Logo En ContactoEn Contacto
All legal documents

Data Processing Agreement

Effective 27 August 2026

Version 1.0

Parties

Processor: Smart Digital Solutions LLC, a limited liability company registered in New Mexico, USA, operator of En Contacto.
Correspondence address: 211 E 43rd St, 7th Flr #213, New York, NY 10017, USA.
Data protection contact: support@encontacto.io

Controller / Customer: the individual or entity identified in the account registered with us.

This DPA forms part of, and is incorporated into, our Terms of Service. This published page is for reference and does not by itself constitute acceptance. It is accepted by agreeing to our Terms of Service when you create an account, or by a signed copy where you need one — email support@encontacto.io to request one.

1. Definitions

“Data Protection Laws” means all laws applicable to a party's processing of Personal Data, including the EU GDPR, UK GDPR, Swiss FADP, and the CCPA/CPRA and similar US state laws, together with any implementing or successor laws.

“Customer Data” means Personal Data that we process on your behalf through the Services. This means Leads and Card Visitor data: contact details submitted through your Digital Cards, contact details you capture using our tools, and contact details extracted from business cards you scan.

“Card Visitor” means a person who views or interacts with a Digital Card you have published.

“SCCs” means the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914).

“UK Addendum” means the ICO International Data Transfer Addendum, version B.1.0, 21 March 2022.

Other capitalised terms have the meaning given in our Terms of Service or, where relevant, in the GDPR.

2. Scope and roles

2.1 What this DPA covers

We act as Processor and you act as Controller in respect of Customer Data. We process Customer Data only on your behalf and only as necessary to provide the Services.

2.2 What this DPA does not cover

We act as Controller, not Processor, in respect of your own account information, your billing records, and data about how you use the Services. Our Privacy Policy governs that information. This DPA does not apply to it.

This distinction is deliberate and we state it plainly so there is no ambiguity about which of us answers a given request.

2.3 Where you are yourself a Processor

Where you use the Services on behalf of your own customers — for example, an agency managing Digital Cards for client organisations — you act as a Processor and we act as your Sub-processor. This DPA applies with the necessary changes, and Module 3 of the SCCs applies to transfers, as set out in Annex IV.

2.4 Your responsibilities

You are responsible for determining the lawfulness of your processing, for giving any notice and obtaining any consent required by Data Protection Laws, and for responding to Data Subjects about the information you hold.

This matters particularly for scanned business cards. The person on a card you scan has no relationship with us. You are responsible for having a lawful basis to capture, extract and keep their details, and for being able to answer them if they ask what you hold.

3. Our obligations

Processing on instructions. We process Customer Data only on your documented instructions, which comprise this DPA, our Terms of Service, and your use and configuration of the Services. We will tell you if, in our opinion, an instruction infringes Data Protection Laws.

Confidentiality. Persons authorised to process Customer Data are bound by confidentiality obligations.

Security. We implement and maintain the technical and organisational measures described in Annex II.

Assistance. Taking into account the nature of the processing and the information available to us, we will assist you with security obligations, with data protection impact assessments and prior consultations, and with Data Subject requests, so far as reasonably possible.

Breach notification. We will notify you without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. We will provide the information required by law as it becomes available, and cooperate with your notifications to authorities and Data Subjects.

Records. We maintain records of our processing activities and will make them available to you on request.

Deletion and return. On termination or expiry, you may export your Customer Data through the Services. We will then delete it, unless retention is required by law.

Deletion timescales. On termination, Customer Data — including database records, files and backups — is deleted within 30 days, unless the law requires us to keep it. This reflects the commitment our database provider makes to us.

4. Sub-processors

Authorisation. You give us general authorisation to engage Sub-processors for the purpose of providing the Services. We remain responsible for their performance.

Contracts. We impose data protection obligations on Sub-processors that are no less protective than those in this DPA.

Current list. Our Sub-processors are listed in Annex III below, published on this page.

Notice and objection. We will give at least 30 days' notice before adding or replacing a Sub-processor, except for emergency replacements, which we will notify as soon as we can. You may object on reasonable data protection grounds within that period. We will discuss it in good faith; if we cannot resolve it, you may terminate the affected Services and receive a pro-rated refund of prepaid unused fees.

5. International transfers

We are established in the United States, and our Sub-processors are located as set out in Annex III.

Where Customer Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the SCCs apply as set out in Annex IV, incorporated by reference. Both Module 2 and Module 3 are selected, so this DPA works whether you are a Controller or are yourself acting as a Processor for your own clients.

Where the SCCs or an applicable addendum conflict with this DPA, the SCCs and addenda prevail.

6. Data Subject requests

Where a Card Visitor or other Data Subject contacts us directly about Customer Data, we will promptly tell you and will not respond ourselves except on your documented instructions, unless the law requires otherwise.

We provide tools within the Services allowing you to access, correct, export and delete Leads, and will give reasonable further assistance where the tools are not sufficient.

7. Audits and documentation

We will provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of our security measures and answers to a reasonable security questionnaire.

You may request an audit no more than once a year, and additionally after a confirmed Personal Data Breach affecting your Customer Data. Audits take the form of a remote document review or questionnaire. On-site audits are permitted only where required by a supervisory authority or by law, on 30 days' notice and during business hours. You bear your own audit costs; our reasonable support costs are reimbursable.

8. US state privacy laws

To the extent the CCPA/CPRA or a similar US state law applies, we act as a “service provider” or “processor”. We do not sell or share Customer Data, and we do not retain, use or disclose it for any purpose other than providing the Services or as permitted by law. We will tell you if we determine we can no longer meet these obligations.

9. Liability

The liability limitations in our Terms of Service apply to this DPA, cumulatively and in the aggregate.

