Data processing agreement

Last updated 7 October 2026.

When a client shares customer or prospect data with us, we process it on their behalf. Our data processing agreement sets out how. This page summarises it; the full agreement is provided and signed before the first transfer of data.

Roles

For the data a client provides, the client is the controller and Vectify is the processor. For the prospect data we source ourselves to run outreach, Vectify acts as an independent controller, as described in our privacy policy.

What the agreement covers

  • Subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects.
  • Processing only on documented instructions from the client, with confidentiality obligations for everyone involved.
  • Technical and organisational security measures, described in the security overview that accompanies the agreement.
  • Sub-processors, with a current list and prior notice of changes.
  • Assistance with data subject requests, security incidents and impact assessments.
  • Return or deletion of data at the end of the engagement.
  • Audit rights and international transfer safeguards where applicable.

How customer data reaches us

Customer lists, suppression lists and conversion data are transferred through our secure SFTP setup, never by email. Access on our side is limited to the people working on your account.

Sub-processors

Our current sub-processors include our hosting provider, our email and sending infrastructure providers, and our data and workflow tooling. The full list with locations is part of the agreement.

Requesting the agreement

Write to info@vectify.io and we send the agreement and the security overview for your legal and IT teams to review.