Data Processing Addendum
This addendum applies where GrowOutly processes personal data on your behalf and data protection law — such as the UK GDPR, EU GDPR, or CCPA/CPRA — requires a written processing agreement.
Last updated August 28, 2026 · GrowOutly, Inc.
1. Scope and order of precedence
This Data Processing Addendum (“DPA”) supplements the Terms of Service between GrowOutly, Inc. and the customer (“you”). Where this DPA conflicts with the Terms in relation to the processing of personal data, this DPA prevails. A countersigned copy is available for Enterprise customers on request from privacy@growoutly.com.
2. Roles of the parties
You are the controller (or, where you act for your own customers, the processor) of the personal data you upload to or generate in the platform. GrowOutly is the processor (or sub-processor) of that data. We process it only on your documented instructions, which are given through your configuration and use of the platform, plus any written instructions you send us.
If we believe an instruction breaches data protection law we will tell you and may pause that processing.
3. Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the GrowOutly sales communications platform. |
| Duration | For the term of your subscription, plus the deletion period in section 9. |
| Nature and purpose | Hosting, storage, transmission, routing, recording, transcription, scheduling, and display of communications and contact records. |
| Categories of data subjects | Your staff and authorised users; your prospects, leads, and customers; individuals who call or message your numbers. |
| Types of personal data | Names, business and personal contact details, job titles, company details, call and message content, recordings and transcripts where enabled, calendar events, notes, and communication metadata. |
| Special category data | Not requested or required. You must not upload special category data or use the platform for it without a separate written agreement. |
4. Our obligations
- Process personal data only on your documented instructions;
- Ensure personnel authorised to process personal data are bound by confidentiality obligations;
- Implement the technical and organisational measures described in section 6;
- Assist you, taking into account the nature of the processing, with data subject requests, data protection impact assessments, and prior consultations;
- Notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting your data, with the information reasonably available to us;
- Make available the information necessary to demonstrate compliance with this DPA.
5. Your obligations
- Establish and maintain a lawful basis for the processing you instruct, including any consent required for calling, texting, emailing, and recording;
- Provide the privacy notices required to the individuals whose data you upload;
- Configure the platform appropriately, including retention settings, recording settings, quiet hours, and access controls;
- Respond to data subject requests you receive, using the tools we provide.
6. Security measures
We maintain measures appropriate to the risk, including:
- Encryption of personal data in transit (TLS) and at rest;
- Role-based access control, least-privilege internal access, and unique credentials;
- Multi-factor authentication for administrative access;
- Network segmentation, firewalling, and monitoring of our production environment;
- Audit logging of privileged and security-relevant events;
- Encrypted backups with periodically tested restoration;
- Documented incident response and business continuity procedures;
- Security review of new subprocessors before onboarding.
7. Subprocessors
You give general authorisation for us to engage subprocessors to deliver the service. These fall into the following categories:
- Cloud infrastructure, hosting, and storage providers;
- Telecommunications carriers and SMS aggregators that deliver calls and messages;
- Speech-to-text providers for call transcription, where you enable it;
- Email delivery providers;
- Payment processing, customer support, and error-monitoring tooling.
A current list naming each subprocessor is available on request. We will give at least 30 days notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected service for a prorated refund. Every subprocessor is bound by data protection obligations no less protective than this DPA, and we remain liable for their performance.
8. International transfers
Where personal data is transferred from the UK, EEA, or Switzerland to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, or Module Three where you are yourself a processor), together with the UK International Data Transfer Addendum where applicable. Those clauses are incorporated into this DPA by reference, with GrowOutly as data importer and you as data exporter.
9. Return and deletion
You may export Customer Data at any time during the subscription. On termination, data remains available for export for 30 days. After that we delete it from active systems within a further 30 days and from backups within 90 days, unless retention is required by law.
10. Audits
On request, and no more than once in any twelve-month period unless required by a supervisory authority, we will provide our current security documentation and answer a reasonable security questionnaire. Where that is insufficient to demonstrate compliance, we will cooperate with an on-site audit conducted on reasonable notice, during business hours, under confidentiality, and at your cost.
11. CCPA/CPRA
Where you are a “business” and we are a “service provider” under California law: we do not sell or share personal information, we do not retain, use, or disclose it for any purpose other than performing the service, and we do not combine it with personal information received from other sources except as permitted. We certify that we understand and will comply with these restrictions.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
13. Contact
For a signed copy, the subprocessor list, or any data protection question, contact privacy@growoutly.com.