and database infrastructure
StripeSubscription billing and payment processing
ResendDelivery of SalesWind's own transactional email
PerplexityWeb research on prospects and their companies
OpenAIEmail drafting, quality review, and the in-app assistant
GoogleSending your outreach from your connected Gmail mailbox; sign-in
MicrosoftSending your outreach from your connected Microsoft 365 mailbox
AppleSign-in, if you use Apple sign-in

These providers are headquartered in the United States and may process data in the United States and in other regions in which they operate. We will give at least 30 days' notice before adding or replacing a subprocessor, by email to your account address or in the app. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none is available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of the then-current term, which is your exclusive remedy. This is the only refund SalesWind offers; all other fees are non-refundable under the Terms.

7. Data subject requests and assistance

The Service gives you direct tools to access, correct, export, and delete Customer Personal Data, which in most cases lets you respond to data subject requests without our involvement. Where you cannot, SalesWind will provide reasonable assistance, taking into account the nature of the processing. If a data subject contacts SalesWind directly about data we process on your behalf, we will not respond substantively except to refer them to you, and will inform you of the request.

SalesWind will also provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Articles 32 to 36 GDPR and relating to the Service.

8. Personal data breach

SalesWind will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to us to help you meet your own notification obligations, including the nature of the breach, the categories and approximate number of data subjects and records concerned where known, likely consequences, and measures taken or proposed. We will take reasonable steps to mitigate and remediate. Our notification is not an acknowledgement of fault or liability.

9. Return and deletion

You may export Customer Personal Data at any time using the Service's CSV export tools. Deleting a contact places it in a recoverable bin and permanently erases it after 30 days, along with its drafted sequences, notes, call logs, and unsent scheduled emails; a record of emails actually sent is retained as a business record of your outreach. Deleting the last remaining account in a workspace erases the workspace and all Customer Personal Data in it, and deletes stored mailbox credentials. Disconnecting a mailbox deletes its stored OAuth tokens immediately. Residual copies in server logs and encrypted infrastructure backups are purged within 30 days. We will delete or return Customer Personal Data on termination in accordance with this section, except where retention is required by law.

10. Audits and information

On written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, SalesWind will make available the information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire. Where that is genuinely insufficient to satisfy an audit obligation under Data Protection Laws, we will cooperate with an audit conducted by you or an independent auditor you appoint who is not a competitor of SalesWind, on at least 30 days' notice, during business hours, subject to confidentiality, in a manner that does not disrupt the Service or compromise other customers' data, and at your expense.

11. International transfers

The Service is operated from the United States. Where SalesWind processes personal data of individuals in the EEA, the UK, or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply to such transfers, with: Clause 7 (docking) included; Clause 9 option 2 (general written authorisation) with the 30 days' notice period in Section 6; Clause 11 optional independent dispute resolution excluded; Clause 17 governed by the law of Ireland; Clause 18 forum the courts of Ireland; Annex I, II, and III populated by Annex A, Annex B, and the subprocessor table in Section 6 of this DPA respectively. For UK transfers, the UK International Data Transfer Addendum applies to those Clauses. For Swiss transfers, references are read to include the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner. Where a valid alternative transfer mechanism applies, it takes precedence for transfers it covers.

12. US state privacy laws

Where the CCPA or a comparable US state privacy law applies, SalesWind acts as your service provider (or processor) and receives Customer Personal Data only for the limited and specified business purpose of providing the Service. SalesWind will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than performing the Service, or outside the direct business relationship with you; or combine it with personal data received from another source, except as permitted by law. SalesWind certifies that it understands and will comply with these restrictions. You may take reasonable and appropriate steps to stop and remediate unauthorised use.

13. Liability and term

Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service. This DPA takes effect when you accept the Terms and continues for as long as SalesWind processes Customer Personal Data on your behalf. Sections that by their nature should survive termination do so.

Annex A — Details of processing

Roles. Customer is controller (data exporter); SalesWind is processor (data importer).

Subject matter and nature of processing. Provision of the SalesWind B2B outreach platform: storing prospect and company records, conducting automated web research, generating and reviewing email sequences, scheduling, sending from the customer's connected mailbox, recording delivery and (where enabled) open events, and reporting.

Purpose. Enabling the customer to research and conduct its own business-to-business sales outreach.

Duration. For the term of the subscription, plus the retention windows in Section 9.

Frequency. Continuous, for the duration of the subscription.

Categories of data subjects. The customer's prospects and their colleagues (business contacts at target companies); the customer's own personnel who use the Service.

Types of personal data. Name; business email address; job title and seniority; employer; business phone number; LinkedIn or other public profile URL; country and timezone; research results compiled from public sources and their citations; notes, call logs, and activity records created by the customer; generated email content addressed to the data subject; delivery status and, where the customer enables tracking, open events with time and user agent.

Special category data. None. The Terms prohibit uploading special category data and data about children.

Competent supervisory authority. Determined under Clause 13 of the Standard Contractual Clauses by reference to the data exporter's establishment or representative.

Annex B — Technical and organisational measures

  • Encryption in transit. All traffic to the Service is encrypted with TLS.
  • Encryption at rest. Mailbox OAuth tokens and tenant API keys are encrypted at rest with Fernet (AES-128-CBC with HMAC-SHA256 authentication) before being written to the database.
  • Credential storage. Account passwords are stored only as bcrypt hashes. Payment card numbers are never stored by SalesWind; card data is handled by Stripe.
  • Least-privilege mailbox access. Google authorisation requests only the gmail.send scope plus basic profile; Microsoft only Mail.Send and User.Read. Mailbox contents are not read, stored, or analysed.
  • Tenant isolation. Workspace data is scoped to a tenant identifier and isolated at the query layer, so one workspace cannot read another's data.
  • Access control and session revocation. Authentication is token-based with role-based permissions inside a workspace. Every login token carries a version; logging out or changing a password increments it and invalidates all previously issued tokens immediately.
  • Rate limiting and abuse controls. Endpoints are rate limited to resist credential stuffing and automated abuse.
  • Audit logging. Sign-in protection events, team and permission changes, and mailbox connections are logged and retained for up to one year, then deleted automatically.
  • Retention enforcement. Deleted contacts and expired audit records are purged on an automated recurring sweep rather than manually.
  • Export and portability. Contacts, sequences, call logs, and schedules can be exported as CSV at any time from the app.
  • Subprocessor controls. AI providers are accessed through business APIs whose terms restrict use of submitted data to producing the requested output; per those providers' current API data-use policies, API inputs are not used to train their models.

Contact

Questions about this DPA, or requests for a countersigned copy: [email protected], or Vantaire LLC (doing business as SalesWind), 1401 21st Street, Sacramento, CA 95811, USA.