COLDWIRES
Who it's for How it works Pricing
Log in Get started

Effective July 22, 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the ColdWires Terms of Service between Coldwires LLC ("ColdWires," "we") and the customer ("you"). It applies automatically whenever data protection laws such as the EU GDPR, UK GDPR, or similar laws ("Data Protection Laws") apply to personal data you process using ColdWires. No signature is required; if your procurement process needs a countersigned copy, email support@coldwires.com and we will provide one.

1. Roles and scope

For the prospect and contact data you upload to or generate in ColdWires (lead lists, campaign recipients, and the resulting conversations), you are the controller and ColdWires is your processor. We process that data only to provide the service as described in the Terms of Service and this DPA.

For your own account data (your name, login, billing), ColdWires is the controller, as described in our Privacy Policy; that data is outside this DPA.

2. Details of processing

  • Subject matter and nature: hosting, storage, and transmission of email sent and received through infrastructure we provision (including email you send via third-party sequencers you connect), warmup traffic, deliverability monitoring, verification and enrichment lookups where used, reply classification where used, analytics, and related operations.
  • Duration: the term of your subscription plus the wind-down period in the Terms of Service.
  • Categories of data subjects: your prospects, leads, and email recipients, and their colleagues appearing in conversations.
  • Categories of personal data: business contact information (name, job title, company, business email address and similar), the content of email correspondence, and engagement data (sends, opens, replies, bounces, unsubscribes).
  • Special categories: none. You agree not to submit sensitive data (health, financial account numbers, government identifiers, data about minors) to the service.

3. Our obligations as processor

We will:

  1. Follow your instructions. We process the data only on your documented instructions, including as configured by you in the product, and not for our own purposes. The Terms of Service and this DPA are your complete instructions. We will tell you if we believe an instruction violates Data Protection Laws.
  2. Keep it confidential. People who can access the data are bound by confidentiality obligations and access it only as needed to operate and support the service.
  3. Secure it. We implement appropriate technical and organizational measures, described in Annex 1.
  4. Help with data subject requests. If a person whose data you process in ColdWires exercises a right (access, erasure, objection, and so on), we will assist you with the tools in the product (deletion, suppression, export) and reasonable further help on request. If a request comes to us directly, we will forward it to you without undue delay.
  5. Tell you about breaches. If we become aware of a personal data breach affecting your data, we will notify you without undue delay with the information we have, and keep you updated as we learn more, so you can meet your own notification obligations.
  6. Help with assessments. We will provide reasonable assistance with data protection impact assessments and regulator consultations, to the extent the needed information is in our hands.
  7. Delete on exit. When your subscription ends, we delete your data after the export window described in the Terms of Service, except where law requires retention. On request we will confirm deletion.
  8. Prove it. We will answer reasonable security and compliance questionnaires and make available information necessary to demonstrate compliance with this DPA. Where that is not sufficient, we will allow an audit (at your cost, at most once per year, with reasonable notice, during business hours, without disrupting the service).

4. Subprocessors

You give general authorization for us to use subprocessors. We bind every subprocessor to data protection obligations materially equivalent to this DPA, and we remain responsible to you for their performance.

Sending tools you connect to your inboxes (such as Instantly, Smartlead, Email Bison, or Apollo) act on your instructions as your own processors and are not ColdWires subprocessors.

Current subprocessor categories:

SubprocessorPurposeLocation
Microsoft CorporationEmail infrastructure (sending, receiving, mailboxes)United States
Stripe Inc.Payment processing (your billing data, not prospect data)United States
A Microsoft cloud solutions distributorProvisioning of dedicated Microsoft email tenancyUnited States
Cloud hosting and database providersApplication hosting, background processing, and data storageUnited States
An AI providerClassification of inbound replies; content not used to train modelsUnited States
A domain registrarDomain registration and DNSUnited States
Email verification partnersA minority of verification checks our own systems cannot resolve (email address only)United States

A complete list naming each subprocessor is available to customers on request at support@coldwires.com and forms Annex III to the Standard Contractual Clauses incorporated below.

We will notify customers at least 14 days before a new subprocessor processes your data (sign up for change notices at support@coldwires.com). If you reasonably object to a new subprocessor on data protection grounds and we cannot offer an alternative, you may cancel the affected subscription and receive a pro-rated refund of prepaid fees for the unused period.

5. International transfers

ColdWires processes data in the United States. Where Data Protection Laws restrict transfers from the EEA, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), into this DPA by reference, with you as data exporter and ColdWires as data importer; the details of processing in section 2 and the measures in Annex 1 complete the Clauses' annexes. For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Clauses is likewise incorporated. If a transfer mechanism we rely on is invalidated, we will work with you in good faith on a replacement.

6. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits either party's liability where Data Protection Laws do not permit it to be limited.

Annex 1: Technical and organizational measures

  • Encryption of data in transit (TLS) across the service.
  • Encryption at rest for credentials and mail-access tokens, with per-purpose derived keys; database-level encryption at rest via our hosting providers.
  • Access controls: customer data is scoped per workspace; internal access is limited to personnel who need it to operate and support the service.
  • Authentication: hashed passwords, session controls, and role-based permissions inside customer workspaces.
  • Audit logging of security-relevant account and data actions.
  • Continuous monitoring and alerting on core infrastructure.
  • Backups managed by our database provider, with tested restore paths.
  • Vendor diligence: subprocessors are established providers bound by their own security programs and data processing terms.
  • Breach response: internal process to assess, contain, and notify without undue delay.

Product

Who it's forHow it worksFAQ

Company

AboutPricing

Get started

Buy nowGet a demo
Privacy|Terms|DPA|Refund guarantee © 2026 ColdWires. All rights reserved.
X|LinkedIn|Email