Skip to content
Legal

Data Processing Agreement

Does Cuvy sign a data processing agreement?

Yes. Cuvy acts as your processor for the workspace data you put into it — your account, your lists, anything you upload — and as a controller for its own index of business contact data. Transfers rely on the standard contractual clauses. We notify you of a breach without undue delay and within 72 hours, and delete workspace data within 30 days of termination.

Last updated
23 August 2026
Role for workspace data
Processor
Role for its own index
Controller
Transfer mechanism
Standard contractual clauses
Breach notice
Within 72 hours

Last updated · Forms part of the Terms of Service when you use Cuvy with personal data

On this page

When this applies, and how to have it signed

This agreement applies whenever you use Cuvy to process personal data and the GDPR, the UK GDPR, the Swiss FADP or a comparable law applies to that processing. It sits alongside the Terms of Service and does not replace them.

For a signed copy, email support@cuvy.io with your legal entity name, its registered address and who is signing. We countersign a PDF and send it back, usually within two working days. There is no click-through version in the product yet; when there is, this page will say so.

The two roles, and the line between them

Cuvy is a processor for some things and a controller for others, and a DPA that pretends otherwise will not survive contact with your own regulator. The line is this.

We are your processor for everything inside your workspace: the accounts of your users, the people and companies on your lists, the CSVs you upload, the notes, tags and custom fields you add, your saved searches, your exports, and the records of who in your team did what. You decide what goes in and why. We act on your instructions and hold it for you.

We are a controller of our own index of business contact data — the names, employers, job titles and work addresses Cuvy searches when you ask it to find somebody. We decide what enters that index, how long it stays and how a person gets themselves out of it. It exists independently of you: it is not made of your lists, though an address one of your lookups establishes may be retained in it, and it does not become yours because a lookup touched it. Our basis for holding it, and the route out of it, are in the privacy policy and on the opt-out page.

We are also a controller of our own business records: your billing history, our support correspondence with you, and the operational logs that tell us whether the service is working.

One consequence is worth stating in the open. When we hand you an address, you become a controller of it for your own purposes. If a person asks you to delete it, that request is yours to honour; if they ask us, ours is. Neither of us can answer for the other, and a request that arrives at the wrong door is passed to the right one.

What is processed, and for how long

  • Subject matter. Providing the Cuvy service: finding and checking business contact details, storing the lists you build, and exporting them where you direct.
  • Duration. For as long as your account exists, and then as set out in deletion and return.
  • Categories of data subject. Your own users, and the business contacts you look up, import or save.
  • Types of personal data. Name, employer, job title, work email address, professional profile address, and — where you have asked for them and they are available — a business phone number or a personal email address. Plus whatever you choose to upload in your own columns.
  • Special categories. None. Cuvy is not built for them, and you must not upload them.

Your instructions

We process workspace data only on your documented instructions. Your use of the product is the instruction: running a search, revealing a person, uploading a file, pushing to your CRM. Anything beyond that needs to be agreed in writing, and support email counts as writing.

If an instruction looks to us as though it would break data protection law, we will tell you rather than carrying it out quietly. If we are compelled by law to process or disclose something, we will tell you before we do unless the law forbids it.

The people with access

Everyone at Cuvy who can reach production data is bound to keep it confidential, and that obligation outlives their working here. Access is given to the people who need it to do the job in front of them, and removed when they no longer do. Nobody has a standing reason to read a customer's lists, and nobody does it out of curiosity.

Security, described as behaviour

We hold no security certification, no attestation and no audit report, and we are not going to imply one. What we can do is tell you what happens, which is the thing a certificate would be evidence of:

  • Data in transit is encrypted. The app, the API and the extension talk over TLS and nothing accepts plain HTTP.
  • The databases are not reachable from the public internet. The application reaches them privately, and every account on them has credentials of its own — a service that trusts a connection because of where it appears to come from is a service that trusts anybody who finds the hostname.
  • The extension holds a token of its own rather than your LinkedIn session, and that token can be revoked from your account without touching anything else.
  • Every query for workspace data is keyed to the workspace, so one customer's search cannot return another customer's rows. This is enforced in the code and covered by tests rather than by convention.
  • Card details never reach us. They are handled by the payment processor.
  • Backups are encrypted, stored separately from the running service, and restored into a test environment rather than over live data.
  • Changes to the product are reviewed before they ship, and changes to how credits are charged need a test that proves what they do.

If your review needs more detail than this, ask for the questionnaire route in audits and questionnaires.

Sub-processors

You give general authorisation for us to use sub-processors, on the terms below. Each is engaged under a written contract with obligations no weaker than these, and we remain responsible to you for what they do. The categories are:

  • Payments — subscriptions, invoices, card handling.
  • Application hosting and the managed database — where the service runs and where workspace data is stored.
  • Object storage and content delivery — exports, backups, and serving the site.
  • Email verification — checking whether an address is reachable before it is handed over.
  • Transactional email — sign-in links, receipts and run notifications sent to your users.

