Data Processing Agreement
Last updated: October 2, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sellinger AI OOD ("Sellinger" or "Processor") and the Customer ("Controller"). It applies whenever Sellinger processes personal data on the Customer's behalf in providing the Service, and is accepted together with the Terms, without a separate signature. Customers who need a countersigned copy can request one at hello@sellinger.ai. Capitalized terms not defined here have the meaning given in the Terms or in the GDPR.
Sellinger AI OOD („Селинджър АИ“ ООД)
UIC (EIK) 208752836, registered in the Commercial Register and Register of Non-Profit Legal Entities kept by the Registry Agency of the Republic of Bulgaria
Registered office and address of management: Ring Tower business building No. 1, bl. 621, entr. 1, fl. 3, apt. 1, Mladost district, Sofia 1766, Bulgaria
Managed by Asen Asenov Levov and Viktorio Borisov Shopov, each acting separately
Email: hello@sellinger.ai · Phone: +359 896 699 009
1. Scope and Roles
- For Customer Personal Data (personal data in Customer Data), the Customer is the controller and Sellinger is the processor. Where the Customer acts as a processor for its own clients (for example as an agency or white label partner), Sellinger is a sub-processor, and the Customer confirms its controller has authorized this DPA.
- Sellinger is an independent controller, not a processor, for account, billing, support, security and usage data, and for aggregated or anonymized statistics, as described in the Privacy Policy.
- The details of processing are set out in Annex 1.
2. Customer Obligations
The Customer is responsible for the lawfulness of the processing it instructs, including having a valid legal basis, giving the information required by Articles 13 and 14 GDPR to data subjects, obtaining consents where needed, and complying with Section 9 of the Terms. The Customer must not submit special categories of data or data of children unless the Service is expressly configured for it and the law allows it.
3. Processing on Instructions
Sellinger processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless Union or Member State law requires otherwise, in which case Sellinger will inform the Customer first unless that law prohibits it. The Terms, this DPA, and the Customer's configuration and use of the Service (including its agents, campaigns and connected accounts) are the Customer's complete instructions. Sellinger will tell the Customer if, in its opinion, an instruction infringes data protection law.
4. Confidentiality
Sellinger ensures that everyone authorized to process Customer Personal Data is bound by confidentiality obligations and accesses it only as needed to provide, support or secure the Service.
5. Security
Sellinger implements the technical and organizational measures in Annex 2, appropriate to the risk as required by Article 32 GDPR. Sellinger may update these measures provided the overall level of protection is not reduced.
6. Sub-processors
- The Customer gives a general authorization for Sellinger to engage sub-processors. The current list is published in Section 7 of the Privacy Policy.
- Sellinger will notify the Customer of any intended addition or replacement at least 14 days in advance, by email to the account owner or in the Service. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro rata refund of prepaid fees for it.
- Sellinger imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains liable to the Customer for its sub-processors' performance.
- Platforms and integrations that the Customer connects or chooses (such as LinkedIn, Meta, email providers, CRMs, calendars and AI assistants) are not Sellinger's sub-processors; the Customer engages them directly.
7. International Transfers
Sellinger is established and hosts its primary systems in the European Union. Where Sellinger transfers Customer Personal Data to a sub-processor in a country without an adequacy decision, Sellinger concludes the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Three (processor to processor), with that sub-processor, or relies on the EU US Data Privacy Framework. Where the Customer is established outside the European Economic Area, Module Four (processor to controller) applies between Sellinger and the Customer and is incorporated by reference. For those clauses: clause 7 (docking) applies; under clause 9 option 2 (general authorization) applies with the notice period in Section 6; the optional language in clause 11 does not apply; clauses 17 and 18 are governed by and subject to the courts of Bulgaria; and the annexes are completed by Annexes 1 and 2 of this DPA. For data subject to UK law, the UK International Data Transfer Addendum applies. Sellinger ensures onward transfers to sub-processors are covered by an adequacy decision, the EU US Data Privacy Framework or Standard Contractual Clauses.
