PitchWhip

Legal

Data Processing Agreement

Effective 2 September 2026 · updated 4 October 2026 (announced changes take effect 26 October 2026, or from acceptance for customers who first accept these terms on or after 4 October 2026)

This Data Processing Agreement (“DPA”) sets out the terms on which PitchWhip Ltd processes personal data on behalf of its customers. Article 28 of the UK GDPR and the EU GDPR requires it. It forms part of the Terms of Use and applies automatically to every customer, no signature needed. A countersigned copy is available on request.

New wording from 26 October 2026 (from 4 October 2026 for new customers)

Section 9 (Sub-processors): the first two bullets become

  • tell the Customer at least 10 business days before a new or replacement Sub-processor begins processing Customer Personal Data. Notice is by email to the address on the Customer’s purchase and to each admin on the Customer’s account, and by updating Annex 3 on this page. The period runs from the day the email is sent. “Business day” means Monday to Friday, except public holidays in England;
  • allow the Customer to object in writing, to hello@pitchwhip.com, on reasonable data-protection grounds within that period. PitchWhip will work with the Customer in good faith on a solution, such as not using that Sub-processor for the Customer’s data or switching off the feature that uses it. If no solution acceptable to the Customer is found, the Customer may terminate the affected part of the Service (or, if it cannot be separated, its Subscription). PitchWhip will refund prepaid fees for the period after termination. If the Customer does not object within the period, it is treated as accepting the change;

The rest of section 9 is unchanged.

Section 10 (Assistance with rights requests and DPIAs): a new second paragraph

Two standing instructions. A person may ask PitchWhip directly to be kept out of the Service (the notice to prospects). For that case the Customer instructs PitchWhip in advance: (a) from when the request is applied, to refuse new access to that person through the Service: no new Reveals of them, no calls to a number they removed, no place for them in a list the Customer uploads, and no email through the Service to an address they removed, whoever holds it; and (b) to tell that person, on request, that the Customer holds their details and how to reach the Customer, so that they can exercise their rights against it. A request takes nothing away from what the Customer already held when it was applied: a number or email address it had revealed through the Service or had on a list in the Service, or a number it had called through the Service, before then. The Customer can still see and export what it held, keep that person on its lists, and call a number it held. A person also keeps their place in a list the Customer uploads, whenever it is uploaded, where the Customer’s own list supplies a phone number or an email address for them; only that Customer may call that number, and PitchWhip adds nothing to that person’s row from its own data. PitchWhip does not add a held number to the Customer’s do-not-call records. Where the Customer looked the removed email address up through the Service, PitchWhip adds it to the Customer’s do-not-email list. The Customer’s own do-not-call and do-not-contact lists still apply to its calls through the Service, whatever it held. Where PitchWhip can identify the Customer without disproportionate effort, it will tell the Customer when it acts on either instruction. Everything else the Customer holds about that person is the Customer’s to decide.

Section 14 (International transfers): the Clause 9(a) selection for EEA Customers becomes

Clause 9(a): Option 2 (general authorisation; at least 10 business days, as in section 9).

Section 16 (Term, precedence and changes): the fourth, fifth and sixth sentences become

PitchWhip may update this DPA to reflect changes in law, in the Service, in its Sub-processors, or in how it gives notice under this DPA. It will post the new version here with a new effective date. Changes to Sub-processors follow section 9. For any other change that reduces the Customer’s protections, it will give at least 30 days’ email notice, during which the Customer may terminate as described in section 9.

The rest of section 16 is unchanged.

Annex 1 adds or changes

  • Subject matterWhere the Customer uses calling: calls placed through a telephony provider, dialled-call records, and optional recording and transcript saving.
  • DurationCall recordings and saved call transcripts: for the period the Customer’s admin chooses, 90 days from the call (the default), 1 year, 2 years, or until they are deleted; whatever the choice, they are deleted with the Customer’s other data after its licence ends. The number dialled: in the short-lived store that places the call, about ninety minutes; the copy kept with that call’s record, until the call is deleted or with the call log.
  • Nature of processingPlacing calls: sending the number the User chooses and the Customer’s verified caller ID to the telephony provider, which carries the call between the User’s browser and the person called. Storing that number with the call’s record. Where the Customer connects HubSpot or Salesforce, writing it to that call’s record there unless the User’s outcome marks it a wrong number. Where switched on: recording from answer, playing the announcement, storing the transcript.
  • PurposeTo let Users call prospects from the Service, bill minutes for connected time, and keep the call’s record, recording and transcript where the Customer chooses.
  • Categories of personal data: Prospects (the transcripts item)The exception: where the Customer switches on transcript saving, the transcript of a call dialled through the Service is stored for the period the Customer’s admin chooses (90 days by default; up to 8,000 characters). The User who made the call and the Customer’s admin can read it.
  • Categories of personal data: ProspectsDialled-call data: the number called, stored with that call’s record (and, while the call is placed, in a short-lived store), and a one-way hash of it with its country and rate band. Call times, duration, end reason and the telephony provider’s call identifiers. A phone number or email address the User typed for a call. The call audio in transit.
  • Categories of personal data: ProspectsCall recordings, where the Customer switches recording on: audio of both parties from answer, held by the telephony provider for the period the Customer’s admin chooses (90 days by default). The User who made the call and the Customer’s admin can play and delete them.
  • Categories of personal data: Prospects (the call-log item)The cloud call log excludes private extension notes, and transcripts other than saved transcripts of dialled calls.
  • Categories of personal data: UsersThe User’s own speech within recordings and saved transcripts of dialled calls, where switched on.

