Data Processing Agreement

This DPA governs Mahleon's processing of personal data on behalf of the customer. The customer is the controller; Mahleon is the processor. It forms part of the Mahleon terms of service. Customers may countersign a copy — contact your Mahleon representative.

1. Roles

The customer determines the purposes and means of processing (controller). Mahleon processes personal data only on the customer's documented instructions (processor), including the instruction to prospect via LinkedIn Sales Navigator and to deduplicate against the customer's CRM.

2. Subject matter & duration

Processing of prospect identification data (name, title, company, location, photo, LinkedIn URL) and messaging metadata for the duration of the customer's subscription, then deletion per the retention policy (default 12 months for prospect data; audit logs retained as a compliance obligation).

3. Mahleon's obligations

Process only on instructions; ensure confidentiality; apply appropriate technical and organisational measures (encryption at rest, RLS tenant isolation, hash-chained audit log, per-org engine isolation); assist with data-subject requests and breach notification; delete or return data on termination.

4. Sub-processors

The customer authorises the sub-processors listed at /legal/sub-processors. Mahleon notifies customers of material changes in advance and remains liable for its sub-processors.

5. International transfers

EU customer data is processed on EU infrastructure. Where a sub-processor is outside the UK/EU (e.g. transactional email), only the minimum data is transferred under appropriate safeguards, and never prospect PII in message bodies.

6. Data-subject rights & erasure

Mahleon provides tooling for the controller to honour access, objection, and erasure requests, including one-click prospect erasure across scans, sequences, and replies, with an audit record.

7. Security & breach

Mahleon maintains the measures above, halts automation on detection of a security challenge (it never attempts to bypass one), and will notify the customer without undue delay on becoming aware of a personal-data breach.

Template version v1 · 29 June 2026. Not legal advice.