PitchWhip

Legal

Data Processing Agreement

Effective 16 August 2026

This Data Processing Agreement (“DPA”) sets out the terms on which PitchWhip Ltd processes personal data on behalf of its customers, as required by Article 28 of the UK GDPR and the EU GDPR. It forms part of the Terms of Use and applies automatically to every customer — no signature needed. A countersigned copy is available on request.

1. Parties and how this DPA applies

This DPA is between PitchWhip Ltd, a company registered in England and Wales (company number 17389184) with its registered office at 96A Wandsworth Bridge Road, London SW6 2TF, United Kingdom (“PitchWhip”), and the customer that has accepted the Terms of Use — the person or organisation to whom a PitchWhip licence key is issued, or on whose behalf licence keys are used (the “Customer”). Together, the “Parties”.

It applies whenever PitchWhip processes personal data as a processor on the Customer’s behalf in providing the Service, and takes effect when the Customer first uses the Service after the effective date above. Where the Customer is an organisation, its licence holders ( “Users”) act on its behalf. If the Customer needs a signed copy, or wishes to attach its own pre-approved terms, email hello@pitchwhip.com; we will sign this DPA and consider reasonable additions that reflect the Service as it actually works.

2. Definitions

  • Data Protection Law — all laws that apply to the processing of personal data under this DPA, including the UK GDPR and the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), the Swiss Federal Act on Data Protection, and applicable US state privacy laws (such as the CCPA) to the extent they apply.
  • Personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in the UK GDPR / EU GDPR. Where the CCPA applies, “controller” includes a “business” and “processor” includes a “service provider”.
  • Customer Personal Data — personal data that PitchWhip processes on the Customer’s behalf, as described in Annex 1. It principally comprises Prospect Data (business contact data about the people Users research, reveal or call) and limited User Data (a User’s display name and call activity).
  • Service — the PitchWhip Chrome extension, PitchWhip Cloud (the API proxy, contact reveals and credit ledger, call log and team features) and the customer portal, as defined in the Terms of Use.
  • Sub-processor — a third party engaged by PitchWhip to process Customer Personal Data.
  • Standard Contractual Clauses or SCCs — the clauses approved by the European Commission under Decision (EU) 2021/914; UK Addendum — the ICO’s International Data Transfer Addendum to the SCCs; IDTA — the ICO’s International Data Transfer Agreement.
  • Terms — the PitchWhip Terms of Use.

3. Roles of the parties

For Customer Personal Data, the Customer is the controller (or, where the Customer is itself a processor for another organisation, a processor — in which case the Customer warrants that its instructions to PitchWhip are authorised by that controller) and PitchWhip is the processor. PitchWhip processes Customer Personal Data only to provide the Service and on the Customer’s documented instructions.

For personal data that PitchWhip processes for its own purposes — customer account records, licence and billing status, website analytics, support correspondence, and the anonymised Team Learning pool — PitchWhip is an independent controller and its Privacy Policy applies. Lemon Squeezy is an independent controller for payments. FullEnrich is an independent controller of its own contact database; PitchWhip’s transmission of a Reveal request to FullEnrich is processing on the Customer’s behalf and is covered by this DPA.

4. Details of the processing

The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data are set out in Annex 1. In short: PitchWhip hosts, on the Customer’s instruction, the Customer’s revealed prospect contacts and call log; forwards profile text and, for the live-call features, call transcript and coaching text to an AI provider to generate call preparation, suggestions and summaries without retaining it (save for the quality-telemetry excerpts in Annex 2); and forwards a prospect’s name, company and LinkedIn URL to a contact-data provider to find business contact details — for the life of the Customer’s licence.

5. Instructions

PitchWhip will process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to PitchWhip — in which case PitchWhip will tell the Customer before processing, unless the law prohibits it on important grounds of public interest. The Customer’s instructions are: the Terms; this DPA; and the Customer’s and its Users’ use of the Service’s features and settings (for example: pressing “Reveal”, logging a call, enabling call visibility for a Team, requesting deletion). Additional instructions may be agreed in writing; PitchWhip may charge reasonably for instructions that go beyond the Service. PitchWhip will inform the Customer without delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is confirmed or withdrawn.

