Data Processing Agreement

Last updated: October 2, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sellinger AI OOD ("Sellinger" or "Processor") and the Customer ("Controller"). It applies whenever Sellinger processes personal data on the Customer's behalf in providing the Service, and is accepted together with the Terms, without a separate signature. Customers who need a countersigned copy can request one at hello@sellinger.ai. Capitalized terms not defined here have the meaning given in the Terms or in the GDPR.

Sellinger AI OOD („Селинджър АИ“ ООД)

UIC (EIK) 208752836, registered in the Commercial Register and Register of Non-Profit Legal Entities kept by the Registry Agency of the Republic of Bulgaria

Registered office and address of management: Ring Tower business building No. 1, bl. 621, entr. 1, fl. 3, apt. 1, Mladost district, Sofia 1766, Bulgaria

Managed by Asen Asenov Levov and Viktorio Borisov Shopov, each acting separately

Email: hello@sellinger.ai · Phone: +359 896 699 009

1. Scope and Roles

  • For Customer Personal Data (personal data in Customer Data), the Customer is the controller and Sellinger is the processor. Where the Customer acts as a processor for its own clients (for example as an agency or white label partner), Sellinger is a sub-processor, and the Customer confirms its controller has authorized this DPA.
  • Sellinger is an independent controller, not a processor, for account, billing, support, security and usage data, and for aggregated or anonymized statistics, as described in the Privacy Policy.
  • The details of processing are set out in Annex 1.

2. Customer Obligations

The Customer is responsible for the lawfulness of the processing it instructs, including having a valid legal basis, giving the information required by Articles 13 and 14 GDPR to data subjects, obtaining consents where needed, and complying with Section 9 of the Terms. The Customer must not submit special categories of data or data of children unless the Service is expressly configured for it and the law allows it.

3. Processing on Instructions

Sellinger processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless Union or Member State law requires otherwise, in which case Sellinger will inform the Customer first unless that law prohibits it. The Terms, this DPA, and the Customer's configuration and use of the Service (including its agents, campaigns and connected accounts) are the Customer's complete instructions. Sellinger will tell the Customer if, in its opinion, an instruction infringes data protection law.

4. Confidentiality

Sellinger ensures that everyone authorized to process Customer Personal Data is bound by confidentiality obligations and accesses it only as needed to provide, support or secure the Service.

5. Security

Sellinger implements the technical and organizational measures in Annex 2, appropriate to the risk as required by Article 32 GDPR. Sellinger may update these measures provided the overall level of protection is not reduced.

6. Sub-processors

  • The Customer gives a general authorization for Sellinger to engage sub-processors. The current list is published in Section 7 of the Privacy Policy.
  • Sellinger will notify the Customer of any intended addition or replacement at least 14 days in advance, by email to the account owner or in the Service. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro rata refund of prepaid fees for it.
  • Sellinger imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains liable to the Customer for its sub-processors' performance.
  • Platforms and integrations that the Customer connects or chooses (such as LinkedIn, Meta, email providers, CRMs, calendars and AI assistants) are not Sellinger's sub-processors; the Customer engages them directly.

7. International Transfers

Sellinger is established and hosts its primary systems in the European Union. Where Sellinger transfers Customer Personal Data to a sub-processor in a country without an adequacy decision, Sellinger concludes the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Three (processor to processor), with that sub-processor, or relies on the EU US Data Privacy Framework. Where the Customer is established outside the European Economic Area, Module Four (processor to controller) applies between Sellinger and the Customer and is incorporated by reference. For those clauses: clause 7 (docking) applies; under clause 9 option 2 (general authorization) applies with the notice period in Section 6; the optional language in clause 11 does not apply; clauses 17 and 18 are governed by and subject to the courts of Bulgaria; and the annexes are completed by Annexes 1 and 2 of this DPA. For data subject to UK law, the UK International Data Transfer Addendum applies. Sellinger ensures onward transfers to sub-processors are covered by an adequacy decision, the EU US Data Privacy Framework or Standard Contractual Clauses.

