1. Overview & scope
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Adstime (trading as "Hemlead", "we," "us," or "our") and the customer using the Hemlead CRM ("Customer," "you," or "your") — whether that agreement is our standard Terms & Conditions or a separately signed order form or contract.
This DPA applies whenever Hemlead processes personal data on your behalf as part of providing the CRM — most notably, the lead and contact data your team stores, works, and syncs to Meta through the product. It sets out what each of us is responsible for, and reflects the requirements of applicable data protection law, including the EU/UK GDPR (where relevant to your leads or team) and India's Digital Personal Data Protection Act, 2023 ("DPDPA").
Where this DPA and the underlying agreement conflict on data protection matters, this DPA controls. On everything else, the underlying agreement controls.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, processed by Hemlead on Customer's behalf under the agreement — primarily lead and contact records (names, phone numbers, email addresses, and notes) that Customer's team stores in the CRM.
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
- "Controller" / "Data Fiduciary" means the party that determines the purposes and means of processing Personal Data — for lead data stored in Hemlead, this is Customer.
- "Processor" / "Data Processor" means the party that processes Personal Data on behalf of, and under the instructions of, the Controller — this is Adstime, with respect to Customer's lead data.
- "Sub-processor" means any third party engaged by Hemlead to process Personal Data in order to provide the service (see Section 8).
- "Data Subject" means the individual to whom Personal Data relates — typically a lead, contact, or end customer of the Customer's business.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
3. Roles of the parties
For the lead and contact data Customer stores, works, and syncs through Hemlead, the parties act in the following capacities:
- Customer is the Controller (Data Fiduciary). You determine what data to collect, why you're collecting it, and your lawful basis for contacting the individuals in your pipeline. You're responsible for having a lawful basis to collect and process your leads' data.
- Adstime is the Processor. We process that data only on your instructions — to provide, maintain, and support the Hemlead product — and not for our own independent purposes.
This DPA does not apply to data about Customer's own personnel (e.g. account admin/user names and emails used to log in to Hemlead), which Hemlead processes as an independent controller under our Privacy Policy.
4. Subject matter & duration
The subject matter of processing under this DPA is the Personal Data submitted to, stored in, or processed through the Hemlead CRM by or on behalf of Customer. Processing continues for the duration of the underlying agreement between the parties, and thereafter only as needed to fulfil our obligations under Section 14 (Return or deletion of data) or as required by law.
5. Nature & purpose of processing
Hemlead processes Personal Data to provide the core functions of the CRM, including:
- Capturing leads from Meta Instant Forms, web forms, and other connected sources into Customer's pipeline.
- Storing, organising, and displaying lead and contact records so Customer's team can work them.
- Routing and auto-assigning leads to reps, and logging pipeline stage changes, calls, and notes.
- Syncing qualification and conversion events back to Meta CAPI (with email and phone number hashed via SHA-256 before transmission).
- Sending WhatsApp messages and, where the telephony add-on is enabled, placing and logging calls, on Customer's instruction.
- Generating reports, exports, and tax invoices Customer requests from within the product.
- Providing customer support in connection with the above.
6. Data subjects & categories of data
| Data subjects | Typical categories of Personal Data |
|---|---|
| Customer's leads and contacts | Name, phone number, email address, company name, enquiry details, pipeline notes, call recordings and metadata (where telephony is enabled), WhatsApp message content (where enabled) |
| Customer's own team members (reps, admins) | Name, work email, role, activity/performance data within the CRM — see our Privacy Policy for how this is handled |
Hemlead does not require or knowingly process special categories of Personal Data (e.g. health, religious belief, biometric data) as part of the core CRM functionality. Customer should not enter special category data into free-text fields (such as notes) unless it is strictly necessary for its own lawful business purpose.
7. Our obligations as processor
With respect to Personal Data processed on Customer's behalf, Adstime:
- Processes Personal Data only on Customer's documented instructions (including as set out in the agreement and this DPA), unless required to do otherwise by law, in which case we'll inform Customer before processing unless legally prohibited from doing so.
- Ensures personnel authorised to process Personal Data are subject to confidentiality obligations.
- Implements appropriate technical and organisational security measures (Section 9).
- Does not engage a new sub-processor without providing notice as described in Section 8.
