Effective July 22, 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the ColdWires Terms of Service between Coldwires LLC ("ColdWires," "we") and the customer ("you"). It applies automatically whenever data protection laws such as the EU GDPR, UK GDPR, or similar laws ("Data Protection Laws") apply to personal data you process using ColdWires. No signature is required; if your procurement process needs a countersigned copy, email support@coldwires.com and we will provide one.
1. Roles and scope
For the prospect and contact data you upload to or generate in ColdWires (lead lists, campaign recipients, and the resulting conversations), you are the controller and ColdWires is your processor. We process that data only to provide the service as described in the Terms of Service and this DPA.
For your own account data (your name, login, billing), ColdWires is the controller, as described in our Privacy Policy; that data is outside this DPA.
2. Details of processing
- Subject matter and nature: hosting, storage, and transmission of email sent and received through infrastructure we provision (including email you send via third-party sequencers you connect), warmup traffic, deliverability monitoring, verification and enrichment lookups where used, reply classification where used, analytics, and related operations.
- Duration: the term of your subscription plus the wind-down period in the Terms of Service.
- Categories of data subjects: your prospects, leads, and email recipients, and their colleagues appearing in conversations.
- Categories of personal data: business contact information (name, job title, company, business email address and similar), the content of email correspondence, and engagement data (sends, opens, replies, bounces, unsubscribes).
- Special categories: none. You agree not to submit sensitive data (health, financial account numbers, government identifiers, data about minors) to the service.
3. Our obligations as processor
We will:
- Follow your instructions. We process the data only on your documented instructions, including as configured by you in the product, and not for our own purposes. The Terms of Service and this DPA are your complete instructions. We will tell you if we believe an instruction violates Data Protection Laws.
- Keep it confidential. People who can access the data are bound by confidentiality obligations and access it only as needed to operate and support the service.
- Secure it. We implement appropriate technical and organizational measures, described in Annex 1.
- Help with data subject requests. If a person whose data you process in ColdWires exercises a right (access, erasure, objection, and so on), we will assist you with the tools in the product (deletion, suppression, export) and reasonable further help on request. If a request comes to us directly, we will forward it to you without undue delay.
- Tell you about breaches. If we become aware of a personal data breach affecting your data, we will notify you without undue delay with the information we have, and keep you updated as we learn more, so you can meet your own notification obligations.
- Help with assessments. We will provide reasonable assistance with data protection impact assessments and regulator consultations, to the extent the needed information is in our hands.
- Delete on exit. When your subscription ends, we delete your data after the export window described in the Terms of Service, except where law requires retention. On request we will confirm deletion.
- Prove it. We will answer reasonable security and compliance questionnaires and make available information necessary to demonstrate compliance with this DPA. Where that is not sufficient, we will allow an audit (at your cost, at most once per year, with reasonable notice, during business hours, without disrupting the service).
4. Subprocessors
You give general authorization for us to use subprocessors. We bind every subprocessor to data protection obligations materially equivalent to this DPA, and we remain responsible to you for their performance.
Sending tools you connect to your inboxes (such as Instantly, Smartlead, Email Bison, or Apollo) act on your instructions as your own processors and are not ColdWires subprocessors.
Current subprocessor categories:
| Subprocessor | Purpose | Location |
|---|---|---|
| Microsoft Corporation | Email infrastructure (sending, receiving, mailboxes) | United States |
| Stripe Inc. | Payment processing (your billing data, not prospect data) | United States |
| A Microsoft cloud solutions distributor | Provisioning of dedicated Microsoft email tenancy | United States |
| Cloud hosting and database providers | Application hosting, background processing, and data storage | United States |
| An AI provider | Classification of inbound replies; content not used to train models | United States |
| A domain registrar | Domain registration and DNS | United States |
| Email verification partners | A minority of verification checks our own systems cannot resolve (email address only) | United States |
A complete list naming each subprocessor is available to customers on request at support@coldwires.com and forms Annex III to the Standard Contractual Clauses incorporated below.
We will notify customers at least 14 days before a new subprocessor processes your data (sign up for change notices at support@coldwires.com). If you reasonably object to a new subprocessor on data protection grounds and we cannot offer an alternative, you may cancel the affected subscription and receive a pro-rated refund of prepaid fees for the unused period.
5. International transfers
ColdWires processes data in the United States. Where Data Protection Laws restrict transfers from the EEA, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), into this DPA by reference, with you as data exporter and ColdWires as data importer; the details of processing in section 2 and the measures in Annex 1 complete the Clauses' annexes. For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Clauses is likewise incorporated. If a transfer mechanism we rely on is invalidated, we will work with you in good faith on a replacement.
6. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits either party's liability where Data Protection Laws do not permit it to be limited.
Annex 1: Technical and organizational measures
- Encryption of data in transit (TLS) across the service.
- Encryption at rest for credentials and mail-access tokens, with per-purpose derived keys; database-level encryption at rest via our hosting providers.
- Access controls: customer data is scoped per workspace; internal access is limited to personnel who need it to operate and support the service.
- Authentication: hashed passwords, session controls, and role-based permissions inside customer workspaces.
- Audit logging of security-relevant account and data actions.
- Continuous monitoring and alerting on core infrastructure.
- Backups managed by our database provider, with tested restore paths.
- Vendor diligence: subprocessors are established providers bound by their own security programs and data processing terms.
- Breach response: internal process to assess, contain, and notify without undue delay.