Data Processing Addendum
Last updated: July 30, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Smith Business Solutions SRL (“STOICA”, “we”, the “Processor”), Trade Register No. J29/1411/2014, CIF RO33734100, sat Predesti, com. Tinosu, nr. 28, Prahova, Romania, and the client organization using the noombat platform (the “Customer”, the “Controller”). It applies whenever we process personal data on the Customer's behalf in providing the Service, and is accepted together with the Terms. A countersigned copy is available on request at hello@noombat.ai.
“GDPR” means Regulation (EU) 2016/679; “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given there. “Customer Personal Data” means personal data the Customer submits to the Service or instructs the Service to obtain on its behalf, as described in Annex 1.
1. Roles and scope
For Customer Personal Data, the Customer is the controller and we are the processor. This DPA does not apply to data we process as an independent controller — our own website, marketing, accounts and usage telemetry — which is covered by our Privacy Policy. The Customer warrants that it has a lawful basis for the Customer Personal Data it brings into the Service and for the processing it instructs.
2. Instructions
We process Customer Personal Data only on the Customer's documented instructions — the Agreement, this DPA, the Customer's configuration and use of the Service, and any further written instructions — unless required otherwise by EU or member-state law, in which case we inform the Customer before processing unless the law forbids it. We will inform the Customer if, in our opinion, an instruction infringes the GDPR.
Purpose limitation. We process Customer Personal Data only to provide the Service. We do not sell it; we do not use it to train artificial-intelligence or machine-learning models; and we do not combine it with the data of other customers or with data from other sources, except as strictly necessary to provide the Service to the Customer. We may derive aggregated or fully anonymized data that no longer identifies the Customer or any individual; once anonymized in line with applicable data-protection standards, such data falls outside the scope of this DPA.
3. Confidentiality
We ensure that every person we authorize to process Customer Personal Data is bound by confidentiality obligations, contractual or statutory. Personnel with access to Customer Personal Data receive appropriate data-protection training.
4. Security
We implement and maintain the technical and organizational measures described in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, to ensure a level of security appropriate to the risk (Article 32 GDPR). We may update those measures provided the update does not materially reduce the overall level of protection.
5. Subprocessors
The Customer gives general authorization for the subprocessors listed in Annex 3. We will give at least thirty (30) days' notice (by email to Workspace administrators or in the product) before adding or replacing a subprocessor. The Customer may object on reasonable data-protection grounds within that period; if we cannot offer a reasonable alternative, the Customer may terminate the affected feature or the Agreement and receive a pro-rata refund of prepaid unused fees for it. We impose data-protection obligations on each subprocessor materially equivalent to this DPA and remain liable for their performance.
6. Data subject requests
Taking into account the nature of the processing, we assist the Customer with appropriate technical and organizational measures in fulfilling its obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts us directly about data in a Customer workspace, we will forward the request to the Customer without undue delay and will not respond substantively except on the Customer's instruction or where legally required.
7. Assistance
We assist the Customer, insofar as reasonably possible and taking into account the information available to us, with its obligations under Articles 32–36 GDPR (security, breach notification, data-protection impact assessments and prior consultation).
8. Personal data breach
We notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data, providing the information reasonably available to us — nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed — and we supplement the notice as more information becomes available.
9. International transfers
Customer Personal Data is stored in the EU (Frankfurt). Where processing by us or a subprocessor takes place outside the EEA (see Annex 3), we ensure a valid transfer mechanism: an adequacy decision, certification under the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses (2021/914) — applying the module appropriate to the transfer (Module Two, controller-to-processor, or Module Three, processor-to-processor) — with the UK and Swiss addenda where relevant.
10. Government and law-enforcement requests
If a public authority or law-enforcement body requests access to Customer Personal Data, we will direct the authority to request the data from the Customer directly, and will notify the Customer without undue delay unless legally prohibited from doing so. Where a legally binding demand compels disclosure, we will disclose only the minimum necessary to comply, and we will use reasonable efforts to challenge demands that appear unlawful or overbroad.