The current list, by name and location, is sent on request rather than published, because a published list is one nobody updates the week a vendor changes. We give 30 days notice by email before a new sub-processor starts handling customer data. If you object on reasonable data protection grounds and we cannot resolve it between us, you may terminate the affected part of the service and we refund the unused period.

International transfers

Cuvy is operated from Delaware and Toronto, and personal data may be processed in the United States, in Canada, and by sub-processors elsewhere. Ask and we will name the current countries. Where personal data leaves the EEA, the UK or Switzerland, the transfer rests on the European Commission's standard contractual clauses, with the UK International Data Transfer Addendum where the UK is involved and the equivalent Swiss adaptations where it is Switzerland.

We do not rely on an adequacy decision and we are not certified under any transatlantic framework. The clauses are incorporated into the signed copy of this agreement, with Cuvy as data importer. Where your own assessment needs detail about the destinations and the safeguards, ask and we will set them out in writing.

If there is a breach

If personal data we hold for you is lost, exposed or accessed by someone who should not have it, we tell you without undue delay and in any case within 72 hours of becoming aware of it. Not once we have finished investigating — you have your own clock to run and cannot start it on our schedule.

The first message will say what we know: what happened, when, which workspaces are affected, what data was involved, what we have done and what we are doing next. It will say plainly which parts are still unknown. We keep telling you as the picture fills in, and we do not notify anyone on your behalf, because it is your decision what your customers and your regulator hear.

Helping you answer people

If somebody exercises a right against you — access, correction, deletion, objection, portability — and answering means reaching into your Cuvy workspace, we help. Most of it you can do yourself from the app: find the person, export what is held, edit it, delete it. Where you cannot, ask us and we will do it.

A request that arrives at Cuvy about data in your workspace is not one we answer for you. We will tell the person that the workspace belongs to a customer, pass the request to you, and act on your instruction. Where the request concerns our own index rather than your list, we handle it ourselves — see the opt-out page.

We will also give you what you reasonably need for a data protection impact assessment or a consultation with a supervisory authority.

Deletion and return

You can export your data at any time while the account exists, and that export is the return mechanism — there is no separate request to make.

When the agreement ends, or when you ask, we delete workspace data within 30 days: the people, the lists, the uploads, the exports, the saved searches and the integration tokens. Backup copies age out on the backup cycle, and a restore never puts deleted workspace data back into the running service. We keep only what the law requires us to keep, which in practice means billing records.

Deleting your workspace does not remove a contact detail from our own index, because that record is not held for you. That distinction is the point of the two roles, and the route to suppress an address itself is open to the person it belongs to.

Audits and questionnaires

We do not run an on-site audit programme and we have no third-party report to hand over. What we do:

  • Answer a written security questionnaire, in your format.
  • Get on a call with your reviewer and answer what they ask.
  • Confirm in writing anything we tell them on that call.
  • Tell you when the answer is "we do not do that", rather than choosing the option that scores best.

Where the standard contractual clauses give you an audit right, this is how we expect to satisfy it, and we will discuss anything more that a specific obligation of yours genuinely requires.

Precedence and changes

Where this agreement and the Terms of Service conflict about personal data, this agreement wins. Where it conflicts with the standard contractual clauses, the clauses win. Everything else in the Terms continues to apply, including the limits on liability.

We will update this page when what we do changes, and the date at the top is when the text last moved. Customers who have a signed copy are emailed before a change takes effect. Questions, and requests for the signed version, go to support@cuvy.io.

Questions

What a security review asks

How do I get a signed copy of the Cuvy DPA?

Email support with your legal entity name, its registered address and the name of the person signing. We countersign a PDF and send it back, usually within two working days. There is no click-through DPA inside the product yet, so a signed copy is the only version there is.

Will you sign our DPA instead of yours?

Usually, if it matches what we actually do. We read it rather than initialling it, and we will come back on anything that describes behaviour we do not have — an audit programme, a certification, a regional hosting choice. A clause we cannot honour is worse for you than a redline.

Are you our processor for the addresses Cuvy finds, or the controller?

The controller. Our index of business contact data is ours: we decide what goes in it, how long it stays, and how somebody gets out of it. Once an address is delivered into your workspace and you decide who to contact, you are the controller of that. We are your processor for everything in the workspace itself.

Will you tell us before you add a sub-processor?

Yes. We give 30 days written notice by email to the address on the account before a new sub-processor starts handling customer data. If you object on reasonable data protection grounds within that window and we cannot resolve it, you may cancel the affected part of the service and we refund the unused period.

Can you send a security certificate with the signed DPA?

No. Cuvy holds no third-party security certification, there is no certificate against an information-security standard to attach, and no audit is under way that it would be honest to call in progress. What comes with the signed copy is a description of what we do, answers to a written questionnaire, and the commitments on this page — which is what a certificate would attest to rather than replace.

Can we audit Cuvy?

Not on site, and there is no penetration test report to hand over. We answer security questionnaires in writing, we will get on a call with your reviewer, and we will confirm in writing anything we tell you there. Where the standard contractual clauses give you an audit right, that is how we expect to satisfy it.