6. Customer obligations

The Customer is responsible for:

  • having a lawful basis for the processing it instructs, and giving data subjects any notices Data Protection Law requires — including, for prospects, information about the source of their data where required;
  • the accuracy and lawfulness of the Prospect Data its Users obtain and enter, and compliance with LinkedIn’s terms, direct-marketing rules and call-recording law;
  • responding to data subjects who exercise their rights against it (PitchWhip will assist as set out in section 10);
  • keeping licence keys secure — a licence key is the credential that reads that licence’s Customer Personal Data — and telling PitchWhip promptly if one is compromised;
  • where it runs a Team, ensuring it has authority to add each member, telling members what team-mates can see, and configuring the visibility settings appropriately;
  • using data obtained through Reveals only as permitted by the Terms.

7. Confidentiality

PitchWhip ensures that the people it authorises to process Customer Personal Data — currently only the people who operate the Service — are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality, are given access only to the extent needed to operate, support or secure the Service, and have received appropriate data-protection guidance. PitchWhip does not look at the content of a Customer’s revealed contacts or call log except to provide support the Customer has asked for, to investigate a security incident, or where the law requires.

8. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, and the risk to data subjects, PitchWhip implements and maintains the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, including protection against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. PitchWhip may update those measures from time to time, provided the overall level of security is not reduced. The Customer is responsible for its own environment: browser and device security, Google account security, and the secrecy of its licence keys.

9. Sub-processors

The Customer gives PitchWhip general written authorisation to engage the Sub-processors listed in Annex 3 and, subject to this section, to add or replace Sub-processors. PitchWhip will:

  • give the Customer at least 30 days’ notice before a new Sub-processor begins processing Customer Personal Data, by email to the address on the Customer’s purchase and by updating Annex 3 on this page (the “effective” date at the top changes when it does);
  • allow the Customer to object on reasonable, documented data-protection grounds within that period. If the Parties cannot resolve the objection, the Customer may terminate the affected part of the Service (or, if it cannot be separated, its Subscription) and PitchWhip will refund prepaid fees for the period after termination;
  • impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, in particular as to security and, where relevant, international transfers; and
  • remain fully liable to the Customer for the performance of each Sub-processor’s obligations.

Emergency replacement of a Sub-processor (for example, if a provider fails or is compromised) may be made on shorter notice; PitchWhip will tell the Customer as soon as reasonably practicable and the objection right still applies.

10. Assistance with rights requests and DPIAs

Taking into account the nature of the processing, PitchWhip will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to data subjects’ requests to exercise their rights (access, rectification, erasure, restriction, portability, objection). In practice: the customer portal shows and exports the Customer’s call log and revealed contacts for its own licence, and PitchWhip will delete or correct specific rows on request within 10 business days. If PitchWhip receives a request directly from a data subject about Customer Personal Data, it will not respond substantively (beyond acknowledging receipt and pointing to the controller) unless required by law, and will forward the request to the Customer where it can identify the Customer without disproportionate effort.

PitchWhip will also assist the Customer, taking into account the nature of the processing and the information available to PitchWhip, with the Customer’s obligations relating to security, breach notification, data-protection impact assessments and prior consultation with a supervisory authority (Articles 32 to 36 GDPR). The description of processing in Annex 1, the measures in Annex 2 and the Privacy Policy are provided for this purpose; PitchWhip will answer reasonable written questions and may charge reasonably for assistance beyond that.

11. Personal data breaches

PitchWhip will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data — and in any event will make initial notification within 72 hours of becoming aware, so that the Customer can meet its own notification deadlines. Notification is by email to the address on the Customer’s purchase (or another address the Customer has told us to use) and will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point. Information may be provided in phases as it becomes available. PitchWhip will take reasonable steps to contain and remediate the breach and will cooperate with the Customer’s investigation. Notification is not an admission of fault or liability.

12. Deletion and return

Throughout the term the Customer may delete its own Customer Personal Data by asking PitchWhip (and through any deletion controls the portal offers). On termination or expiry of the Customer’s Subscription (or of the Terms), PitchWhip will delete the Customer Personal Data held for that licence key — revealed contacts, call log, team membership and settings, and any stored feedback and quality-telemetry records — on the Customer’s request without undue delay and in any event within 90 days as part of its clean-up of lapsed licences, and will on written request confirm deletion. Before deletion the Customer may export its call log and revealed contacts from the portal; PitchWhip will provide a machine-readable copy on request instead. PitchWhip may retain: purchase and refund entries in the credit ledger (which contain no Prospect Data) for accounting and tax purposes; and any Customer Personal Data it is required by law to retain, for as long as the law requires, keeping it confidential and processing it for no other purpose. Backups held by hosting providers are overwritten in the ordinary course and are not restored except to recover the Service.

