Legal documents

Breakcold · Legal

Data processing addendum

Last updated · September 3, 2026

Our obligations when processing customer data, including security, transfers and the provider inventory.

This document is available in English. The English version is shown below.

On this page

1. Scope, parties and interpretation

This Data Processing Addendum (DPA) forms part of the agreement for Breakcold services between the customer identified in the subscription or order (Customer) and Logike SAS, SIRET 90230339500021, 128 rue de la Boétie, 75008 Paris, France (Breakcold). It applies when Breakcold processes personal data on the Customer’s behalf (Customer Personal Data). Data protection contacts: support@breakcold.com; company contact: contact@breakcold.com.

The Customer acts as controller, or as processor for a controller that has authorized these services. Breakcold acts as processor or subprocessor accordingly. References to the Customer’s instructions include the lawful instructions of that underlying controller communicated through the Customer. The terms controller, processor, personal data, processing and personal data breach have the meanings given in the GDPR. Applicable data protection law means the laws governing the processing covered here, including the GDPR where applicable.

This DPA prevails over conflicting service terms about Customer Personal Data. Mandatory transfer terms prevail where they conflict with this DPA. Neither this DPA nor a limitation in the service agreement restricts a person’s statutory rights or an authority’s powers. Breakcold’s separate controller activities are described in its Privacy Policy and are not converted into customer processing by this DPA.

2. Instructions and customer responsibilities

The Customer instructs Breakcold to process Customer Personal Data to provide the subscribed services, including actions selected through workspace settings, authorized users, integrations, APIs and support requests. The processing description below specifies the permitted scope. Additional instructions must be documented and agreed where they change that scope. Breakcold will not use Customer Personal Data for its own advertising, sell it or use it to train generalized AI models.

Breakcold will process Customer Personal Data only on documented instructions, including instructions about transfers, unless Union or Member State law requires otherwise. In that case Breakcold will inform the Customer of the legal requirement before processing unless the law prohibits this on important public-interest grounds. Breakcold will immediately inform the Customer if, in its opinion, an instruction infringes applicable data protection law. It may suspend the affected instruction while the parties resolve the issue, rather than carry out unlawful processing.

The Customer determines purposes, lawful bases, notices, retention instructions and authorized access. It must obtain required permissions for imported contacts, communications, connected accounts and recordings, including from its underlying controller if it is a processor. Public professional information remains personal data. Customer instructions must respect applicable law and platform restrictions; the availability of a feature is not permission to collect or contact people unlawfully.

Authorized integration data may include session cookies and authentication tokens needed for the connected account. These are processed only for the documented connection functions and subject to the credential safeguards in Annex B. Applicable data protection law includes the French Data Protection Act, Law No. 78-17 of 6 January 1978, as amended, where it governs the processing.

2.1. California service-provider terms

Where the California Consumer Privacy Act, as amended, applies to Customer Personal Data processed under this DPA, Breakcold acts as the Customer’s service provider. The limited business purposes are CRM storage and organization, authorized communication synchronization, customer-requested AI processing, export, deletion, security and related support, as specified in Annex A. The CCPA defines the California terms used here.

Breakcold will not sell or share that information, retain, use or disclose it outside those specified purposes or the direct business relationship with the Customer, or combine it with information from other customers or its own interactions with individuals, except as expressly permitted by the CCPA. Breakcold certifies that it understands and will comply with these restrictions.

Breakcold will comply with applicable CCPA obligations and provide the required level of privacy protection, including assistance with consumer requests and reasonable security. It will notify the Customer if it can no longer comply. The Customer may take reasonable and appropriate steps to verify compliance and stop and remedy unauthorized use through the information and audit arrangements in this DPA. Authorized downstream providers must be bound to equivalent applicable restrictions and notified under the subprocessor provisions.

3. Confidentiality and security

Breakcold will ensure that people authorized to process Customer Personal Data are subject to confidentiality commitments or an appropriate statutory duty and have access only as needed for their functions. Access to production data, credentials and support material must be controlled and removed when no longer justified.

Breakcold will maintain technical and organizational measures proportionate to the nature and risk of the processing, as specified in the security annex below. Measures will be reviewed as the service changes; updates must not materially reduce the protection required by this DPA. The Customer manages its own users, permissions, devices and instructions and should report suspected unauthorized access promptly.

