Data Processing Addendum
The data-protection terms that apply when Dotless processes personal data for a customer.
Last updated August 7, 2026
1. Parties and application
This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer identified in a Dotless Order or account (“Customer”) and Saem Group s. r. o. (“Dotless”) governing the Service. It applies when Dotless processes Customer Personal Data on Customer’s behalf. It is effective when Customer accepts the agreement and supersedes prior data-processing terms for the same processing.
“Customer Personal Data” means personal data contained in Customer Content that Dotless processes as a processor or subprocessor to provide the Service. “Data Protection Law” means laws applicable to that processing, including the GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, and applicable US state privacy laws. “Controller”, “processor”, “data subject”, “personal data”, “process”, and “personal data breach” have the meanings in applicable Data Protection Law.
Customer is a controller and Dotless its processor, or Customer is a processor and Dotless its subprocessor, as applicable. Each party will comply with obligations applicable to its role. Dotless is an independent controller, not a processor under this DPA, for account administration, billing, security, abuse prevention, service telemetry, legal compliance, and its independently controlled business-contact data as described in the Privacy Policy.
2. Processing instructions
Dotless will process Customer Personal Data only on Customer’s documented instructions, including the agreement, configured features, authorized user actions, support requests, and written instructions consistent with the agreement. Dotless may process it where required by applicable law; unless prohibited, Dotless will inform Customer of that requirement before processing. Dotless will immediately inform Customer if, in its opinion, an instruction violates applicable Data Protection Law and may suspend the affected processing while the parties resolve it.
Dotless will not sell Customer Personal Data, share it for cross-context behavioural advertising, use it outside the parties’ direct business relationship, or combine it with personal data received from another person except as permitted by Data Protection Law and needed to provide or secure the Service. Dotless will not use Customer Content to train a general-purpose generative model unless Customer gives a separate affirmative instruction. Customer instructs Dotless to use subprocessors as set out below and to make restricted transfers using Section 10.
3. Customer responsibilities
Customer will:
•
ensure its instructions and processing comply with Data Protection Law and the agreement;
•
provide required notices and have a valid lawful basis for collection, enrichment, upload, communication, publication, and other processing;
•
honour rights, objections, suppression lists, consent withdrawals, and communications rules applicable to its recipients and website visitors;
•
use the Service only for appropriate data and avoid special-category, highly sensitive, children’s, or regulated data unless separately agreed in writing;
•
configure access, workspaces, retention, integrations, and security appropriately and protect credentials and endpoints; and
•
if it is a processor, have authority from the relevant controller to appoint Dotless and provide all instructions.
Customer’s use of business-contact data supplied from Dotless’s independent index is governed by the Terms and Privacy Policy rather than this DPA until Customer selects or saves it into Customer Content, after which Dotless processes Customer’s copy under this DPA while retaining its independent obligations for the source index.
4. Confidentiality and personnel
Dotless will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty and access it only as needed for assigned responsibilities. Dotless will provide privacy and security guidance appropriate to those responsibilities and will revoke access when it is no longer needed.
5. Security measures
Taking account of the state of the art, implementation costs, processing nature and context, and risks to individuals, Dotless will maintain technical and organisational measures designed to provide security appropriate to risk. The current baseline is described in Annex II below. Dotless may update measures as technology and risks change, provided the overall protection is not materially reduced during a paid subscription term.
Customer acknowledges that use of Customer-selected SMTP, OAuth, domain, deployment, or other connected providers involves transmitting data to providers Customer controls or directs. Customer is responsible for permissions and account security at those providers. This does not reduce Dotless’s responsibility for a provider acting as Dotless’s subprocessor.
6. Subprocessors
Customer gives general written authorization for Dotless to appoint the subprocessors identified in its current written Subprocessor Register. Dotless will provide the register to current or prospective Customers on request, and a Customer may request and review it before entering this DPA. The register provided to Customer is the agreed list for that authorization and identifies each subprocessor’s legal provider name, broad processing purpose, general categories of personal data, and relevant processing-location or transfer information.
The register includes only providers that process Customer Personal Data on Dotless’s behalf; it does not authorize independent controllers, Customer-selected recipients or integrations, or software that does not receive Customer Personal Data. Dotless will impose data-protection obligations that provide materially equivalent protection for the relevant processing, assess each appointment proportionately, and remain responsible for a subprocessor’s performance to the extent required by Data Protection Law.