13. Audits and information

PitchWhip will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Because PitchWhip is a small company running on managed cloud infrastructure, audits are satisfied in the first instance by: this DPA and its Annexes; PitchWhip’s written answers to a reasonable security questionnaire; and the current compliance reports and certifications of its Sub-processors (which PitchWhip will help the Customer obtain). An on-site or remote inspection may be requested no more than once in any 12-month period (or additionally following a personal data breach or a supervisory authority’s request), on at least 30 days’ written notice, during business hours, subject to reasonable confidentiality undertakings, and at the Customer’s cost. Audit rights do not extend to Sub-processors’ premises or to other customers’ data.

14. International transfers

PitchWhip is established in the United Kingdom and uses Sub-processors in the United Kingdom, the European Union and the United States (Annex 3). The Customer authorises the transfers this involves, on the following terms:

  • UK Customers. Transfers from the UK to the EU rely on the UK adequacy regulations for the EEA. Transfers from the UK to the US or other third countries rely on the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, and otherwise on the IDTA or the UK Addendum to the SCCs, which PitchWhip has entered into (or will enter into) with each relevant Sub-processor.
  • EEA Customers. Transfers from the EEA to PitchWhip in the UK rely on the European Commission’s adequacy decision for the UK. Where that decision ceases to apply, the SCCs (Module 2, controller to processor) are incorporated by reference into this DPA between the Customer as data exporter and PitchWhip as data importer, with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorisation, 30 days); Clause 11 optional language not included; Clause 13 governed by the supervisory authority of the Customer’s member state; Clause 17 Option 1 with Irish law; Clause 18 courts of Ireland; and Annexes I–III of the SCCs populated by Annexes 1–3 of this DPA. Onward transfers by PitchWhip to Sub-processors outside the EEA/UK rely on the SCCs (Module 3, processor to processor) or the EU–US Data Privacy Framework.
  • Swiss Customers. The SCCs apply as adapted for Swiss law, with the Federal Data Protection and Information Commissioner as competent authority.
  • Transfer risk. PitchWhip has assessed the transfers in Annex 3 and considers that the safeguards, the limited and business-contact nature of the data, and the encryption and access controls in Annex 2 provide appropriate protection. PitchWhip will tell the Customer if it becomes unable to comply with the transfer mechanism relied on. Copies of the executed transfer terms with Sub-processors (redacted for commercial information) are available on request.

15. Liability

Each Party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms, and the cap in the Terms applies to the Parties’ combined liability under the Terms and this DPA together, save that nothing limits either Party’s liability to data subjects or supervisory authorities where Data Protection Law does not permit it to be limited. The Customer is responsible for its Users’ and Team members’ compliance with this DPA.

16. Term, precedence and changes

This DPA lasts for as long as PitchWhip processes Customer Personal Data and until deletion is complete under section 12. If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails; if there is a conflict between this DPA and the SCCs or IDTA, the SCCs or IDTA prevail. PitchWhip may update this DPA to reflect changes in law, in the Service, or in its Sub-processors; it will post the new version here with a new effective date and, for changes that reduce the Customer’s protections, give at least 30 days’ email notice, during which the Customer may terminate as described in section 9. Where the CCPA applies, PitchWhip acts as a “service provider”: it will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in Annex 1, or combine it with personal data from other sources except as the CCPA permits, and it certifies that it understands these restrictions.

17. Governing law

This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, except where the SCCs or the IDTA require otherwise for the clauses they contain (in which case the choices in section 14 apply to those clauses).

