TL
TrueLead
ES ← Back to home

Data Processing Agreement

TrueLead — Data Processing Agreement ("DPA")

Last updated: September 22, 2026

Effective Date: September 22, 2026


Template notice: This document is a drafting template prepared for TrueLead (trueleadapp.com) and must be reviewed and adapted by a licensed attorney in the relevant jurisdictions before publication or execution. Square-bracketed items must be completed by the operator.

1. Preamble; Incorporation; Order of Precedence

1.1. This Data Processing Agreement ("DPA") is entered into by and between:

(a) Sareli Labs S.A.S., with registered address at Zapopan, Jalisco, Mexico ("TrueLead", "Processor", "we", "us"), operator of the TrueLead email and phone number validation service available at https://trueleadapp.com/ (the "Service"); and

(b) the customer entity or individual that has accepted the TrueLead Terms of Service and uses the Service to submit third-party contact data for validation ("Customer", "Controller", "you").

1.2. This DPA is incorporated into and forms part of the TrueLead Terms of Service and any order form, subscription, or other agreement between the parties governing the use of the Service (collectively, the "Agreement"). By submitting Submitted Data to the Service, the Customer accepts this DPA. This DPA applies to the processing of Personal Data by TrueLead on behalf of the Customer in connection with the Service.

1.3. Order of precedence. In the event of any conflict or inconsistency: (a) the Standard Contractual Clauses (where applicable under Section 7) prevail over this DPA and the Agreement; (b) this DPA prevails over the remainder of the Agreement with respect to the processing of Personal Data; and (c) the Agreement prevails over this DPA for all other matters.

1.4. This DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the processor obligations under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, "LFPDPPP") and its Regulations.

2. Definitions

Capitalized terms not defined below have the meanings given in the Agreement or in the GDPR.

2.1. "Submitted Data" means the email addresses, phone numbers, and any associated data that the Customer uploads, submits, or transmits to the Service (via dashboard, API, file upload, or otherwise) for validation, together with the validation results and metadata derived therefrom.

2.2. "Personal Data" means any information relating to an identified or identifiable natural person contained in Submitted Data. For the avoidance of doubt, email addresses and phone numbers of natural persons are treated as Personal Data.

2.3. "Controller" means the Customer, which alone determines the purposes and means of the processing of Submitted Data.

2.4. "Processor" means TrueLead, which processes Submitted Data on behalf of the Controller.

2.5. "Sub-processor" means any third party engaged by TrueLead to process Submitted Data in connection with the Service, as listed in Annex III.

2.6. "Data Subject" means the identified or identifiable natural person to whom Personal Data relates (typically the Customer's contacts, leads, or prospects).

2.7. "Processing" means any operation performed on Submitted Data, including collection, storage, analysis, validation, retrieval, transmission, and deletion.

2.8. "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Submitted Data transmitted, stored, or otherwise processed.

2.9. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, or any successor clauses adopted under the GDPR.

2.10. "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including, where applicable, the GDPR, the UK GDPR, the e-Privacy framework, the LFPDPPP and its Regulations, and other applicable data protection, privacy, and anti-spam legislation.

2.11. "Services" means the TrueLead real-time and bulk email and phone number validation API and web dashboard, as described in the Agreement.

3. Subject Matter, Duration, Nature, Purpose, and Categories of Processing

3.1. Subject matter. The processing of Submitted Data by TrueLead to provide the validation Services ordered by the Customer under the Agreement.

3.2. Duration. Processing will occur for the duration of the Customer's subscription and thereafter in accordance with the deletion and return provisions of Section 5.7 and Annex I.

3.3. Nature and purpose of processing. TrueLead processes Submitted Data solely to:

(a) perform real-time and bulk validation of email addresses, including syntax checks, domain and MX-record verification, disposable/temporary email detection, and mailbox verification;

(b) perform validation of phone numbers, including format validation, carrier lookup, and line-type identification;

(c) return validation results and derived validation metadata to the Customer via the dashboard and API;

(d) store Submitted Data transiently as required to deliver the results, operate the Service, ensure security, and comply with law.

TrueLead does not source, sell, rent, enrich, or otherwise commercialize contact data, and does not use Submitted Data for its own purposes, advertising, profiling beyond the requested validation, or to contact Data Subjects.