8. Data Subject Requests

Taking into account the nature of the processing, Sellinger assists the Customer by appropriate technical and organizational measures to respond to requests from data subjects. Customers can view, edit, export and erase lead data in the Service, and can erase a person across their Workspace with the erasure tool. If Sellinger receives a request directly, it will refer the data subject to the Customer where it can identify the Customer, and will not respond itself except to confirm the referral, unless the law requires otherwise.

9. Personal Data Breaches

Sellinger notifies the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, and Sellinger will update it as more information becomes available. Notification is not an acknowledgment of fault.

10. Assistance

Sellinger provides reasonable assistance to the Customer with data protection impact assessments, prior consultations with supervisory authorities, and security obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to Sellinger. Assistance beyond what the Service and its documentation provide may be charged at reasonable rates.

11. Deletion and Return

After the Service ends, the Customer may export Customer Personal Data for 30 days. Sellinger then deletes or irreversibly anonymizes Customer Personal Data within 60 days, including in backups as they rotate, unless Union or Member State law requires storage. Data that Sellinger holds as an independent controller (Section 1) is governed by the Privacy Policy.

12. Audits

Sellinger makes available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including written answers to security questionnaires. If that is not sufficient, or a supervisory authority requires it, the Customer may audit Sellinger, itself or through an independent auditor bound by confidentiality, no more than once a year, on at least 30 days' written notice, during business hours, without disrupting operations or accessing other customers' data, and at the Customer's cost.

13. Liability and Precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except where the GDPR or the Standard Contractual Clauses do not allow it. If this DPA conflicts with the Terms, this DPA prevails on the processing of personal data. If it conflicts with the Standard Contractual Clauses, the clauses prevail. This DPA lasts as long as Sellinger processes Customer Personal Data.

14. Annex 1: Details of Processing

ItemDescription
Subject matterProvision of the Sellinger AI sales platform under the Terms
DurationThe term of the Terms plus the deletion period in Section 11
Nature and purposeHosting, storage, retrieval, enrichment, analysis, generation of messages and replies with AI models, sending and receiving messages and calls through connected accounts, scheduling meetings, reporting, and support, all to provide the Service to the Customer
Categories of data subjectsThe Customer's leads, prospects, contacts and customers; people who reply to, call or chat with the Customer's agents; visitors to the Customer's websites where the Customer installs a Sellinger pixel or chat widget; the Customer's Users
Categories of personal dataName, job title, employer and professional profile data; business contact details (email, phone, profile URLs); message, email, chat and comment content; call audio and transcripts; meeting details; IP address, pages visited and similar website visit data; enrichment data; notes, tags and lead status set by the Customer
Special categoriesNone intended. The Customer must not submit them.
FrequencyContinuous for the term of the Service
Sub-processorsAs listed in Section 7 of the Privacy Policy
Competent supervisory authorityCommission for Personal Data Protection, Bulgaria, unless the SCCs designate another

15. Annex 2: Technical and Organizational Measures

Access and confidentiality

  • Role based access to production systems on a least privilege basis, limited to personnel who need it.
  • Logical separation of customer Workspaces with database row level security.
  • Authentication through a managed identity provider, with password hashing and support for Google, Microsoft and single sign on.
  • Secrets and API keys kept outside source code and rotated when exposure is suspected.

Encryption

  • TLS for data in transit between users, the Service and sub-processors.
  • Encryption at rest of databases, file storage and backups by our hosting providers.

Availability and resilience

  • Managed database with automated backups and point in time recovery.
  • Hosting in professional data centers in the European Union with physical security controls.
  • Error monitoring, health checks and alerting for application and worker services.

Integrity and accountability

  • Logging of access to the API and AI assistant connectors.
  • Version controlled changes to production with the ability to roll back.
  • Suppression lists that prevent erased or objecting contacts from being imported again.
  • Incident response procedure with breach assessment and notification.
  • Due diligence and written data protection terms for sub-processors.

Contact for data protection matters: hello@sellinger.ai.

Unit4PendoRocket.ChatGetAcceptDC ThomsonTalentSight

Join 500+ companies scaling their sales with AI

Start Free Trial