This Data Processing Agreement ("DPA") forms part of the Terms and Conditions (the "Principal Agreement") between Threadline, Lda. ("Processor", "we", "us") and the User/Customer ("Controller", "you") who subscribes to the Threadline SaaS platform and Chrome Extension.
Definitions
"Data Protection Laws" means all applicable privacy and data protection laws, including the General Data Protection Regulation (GDPR) (EU) 2016/679.
"Personal Data", "Data Subject", "Processing", "Controller", and "Processor" shall have the meanings given to them in the GDPR.
"Sub-processor" means any third party engaged by Threadline to process Personal Data on behalf of the Controller.
Scope and Roles
This DPA applies when Threadline processes Personal Data on your behalf in the course of providing the Service (including the Web App and Chrome Extension).
For the purposes of the GDPR:
- you are the Data Controller
- Threadline is the Data Processor
Threadline will process Personal Data only for the purpose of providing the Service as described in the Principal Agreement and this DPA.
Threadline processes only the minimum amount of Personal Data necessary to provide the Service.
Customer (Controller) Obligations
You agree that:
you have a valid legal basis (such as Legitimate Interest) to process the Personal Data of Prospects collected via the Threadline Service;
you are responsible for ensuring that your use of the Service complies with applicable Data Protection Laws;
you will comply with applicable marketing and communication laws, including but not limited to the ePrivacy Directive and anti-spam laws such as CAN-SPAM where applicable.
You remain solely responsible for determining the purposes and means of processing Personal Data through the Service.
Threadline (Processor) Obligations
Threadline shall not sell, rent, or otherwise disclose Personal Data processed on behalf of the Controller for its own commercial purposes.
Threadline shall:
Process on Instructions
Process Personal Data only on documented instructions from the Controller, as set out in the Principal Agreement and this DPA, unless required to do so by applicable law.
Confidentiality
Ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
Security
Implement appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk.
Such measures include, where appropriate:
- encryption of data in transit (TLS)
- encryption of data at rest
- role-based access controls
- secure cloud infrastructure
- system monitoring and logging
- vulnerability management and patching
If Threadline receives a legally binding request from a public authority for disclosure of Personal Data, Threadline will, where legally permitted, notify the Controller before disclosing such data.
Sub-processors
You grant Threadline general authorization to engage Sub-processors in order to provide the Service.
Threadline currently uses the following core Sub-processors:
- Supabase, Inc. — database and authentication infrastructure
- OpenAI, L.L.C. — artificial intelligence processing via API
- Stripe, Inc. — payment processing services
Threadline shall enter into written agreements with each Sub-processor imposing data protection obligations no less protective than those set out in this DPA.
Threadline will notify the Controller of any intended changes concerning the addition or replacement of Sub-processors. The Controller may object to such changes on reasonable data protection grounds.
Personal data transmitted to AI Sub-processors such as OpenAI is processed solely to generate responses and is not used to train foundational AI models.
AI Sub-processors process Personal Data only for the purpose of generating responses requested by the User and do not retain such data beyond what is necessary to deliver the Service.
Data Subject Rights
Taking into account the nature of the processing, Threadline will assist the Controller through appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under the GDPR, including:
- right of access
- right to rectification
- right to erasure
- right to restriction of processing
- right to data portability
- right to object
Personal Data Breaches
Threadline will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed on behalf of the Controller.
Threadline will provide reasonable assistance to help the Controller meet its obligations under applicable Data Protection Laws, including breach notification obligations.
Assistance with Compliance
Threadline shall assist the Controller in ensuring compliance with the Controller's obligations under applicable Data Protection Laws, including with respect to:
- security of processing
- data protection impact assessments (DPIAs)
prior consultation with supervisory authorities where required.
Such assistance will be provided taking into account the nature of processing and the information available to Threadline.
International Data Transfers
Where Threadline transfers Personal Data outside the European Economic Area (EEA) to a country not recognized by the European Commission as providing an adequate level of protection, such transfers shall be governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914.
Audits and Compliance
Threadline shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and applicable Data Protection Laws.
Upon reasonable prior notice, the Controller may request documentation regarding Threadline's security practices or compliance measures. Any such request shall be limited to what is reasonably necessary and shall not interfere with Threadline's normal business operations.
Return or Deletion of Data
Upon termination of the Principal Agreement or the User's account, Threadline will delete all Personal Data processed on behalf of the Controller unless applicable laws require further storage of such Personal Data.
Backup copies containing Personal Data may remain in encrypted archives for a limited period consistent with Threadline's internal data retention and backup policies.
ANNEX 1: DETAILS OF PROCESSING
A. Nature and Purpose of Processing
Threadline provides a B2B sales intelligence and outreach platform.
Processing activities include:
extraction of publicly available professional data via a Chrome Extension
storage of such data in cloud infrastructure
analysis of data using artificial intelligence APIs to generate B2B insights and messaging suggestions.
B. Categories of Data Subjects
Users
Employees or authorized personnel of the Controller using the Threadline platform.
Prospects
Third-party professionals whose publicly available LinkedIn profiles are viewed and analyzed by the User through the Threadline Chrome Extension.
C. Categories of Personal Data
User Data
name
email address
billing information
account credentials
usage logs
Prospect Data
full name
job title
current and past employers
professional biographies
LinkedIn profile URLs
inferred professional insights generated by the Service