Free Trial
Home Features Pricing About Blog Contact
Legal

Data Processing Agreement

Effective date: 1 September 2026
Contents
  1. 1. Overview & scope
  2. 2. Definitions
  3. 3. Roles of the parties
  4. 4. Subject matter & duration
  5. 5. Nature & purpose of processing
  6. 6. Data subjects & categories of data
  7. 7. Our obligations as processor
  8. 8. Sub-processors
  9. 9. Security measures
  10. 10. Assisting with data subject rights
  11. 11. Personal data breach notification
  12. 12. International data transfers
  13. 13. Audit rights
  14. 14. Return or deletion of data
  15. 15. Liability
  16. 16. Term & termination
  17. 17. Governing law
  18. 18. Contact & signed copies

1. Overview & scope

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Adstime (trading as "Hemlead", "we," "us," or "our") and the customer using the Hemlead CRM ("Customer," "you," or "your") — whether that agreement is our standard Terms & Conditions or a separately signed order form or contract.

This DPA applies whenever Hemlead processes personal data on your behalf as part of providing the CRM — most notably, the lead and contact data your team stores, works, and syncs to Meta through the product. It sets out what each of us is responsible for, and reflects the requirements of applicable data protection law, including the EU/UK GDPR (where relevant to your leads or team) and India's Digital Personal Data Protection Act, 2023 ("DPDPA").

Where this DPA and the underlying agreement conflict on data protection matters, this DPA controls. On everything else, the underlying agreement controls.

2. Definitions

3. Roles of the parties

For the lead and contact data Customer stores, works, and syncs through Hemlead, the parties act in the following capacities:

This DPA does not apply to data about Customer's own personnel (e.g. account admin/user names and emails used to log in to Hemlead), which Hemlead processes as an independent controller under our Privacy Policy.

4. Subject matter & duration

The subject matter of processing under this DPA is the Personal Data submitted to, stored in, or processed through the Hemlead CRM by or on behalf of Customer. Processing continues for the duration of the underlying agreement between the parties, and thereafter only as needed to fulfil our obligations under Section 14 (Return or deletion of data) or as required by law.

5. Nature & purpose of processing

Hemlead processes Personal Data to provide the core functions of the CRM, including:

6. Data subjects & categories of data

Data subjectsTypical categories of Personal Data
Customer's leads and contactsName, phone number, email address, company name, enquiry details, pipeline notes, call recordings and metadata (where telephony is enabled), WhatsApp message content (where enabled)
Customer's own team members (reps, admins)Name, work email, role, activity/performance data within the CRM — see our Privacy Policy for how this is handled

Hemlead does not require or knowingly process special categories of Personal Data (e.g. health, religious belief, biometric data) as part of the core CRM functionality. Customer should not enter special category data into free-text fields (such as notes) unless it is strictly necessary for its own lawful business purpose.

7. Our obligations as processor

With respect to Personal Data processed on Customer's behalf, Adstime:

8. Sub-processors

Customer authorises Adstime to engage the following sub-processors to provide the Hemlead service, each of which is bound by data protection terms consistent with this DPA:

Sub-processorPurposeData involved
Meta (Facebook/Instagram)Instant Form lead capture, Meta CAPI syncEmail and phone number, hashed with SHA-256 before transmission
BrevoAccount and marketing emailsName and email address
InteraktWhatsApp messaging, where enabledPhone number and message content
Exotel, Tata SmartFlo & TeleCMIClick-to-call and call recording, where the telephony add-on is activatedPhone number, call metadata, and call recordings
Hosting & infrastructure providersStoring data and running the applicationAll account and lead data

We'll give Customer reasonable advance notice before adding a new sub-processor that will process Customer's Personal Data, by updating this page or by direct communication. If Customer reasonably objects to a new sub-processor on data protection grounds, we'll work in good faith to address the concern — which may include, where the objection can't be resolved, Customer's right to terminate the affected service.

9. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

No system is completely immune to risk, and these measures are reviewed and updated as the product and threat landscape evolve.

10. Assisting with data subject rights

Where Customer receives a request from a data subject to exercise their rights (such as access, correction, or deletion) in respect of data stored in Hemlead, we'll provide reasonable assistance to help Customer respond — including, where technically feasible, tools within the product to look up, export, correct, or delete a specific lead record. Because Customer is the controller of this data, we'll generally direct data subjects who contact us directly back to Customer, unless the request specifically concerns data we process as an independent controller (see Section 3).

11. Personal data breach notification

If we become aware of a Personal Data Breach affecting Customer's data, we'll notify Customer without undue delay after becoming aware of it, and provide the information reasonably available to us to help Customer meet its own notification obligations — including a description of the nature of the breach, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to address it.

12. International data transfers

Hemlead is based in India, and Personal Data may be stored and processed on servers located in India or other countries where our sub-processors operate. Where Customer's Personal Data — including data belonging to individuals located in the EU/UK — is transferred outside of the jurisdiction it was collected in, we take steps to ensure it's handled consistently with this DPA and applicable law, which may include reliance on the EU Standard Contractual Clauses or an equivalent transfer mechanism where required. Customers with specific cross-border transfer requirements (e.g. requiring executed SCCs as an annex) should contact us using the details in Section 18.

13. Audit rights

On reasonable written request, and no more than once per year (unless required following a Personal Data Breach or by a supervisory authority), we'll make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for an audit — including inspections — conducted by Customer or a mutually agreed independent auditor, subject to reasonable confidentiality restrictions and at Customer's expense.

14. Return or deletion of data

On termination of the underlying agreement, we'll delete or return Customer's Personal Data in accordance with our standard retention practice described in our Privacy Policy, unless we're required to retain it by law. Customer can also request deletion directly at any time via our account deletion page.

15. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying agreement between the parties.

16. Term & termination

This DPA takes effect on the date Customer begins using Hemlead (or the effective date of the underlying agreement, if later), and remains in effect for as long as we process Personal Data on Customer's behalf, notwithstanding termination of the underlying agreement to the extent necessary to give effect to Sections 11 and 14.

17. Governing law

This DPA is governed by the laws of India, consistent with the governing law provision in our Terms & Conditions, without prejudice to any additional rights data subjects or Customer may have under mandatory local data protection law (such as the GDPR) that applies to the Personal Data in question.

18. Contact & signed copies

Questions about this DPA, or need a countersigned copy for your own compliance or vendor-review process? Reach us at support@hemlead.com or via our contact page.