- Assists Customer, to the extent reasonably possible, in responding to data subject requests and in meeting Customer's own obligations around security, breach notification, and data protection impact assessments (Sections 10–11).
- Makes available information reasonably necessary to demonstrate compliance with this DPA and allows for audits as described in Section 13.
- Does not sell Customer's Personal Data or use it for our own independent marketing purposes.
8. Sub-processors
Customer authorises Adstime to engage the following sub-processors to provide the Hemlead service, each of which is bound by data protection terms consistent with this DPA:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Meta (Facebook/Instagram) | Instant Form lead capture, Meta CAPI sync | Email and phone number, hashed with SHA-256 before transmission |
| Brevo | Account and marketing emails | Name and email address |
| Interakt | WhatsApp messaging, where enabled | Phone number and message content |
| Exotel, Tata SmartFlo & TeleCMI | Click-to-call and call recording, where the telephony add-on is activated | Phone number, call metadata, and call recordings |
| Hosting & infrastructure providers | Storing data and running the application | All account and lead data |
We'll give Customer reasonable advance notice before adding a new sub-processor that will process Customer's Personal Data, by updating this page or by direct communication. If Customer reasonably objects to a new sub-processor on data protection grounds, we'll work in good faith to address the concern — which may include, where the objection can't be resolved, Customer's right to terminate the affected service.
9. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- Email and phone numbers are hashed with SHA-256 before being sent to Meta — Meta never receives this data in plain text.
- Encryption of data in transit between Customer's browser, the Hemlead application, and our servers.
- Role-based access control within Hemlead — admins and reps only see what their permissions allow.
- Internal access to production data is limited to what's necessary for support and engineering work.
- Call recordings (where telephony is enabled) are stored and access-controlled the same way as other account data.
No system is completely immune to risk, and these measures are reviewed and updated as the product and threat landscape evolve.
10. Assisting with data subject rights
Where Customer receives a request from a data subject to exercise their rights (such as access, correction, or deletion) in respect of data stored in Hemlead, we'll provide reasonable assistance to help Customer respond — including, where technically feasible, tools within the product to look up, export, correct, or delete a specific lead record. Because Customer is the controller of this data, we'll generally direct data subjects who contact us directly back to Customer, unless the request specifically concerns data we process as an independent controller (see Section 3).
11. Personal data breach notification
If we become aware of a Personal Data Breach affecting Customer's data, we'll notify Customer without undue delay after becoming aware of it, and provide the information reasonably available to us to help Customer meet its own notification obligations — including a description of the nature of the breach, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to address it.
12. International data transfers
Hemlead is based in India, and Personal Data may be stored and processed on servers located in India or other countries where our sub-processors operate. Where Customer's Personal Data — including data belonging to individuals located in the EU/UK — is transferred outside of the jurisdiction it was collected in, we take steps to ensure it's handled consistently with this DPA and applicable law, which may include reliance on the EU Standard Contractual Clauses or an equivalent transfer mechanism where required. Customers with specific cross-border transfer requirements (e.g. requiring executed SCCs as an annex) should contact us using the details in Section 18.
13. Audit rights
On reasonable written request, and no more than once per year (unless required following a Personal Data Breach or by a supervisory authority), we'll make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for an audit — including inspections — conducted by Customer or a mutually agreed independent auditor, subject to reasonable confidentiality restrictions and at Customer's expense.
14. Return or deletion of data
On termination of the underlying agreement, we'll delete or return Customer's Personal Data in accordance with our standard retention practice described in our Privacy Policy, unless we're required to retain it by law. Customer can also request deletion directly at any time via our account deletion page.
15. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying agreement between the parties.
16. Term & termination
This DPA takes effect on the date Customer begins using Hemlead (or the effective date of the underlying agreement, if later), and remains in effect for as long as we process Personal Data on Customer's behalf, notwithstanding termination of the underlying agreement to the extent necessary to give effect to Sections 11 and 14.
17. Governing law
This DPA is governed by the laws of India, consistent with the governing law provision in our Terms & Conditions, without prejudice to any additional rights data subjects or Customer may have under mandatory local data protection law (such as the GDPR) that applies to the Personal Data in question.
18. Contact & signed copies
Questions about this DPA, or need a countersigned copy for your own compliance or vendor-review process? Reach us at support@hemlead.com or via our contact page.