Data Processing Agreement
This DPA governs Mahleon's processing of personal data on behalf of the customer. The customer is the controller; Mahleon is the processor. It forms part of the Mahleon terms of service. Customers may countersign a copy — contact your Mahleon representative.
1. Roles
The customer determines the purposes and means of processing (controller). Mahleon processes personal data only on the customer's documented instructions (processor), including the instruction to prospect via LinkedIn Sales Navigator and to deduplicate against the customer's CRM.
2. Subject matter & duration
Processing of prospect identification data (name, title, company, location, photo, LinkedIn URL) and messaging metadata for the duration of the customer's subscription, then deletion per the retention policy (default 12 months for prospect data; audit logs retained as a compliance obligation).
3. Mahleon's obligations
Process only on instructions; ensure confidentiality; apply appropriate technical and organisational measures (encryption at rest, RLS tenant isolation, hash-chained audit log, per-org engine isolation); assist with data-subject requests and breach notification; delete or return data on termination.
4. Sub-processors
The customer authorises the sub-processors listed at /legal/sub-processors. Mahleon notifies customers of material changes in advance and remains liable for its sub-processors.
5. International transfers
EU customer data is processed on EU infrastructure. Where a sub-processor is outside the UK/EU (e.g. transactional email), only the minimum data is transferred under appropriate safeguards, and never prospect PII in message bodies.
6. Data-subject rights & erasure
Mahleon provides tooling for the controller to honour access, objection, and erasure requests, including one-click prospect erasure across scans, sequences, and replies, with an audit record.
7. Security & breach
Mahleon maintains the measures above, halts automation on detection of a security challenge (it never attempts to bypass one), and will notify the customer without undue delay on becoming aware of a personal-data breach.
Template version v1 · 29 June 2026. Not legal advice.