Dotless will provide at least 15 days’ advance notice of a new subprocessor that will process Customer Personal Data, ordinarily by updating the register and notifying subscribed account contacts. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Dotless may refrain from using that subprocessor for Customer or either party may terminate only the affected feature; Dotless will refund prepaid fees for the unused terminated portion. An emergency replacement needed to protect availability, security, or law may occur on shorter notice, with notice as soon as reasonably practicable.
On reasonable request, Dotless will provide configuration-specific legal entities, processing locations, applicable transfer mechanisms, and onward-subprocessor information where appropriate and available to Dotless.
7. Data-subject requests
Taking account of the processing, Dotless will provide Customer with reasonable technical and organisational assistance to respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Dotless receives a request that clearly relates to Customer’s processing, Dotless will direct the person to Customer or notify Customer and will not independently respond except on Customer’s instruction or where legally required. Customer is responsible for assessing and responding to the request. Dotless may require reimbursement of reasonable costs for unusually burdensome assistance not caused by Dotless’s breach.
8. Personal data breaches
Dotless will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. Notice will include, as information becomes available, the nature of the breach, affected data and people, likely consequences, measures taken or proposed, and a contact for follow-up. Dotless may provide information in phases and notification is not an admission of fault.
Dotless will take reasonable steps to contain, investigate, mitigate, and remediate the breach and preserve relevant evidence. Customer is responsible for controller notifications to authorities and individuals; Dotless will provide reasonable assistance. Customer must promptly give Dotless the account and contact information needed for incident notices and notify Dotless of compromise involving Customer credentials or connected systems.
9. Assessments, consultations, and audits
Dotless will provide information reasonably needed to demonstrate compliance with Article 28 GDPR and assist with Customer’s data-protection impact assessment or prior consultation to the extent the requested assistance relates to the Service and information available to Dotless. Customer remains responsible for its assessment, lawful basis, notices, and consultation.
On reasonable written request, Dotless will provide available security and privacy documentation and responses to a proportionate questionnaire. If that is insufficient, Customer may conduct one audit in any 12-month period through an independent qualified auditor bound by confidentiality, on at least 30 days’ notice, during business hours, without accessing another customer’s data or creating security or operational risk. Customer bears costs unless the audit identifies a material breach by Dotless, in which case Dotless will bear reasonable audit costs. Frequency and notice limits do not apply after a relevant breach or where an authority requires an earlier audit. Dotless may satisfy an audit request with a recent independent report where it covers the requested controls; this clause does not claim any current certification.
10. International transfers
A “Restricted Transfer” is a transfer of Customer Personal Data requiring safeguards under the GDPR, UK GDPR, or Swiss data-protection law. Dotless will not make a Restricted Transfer without a valid mechanism, such as an applicable adequacy decision, valid recognized framework, or standard contractual clauses with supplementary measures where required.
For a Restricted Transfer from Customer to Dotless not covered by another valid mechanism, the European Commission Standard Contractual Clauses in Decision 2021/914 (“EU SCCs”) are incorporated by reference and completed as follows: Module Two applies where Customer is controller and Dotless is processor; Module Three applies where Customer is processor and Dotless is subprocessor; Clause 7 applies; Option 2 in Clause 9 applies with the 15-day notice period in Section 6; the optional language in Clause 11 does not apply; Slovak law applies under Clause 17; Slovak courts apply under Clause 18; Annex I is completed by the parties and Annex I below; and Annex II is the security annex below. The Subprocessor Register provided under Section 6 is the agreed list for the general written authorization in Clause 9(a), Option 2. Because Option 2 applies, SCC Annex III for specific prior authorization is not used unless the parties separately agree to specific authorization; if required, the parties will complete it using the current register and applicable configuration-specific information. If this DPA conflicts with the EU SCCs, the EU SCCs control.
For a UK Restricted Transfer, the then-current UK International Data Transfer Addendum to the EU SCCs is incorporated and completed using the information in this DPA. For a Swiss Restricted Transfer, references in the EU SCCs will be read to include the Swiss Federal Act on Data Protection and competent Swiss authority, data-subject rights extend to Swiss individuals, and governing-law and forum provisions will be adjusted as required to make the clauses effective. The parties will reasonably complete or replace a mechanism if a regulator or law requires it.