Annex 2 adds

  • Access control and tenant isolationA recording can be played or deleted only by the User who made the call or the Customer’s admin, and a saved transcript read or deleted only by the same two. A refused transcript request gets the same answer whatever the reason, including for a call that does not exist, so call identifiers cannot be probed. A saved transcript is never included in a team list, an export to a CRM or an error report.
  • Data minimisation and retentionThe number dialled is held in a short-lived store while the call is placed, which expires within about ninety minutes. A copy is kept with that call’s record. Inside the Service only the User who made the call can see it, and it is never pooled across the account. Dialling limits keep only a one-way hash. Recordings are held at the telephony provider, not by PitchWhip, and an automatic sweep deletes recordings and saved transcripts at the end of the period the Customer’s admin chooses (90 days after the call by default), unless the admin chooses to keep them until they are deleted.

1. Parties and how this DPA applies

This DPA is between PitchWhip Ltd (“PitchWhip”) and the Customer. PitchWhip Ltd is a company registered in England and Wales (company number 17389184) with its registered office at 96A Wandsworth Bridge Road, London SW6 2TF, United Kingdom. The “Customer” is the customer that has accepted the Terms of Use: the person or organisation to whom a PitchWhip licence key is issued, or on whose behalf licence keys are used. Together, the “Parties”.

It applies whenever PitchWhip processes personal data as a processor on the Customer’s behalf in providing the Service. It takes effect when the Customer first uses the Service after the effective date above. Where the Customer is an organisation, its licence holders ( “Users”) act on its behalf. If the Customer needs a signed copy, or wishes to attach its own pre-approved terms, email hello@pitchwhip.com. We will sign this DPA and consider reasonable additions that reflect the Service as it actually works.

2. Definitions

  • Data Protection Law: all laws that apply to the processing of personal data under this DPA. That includes the UK GDPR and the Data Protection Act 2018, and the EU GDPR (Regulation (EU) 2016/679). It also includes the Swiss Federal Act on Data Protection and, to the extent they apply, US state privacy laws such as the CCPA.
  • Personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in the UK GDPR / EU GDPR. Where the CCPA applies, “controller” includes a “business” and “processor” includes a “service provider”.
  • Customer Personal Data: personal data that PitchWhip processes on the Customer’s behalf, as described in Annex 1 below. It principally comprises Prospect Data: business contact data about the people Users research, reveal, call, upload to a contact list or add to a sequence. It includes the contact basis a User records against a person added to a sequence. It also comprises limited User Data: a User’s display name, call activity and the notes they write in the learnings box.
  • Service: the PitchWhip Chrome extension, PitchWhip Cloud and the customer portal, as defined in the Terms of Use. PitchWhip Cloud is the API proxy, contact reveals and credit ledger, call log, team features, sequences, campaigns, contact lists and reports.
  • Sub-processor: a third party engaged by PitchWhip to process Customer Personal Data.
  • Standard Contractual Clauses or SCCs: the clauses approved by the European Commission under Decision (EU) 2021/914. UK Addendum: the ICO’s International Data Transfer Addendum to the SCCs. IDTA: the ICO’s International Data Transfer Agreement.
  • Terms: the PitchWhip Terms of Use.

3. Roles of the parties

For Customer Personal Data, the Customer is the controller and PitchWhip is the processor. Where the Customer is itself a processor for another organisation, the Customer is a processor, and warrants that its instructions to PitchWhip are authorised by that controller. PitchWhip processes Customer Personal Data only to provide the Service and on the Customer’s documented instructions.

The Customer decides the lawful basis on which it contacts each Prospect. PitchWhip does not decide it and cannot establish it for the Customer. Where a User records a contact basis against a person added to a sequence (Annex 1), that record is the Customer’s statement about its own relationship with that person. PitchWhip stores it, acts on it, and applies the sending restriction described in Annex 1 from it. PitchWhip does not verify it.

For personal data that PitchWhip processes for its own purposes, PitchWhip is an independent controller and its Privacy Policy applies. That covers customer account records, licence and billing status, website analytics, support correspondence, and the anonymised Team Learning pool. Lemon Squeezy is an independent controller for payments. Our contact-data enrichment provider is an independent controller of its own contact database. PitchWhip’s transmission of a Reveal request to that provider is processing on the Customer’s behalf and is covered by this DPA; for that look-up the provider is PitchWhip’s Sub-processor (Annex 3).