Annex 1 — Details of processing

Annex 1 — Details of processing
ItemDescription
Subject matterProvision of the PitchWhip Service: AI-generated call preparation, contact reveals, a per-licence call log and revealed-contact store, and team features, as instructed through the extension and portal.
DurationThe term of the Customer's Subscription plus the deletion window in section 12 (on request without undue delay; otherwise up to 90 days). AI generation inputs are processed transiently (seconds) and are not retained, save for the feedback and quality-telemetry excerpts described in Annex 2, which are kept until deleted on request or no longer needed for tuning.
Nature of processingCollection (receipt from the extension), storage, retrieval, transmission to Sub-processors (AI provider, contact-data provider), matching (recognising a prospect across calls and reveals by URL or name + company), display to the Customer's Users and, if enabled, to Team members, and erasure.
PurposeTo let Users prepare for and log sales calls, find business contact details for prospects they have chosen, keep that data across devices, view it in the portal, and — within a Team — avoid duplicate outreach and share anonymised rebuttals.
Categories of data subjects(a) Prospects: business people whose LinkedIn or Sales Navigator profile a User views, reveals or calls. (b) Users: the Customer's licence holders and Team members.
Categories of personal data — ProspectsName, job title, company, LinkedIn profile URL; business phone number(s) and business email address(es) where revealed; call outcome codes, call times and durations, callback dates as logged by the User; profile text as displayed on LinkedIn (transient, for AI generation only); and, where the User enables transcription, the Prospect's speech — as audio streamed by the browser to Google's speech service for conversion to text (Annex 3), and as the resulting live-call excerpts and post-call transcripts forwarded through the API proxy to the AI provider for live suggestions, summaries, replay and voice learning (transient; not stored). Notes and transcripts are never stored in PitchWhip Cloud; the cloud call log holds outcome metadata only. Quality telemetry (Annex 2) contains no Prospect Personal Data.
Categories of personal data — UsersLicence key (masked in the portal), display name chosen for the Team, call activity metadata (which prospects were called, when, outcome, duration, callback date — visible to Team members, including in the portal's combined team call log, when the Team's call visibility is enabled), team membership and settings; the User's own speech within call transcripts, coaching lessons, call outcomes, Redo instructions and voice-profile text (transient, AI generation only); feedback text a User chooses to send and quality-telemetry diagnostics, which carry rule identifiers and timings but no script text (stored, Annex 2). The purchaser email address held for billing is processed by PitchWhip as controller (Privacy Policy).
Special categories / criminal dataNone intended. Users must not enter such data; the Service is designed for business contact data only.
FrequencyContinuous, driven by Users' actions.
Competent supervisory authorityUK: the Information Commissioner's Office. EEA Customers: the authority of the Customer's establishment, per the SCCs.

Annex 2 — Technical and organisational measures

Technical and organisational measures maintained by PitchWhip for Customer Personal Data:

Encryption

  • All traffic between the extension, the portal, PitchWhip Cloud and Sub-processors is encrypted in transit with TLS 1.2 or higher.
  • Data at rest in the database, key-value store and backups is encrypted by the hosting provider (AES-256 or equivalent).

Access control and tenant isolation

  • Customer Personal Data is partitioned by licence key. Every database query is scoped to the calling licence or, for Team features, to the licence keys that are members of the caller’s Team; there is no cross-tenant read path.
  • The extension authenticates with the licence key over TLS in a request header (never in URLs or logs); the portal authenticates with a short-lived signed token held in an httpOnly, Secure cookie and forwarded server-to-server, so the key is never exposed to browser scripts after login.
  • Team visibility is enforced server-side (a member cannot see another’s calls unless the Team’s setting allows it, and notes are never stored in the cloud at all).
  • Administrative access to production (Cloudflare, Vercel, Lemon Squeezy, Anthropic, FullEnrich consoles) is limited to the people who operate the Service, on individual accounts protected by multi-factor authentication, on a least-privilege basis.

Secrets management

  • API keys, signing secrets and webhook secrets are stored in the hosting providers’ encrypted secret stores and injected at runtime; they are never committed to source control or shipped in the extension.
  • Inbound webhooks from payment and data providers are verified with HMAC signatures using constant-time comparison before any write.

Data minimisation and retention

  • AI generation requests (profile text, pitch context and, for the live-call features, transcript and coaching text) are forwarded and streamed back without storing their content; only token counts are metered. The one exception is quality telemetry: when the extension’s automatic writing checks flag a generated script, it sends a diagnostic record — the identifiers of the rules that fired, the opener style and timings, and no script text or Prospect Personal Data — which, together with any feedback text a User chooses to send, is stored keyed to the licence, used only to tune the writing rules, never shown to other users, and deleted on request.
  • The cloud call log stores outcome metadata only — never notes, transcripts or coaching content.
  • Team Learning records are anonymised inside the Service before storage (AI scrub plus rule-based backstop; anything that cannot be cleaned is discarded).
  • Customer Personal Data is deleted on request without undue delay and otherwise within 90 days of the end of the Subscription, as part of the clean-up of lapsed licences (section 12).