Nothing in this DPA limits or excludes either party's liability where the law does not permit it, including liability to Data Subjects under Article 82 GDPR, or any liability arising under the SCCs where a limitation would conflict with their protections.

10. Order of precedence

Where there is a conflict, the following order applies: the SCCs and applicable addenda, then this DPA, then our Terms of Service.

We may update this DPA where required by law or to reflect new safeguards. We will give advance notice of any material adverse change, and no change will reduce the level of protection.

11. Term

This DPA takes effect on the date you accept our Terms of Service and remains in force for as long as we process Customer Data on your behalf. Provisions on deletion, liability and audit survive termination as necessary.


Annex I — Details of processing

(Article 28(3) GDPR and Annex I to the SCCs)

Data exporter (Controller, or Processor under section 2.3): the customer identified in the account.

Data importer (Processor, or Sub-processor under section 2.3): Smart Digital Solutions LLC, 211 E 43rd St, 7th Flr #213, New York, NY 10017, USA. support@encontacto.io

Subject matter: provision of the En Contacto digital business card and lead capture Services.

Nature of processing: collection, storage, organisation, retrieval, transmission, extraction of text from images, and deletion, as necessary to provide the Services.

Purpose: to provide, secure and support the Services in accordance with the Controller's instructions.

Duration: the term of the agreement, plus the deletion periods in section 3.

Categories of Data Subjects:

  • Card Visitors who submit their details through a published Digital Card
  • Individuals whose paper business cards are scanned by the Controller
  • Individuals whose contact details the Controller otherwise captures using the Services
  • Members of the Controller's Team Workspace

Categories of Personal Data: name, employer, job title, email address, telephone number, postal address, social media handles, and any notes or other information the Controller records against a contact.

Special categories: none intended. The Services are not designed for special category data. If the Controller records it, the Controller is responsible for the lawful basis and safeguards.

Frequency of transfer: continuous, for the term of the agreement.

Competent supervisory authority: where the exporter is established in the EEA, the authority of the exporter's main establishment; otherwise the Irish Data Protection Commission, unless the exporter designates another by notice.


Annex II — Technical and organisational measures

Encryption. Customer Data is encrypted in transit using TLS 1.2 or higher, with HTTPS enforced. Backups are encrypted at rest. Account passwords are stored as salted cryptographic hashes, never in readable form.

Access control. Access to production systems is limited to the operator of the Service. Credentials and API keys are held in our hosting provider's encrypted environment configuration and are not committed to source control.

Authentication. Customer accounts support strong passwords and two-factor authentication. Sign-up and sign-in are protected against automated abuse.

Tenant separation. Customer Data is segregated by account, so one customer cannot access another's data.

Data minimisation. Scanned business card images are processed in memory and are not stored. Only the extracted contact fields are retained.

Backups. Our database provider takes automated snapshots and keeps encrypted backups of stored files.

Application security. Code is version controlled, and development and production environments are separated.

Logging. Application and access logs are retained for troubleshooting and security investigation.

Incident response. We maintain a documented process for identifying, assessing and notifying Personal Data Breaches, including the notification commitments in section 3.

Sub-processor management. Sub-processors are assessed before engagement and are bound by data protection obligations no less protective than this DPA.


Annex III — Sub-processors

Sub-processorPurposeLocation
NoCodeBackendDatabase — accounts, cards, LeadsData hosted in the USA (Austin, TX) and the EU; provider established in India
VercelApplication hosting; IP addresses and server logsUSA
CloudinaryProfile photos and company logosUSA
OpenAIBusiness card text extractionUSA
Zoho ZeptoMailTransactional emailUSA
CloudflareBot protectionUSA
Microsoft ClarityProduct analytics, consent-gatedUSA
TiledeskLive chat supportEuropean Union (Italy)
GetTermsCookie consent managementAustralia and Singapore
GoogleGoogle Wallet pass generationUSA

Paddle, Substack and Google Sign-In are not Sub-processors. They act as independent controllers for the data they receive, as described in our Privacy Policy.

KickoffLabs, tinyEmail and Canny process our own marketing and feedback contacts, not Customer Data, and are therefore not Sub-processors under this DPA. They are listed in our Privacy Policy.

We will give at least 30 days' notice of changes to this list, except for emergency replacements.


Annex IV — SCC selections and local addenda

EU Standard Contractual Clauses

Modules: Module 2 (Controller to Processor) applies where the Customer is a Controller. Module 3 (Processor to Sub-processor) applies where the Customer is itself a Processor, as described in section 2.3.

Docking clause (Clause 7): enabled.

Clause 9(a) — Sub-processors: Option 2, general written authorisation, with the notice period in section 4.

Clause 11(a) — Independent dispute resolution: not selected.

Clause 17 — Governing law: the law of Ireland.

Clause 18 — Forum: the courts of Ireland.

Annexes: Annexes I, II and III to the SCCs are completed by Annexes I, II and III of this DPA.

UK Addendum

The ICO International Data Transfer Addendum (version B.1.0) applies to transfers subject to UK GDPR. Table 1 is completed by the parties in Annex I; Table 2 by the module selections above; Table 3 by Annexes I to III. Neither party may end the Addendum when it changes under Section 19, other than as the Addendum permits.

Switzerland

For transfers subject to the Swiss FADP, references to the GDPR are read as references to the FADP, “Member State” as “Switzerland”, and the competent authority as the Swiss FDPIC.

Contact

Smart Digital Solutions LLC
Operator of En Contacto
211 E 43rd St, 7th Flr #213, New York, NY 10017, USA
support@encontacto.io
Accord de Traitement des Données | En Contacto