4. Details of the processing

The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data are set out in Annex 1 below. This DPA covers only the personal data PitchWhip processes on the Customer’s behalf. It does not cover PitchWhip’s own prospect index, for which PitchWhip is an independent controller: see section 8 of the Privacy Policy and the notice to prospects. In short: PitchWhip hosts, on the Customer’s instruction, the Customer’s revealed prospect contacts and call log. It forwards profile text and, for the live-call features, call transcript and coaching text to an AI provider to generate call preparation, suggestions and summaries. It does not retain that text, save for the quality-telemetry diagnostics in Annex 2. It forwards a prospect’s name, company and LinkedIn URL to a contact-data provider to find business contact details. Each of these lasts for the life of the Customer’s licence. Where the Customer uses sequences, PitchWhip also hosts its contact lists, the people in its sequences, its learnings and campaign images. It sends the Customer’s 1:1 sequence emails from the User’s own mailbox, and its campaign emails through an email provider from the Customer’s verified subdomain. It records the delivery events that provider reports and, only if the Customer switches it on, open events, and computes reports from those records. For each person added to a sequence it also stores the contact basis a User records: inbound, customer, reply or cold. A person recorded as cold cannot be added to a sequence that sends from the User’s own mailbox. Cold outreach is confined to campaign sending from the Customer’s verified subdomain, and to LinkedIn and call steps, which send no email.

5. Instructions

PitchWhip will process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to PitchWhip. In that case PitchWhip will tell the Customer before processing, unless the law prohibits it on important grounds of public interest. The Customer’s instructions are: the Terms; this DPA; and the Customer’s and its Users’ use of the Service’s features and settings. Examples of the last: pressing “Reveal”, logging a call, enabling call visibility for a Team, uploading a contact list, adding people to a sequence, switching open tracking on, requesting deletion. Additional instructions may be agreed in writing; PitchWhip may charge reasonably for instructions that go beyond the Service. PitchWhip will inform the Customer without delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is confirmed or withdrawn.

6. Customer obligations

The Customer is responsible for:

  • having a lawful basis for the processing it instructs, and giving data subjects any notices Data Protection Law requires (including, for prospects, information about the source of their data where required);
  • the accuracy and lawfulness of the Prospect Data its Users obtain and enter, and compliance with LinkedIn’s terms, direct-marketing rules and call-recording law;
  • recording the contact basis honestly for each person a User adds to a sequence, and holding whatever evidence stands behind it. The record states a fact about the Customer’s own relationship with that person; it does not create a lawful basis, and PitchWhip does not verify it;
  • not using bought, rented, swapped or scraped lists with the Service, and honouring opt-outs and objections however they arrive, including ones that reach it directly;
  • responding to data subjects who exercise their rights against it (PitchWhip will assist as set out in section 10);
  • keeping licence keys secure (a licence key is the credential that reads that licence’s Customer Personal Data) and telling PitchWhip promptly if one is compromised;
  • where it runs a Team, ensuring it has authority to add each member, telling members what team-mates can see, and configuring the visibility settings appropriately;
  • using data obtained through Reveals only as permitted by the Terms.

7. Confidentiality

PitchWhip ensures that the people it authorises to process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality. Currently that is only the people who operate the Service. They are given access only to the extent needed to operate, support or secure the Service, and have received appropriate data-protection guidance. PitchWhip does not look at the content of a Customer’s revealed contacts or call log. The exceptions: support the Customer has asked for, investigating a security incident, or where the law requires.

8. Security

PitchWhip implements and maintains the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk. That takes into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk to data subjects. It includes protection against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. PitchWhip may update those measures from time to time, provided the overall level of security is not reduced. The Customer is responsible for its own environment: browser and device security, Google account security, and the secrecy of its licence keys.

9. Sub-processors

The Customer gives PitchWhip general written authorisation to engage the Sub-processors listed in Annex 3 and, subject to this section, to add or replace Sub-processors. PitchWhip will:

  • give the Customer at least 30 days’ notice before a new Sub-processor begins processing Customer Personal Data. Notice is by email to the address on the Customer’s purchase and by updating Annex 3 on this page (the “effective” date at the top changes when it does);
  • allow the Customer to object on reasonable, documented data-protection grounds within that period. If the Parties cannot resolve the objection, the Customer may terminate the affected part of the Service (or, if it cannot be separated, its Subscription). PitchWhip will then refund prepaid fees for the period after termination;
  • impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, in particular as to security and, where relevant, international transfers; and
  • remain fully liable to the Customer for the performance of each Sub-processor’s obligations.

Emergency replacement of a Sub-processor (for example, if a provider fails or is compromised) may be made on shorter notice. PitchWhip will tell the Customer as soon as reasonably practicable and the objection right still applies.

10. Assistance with rights requests and DPIAs

PitchWhip will assist the Customer, taking into account the nature of the processing, in fulfilling its obligation to respond to data subjects’ requests to exercise their rights. It does so by appropriate technical and organisational measures, insofar as possible. Those rights are access, rectification, erasure, restriction, portability and objection. In practice: the customer portal shows and exports the Customer’s call log, revealed contacts and contact lists for its own licence. PitchWhip will delete or correct specific rows on request within 10 business days. If PitchWhip receives a request directly from a data subject about Customer Personal Data, it will not respond substantively (beyond acknowledging receipt and pointing to the controller) unless required by law. It will forward the request to the Customer where it can identify the Customer without disproportionate effort.

