LeadCat CRM

Data Processing Addendum

Effective date: August 13, 2026

Version 1.1

LeadCat is a product of Staminal Technologies Private Limited.

This Data Processing Addendum ("DPA") forms part of the LeadCat CRM Terms of Service, an order form, or another written agreement governing the Customer's use of LeadCat CRM (the "Main Agreement").

This DPA is between the business identified in the applicable CRM workspace, order form, or Main Agreement ("Customer") and STAMINAL TECHNOLOGIES PRIVATE LIMITED (CIN: U62013TN2023PTC165254), a company incorporated in India with its registered office in Tamil Nadu ("Staminal"). Customer and Staminal are each a "Party" and together the "Parties".

For Customer Personal Data processed through the CRM, the Customer normally acts as the Data Fiduciary or Controller and Staminal acts as the Data Processor or Processor. Customer remains responsible for deciding the lawful purpose and permitted use of its lead and enquiry data.

1. Definitions

In this DPA:

2. Scope, Roles, and Customer Instructions

  1. Customer appoints Staminal to process Customer Personal Data only to provide, secure, support, maintain, back up, and improve the reliability of the Service; operate Customer-enabled integrations; comply with the Customer's documented instructions; and meet legal obligations applicable to Staminal.
  2. The Main Agreement, the Customer's configuration and use of the Service, support requests made by authorized Customer users, and Schedule 1 are the Customer's documented instructions. Additional instructions must be lawful, technically feasible, and agreed in writing. Staminal may charge reasonable costs for material work outside the Service.
  3. Staminal will notify the Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law. Staminal may suspend the affected processing while the Parties resolve the concern.
  4. If law requires Staminal to process Customer Personal Data outside the Customer's instructions, Staminal will inform the Customer before processing unless the law prohibits that notice.

3. Customer Responsibilities

Customer will:

4. Staminal Processing Obligations

Staminal will:

5. Confidentiality and Access

Staminal will restrict access to Customer Personal Data to personnel and subprocessors that need access to provide or secure the Service. Access will be subject to confidentiality, authentication, authorization, and logging controls appropriate to the role. Support access must be limited to an identified operational or security need.

6. Security and Personal Data Breaches

  1. Staminal will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, loss, or destruction. The current baseline measures are in Schedule 2.
  2. Staminal will notify the Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the Customer's registered owner or security contact and, as information becomes available, will describe the known nature of the incident, affected data, likely consequences, containment or remediation, and a contact for follow-up.
  3. Staminal will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and will provide reasonable cooperation for the Customer's legally required assessment or notification.
  4. Customer remains responsible for notices to Data Principals and regulators unless Applicable Data Protection Law requires Staminal to notify them directly. A breach notice is not an admission of fault or liability.

7. Data Principal Requests and Compliance Assistance

  1. Taking into account the nature of the processing, Staminal will provide reasonable technical and organizational assistance so the Customer can respond to lawful requests for access, information, correction, completion, updating, erasure, or grievance redressal.
  2. If Staminal receives a request relating primarily to Customer Personal Data, Staminal may direct the requester to the Customer and notify the Customer where legally permitted. Staminal will not independently decide the request unless required by law.
  3. Staminal will provide reasonable information available to it for a Customer's legally required data-protection assessment, regulator inquiry, or consultation relating to the Service.
  4. Assistance beyond standard Service functionality may be subject to reasonable fees when permitted by law, particularly where a request is repetitive, unusually broad, or requires custom development.

8. Subprocessors

  1. Customer gives Staminal general authorization to use the Subprocessors listed in Schedule 3 for the stated purposes.
  2. Staminal will impose written data-protection and confidentiality obligations on each Subprocessor that are appropriate to the services it performs. Staminal remains responsible for the Subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.
  3. Staminal will provide notice through the Service, by email, or on this page before a new material Subprocessor begins processing Customer Personal Data. Customer may object on reasonable data-protection grounds by emailing director@staminal.in within 15 days after the notice.
  4. The Parties will work in good faith to address a reasonable objection. If no reasonable alternative is available, either Party may terminate the affected feature or Service under the Main Agreement. An objection does not remove payment obligations accrued before termination.

9. Customer-Directed Third-Party Integrations

The Customer may direct the Service to exchange data with third-party platforms such as Meta, Instagram, Facebook, WhatsApp, YouTube, Telegram, or other Customer-selected services. Those providers may act as independent Data Fiduciaries or Controllers under their own terms, rather than as Staminal's Subprocessors. Customer authorizes the requested exchange and is responsible for the third-party account, permissions, lawful use, and provider terms. Staminal is responsible for securely implementing its side of the integration.

10. International Processing and Transfers

  1. Customer authorizes Staminal and the listed Subprocessors to process Customer Personal Data in the locations shown in Schedule 3, subject to Applicable Data Protection Law.
  2. Staminal will not transfer Customer Personal Data to a country or territory prohibited by applicable Indian law. If another applicable law requires a recognized transfer mechanism or additional contract, the Parties will reasonably cooperate to put it in place before the restricted transfer.
  3. Where multiple laws apply, Staminal will follow the higher protection or restriction to the extent the obligations are compatible and applicable to its role.