8. Data Subject Requests
Taking into account the nature of the processing, Sellinger assists the Customer by appropriate technical and organizational measures to respond to requests from data subjects. Customers can view, edit, export and erase lead data in the Service, and can erase a person across their Workspace with the erasure tool. If Sellinger receives a request directly, it will refer the data subject to the Customer where it can identify the Customer, and will not respond itself except to confirm the referral, unless the law requires otherwise.
9. Personal Data Breaches
Sellinger notifies the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, and Sellinger will update it as more information becomes available. Notification is not an acknowledgment of fault.
10. Assistance
Sellinger provides reasonable assistance to the Customer with data protection impact assessments, prior consultations with supervisory authorities, and security obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to Sellinger. Assistance beyond what the Service and its documentation provide may be charged at reasonable rates.
11. Deletion and Return
After the Service ends, the Customer may export Customer Personal Data for 30 days. Sellinger then deletes or irreversibly anonymizes Customer Personal Data within 60 days, including in backups as they rotate, unless Union or Member State law requires storage. Data that Sellinger holds as an independent controller (Section 1) is governed by the Privacy Policy.
12. Audits
Sellinger makes available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including written answers to security questionnaires. If that is not sufficient, or a supervisory authority requires it, the Customer may audit Sellinger, itself or through an independent auditor bound by confidentiality, no more than once a year, on at least 30 days' written notice, during business hours, without disrupting operations or accessing other customers' data, and at the Customer's cost.
13. Liability and Precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where the GDPR or the Standard Contractual Clauses do not allow it. If this DPA conflicts with the Terms, this DPA prevails on the processing of personal data. If it conflicts with the Standard Contractual Clauses, the clauses prevail. This DPA lasts as long as Sellinger processes Customer Personal Data.
14. Annex 1: Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Sellinger AI sales platform under the Terms |
| Duration | The term of the Terms plus the deletion period in Section 11 |
| Nature and purpose | Hosting, storage, retrieval, enrichment, analysis, generation of messages and replies with AI models, sending and receiving messages and calls through connected accounts, scheduling meetings, reporting, and support, all to provide the Service to the Customer |
| Categories of data subjects | The Customer's leads, prospects, contacts and customers; people who reply to, call or chat with the Customer's agents; visitors to the Customer's websites where the Customer installs a Sellinger pixel or chat widget; the Customer's Users |
| Categories of personal data | Name, job title, employer and professional profile data; business contact details (email, phone, profile URLs); message, email, chat and comment content; call audio and transcripts; meeting details; IP address, pages visited and similar website visit data; enrichment data; notes, tags and lead status set by the Customer |
| Special categories | None intended. The Customer must not submit them. |
| Frequency | Continuous for the term of the Service |
| Sub-processors | As listed in Section 7 of the Privacy Policy |
| Competent supervisory authority | Commission for Personal Data Protection, Bulgaria, unless the SCCs designate another |
15. Annex 2: Technical and Organizational Measures
Access and confidentiality
- Role based access to production systems on a least privilege basis, limited to personnel who need it.
- Logical separation of customer Workspaces with database row level security.
- Authentication through a managed identity provider, with password hashing and support for Google, Microsoft and single sign on.
- Secrets and API keys kept outside source code and rotated when exposure is suspected.
Encryption
- TLS for data in transit between users, the Service and sub-processors.
- Encryption at rest of databases, file storage and backups by our hosting providers.
Availability and resilience
- Managed database with automated backups and point in time recovery.
- Hosting in professional data centers in the European Union with physical security controls.
- Error monitoring, health checks and alerting for application and worker services.
Integrity and accountability
- Logging of access to the API and AI assistant connectors.
- Version controlled changes to production with the ability to roll back.
- Suppression lists that prevent erased or objecting contacts from being imported again.
- Incident response procedure with breach assessment and notification.
- Due diligence and written data protection terms for sub-processors.
Contact for data protection matters: hello@sellinger.ai.