PitchWhip will also assist the Customer with its obligations relating to security, breach notification, data-protection impact assessments and prior consultation with a supervisory authority (Articles 32 to 36 GDPR). That assistance takes into account the nature of the processing and the information available to PitchWhip. The description of processing in Annex 1, the measures in Annex 2 and the Privacy Policy are provided for this purpose. PitchWhip will answer reasonable written questions and may charge reasonably for assistance beyond that.

11. Personal data breaches

PitchWhip will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. In any event it will make initial notification within 72 hours of becoming aware, so that the Customer can meet its own notification deadlines. Notification is by email to the address on the Customer’s purchase (or another address the Customer has told us to use). It will describe, to the extent known, the nature of the breach and the categories and approximate number of data subjects and records concerned. It will also give the likely consequences, the measures taken or proposed to address it, and a contact point. Information may be provided in phases as it becomes available. PitchWhip will take reasonable steps to contain and remediate the breach and will cooperate with the Customer’s investigation. Notification is not an admission of fault or liability.

12. Deletion and return

Throughout the term the Customer may delete its own Customer Personal Data by asking PitchWhip (and through any deletion controls the portal offers). On termination or expiry of the Customer’s Subscription (or of the Terms), PitchWhip will delete the Customer Personal Data held for that licence key. Deletion is on the Customer’s request without undue delay and in any event within 90 days as part of its clean-up of lapsed licences, and PitchWhip will on written request confirm deletion. That data is: revealed contacts, call log, team membership and settings, and any stored feedback and quality-telemetry records. Where the Customer used them, it also includes: sequences and the people in them, sequence events, contact lists and their members, learnings, and campaign images and their stored bytes. And: campaign delivery events, open records, the open-tracking switch, mailbox connections and the sending-domain record. Before deletion the Customer may export its call log, revealed contacts and contact lists from the portal; PitchWhip will provide a machine-readable copy on request instead. PitchWhip may retain three things. Purchase and refund entries in the credit ledger (which contain no Prospect Data), for accounting and tax purposes. The Customer’s do-not-email list (addresses that unsubscribed, bounced or were added by the Customer), so that a person who asked not to be emailed is never emailed again. And any Customer Personal Data it is required by law to retain, for as long as the law requires, keeping it confidential and processing it for no other purpose. Backups held by hosting providers are overwritten in the ordinary course and are not restored except to recover the Service.

13. Audits and information

PitchWhip will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. It will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Because PitchWhip is a small company running on managed cloud infrastructure, audits are satisfied in the first instance by three things. This DPA and its Annexes. PitchWhip’s written answers to a reasonable security questionnaire. And the current compliance reports and certifications of its Sub-processors (which PitchWhip will help the Customer obtain). An on-site or remote inspection may be requested no more than once in any 12-month period (or additionally following a personal data breach or a supervisory authority’s request). It is on at least 30 days’ written notice, during business hours, subject to reasonable confidentiality undertakings, and at the Customer’s cost. Audit rights do not extend to Sub-processors’ premises or to other customers’ data.

14. International transfers

PitchWhip is established in the United Kingdom and uses Sub-processors in the United Kingdom, the European Union and the United States (Annex 3). The Customer authorises the transfers this involves, on the following terms:

  • UK Customers. Transfers from the UK to the EU rely on the UK adequacy regulations for the EEA. Transfers from the UK to the US or other third countries rely on the UK Extension to the EU–US Data Privacy Framework where the recipient is certified. Otherwise they rely on the IDTA or the UK Addendum to the SCCs, which PitchWhip has entered into (or will enter into) with each relevant Sub-processor.
  • EEA Customers. Transfers from the EEA to PitchWhip in the UK rely on the European Commission’s adequacy decision for the UK. Where that decision ceases to apply, the SCCs (Module 2, controller to processor) are incorporated by reference into this DPA, with the Customer as data exporter and PitchWhip as data importer. They are incorporated with these selections:
    • Clause 7 (docking): included.
    • Clause 9(a): Option 2 (general authorisation, 30 days).
    • Clause 11: the optional language is not included.
    • Clause 13: governed by the supervisory authority of the Customer’s member state.
    • Clause 17: Option 1, with Irish law.
    • Clause 18: the courts of Ireland.
    • Annexes I–III of the SCCs: populated by Annexes 1–3 of this DPA.
    Onward transfers by PitchWhip to Sub-processors outside the EEA/UK rely on the SCCs (Module 3, processor to processor) or the EU–US Data Privacy Framework.
  • Swiss Customers. The SCCs apply as adapted for Swiss law, with the Federal Data Protection and Information Commissioner as competent authority.
  • Transfer risk. PitchWhip has assessed the transfers in Annex 3 below. It considers that the safeguards, the limited and business-contact nature of the data, and the encryption and access controls in Annex 2 provide appropriate protection. PitchWhip will tell the Customer if it becomes unable to comply with the transfer mechanism relied on. Copies of the executed transfer terms with Sub-processors (redacted for commercial information) are available on request.

