Introducing GTMRouter — one API for the entire GTM loop Join the beta ›
LEGAL
GTMRouterLast updated

Data Processing Addendum

The Article 28 terms on which GTMRouter processes personal data on your behalf. Incorporated into the Terms of Service for every customer; no signature required.

01Scope and roles

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between you (the “Customer”) and GTMRouter (the “Provider”) and applies whenever we process personal data on your behalf in providing the Service. It applies automatically; you do not need to sign it. If you require a countersigned copy for your records, email founders@gtmrouter.dev.

For Customer Content and Recipient Data, as defined in our Privacy Policy, you are the controller and we are the processor. For your account, keys, ledger and billing records we are an independent controller, and this DPA does not apply.

“Data Protection Law” means the UK GDPR and Data Protection Act 2018, the EU GDPR, and any other privacy law applicable to the processing. Terms defined in Data Protection Law have the same meaning here.

02Processing on your instructions

We process personal data only on your documented instructions, which are: the Terms, this DPA, and the API calls made with your keys, including calls made by agents you have connected. We will inform you if, in our opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is resolved.

We may process personal data otherwise than on your instructions only where required by law, in which case we will tell you before processing unless the law prohibits it.

Suppression records are maintained under our own legal obligation to honour opt-outs and are retained after this DPA ends; you agree that this is a lawful instruction.

03Confidentiality

We ensure that every person we authorise to process personal data is bound by an appropriate duty of confidentiality, and that production access is limited to personnel with a demonstrated need.

04Security

We implement the technical and organisational measures described in Annex 2, and we keep them under review. We may update them, provided the level of protection does not decrease.

05Sub-processors

You give general written authorisation for us to engage the categories of sub-processor listed in Annex 3, and the named providers within them. The current named list is available on request from founders@gtmrouter.dev.

We will give you at least 14 days’ notice by email before adding or replacing a sub-processor that processes Customer Content. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith; where no resolution is possible, you may close your account and receive a refund of unspent purchased credits.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance.

06International transfers

We may transfer personal data outside the UK and the EEA only under a lawful transfer mechanism: an adequacy decision, the UK International Data Transfer Addendum, or the EU Standard Contractual Clauses (module two, controller to processor, or module three, processor to processor, as appropriate), together with any supplementary measures a transfer risk assessment requires. Where the Clauses apply between us, they are incorporated by reference, with you as data exporter and us as data importer, and the details in Annex 1 completing their annexes.

07Assistance

Taking into account the nature of the processing, we will assist you, by appropriate technical and organisational measures, in responding to data subject requests, and in meeting your obligations regarding security, breach notification, data protection impact assessments and prior consultation. Where a request from a data subject reaches us directly, we will suppress the address if asked and forward the request to you without undue delay.

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Content, and will provide the information reasonably needed for your own notifications as it becomes available.

08Return and deletion

You may export your Customer Content through the API and the Console at any time. When your account closes we erase Customer Content within 30 days, except suppression records and any data we are required by law to retain, which we continue to protect under this DPA for as long as we hold it.

09Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28, including a description of our measures, our sub-processor list and summaries of any independent assessments we hold. Where that information is insufficient to meet a requirement of Data Protection Law, we will allow an audit by you or an independent auditor bound by confidentiality, no more than once in any 12 months, on at least 30 days’ notice, during business hours, in a manner that does not disrupt the Service or compromise other customers, at your cost.

10Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. Where this DPA conflicts with the Terms on a data protection matter, this DPA prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail.

11Annex 1 — Details of the processing

Subject matterProvision of the GTMRouter Service: lead discovery, contact enrichment, email verification, company signals, sending capacity, campaign drafting and launch, reply handling and LLM passthrough, executed on the Customer’s instructions.
DurationFor as long as the Customer holds an account, plus the deletion period in the Terms.
Nature and purposeRetrieval, storage, enrichment, verification, transmission and classification of business contact data for the Customer’s own outbound sales and marketing.
Categories of data subjectThe Customer’s prospects, leads and correspondents (business contacts in their professional capacity); the Customer’s own users.
Categories of personal dataName, job title, employer, work email address, work telephone number, professional profile URL, company and role signals, email content and reply content, deliverability status, opt-out status.
Special category dataNone. The Customer must not submit it.
FrequencyContinuous, as the Customer’s agents call the API.
Competent supervisory authorityThe Information Commissioner’s Office (UK), or the authority of the Customer’s EEA establishment where EU GDPR applies.

12Annex 2 — Technical and organisational measures

  • Encryption: TLS for all data in transit; encryption at rest for databases and backups; backups additionally encrypted with a key held outside the storage provider.
  • Authentication: no stored passwords; single-use emailed sign-in links or codes, or Google sign-in; API keys stored only as one-way hashes, scoped per verb, with optional spend limits; OAuth grants revocable from the Console.
  • Authorisation and human control: server-enforced human confirmation before any purchase of sending capacity or campaign launch; suppression applied at draft, re-checked at launch and propagated to live campaigns.
  • Integrity and accountability: append-only credit ledger; append-only audit log of every administrative action, including the actor and the authentication method.
  • Resilience: encrypted backups every 12 hours held in two independent locations, with point-in-time recovery on the primary database and periodic test restores.
  • Isolation: every resource is namespaced to a workspace; provider references are never exposed to customers; lookups run only through mapping tables.
  • Containment: the ability to pause every campaign in a workspace, confirmed with the sending provider, within minutes of an abuse or compromise signal.
  • Least privilege and change control: production changes ship only through the deployment pipeline from committed, reviewed code; irreversible operations require founder approval and a verified backup.
  • Sub-processor management: written contracts, category disclosure, named list on request, 14 days’ notice of change.

13Annex 3 — Authorised sub-processor categories

CategoryPurposeLocation
Business-data providers (lead search, enrichment, verification, signals)Answering data verbs on the Customer’s instructionUnited States, EU, UK
Sending infrastructure providerDomains, mailboxes, warming, sending and reply retrievalUnited States
AI model providers (Anthropic, OpenAI) via an AI model routing providerLLM passthroughUnited States
Payment processing (Stripe)Credit purchasesUnited States, EU
Cloud hosting, database and backup providersRunning the Service and storing dataUnited States, EU
Email delivery providersSign-in links, notifications and service email to the CustomerUnited States

The named list of current providers within each category is available from founders@gtmrouter.dev.

The unified GTM API for AI agents. One key, one credit balance — find, enrich, verify, and send from warmed inboxes that land.

All systems operational
Product
Verbs Pricing MCP server Providers Social Soon
Company
About Contact Community Soon Best practices
© 2026 GTMRouter — the unified GTM API for AI agents