11. Return, Retention, and Deletion

  1. During an active subscription, Customer may access and export available Customer Personal Data through the Service's ordinary functionality.
  2. Upon a verified deletion request or termination of the Service, Staminal will delete or return Customer Personal Data within the period agreed in the Main Agreement or, where no period is stated, ordinarily within 30 days after the request is verified and any required account-closure steps are complete.
  3. Deleted data may remain in access-controlled backups until normal backup rotation removes it. Backup data will not be used for ordinary Service operations and, if restored, will remain subject to the applicable deletion record.
  4. Staminal may retain selected records where required by law or reasonably necessary for a legal hold, fraud or security investigation, payment dispute, or establishment, exercise, or defence of legal claims. Retained data will be minimized, access-restricted, and used only for that purpose.
  5. Operational retention periods and the verified deletion process are further described in the Privacy Policy and Data Deletion Instructions.

12. Information and Audit Rights

  1. On reasonable written request, Staminal will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policy summaries, security descriptions, and available independent assessment material.
  2. If that information is insufficient for a requirement under Applicable Data Protection Law, Customer may request an audit no more than once in any 12-month period, except after a Personal Data Breach or where a regulator requires otherwise.
  3. An audit must be conducted by an independent qualified auditor under confidentiality obligations, on at least 30 days' notice, during normal business hours, without disrupting the Service or accessing another customer's data, source code, vulnerability details, or Staminal secrets. Customer bears its audit costs unless the audit identifies a material breach of this DPA by Staminal.

13. Term and Legal Effect

  1. This DPA starts when the Customer accepts or enters into the Main Agreement and continues while Staminal processes Customer Personal Data on the Customer's behalf. Electronic acceptance may be evidenced by the signer, Customer workspace, exact document version and hash, acceptance wording, authority confirmation, timestamp, and limited request metadata.
  2. If this DPA conflicts with the Main Agreement on processing Customer Personal Data, this DPA controls to the extent of that conflict. The Main Agreement otherwise remains in effect, including its commercial terms, disclaimers, and limitations of liability.
  3. This DPA does not reduce any non-waivable rights or obligations under Applicable Data Protection Law.
  4. Unless the Main Agreement states otherwise, this DPA is governed by the laws of India and disputes are subject to the competent courts in Chennai, Tamil Nadu.

Schedule 1 — Processing Details

Item Details
Subject matter Providing a tenant-isolated CRM for capturing, organizing, assigning, classifying, reporting, and following up on business enquiries and leads.
Duration For the term of the Main Agreement and the limited deletion, backup-rotation, and legally required retention periods described in this DPA.
Nature of processing Collection or receipt, recording, organization, storage, retrieval, consultation, classification, deduplication, assignment, display, transmission at Customer direction, backup, redaction, export, and deletion.
Purposes Lead capture and management, customer follow-up, connected-channel operation, reporting, Customer-authorized AI assistance, notifications, technical support, security, reliability, and compliance with Customer instructions.
Data Principals / Data Subjects Customer owners, managers, staff, authorized users, prospective customers, leads, customers, social-media users, message or comment senders, and other individuals whose enquiries the Customer lawfully manages.
Personal Data categories Names, business contact details, phone numbers, email addresses, social handles and identifiers, messages and comments, page/account metadata, timestamps, source, product or service interest, location, budget range, lead status, priority, notes, follow-up details, staff assignment, attachments, integration metadata, user roles, and relevant access or audit events.
High-risk data Not intentionally required by the Service. Customer must not submit the high-risk categories identified in Section 3 unless separately agreed in writing with appropriate safeguards.
Frequency Continuous or event-driven while the Customer uses the Service and its enabled integrations.

Schedule 2 — Technical and Organizational Measures

Staminal's baseline controls include:

Staminal may update these measures as technology and risk evolve, provided the overall protection of Customer Personal Data is not materially reduced.

Schedule 3 — Authorized Subprocessors

The following providers are authorized to process Customer Personal Data only for the described Service component. A provider marked "when enabled" receives data only when the corresponding feature is configured for the deployment or Customer.

Provider Purpose and data Processing location Status
Hetzner Online GmbH Cloud compute, network, application hosting, database, queue, and backup infrastructure; Customer Personal Data required to operate the hosted Service. European Union, according to the selected hosting region. Core hosting provider
Resend, Inc. Transactional email, OTP, invitation, password, and Service notification delivery; recipient name, email address, delivery metadata, and applicable message content. United States and locations used by its delivery infrastructure. When enabled
OpenAI, L.L.C. Customer-authorized AI classification and suggested-reply assistance; selected enquiry or lead text and the minimum related context required for the enabled feature. United States and other locations permitted under the provider terms. When enabled

Payment providers processing Staminal's subscription and billing records for their own regulated purposes are addressed in the Privacy Policy rather than this processor list. A separate object-storage provider will be added to this Schedule before Staminal enables that provider to store Customer lead attachments in production.