15. Liability

Each Party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms. The cap in the Terms applies to the Parties’ combined liability under the Terms and this DPA together. Nothing limits either Party’s liability to data subjects or supervisory authorities where Data Protection Law does not permit it to be limited. The Customer is responsible for its Users’ and Team members’ compliance with this DPA.

16. Term, precedence and changes

This DPA lasts for as long as PitchWhip processes Customer Personal Data and until deletion is complete under section 12 above. If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. If there is a conflict between this DPA and the SCCs or IDTA, the SCCs or IDTA prevail. PitchWhip may update this DPA to reflect changes in law, in the Service, or in its Sub-processors. It will post the new version here with a new effective date. For changes that reduce the Customer’s protections, it will give at least 30 days’ email notice, during which the Customer may terminate as described in section 9 above. Where the CCPA applies, PitchWhip acts as a “service provider”. It will not sell or share Customer Personal Data. It will not retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in Annex 1 below. It will not combine it with personal data from other sources except as the CCPA permits. It certifies that it understands these restrictions.

17. Governing law

This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. The exception is where the SCCs or the IDTA require otherwise for the clauses they contain; there the choices in section 14 apply to those clauses.

Annex 1: Details of processing

Annex 1: Details of processing
ItemDescription
Subject matterProvision of the PitchWhip Service, as instructed through the extension and portal: AI-generated call preparation, contact reveals, a per-licence call log and revealed-contact store, and team features. Per account: contact lists, sequences (1:1 email from the User's own mailbox; campaign email from the Customer's verified subdomain; LinkedIn and call steps completed by the User), campaign images, learnings and reports.
Excluded from this DPAPitchWhip's own prospect index (currently switched off, holding no records and receiving nothing): professional details of potential contacts, drawn from published profiles, which could be shown to more than one customer. PitchWhip is an independent controller of that index and does not process it on the Customer's instructions; data subjects exercise their rights against PitchWhip directly. Nothing the Customer records (call logs, notes, transcripts, coaching content or revealed contact details) forms part of it.
DurationThe term of the Customer's Subscription plus the deletion window in section 12 (on request without undue delay; otherwise up to 90 days). AI generation inputs are processed transiently (seconds) and are not retained. The exception is the feedback and quality-telemetry diagnostics described in Annex 2, kept until deleted on request or no longer needed for tuning.
Nature of processing
  • Collection: receipt from the extension and portal, including rows the Customer uploads from a spreadsheet parsed in its own browser.
  • Storage and retrieval.
  • Transmission to Sub-processors (AI provider, contact-data provider, email provider for campaign email) and, where the Customer connects an integration, to the Customer's own CRM.
  • Matching: recognising a prospect across calls, reveals, lists and sequences by email, URL or name + company, including against the Customer's own do-not-contact lists.
  • Classification of list members by job title into segment labels (AI-assisted, on the Customer's instruction).
  • Display to the Customer's Users and, if enabled, to Team members.
  • Checking the contact basis recorded for a person before they are added to a sequence. A person recorded as cold is refused where the sequence sends from the User's own connected mailbox.
  • Composition and sending of sequence emails from the Customer's own connected mailbox, and of campaign emails from the Customer's verified subdomain through the email provider.
  • Hosting of campaign images at an unguessable public address with no access logging.
  • Receipt of the email provider's delivery events (delivered, delayed, bounced, complained) per address.
  • Recording of open events, only where the Customer has switched open tracking on: the pixel records time, count and whether an image proxy loaded it; no IP address or device details.
  • Computation of reports and rule-based diagnostics from those records.
  • Erasure.
  • Stop-on-reply, where the Customer enables it: a copy of each reply is received in transit so its sequence reference and routing headers can be read and the sequence stopped. Ordinary prospect reply bodies are not opened, stored, logged or transmitted onward.
  • On the User's request, Gmail forwarding setup: transient processing of a matching Google confirmation message to extract the approval link for the connected mailbox and generated forwarding address. The message body is not saved or logged. The link and minimal owner, connection, destination, receipt and setup-window identifiers are held temporarily. The link is accessible only to that owner during a 15-minute window; expired links are withheld. A connection change or disconnect removes access to the old setup link. Stored links are erased on close or during expiry cleanup. The User opens Google's link manually. This does not request inbox-reading permission or establish that forwarding works.