Logging, monitoring and resilience

  • Request and error logs exclude request bodies and licence keys; webhook events are logged without prospect data.
  • Rate limits, per-licence caps and a global circuit breaker bound the impact of abuse; failed or unsigned requests are rejected before they reach the database.
  • The database is managed by the hosting provider with automated backups and point-in-time recovery.

Sub-processor due diligence and people

  • Sub-processors are selected for security posture and contractual commitments (DPA, transfer terms, independent certifications such as SOC 2 / ISO 27001 where available) and are listed in Annex 3.
  • Everyone with production access is bound by confidentiality and follows a written incident-response process: contain, assess, notify affected customers within the section 11 timeline, remediate, review.

Annex 3 — Sub-processors

Sub-processors authorised at the effective date. Changes are notified under section 9.

Annex 3 — Sub-processors
Sub-processorProcessingLocationTransfer mechanism
Cloudflare, Inc.Hosting of PitchWhip Cloud: Workers (API proxy, portal API), D1 database (call log, revealed contacts, credit ledger, team settings, feedback and quality-telemetry records) and KV (caches, metering).Global edge; storage in UK, EU and US data centres.UK: IDTA / UK Addendum; EU: SCCs; EU–US DPF certified.
Anthropic, PBCAI generation of call-preparation text, live suggestions, call summaries and coaching from profile text, pitch context and — where the User enables transcription — live-call and post-call transcript text and the User's coaching content (transient; not used for model training under commercial terms). Also performs open-web searches through its own server-side search tool: for the User-initiated Enrich feature, and for an automatic company lookup (company name and, where known, contact job title only) that fills missing industry, headcount and head-office country when a call is synced to the User's CRM sheet.United States.UK: IDTA / UK Addendum; EU: SCCs.
FullEnrichLook-up of business phone numbers and email addresses from a prospect's name, company and LinkedIn URL. Independent controller of its own database.European Union.Not a restricted transfer for UK/EEA Customers (EU / UK adequacy).
Vercel, Inc.Hosting of pitchwhip.com and the customer portal; portal requests (which may include Customer Personal Data) pass through Vercel's servers in transit to Cloudflare.United States, global edge.UK: IDTA / UK Addendum; EU: SCCs; EU–US DPF certified.
Lemon Squeezy, LLCMerchant of record for subscriptions and credit packs; licence-key issuance and validation. Processes purchaser and licence data (no Prospect Data) — independent controller for payments.United States.UK: IDTA / UK Addendum; EU: SCCs.
Google LLCTwo Customer-side cases. (1) Speech recognition: where a User turns on live transcription, Chrome's built-in speech recognition streams the microphone audio — which includes the Prospect's speech — to Google's speech service to convert it to text. That transfer is made by the browser between the User and Google; PitchWhip neither receives nor stores the audio. (2) Where a User connects Google Sheets / Calendar, the extension writes to the User's own Google account. In both cases Google is engaged by the Customer through their own Google agreement; listed for completeness and transparency.Per the Customer's Google agreement.Per the Customer's Google agreement.
Web3FormsDelivery of website enquiry forms to PitchWhip's inbox. Not used for Customer Personal Data; listed for completeness.Cloud-hosted.Not applicable to Customer Personal Data.
ResendTransactional delivery of customer-portal sign-in codes. Processes the recipient's email address and a single-use six-digit code. No prospect data, call records, reveals or transcripts.US-incorporated; sending region configured as EU (Ireland).UK IDTA / EU SCCs.
Google LLCVerification of Google sign-in identity tokens for the customer portal, where the Customer chooses that sign-in method. PitchWhip transmits the token and receives the verified email address. Separate from the Customer's own Google Sheets / Calendar connection, where Google acts for the Customer directly.United States.UK IDTA / EU SCCs; Data Privacy Framework certified.

Requests for a signed copy of this DPA, executed transfer terms, or a completed security questionnaire: hello@pitchwhip.com.