11. Audits
We make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR — documentation, security summaries and third-party attestations where available. Where that is insufficient, the Customer may audit (itself or via a non-competitor auditor bound to confidentiality) at most once per year, on thirty (30) days' notice, during business hours, without disrupting operations, at the Customer's cost. Audits may occur more often after a personal data breach affecting the Customer or where a supervisory authority requires it.
12. Deletion and return
On termination of the Agreement, we will, at the Customer's choice, return Customer Personal Data in a common machine-readable format and/or delete it, within thirty (30) days of the request and in any event within sixty (60) days of termination — except where EU or member-state law requires retention. Residual copies in encrypted backups are deleted in the ordinary rotation cycle and remain protected by this DPA until deleted. We confirm deletion in writing on request.
13. Liability, term and order of precedence
Each party's liability under this DPA is subject to the limitations and exclusions of the Agreement, except that nothing limits either party's liability with respect to a data subject's own rights under the GDPR. If this DPA conflicts with the Agreement on data-protection matters, this DPA prevails.
This DPA takes effect together with the Terms and remains in force for as long as we process Customer Personal Data, surviving termination of the Agreement until deletion or return under Section 12 is complete.
Annex 1 — Details of processing
- Subject matter and duration: provision of the noombat platform to the Customer, for the duration of the Agreement plus the deletion period in Section 12.
- Nature and purpose: hosting, storage, synchronization with the Customer's connected systems (e.g. CRM), enrichment and signal collection from the providers in Annex 3 on the Customer's behalf, scoring and prioritization, AI-assisted analysis, display to authorized Users, and optional delivery to integrations the Customer connects (e.g. Slack).
- Categories of data subjects: the Customer's prospects, leads, customers and their personnel; the Customer's Users; where the Customer enables website-visitor identification, visitors to the Customer's website.
- Categories of personal data: business contact data (name, role/title, work email, phone numbers — including mobile numbers where present in the Customer's CRM or obtained through enrichment the Customer requests — business social-profile URLs, employer), CRM engagement and interaction data, buying-signal and intent data, network-derived identifiers (IP address, company match) for visitor identification. No special categories of data — the Agreement prohibits submitting them.
Annex 2 — Technical and organizational measures
- Access control: workspaces are organization-scoped; every server-side access path enforces organization membership and role checks; platform administration is restricted to named personnel
- Authentication: passwordless email sign-in links to verified work addresses; no shared passwords
- Encryption: TLS for data in transit; encryption at rest via the hosting providers
- Data location: primary database hosted in the EU (Frankfurt)
- Secrets management: credentials and API keys held in a dedicated secrets manager, never in code or client-side variables
- Segregation: each client's data is logically separated per organization schema/scoping
- Operations: scheduled jobs authenticate with bearer secrets; inbound webhooks are verified; audit logging of administrative tenancy actions
- Personnel: access limited to those who need it to operate the Service, under confidentiality obligations
- Resilience: managed backups with encrypted storage and periodic rotation
Annex 3 — Authorized subprocessors
Current subprocessors of Customer Personal Data, the processing role they perform and their location. Providers marked “feature-gated” process data only where the Customer uses the relevant feature or integration:
- Vercel Inc. (USA/EU) — application hosting and edge network
- Supabase Inc. (EU — Frankfurt) — database and authentication infrastructure
- Anthropic PBC (USA) — AI processing for the Snout analyst; API terms exclude model training on submitted data
- PostHog Inc. (USA) — product usage analytics
- Slack Technologies / Salesforce (USA) — messaging integration (feature-gated, Customer-installed)
- HubSpot Inc. (USA/EU) — CRM synchronization (feature-gated, Customer-connected)
- Specialized data-enrichment and signal providers (EU/USA) — contact enrichment, company research and website-visitor identification, all feature-gated. To protect our vendor relationships we do not name these providers publicly; the complete, named list is provided to Customers on request at hello@noombat.ai and every addition or replacement follows the Section 5 notice-and-objection process.
Contact
Smith Business Solutions SRL · Trade Register No. J29/1411/2014 · CIF RO33734100
sat Predesti, com. Tinosu, nr. 28, Prahova, Romania, 107612
hello@noombat.ai