Purpose
  • To let Users prepare for and log sales calls, find business contact details for prospects they have chosen, keep that data across devices, and view it in the portal.
  • To write calls and follow-up tasks into the Customer's own CRM where connected.
  • To keep contact lists and do-not-contact lists.
  • To run follow-up sequences that send from the User's own mailbox and stop when a Prospect replies, and to send campaign emails from the Customer's verified subdomain.
  • To confine cold outreach to campaign sending and to steps that send no email, keeping it out of the User's own mailbox.
  • To report on how those sequences performed.
  • Within a Team, to avoid duplicate outreach and share anonymised rebuttals.
Categories of data subjects(a) Prospects: business people whose LinkedIn or Sales Navigator profile a User views, reveals or calls, and people the Customer uploads to a contact list or a do-not-contact list. Also the recipients of the Customer's sequence and campaign emails. (b) Users: the Customer's licence holders and Team members.
Categories of personal data: Prospects
  • Profile and reveal data: name, job title, company, LinkedIn profile URL; business phone number(s) and business email address(es) where revealed.
  • Call data: call outcome codes, call times and durations, callback dates as logged by the User.
  • Profile text as displayed on LinkedIn (transient, for AI generation only).
  • Transcripts, where the User enables transcription (transient, not stored). The Prospect's speech is streamed by the browser as audio to Google's speech service for conversion to text (Annex 3). The resulting live-call excerpts and post-call transcripts are forwarded through the API proxy to the AI provider for live suggestions, summaries, replay and voice learning.
  • List members, where the Customer keeps contact lists: name, company, job title, business email address, LinkedIn URL and a segment label per member. Rows are uploaded, pasted or copied from the Customer's own call log or reveals.
  • Sequence data, where the Customer runs sequences: the Prospect's business email address, their current step and state, and the subject line of the first email (kept for threading, cleared when they finish). The content of emails sent to them is composed at send time and not retained.
  • Contact basis, where the Customer runs sequences: one of inbound, customer, reply or cold, recorded by the User against the person and stating why that person may lawfully be emailed.
  • Campaign delivery status: for campaign emails, a delivery status per address as reported by the email provider (delivered, delayed, bounced, complained, with a short category).
  • Open records, where open tracking is switched on: one per email (time, count, whether an image proxy loaded it; no IP address or device details).
  • The Customer's do-not-email list: addresses that unsubscribed, bounced or were added by hand.
  • Replies in transit, where stop-on-reply is enabled: sequence references and routing headers only; ordinary prospect reply bodies are not opened, stored, logged or transmitted onward.
  • During user-initiated Gmail forwarding setup: the connected mailbox address, generated forwarding address, temporary Google approval link and associated owner, connection and setup-window timestamps/identifiers. The confirmation message body is processed transiently and is not saved or logged.
  • The cloud call log excludes private extension notes and transcripts. Separate notes explicitly authored in the dashboard are stored for the owning call, with selected export destinations and sync status. They are not automatically imported from extension notes. Quality telemetry (Annex 2) contains no Prospect Personal Data.
Categories of personal data: Users
  • Licence key (masked in the portal), display name chosen for the Team, team membership and settings.
  • Call activity metadata: which prospects were called, when, outcome, duration, callback date. Visible to Team members, including in the portal's combined team call log, when the Team's call visibility is enabled.
  • The User's own speech within call transcripts, coaching lessons, call outcomes, Redo instructions and voice-profile text (transient, AI generation only).
  • Feedback text a User chooses to send, and quality-telemetry diagnostics, which carry rule identifiers and timings but no script text (stored, Annex 2).
  • The notes a User writes in the learnings box about the Customer's own outreach, and the sequence steps and briefs they author.
  • Their connected mailbox (address and an encrypted credential) and sign-off.
  • Images an Admin uploads for campaigns.
  • The Customer's sending-domain details: domain, DNS records, from name and address, replies-to address, business identity line.
  • Which Admin acknowledged the open-tracking switch, and when.
  • The purchaser email address held for billing is processed by PitchWhip as controller (Privacy Policy).
Special categories / criminal dataNone intended. Users must not enter such data; the Service is designed for business contact data only.
FrequencyContinuous, driven by Users' actions.
Competent supervisory authorityUK: the Information Commissioner's Office. EEA Customers: the authority of the Customer's establishment, per the SCCs.