4. Subprocessor authorization and changes

The Customer gives general written authorization for the providers in the inventory below to process Customer Personal Data when their functions are used and when they act as subprocessors. This is not authorization for independent advertising or for sharing unrelated customer content. Before entrusting data to a subprocessor, Breakcold will impose written obligations that provide equivalent protection for that processing, including confidentiality, security, assistance, deletion and lawful transfers. Breakcold remains fully liable to the Customer for the subprocessor’s performance of those obligations.

Breakcold will notify the Customer’s account or designated privacy contact at least 30 days before adding or replacing a subprocessor that will receive Customer Personal Data. Notice will describe its identity, function, relevant data, processing locations and transfer safeguards, so that the Customer can evaluate the change. Publishing a changed list alone does not replace this advance notice.

The Customer may object during the notice period on reasonable, documented data protection grounds. The parties will seek a practical solution, such as additional safeguards, another provider or disabling the affected feature. The proposed provider will not receive the objecting Customer’s data while the objection remains unresolved. If no suitable solution can be agreed, either party may end the affected service before the proposed processing begins; Breakcold will refund prepaid fees for its unused terminated portion. Other services may continue where they can operate without that provider.

5. Assistance and requests from people

Breakcold will assist the Customer, taking account of the processing and information available to it, with requests for access, correction, erasure, restriction, portability, objection and other applicable rights. It will promptly pass on requests concerning Customer Personal Data and will not decide the request for the Customer unless instructed or legally required. Assistance may include locating relevant records, supplying exports and applying authorized changes or restrictions.

Breakcold will also assist with security obligations, breach assessment and notifications, data protection impact assessments and consultation with authorities when the processing requires them. The parties will agree practical steps proportionate to the request. Any separately agreed charges for extraordinary assistance must not prevent performance of mandatory duties or timely cooperation.

6. Personal data breaches

Breakcold will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notice will be sent to the account or designated privacy contact and will contain the information then available: the nature of the breach, affected data and people including approximate numbers where known, likely consequences, mitigation taken or proposed, and a contact for further information. Missing details will follow in phases without undue further delay.

Breakcold will take appropriate containment, investigation and remediation steps and preserve relevant evidence. It will cooperate so that the Customer can meet its own obligations. The controller’s potential 72-hour notification period is not a period Breakcold may wait before informing the Customer. Unless law requires otherwise, the Customer decides notices to affected people and authorities for processing it controls.

7. Information and audits

Breakcold will make available information necessary to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by the Customer or an independent auditor it appoints. The parties will first consider existing documentation and remote review where these adequately address the question; those options do not eliminate the right to an inspection where needed.

Audits must protect other customers’ data, confidential information and system security. The parties will agree reasonable notice, scope and scheduling, without preventing urgent review after an incident, credible non-compliance concern or an authority’s request. Confidentiality arrangements and proportionate access controls may apply, but neither a fixed annual cap nor an unavailable certification may be used to avoid demonstrating compliance. Breakcold will address substantiated deficiencies and cooperate with competent supervisory authorities.

Breakcold will retain the records needed to demonstrate compliance with this DPA for five years after its termination. Those records are limited to relevant instructions, agreements, requests, security and compliance evidence. This period does not authorize retaining all Customer Personal Data or workspace content for five years. Unnecessary personal data in compliance records must be removed or anonymized.

8. Return, deletion and duration

Processing lasts for the service relationship and the limited period needed to complete the Customer’s lawful return or deletion instructions. At the end of the relevant services, the Customer may choose return or deletion of Customer Personal Data. Breakcold will provide a usable return arrangement, then delete remaining copies, or delete without return if the Customer chooses that option, unless Union or Member State law requires retention.

The parties will document the return format, scope and completion schedule in light of the data and applicable deadlines. Breakcold will not retain processor data merely for its own business convenience. Pending completion, access is restricted and processing limited to protection, return, deletion or a binding legal requirement. Where an immediate selective deletion from a backup is technically unavailable, the data remains protected and out of ordinary use until deletion through its applicable lifecycle; any restoration must reapply the deletion instructions. Breakcold will explain any legal retention requirement and confirm completion on request.

This DPA remains effective for any Customer Personal Data retained by Breakcold. Ending a subscription or disconnecting a provider does not itself specify the Customer’s export choice. The Customer should give instructions to support@breakcold.com and provide a working contact for completion.