3.4. Categories of Data Subjects. The Customer's contacts, leads, prospects, customers, newsletter subscribers, or other individuals whose email addresses or phone numbers the Customer submits for validation.

3.5. Categories of Personal Data. (a) email addresses; (b) phone numbers; (c) derived validation metadata (e.g., deliverability status, syntax/domain/MX check results, disposable-email flags, mailbox verification outcomes, phone carrier and line-type information, timestamps, and validation request logs).

3.6. Special categories prohibited. The Customer shall not submit to the Service special categories of personal data within the meaning of Article 9 GDPR (e.g., data revealing racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, sexual orientation) or sensitive personal data within the meaning of the LFPDPPP, nor personal data relating to criminal convictions or offences (Article 10 GDPR). The Service is designed to process email addresses and phone numbers only; the Customer must not include additional personal data fields in submissions.

4. Controller Obligations

4.1. Lawful basis and authority. The Controller warrants and represents that: (a) it has a valid lawful basis under applicable Data Protection Laws for the collection of Submitted Data and its transfer to TrueLead for processing; (b) it has provided all required notices to, and obtained all necessary consents from, Data Subjects; (c) it has the authority and all necessary rights to submit Submitted Data to the Service; and (d) the processing contemplated by this DPA will not violate any applicable law or third-party right.

4.2. Instructions. The Customer instructs TrueLead to process Submitted Data as necessary to provide the Services pursuant to the Agreement and this DPA, as further configured by the Customer in the dashboard or API, and as otherwise instructed in writing. The Customer is responsible for the lawfulness and accuracy of its instructions.

4.3. Compliance with anti-spam and marketing laws. The Controller is solely responsible for ensuring that its collection and use of contact data, and any subsequent communications with Data Subjects, comply with applicable anti-spam, telemarketing, and e-privacy laws (including, as applicable, the CAN-SPAM Act, the TCPA, the EU e-Privacy Directive and national implementations, and applicable Mexican law).

4.4. Data quality and minimization. The Controller shall submit only data necessary for validation and shall not submit special categories of data (Section 3.6).

5. Processor Obligations

5.1. Documented instructions. TrueLead shall process Personal Data only on the Controller's documented instructions, including with regard to transfers to third countries, unless required to do so by applicable law; in such case, TrueLead shall inform the Controller of that legal requirement before processing, unless prohibited by law.

5.2. Confidentiality. TrueLead shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3. Personnel access controls. Access to Submitted Data is limited to authorized personnel on a need-to-know, least-privilege basis, subject to access management, authentication controls, and training as described in Annex II.

5.4. Security. TrueLead shall implement and maintain the technical and organizational measures described in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.

5.5. Assistance. Taking into account the nature of the processing, TrueLead shall provide reasonable assistance to the Controller, by appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Controller's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection) under Chapter III GDPR and ARCO rights (access, rectification, cancellation, opposition) under the LFPDPPP; and shall provide reasonable assistance with data protection impact assessments (DPIAs) and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, where the information is not otherwise available to the Controller. TrueLead may charge a reasonable fee for assistance beyond routine support.

5.6. Personal Data Breach notification. TrueLead shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Submitted Data, with a target notification time of within seventy-two (72) hours of awareness. The notification shall describe, to the extent then known: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed. TrueLead shall provide reasonable further information as it becomes available.

5.7. Deletion or return. At the end of the provision of Services, at the Customer's choice, TrueLead shall delete or return all Submitted Data to the Customer, and delete existing copies, unless applicable law requires storage. Default: unless the Customer requests return in writing before or within 14 days after termination, TrueLead will delete Submitted Data within thirty (30) days of termination or expiry of the Agreement, subject to legally required retention and backup cycle deletion as described in Annex II.

5.8. Audits. TrueLead shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA. At the Controller's written request, no more than once in any twelve (12) month period (unless following a Personal Data Breach or as required by a supervisory authority), TrueLead shall respond to reasonable written security questionnaires and make available relevant third-party reports, certifications, and attestations of its Sub-processors (e.g., AWS compliance reports under NDA). The parties agree that questionnaires and third-party reports are generally sufficient; on-site audits will be permitted only where required by law or where the foregoing is demonstrably insufficient, subject to at least thirty (30) days' prior written notice, reasonable scope and duration, confidentiality obligations, and the Customer bearing its own costs.