Annex 2: Technical and organisational measures

Technical and organisational measures maintained by PitchWhip for Customer Personal Data:

Encryption

  • All traffic between the extension, the portal, PitchWhip Cloud and Sub-processors is encrypted in transit with TLS 1.2 or higher.
  • Data at rest in the database, key-value store and backups is encrypted by the hosting provider (AES-256 or equivalent).

Access control and tenant isolation

  • Customer Personal Data is partitioned by licence key. Every database query is scoped to the calling licence or, for Team features, to the licence keys that are members of the caller’s Team; there is no cross-tenant read path.
  • The extension authenticates with the licence key over TLS in a request header (never in URLs or logs). The portal authenticates with a short-lived signed token held in an httpOnly, Secure cookie and forwarded server-to-server, so the key is never exposed to browser scripts after login.
  • Team visibility is enforced server-side (a member cannot see another’s calls unless the Team’s setting allows it). Separate dashboard-authored notes are accessible through their owning user; private extension notes and transcripts are not imported.
  • Administrative access to production (Cloudflare, Vercel, Lemon Squeezy, Anthropic and enrichment-provider consoles) is limited to the people who operate the Service, on individual accounts protected by multi-factor authentication, on a least-privilege basis.

Secrets management

  • API keys, signing secrets and the keys that verify provider notices are stored in the hosting providers’ encrypted secret stores and injected at runtime. They are never committed to source control or shipped in the extension.
  • Notices sent to PitchWhip by the payment, data and email providers (payment events, delivery and bounce notices) are verified with HMAC signatures using constant-time comparison before any write.

Data minimisation and retention

  • AI generation requests (profile text, pitch context and, for the live-call features, transcript and coaching text) are forwarded and streamed back without storing their content; only token counts are metered. The one exception is quality telemetry. When the extension’s automatic writing checks flag a generated script, it sends a diagnostic record. That record holds the identifiers of the rules that fired, the opener style and timings, and no script text or Prospect Personal Data. It is stored keyed to the licence, together with any feedback text a User chooses to send. Both are used only to tune the writing rules, never shown to other users, and deleted on request.
  • The cloud call log excludes private extension notes, transcripts and per-call coaching content. A separate note explicitly authored in the dashboard is stored for its owning call. Export to HubSpot, Salesforce or Google Sheets requires the User to select that destination for the note. Clearing the note clears its current text. Sync records can retain the last-exported note text and record identifiers while a destination is off or an update is unconfirmed, to check later changes without overwriting other content. Deleting the owning call clears the current note and copied note text from PitchWhip’s sync records; record identifiers and error history may remain. Existing external CRM or Sheets copies are not deleted.
  • Team Learning records are anonymised inside the Service before storage (AI scrub plus rule-based backstop; anything that cannot be cleaned is discarded).
  • Customer Personal Data is deleted on request without undue delay and otherwise within 90 days of the end of the Subscription, as part of the clean-up of lapsed licences (section 12).

Logging, monitoring and resilience

  • Request and error logs exclude request bodies and licence keys; provider notices are logged without prospect data.
  • Rate limits, per-licence caps and a global circuit breaker bound the impact of abuse; failed or unsigned requests are rejected before they reach the database.
  • The database is managed by the hosting provider with automated backups and point-in-time recovery.

Sub-processor due diligence and people

  • Sub-processors are selected for security posture and contractual commitments (DPA, transfer terms, independent certifications such as SOC 2 / ISO 27001 where available) and are listed in Annex 3.
  • Everyone with production access is bound by confidentiality and follows a written incident-response process: contain, assess, notify affected customers within the section 11 timeline, remediate, review.

Annex 3: Sub-processors

Sub-processors authorised at the effective date. Changes are notified under section 9. A row marked “From” was announced under section 9 and applies from the date or dates in its marker.

