DPA
Data processing agreement
Last updated: 24 July 2026
This data processing agreement ("DPA") applies whenever Collaby BV, trading as From Cold To Warm ("Processor"), processes personal data on behalf of a client ("Controller") in the course of delivering its services. It forms part of the agreement between the parties and satisfies Article 28 of the GDPR. Where a client needs a signed copy, we make this DPA available as a separate signable annex to the proposal.
1. Roles and scope
The Controller determines the purposes and means of processing; the Processor processes personal data only on the Controller's documented instructions, including the instructions contained in the proposal and this DPA. If the Processor believes an instruction breaches the GDPR or other data protection law, it will inform the Controller.
2. Subject matter, duration, nature and purpose
- Subject matter: the processing needed to deliver the account-based marketing system described in the proposal.
- Duration: the term of the engagement, plus the deletion/return period in section 9.
- Nature and purpose: collecting, structuring, enriching, storing, analysing, scoring and using business contact and account data to identify and warm up target accounts, deliver advertising, capture signals, and report.
3. Categories of data and data subjects
- Data subjects: the Controller's contacts, and professionals within the Controller's target accounts (its buying groups).
- Categories of personal data: name, job title and role, employer, business email and phone, professional profile and public information, engagement and signal data, and any client-provided CRM fields.
- Special categories: none are requested or intended. The Controller shall not instruct the processing of special-category data through the service.
4. Obligations of the Processor
The Processor shall:
- process personal data only on the Controller's documented instructions, including for international transfers, unless required to do otherwise by law (in which case it will inform the Controller unless the law forbids it);
- ensure that persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (section 7);
- respect the conditions for engaging sub-processors (section 5);
- assist the Controller, taking into account the nature of the processing, in responding to data-subject requests;
- assist the Controller with security, breach notification, data protection impact assessments and prior consultation (Articles 32-36 GDPR);
- at the Controller's choice, delete or return the personal data at the end of the service (section 9); and
- make available the information needed to demonstrate compliance and allow for and contribute to audits (section 8).
5. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed below to deliver the service. The Processor imposes on each sub-processor data protection obligations equivalent to those in this DPA and remains fully liable for their performance. The Processor will inform the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting, application server and database (self-hosted Supabase, n8n, CRM) | Germany / Finland (EU) |
| Cloudflare, Inc. | DNS, CDN, TLS and inbound email routing | USA (SCCs / EU-US DPF) |
| PostHog Inc. (EU Cloud) | Website product analytics (consent-gated) | EU (Frankfurt) |
| LinkedIn Ireland Unlimited Company | Advertising delivery and matched audiences | Ireland (EU) / USA (SCCs) |
| Meta Platforms Ireland Ltd. | Advertising delivery and custom audiences | Ireland (EU) / USA (SCCs) |
| Google Ireland Ltd. | Advertising delivery and measurement | Ireland (EU) / USA (SCCs / EU-US DPF) |
| Anthropic PBC | AI processing for message contextualisation | USA (SCCs) |
| Calendly LLC | Meeting scheduling | USA (SCCs / EU-US DPF) |
| Data enrichment providers | Business contact and firmographic enrichment (list to be finalised per engagement) | EU / USA (SCCs) |
6. International transfers
The Processor keeps the core infrastructure and database within the European Union. Where a sub-processor is located outside the EU, or transfers data outside the EU, such transfer takes place under an adequacy decision, the EU Standard Contractual Clauses, and/or the EU-US Data Privacy Framework.
7. Security measures
Taking into account the state of the art and the risks, the Processor implements appropriate technical and organisational measures, including:
- All traffic encrypted in transit over TLS/HTTPS (managed by a Caddy reverse proxy).
- Data hosted on EU infrastructure (Hetzner, Germany/Finland); the primary database is self-hosted rather than on a shared third-party platform.
- Host firewall (ufw) restricting inbound traffic to ports 22, 80 and 443 only.
- Brute-force protection (fail2ban) and automatic security updates (unattended-upgrades).
- SSH key-based administrative access only; no password login.
- Least-privilege access: production access is limited to the controller.
- Daily encrypted server backups.
- Documented incident-response and breach-notification process (notification of affected clients without undue delay, and of the supervisory authority within 72 hours where required).
8. Audits
On reasonable written request and no more than once per year (or after a personal data breach affecting the Controller), the Processor will make available the information needed to demonstrate compliance with this DPA and will contribute to an audit conducted by the Controller or an independent auditor bound by confidentiality. Our audit readiness pack answers most standard security and procurement questions upfront.
9. Return and deletion
On termination of the service, the Processor will, at the Controller's choice, return or delete the personal data it processes on the Controller's behalf, and delete existing copies, unless retention is required by law. Client data and brand assets remain the property of the Controller at all times.
10. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller needs to meet its own notification obligations under Articles 33 and 34 GDPR.
11. Liability and law
Liability under this DPA is subject to the limitations agreed in the general conditions of the proposal, without prejudice to the rights of data subjects under the GDPR. This DPA is governed by Belgian law and the jurisdiction clause of the proposal.
Controller responsibilities. The Controller warrants that it has a valid legal basis for the data it provides and for the outreach it instructs, that it has met any transparency obligations towards data subjects, and that its instructions are lawful.
