MyLeadFox

Data processing agreement

Effective 1 September 2026

This agreement is part of the terms of service and applies whenever we process personal data on your behalf. It exists so that the person in your company who has to check such things can read it in ten minutes and find every answer they need.

1. Three kinds of data, and who is responsible for each

Your data: the shops you choose to enrich, the views and filters you save, the email addresses of the team members you invite, and the spreadsheets you connect. For this data you are the controller and MyLeadFox is your processor. This agreement covers it.

The shop database: the records we compile from public sources, including business contact routes. For this data MyLeadFox is an independent controller. It is governed by the data sourcing and compliance page, not by this agreement, and ending your subscription does not require us to delete it.

Account and usage data: your email, billing details and how you use the service. For this data MyLeadFox is an independent controller under the privacy policy.

2. What we process for you, and why

Subject: providing the service, meaning receiving your instructions through the application and the API, processing them, and returning results. Duration: your subscription plus the retention periods in the privacy policy. Data: business contact fields of the shops you enrich, the identifiers in your saved views, and the names and email addresses of your team members. People concerned: the shop contacts you choose to enrich, and your own colleagues.

Your instructions are the way you use the service under the terms. We may refuse an instruction that appears unlawful or outside what the service does. You are responsible for having a lawful basis to give us the data, and for not submitting special-category data, data about children, card numbers or government identifiers.

3. Our duties as your processor

We process your data only on your instructions and as this agreement says, unless the law requires otherwise, in which case we tell you first where we may. Everyone who can access it is bound by confidentiality. We protect it with encryption in transit, restricted and logged administrative access, hashed credentials and secure development practice.

We never use your data to build or update the shop database or anything offered to other customers, and we do not sell or share it in any sense of those words.

We help you answer requests from the people whose data it is, and with any impact assessment or regulator consultation, to the extent the law requires and the request concerns our processing. We may charge a reasonable fee for help that goes beyond what the law requires.

If a personal data breach affects your data we notify you without undue delay and within 72 hours of becoming aware of it wherever feasible, with what we know, and we keep you updated as we learn more.

4. Sub-processors

You authorise the companies on the sub-processor page, each named with what it does and where it operates. We bind each to terms at least as protective as this agreement and remain responsible to you for what they do. Before a new sub-processor handles your data we email you at least 15 days in advance. If you object on reasonable data-protection grounds and we cannot resolve it, you may end the affected service and receive a pro-rata refund of any prepaid period; we are not obliged to run the service without a sub-processor it needs.

5. Where the data goes

Your data is stored in the European Union. Some sub-processors operate from the United States and receive only what their function needs, as the sub-processor page states. For transfers out of the European Economic Area, the United Kingdom or Switzerland we rely on the standard contractual clauses or equivalent safeguards each sub-processor offers, and we will provide the details on request. Whether your own use of the service needs a transfer assessment on your side is for you to judge; we do not give legal advice.

6. Deletion, return and audit

When your account closes we delete your data from every table that held it after the 30-day recovery window in the privacy policy, and from backups as they cycle. Before then you may export your saved views and history yourself, and you may ask us in writing for a copy. Billing records are kept for the statutory period.

To show we comply we answer written questionnaires and provide evidence remotely. An on-site audit is available only where the law requires it, under a confidentiality agreement, with reasonable notice, at most once in twelve months unless a breach of this agreement has occurred, at your cost, and never touching other customers' data.

7. Liability, law and term

Our liability under this agreement is subject to the limits in the terms of service except where data protection law does not allow that. You will compensate us for claims arising from your instructions, your data or your downstream use of results, except to the extent we caused them by breaking this agreement. Each of us keeps our own intellectual property; you keep every right in your data, we keep every right in the service and the shop database.

This agreement is governed by the laws of Dubai, United Arab Emirates, and the courts of Dubai have exclusive jurisdiction over it. It starts when you first give us your data and ends when we stop processing it; confidentiality, liability and the deletion limits survive.

8. Contact

Requests under this agreement, and every data-protection question, go to hi@myleadfox.com. A person reads every message and answers within 30 days.