Annex 3: Sub-processors
Sub-processorProcessingLocationTransfer mechanism
Cloudflare, Inc.Hosting of PitchWhip Cloud: Workers (API proxy, portal API) and KV (caches, metering, the bytes of campaign images). D1 database: call log, revealed contacts, credit ledger, team settings, feedback and quality-telemetry records, sequences and the people in them, contact lists, learnings, campaign delivery events, open records.Global edge; storage in UK, EU and US data centres.UK: IDTA / UK Addendum; EU: SCCs; EU–US DPF certified.
Anthropic, PBCAI generation of call-preparation text, live suggestions, call summaries and coaching from profile text and pitch context. Where the User enables transcription, also from live-call and post-call transcript text and the User's coaching content (transient; not used for model training under commercial terms). For sequences: writes sequence plans and the email and LinkedIn drafts each step sends. Those are written from the Customer's pitch profile, brief, learnings, coaching lessons, rebuttal pools and call and sequence statistics. They also read the Prospect's name and company and the outcome of the User's last call to them. Sorts list members into segment labels from job title and company only (no names or addresses are sent). Phrases a report summary from rule-based findings and the sequence's name. Also performs open-web searches through its own server-side search tool: for the User-initiated Enrich feature, and for an automatic company lookup when a call is synced to the User's CRM sheet. That lookup sends the company name and, where known, the contact job title only, and fills missing industry, headcount and head-office country. Its web-search tool uses Brave Search and TurboPuffer, which Anthropic lists as its own sub-processors for that tool.United States.UK: IDTA / UK Addendum; EU: SCCs.
Contact-data enrichment providerLook-up of business phone numbers and email addresses from a prospect's name, company and LinkedIn URL. Independent controller of its own database. Identified by category for reasons of commercial confidentiality; named in the confidential sub-processor schedule provided at contract stage, and confirmed in writing on request. For look-ups it uses its own listed sub-processors; the list is available on request.United States (US-incorporated), with data sources in the EU and US.EU SCCs (June 2021). For UK data: the UK Addendum to those SCCs, completed and agreed with the provider on 28 September 2026.
Twilio (Twilio Ireland Limited, contracting; Twilio Inc., processing)From 4 October 2026 for new customers; 26 October 2026 for earlier customers (announced 25 September 2026)New customers are those who first accept these terms on or after 4 October 2026. Earlier customers are those who accepted before then.Carriage of calls Users place from the Service. It receives the number called, the Customer’s caller ID and the call audio in transit. Where the Customer switches recording on, it makes and holds the recording and plays the announcement to the person called when one is used. The recording is kept for the period the Customer’s admin chooses (90 days from the call unless the admin chooses 1 year, 2 years or until it is deleted), and is deleted sooner when a User or admin deletes it. Where the Customer buys a phone number through the Service, Twilio also:
  • provides and holds the number;
  • carries incoming calls and voicemail;
  • where a User chooses, forwards incoming calls to that User's mobile number;
  • holds the emergency address registered for the number.
For the identity and address records that numbering rules require, and for call records it must keep by law, Twilio acts as an independent controller under its own privacy notice. The browser half of a call uses Twilio’s calling library, which is bundled in the extension.
United States (Twilio's US1 region). Call audio enters Twilio's network at the nearest of its global edge locations.Twilio's Data Protection Addendum: the EU–US Data Privacy Framework and its UK Extension; otherwise Twilio's Binding Corporate Rules, or the EU SCCs with the UK Addendum (which Twilio's DPA calls the “UK International Data Transfer Agreement”).
Vercel, Inc.Hosting of pitchwhip.com and the customer portal; portal requests (which may include Customer Personal Data) pass through Vercel's servers in transit to Cloudflare.United States, global edge.UK: IDTA / UK Addendum; EU: SCCs; EU–US DPF certified.
Lemon Squeezy, LLCMerchant of record for subscriptions and credit packs; licence-key issuance and validation. Processes purchaser and licence data (no Prospect Data). Independent controller for payments.United States.UK: IDTA / UK Addendum; EU: SCCs.
Google LLCThree Customer-side cases. (1) Speech recognition: where a User turns on live transcription, Chrome's built-in speech recognition streams the microphone audio (which includes the Prospect's speech) to Google's speech service to convert it to text. That transfer is made by the browser between the User and Google; PitchWhip neither receives nor stores the audio. (2) Where a User connects Google Sheets / Calendar, the extension writes to the User's own Google account. (3) Where a User connects a Gmail or Google Workspace mailbox for sending, PitchWhip hands each sequence email to Google to send from that User's own account. Google therefore receives the Prospect's address and the message content. The grant PitchWhip holds permits sending only and confers no ability to read the mailbox. In all three cases Google is engaged by the Customer through their own Google agreement; listed for completeness and transparency.Per the Customer's Google agreement.Per the Customer's Google agreement.
Web3FormsDelivery of website enquiry forms to PitchWhip's inbox. Not used for Customer Personal Data; listed for completeness.Cloud-hosted.Not applicable to Customer Personal Data.
ResendTransactional delivery of customer-portal sign-in codes (the recipient's email address and a single-use six-digit code). Where the Customer runs campaigns: delivery of campaign emails from the Customer's verified subdomain (the recipient's address, the message and the Customer's replies-to address). The provider's own open and click tracking is switched off by PitchWhip. Also delivery of bounce, complaint, delay and delivered notices back to PitchWhip per address. No call records, reveals or transcripts.US-incorporated; sending region configured as EU (Ireland) for sign-in codes and campaign domains.UK IDTA / EU SCCs.
Google LLCVerification of the sign-in token Google issues when a Customer chooses to log in to the customer portal with Google. PitchWhip transmits the token and receives the verified email address. Separate from the Customer's own Google Sheets / Calendar connection, where Google acts for the Customer directly.United States.UK IDTA / EU SCCs; Data Privacy Framework certified.
HubSpot, Inc.Where the Customer connects it. An Admin pastes a private-app token for the Customer's own HubSpot account in the portal, and each call a User logs is then written there as a contact and a logged call, plus a follow-up task where a callback date is set. What crosses is the Prospect's name, company and job title, their LinkedIn URL, which User called and when, the outcome, the duration, any callback date, the intel one-liners (signals and why now), and a phone number or email address the account has already revealed for that person. Private extension notes and transcripts are excluded. A separate dashboard-authored note is sent only when the User explicitly selects HubSpot for that note; turning that choice off stops future sync and does not erase earlier exports. Clearing the note while that destination remains selected requests clearing of our own known copy; changed or uncertain records need review. The token is held encrypted and used only for this sync.United States.Per the Customer's HubSpot agreement.
Salesforce, Inc.Only where you connect your own Salesforce org. PitchWhip uses your configured local External Client App, or PitchWhip's own Salesforce Connected App (installed from PitchWhip's managed package), and encrypted OAuth credentials to match existing Contacts or Leads and sync call activities and callback tasks. New Lead creation is optional and off by default. Data includes the prospect identity and revealed contact details needed for matching, logged outcome, duration, call date and callback or meeting dates. Private extension notes and transcripts are excluded. A separate dashboard-authored note is exported only when you explicitly select Salesforce for that note. Turning that choice off stops future sync and does not erase earlier exports. Clearing the note while Salesforce remains selected requests clearing of our own known copy, subject to review if it changed or a write could not be confirmed. Deleting a PitchWhip call does not erase an existing Salesforce record.Your Salesforce org, under your own agreement and hosting configuration with Salesforce.Per the Customer's Salesforce agreement.

Requests for a signed copy of this DPA, executed transfer terms, or a completed security questionnaire: hello@pitchwhip.com.