11. Return and deletion
During the term, Customer may retrieve Customer Personal Data through available export features. After termination or a verified deletion request, Dotless will delete Customer Personal Data from active systems after the 30-day recovery period described in the Terms, unless Customer requests available return before deletion or law requires retention. Time-limited backups will be isolated from ordinary use and overwritten on their cycle, targeted at no more than 90 additional days. Dotless may retain minimal security, suppression, billing, and legal-claim records as an independent controller. On request, Dotless will confirm completion of deletion.
12. Liability and order of precedence
The liability provisions in the Terms apply to this DPA, including the enhanced cap for data-protection and security obligations, unless the EU SCCs or mandatory law prohibits a limitation. This DPA controls over the Terms only for its subject matter, and the EU SCCs control over both for a Restricted Transfer.
Annex I: Processing description
•
Parties: Customer, at the account or Order contact, is exporter/controller or exporter/processor as applicable. Saem Group s. r. o., at the address in the Terms, is importer/processor or importer/subprocessor, privacy contact support@dotless.co.
•
Subject matter: processing Customer Personal Data to provide the subscribed prospecting, enrichment, outreach, connected-email, workspace, AI-assisted, website-building, hosting, support, and related Service features.
•
Duration: the agreement term, 30-day recovery period, and limited backup and legally required retention described in Section 11.
•
Nature and purpose: hosting, storage, organization, retrieval, search, enrichment at Customer’s request, generation, adaptation, transmission, publication, export, support, security, deletion, and other operations initiated through configured features.
•
Data subjects: Customer users, personnel, contractors, clients, prospects and business contacts, message recipients, Customer website visitors and form submitters, and other individuals whose data Customer lawfully submits.
•
Data categories: identity and business-contact data; account and workspace data; prospect source and profile data; Customer files and lists; templates, messages, campaign events and suppression data; website content and form submissions; connected-service identifiers; support and technical data.
•
Sensitive data: not intended or permitted without prior written agreement. The Service may incidentally process message or free-text content containing data Customer submits; Customer must apply appropriate minimisation and safeguards.
•
Frequency: continuous or episodic according to Customer’s use and configured integrations.
•
Subprocessor subject matter: the broad purposes, data categories, and transfer summaries in the Subprocessor Register; configuration-specific information is available as described in Section 6.
•
Competent authority: determined under the EU SCCs and Data Protection Law; for Dotless’s EEA establishment, ordinarily the Office for Personal Data Protection of the Slovak Republic.
Annex II: Technical and organisational measures
•
Access governance: role- and need-based access, unique personnel access, access removal, workspace roles, and privileged-access restriction.
•
Authentication and secrets: provider-supported secure authentication, protected application secrets and connected-service credentials, and controls intended to prevent secrets from being displayed unnecessarily.
•
Encryption: encrypted network transport using current provider-supported protocols and provider-supported encryption at rest for production data and backups where applicable.
•
Tenant and application controls: logical tenant separation, database authorization policies such as row-level restrictions where applicable, input and permission checks, and production-change controls.
•
Availability and recovery: managed infrastructure, backups appropriate to the hosted service, monitoring, recovery procedures, and dependency-provider resilience appropriate to risk.
•
Logging and detection: proportionate security, access, error, rate-limit, and abuse logging; alerting and investigation procedures; and retention limits.
•
Vulnerability management: dependency review and updates, security testing proportionate to changes, remediation based on risk, and a channel for vulnerability reports.
•
Incident response: documented escalation, containment, investigation, remediation, evidence preservation, and notification responsibilities.
•
Data lifecycle: collection minimisation, customer deletion controls, limited recovery and backup periods, suppression handling, and secure deletion or anonymisation.
•
Personnel and vendors: confidentiality duties, access guidance, proportionate vendor assessment, processor terms, transfer review, and ongoing subprocessor oversight.
•
Review: periodic review of measures and adjustment to material changes in processing, threats, or applicable law.
13. Contact and execution
Data-processing enquiries may be sent to support@dotless.co. This DPA is executed when Customer accepts the agreement that incorporates it; no additional signature is required unless applicable law or an Order requires one. On reasonable request, the parties will execute a counterpart identifying the legal Customer and signatories.