5.9. Objection to instructions. TrueLead shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR, other Data Protection Laws, or the LFPDPPP.

6. Sub-processors

6.1. General authorization. The Controller grants TrueLead general written authorization to engage the Sub-processors listed in Annex III (currently Amazon Web Services, Inc.; Stripe, Inc.; and Functional Software, Inc. d/b/a Sentry) and additional or replacement Sub-processors, subject to this Section 6.

6.2. Notice of changes and right to object. TrueLead shall provide the Controller with at least thirty (30) days' advance written notice (via email to the account address or dashboard notification) of any intended addition or replacement of a Sub-processor. The Controller may object in writing, on reasonable data protection grounds, within fourteen (14) days of the notice. If the Controller objects, the parties shall cooperate in good faith to find a commercially reasonable solution; if none is found, the Controller may terminate the affected Services with notice before the change takes effect, and TrueLead shall refund any prepaid, unused fees for the terminated period.

6.3. Flow-down obligations. TrueLead shall impose on each Sub-processor data protection obligations no less protective than those in this DPA and shall remain fully liable to the Controller for the performance of each Sub-processor's obligations.

7. International Transfers

7.1. Processing location. All Submitted Data is processed and stored on AWS infrastructure in the us-east-1 region (United States). Payments are processed by Stripe, and error-monitoring data is processed by Sentry (US). Accordingly, Personal Data is transferred to and processed in the United States.

7.2. Transfer mechanism. Where the GDPR applies to the Controller's transfer of Personal Data to TrueLead, the parties agree that the Standard Contractual Clauses, Module 2 (Controller to Processor), as adopted by Commission Implementing Decision (EU) 2021/914, are incorporated into this DPA by reference and apply as follows: (a) the Controller is the "data exporter" and TrueLead is the "data importer"; (b) the docking clause (Clause 7) is deemed included; (c) for Clause 9, Option 2 (general written authorization) applies with a 30-day notice period; (d) for Clause 11, the optional independent dispute resolution clause is not included; (e) for Clauses 17 and 18, the governing law and forum shall be those of the EU Member State of the data exporter; (f) Annexes I and II of this DPA serve as Annexes I and II of the SCCs.

7.3. Supplementary measures. TrueLead implements supplementary technical and organizational measures, including encryption in transit (TLS) and access controls as described in Annex II, and will notify the Controller if it becomes subject to legal process requiring disclosure of Personal Data to a government authority, to the extent legally permitted, and will challenge or seek to narrow such requests where reasonable.

7.4. Mexico (LFPDPPP). For Controllers subject to the LFPDPPP, the parties acknowledge that cross-border transfers are made pursuant to the Controller's instructions and that TrueLead assumes the processor obligations applicable under the LFPDPPP and its Regulations, including processing only per the Controller's instructions, implementing security measures, maintaining confidentiality, and deleting Submitted Data upon termination absent a legal retention obligation.

8. Liability

8.1. Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service). Nothing in this DPA limits liability that cannot be limited under applicable law, nor any liability of TrueLead to Data Subjects under Article 82 GDPR where applicable.

8.2. The Controller shall indemnify and hold TrueLead harmless from claims by Data Subjects or third parties, and fines or penalties, arising from the Controller's breach of Sections 3.6, 4.1, or 4.3, to the extent permitted by law.

9. Term and Termination

9.1. This DPA takes effect on the Effective Date (or the date the Customer first submits Submitted Data, if later) and continues for the duration of the Agreement.

9.2. Upon termination or expiry of the Agreement, Sections 5.7 (deletion/return), 7 (transfers, until deletion), 8 (liability), and this Section 9 survive. Deletion timelines follow Section 5.7.


ANNEX I — Details of Processing

ItemDescription
Data Exporter (Controller)The Customer, as identified in its TrueLead account and the Agreement. Contact: the email address associated with the Customer's account. Activities: use of the TrueLead Service to validate its own contact lists. Role: Controller.
Data Importer (Processor)Sareli Labs S.A.S., Zapopan, Jalisco, Mexico. Contact: hola@trueleadapp.com. Activities: provision of the TrueLead email and phone validation Service. Role: Processor.
Subject matterProcessing of Submitted Data to provide email and phone number validation services.
DurationDuration of the Customer's subscription; deletion within 30 days after termination unless return is requested (see Section 5.7).
Nature and purposeReal-time and bulk validation of email addresses (syntax, domain, MX records, disposable-email detection, mailbox verification) and phone numbers (format, carrier, line type); storage, retrieval, and transmission of validation results; security and operational logging. TrueLead does not source, sell, or enrich contact data.
Categories of Data SubjectsCustomer's contacts, leads, prospects, customers, and subscribers.
Categories of Personal DataEmail addresses; phone numbers; derived validation metadata (deliverability status, check results, flags, carrier/line-type, timestamps, request logs).
Special categoriesNot processed; submission prohibited (Section 3.6).
FrequencyContinuous, as initiated by the Customer via dashboard or API.
RetentionSubmitted Data and results retained for the duration of the account/subscription or as configured by the Customer; deleted within 30 days of termination; residual backup copies deleted according to backup cycles (target: within 90 days).
Sub-processingSee Annex III.

ANNEX II — Technical and Organizational Measures

TrueLead maintains, at a minimum, the following measures:

  1. Encryption in transit. All traffic between the Customer, the dashboard, and the API is encrypted using TLS (HTTPS). Connections to Sub-processors are encrypted in transit.
  2. Infrastructure security. The Service is hosted on Amazon Web Services (us-east-1), which maintains physical, environmental, and network security controls and holds industry certifications (e.g., ISO 27001, SOC 1/2/3, PCI DSS). Static assets are served via AWS CloudFront; API traffic via AWS API Gateway.
  3. Authentication and account security. Customer account authentication is managed via AWS Cognito (email + password), with hashed credential storage and AWS-managed account-security controls. API access requires per-customer API keys; keys can be rotated or revoked by the Customer.
  4. Access control (least privilege). Internal access to production systems and Submitted Data is restricted to authorized personnel on a least-privilege, need-to-know basis, with unique credentials and administrative access logging.
  5. Logging and monitoring. Application errors and anomalous behavior are monitored via Sentry (US), configured to minimize Personal Data in error payloads; access and security events are logged to support incident detection.
  6. Availability and backups. The Service leverages AWS managed infrastructure designed for high availability; backup and recovery rely on AWS-native mechanisms, with deletion of residual copies per backup cycles.
  7. Incident response. TrueLead maintains an incident response process covering detection, triage, containment, eradication, recovery, post-incident review, and Controller notification per Section 5.6.
  8. Personnel. Personnel with access to Personal Data are bound by confidentiality obligations and receive data-protection and security guidance appropriate to their role.
  9. Data minimization in tooling. Validation requests are processed transiently; payment card data is never handled by TrueLead (Stripe-only); monitoring tools are configured to avoid capturing Submitted Data payloads where feasible.
  10. Secure development. Changes to production systems follow review and deployment practices designed to preserve confidentiality, integrity, and availability.
  1. Encryption at rest. Data stored in AWS services (S3, DynamoDB, CloudWatch) is encrypted at rest using AWS-managed server-side encryption.

ANNEX III — Approved Sub-processors

Sub-processorServiceLocationPurpose
Amazon Web Services, Inc.Cloud hosting: S3 (storage), CloudFront (CDN), API Gateway (API), Cognito (authentication)United States (us-east-1)Hosting, storage, delivery, and operation of the Service; customer authentication
Stripe, Inc.Payment processing; Stripe Customer PortalUnited States (global processing)Subscription billing, invoicing, payment method management, dunning
Functional Software, Inc. (Sentry)Error and performance monitoringUnited StatesDetection and diagnosis of application errors and service reliability

This template must be reviewed by a licensed attorney qualified in the applicable jurisdictions before publication or execution.

© 2026 TrueLead — Sareli Labs S.A.S., Zapopan, Jalisco, Mexico.
hola@trueleadapp.com
Terms Privacy Cookies DPA Refunds Acceptable Use