In the current application at us.breakcold.com and eu.breakcold.com, authorized users can export supported CRM records and selected fields as CSV. Each export is limited to 10,000 records and 8 MiB. Larger selections may need separate exports. Generated downloads remain available for seven days after completion. Contact support before access ends for data categories not covered by that interface or for help with a switching request. These technical limits do not restrict mandatory rights to return, portability or switching.

9. International transfers

Breakcold is a French company. Receiving data in France from an EEA customer does not by itself create a transfer to a third country. Hosting, remote access and onward processing must each be assessed on their actual locations and circumstances. Breakcold will not make a restricted transfer of Customer Personal Data without the applicable legal mechanism and any necessary supplementary safeguards.

For a relevant EEA transfer, Breakcold may rely on an applicable adequacy decision or put in place the European Commission standard contractual clauses, Decision (EU) 2021/914 where they are suitable. Controller-to-processor transfers use Module Two; processor-to-subprocessor transfers use Module Three. The correct module follows the parties’ actual roles and the scope of the clauses, rather than treating every Customer as controller or Breakcold as a non-EEA importer.

Before relying on those clauses, the parties to the actual transfer must identify exporter and importer, their contacts and roles in Annex I.A; describe data subjects, data, purposes, frequency, duration and onward processing in Annex I.B; identify the competent authority under Clause 13 in Annex I.C; specify the actual security measures in Annex II and any required subprocessor information in Annex III. The processing and security annexes below provide relevant inputs, but do not supply unknown importer identities, locations or measures. Clause options, applicable law and courts must be completed consistently with that transfer. Breakcold will assess transfer risks, obtain necessary information from recipients and suspend an affected transfer if adequate protection cannot be maintained.

Where UK transfer rules require contractual safeguards, use the applicable ICO International Data Transfer Agreement or UK Addendum to the EU clauses, with its tables and mandatory provisions properly completed; obsolete pre-GDPR UK clauses are not incorporated here. Swiss transfers require safeguards adapted to applicable Swiss requirements where necessary. These mechanisms are used only when required and applicable. The unmodified mandatory transfer terms take priority; contact support@breakcold.com for the relevant completed documentation and safeguards, subject to justified confidentiality redactions.

Annex A. Description of processing

ItemScopeInstructions and limits
Subject and purposeProvision of the subscribed CRM and related communication, collaboration and automation functions.Customer workspace settings, authorized feature use and documented support instructions define the operations.
Operations and frequencyCollection, import, organization, storage, retrieval, synchronization, display, transmission, analysis, export, restriction and deletion; ongoing during use and event-driven for integrations.No independent commercial reuse of Customer Personal Data.
PeopleCustomer personnel and authorized users; prospects, customers, partners, suppliers and other professional contacts; senders, recipients and people appearing in submitted communications, files or recordings.Customer determines whose information is submitted and supplies required notices and permissions.
DataIdentity and professional contact data, company and relationship details, pipeline records, tasks, notes, communications and metadata, files and media, authorized integration data and credentials, audio and transcripts, AI prompts and outputs.Only categories needed by the enabled function should be supplied.
Conditional featuresEmail/social synchronization and sending; file processing; calls, recordings, transcription and summaries; AI assistance; website scraping, place, logo, avatar and favicon lookup.Applies only where used or enabled. Relevant inputs are sent to the providers needed for that function. Customer must establish any required recording or third-party account permissions.
Sensitive dataThe service is not intended for routine storage of Article 9 special-category data or Article 10 criminal-offence data. Communications may nevertheless contain sensitive information.Do not intentionally submit such data without an agreed lawful processing arrangement and appropriate safeguards. Limit access, disclosure and retention if it is present.
DurationSubscription term plus completion of return/deletion and any mandatory legal retention.See section 8; a particular backup deletion period is not promised by this annex.

AI routing through OpenRouter may involve downstream model providers. The gateway name alone does not identify every recipient. Breakcold must ensure that relevant downstream processing is covered by authorization, contractual safeguards and transfer information before sending Customer Personal Data. The inventory does not represent a certification of every possible model available through a gateway.

Annex B. Security commitments

These measures are obligations for the processing covered by this DPA. Their implementation must remain proportionate to the data, system and risks; this annex does not assert a SOC 2 or ISO certification, a specific data-center control or an audit result.

  • Access management: identify authorized users and administrative personnel; restrict privileges to their functions; protect privileged authentication; review access when duties change and remove it when no longer needed.
  • Credential and transmission protection: use secure transport for service connections; protect stored access tokens and secrets through appropriate encryption and restricted access; prevent secrets from appearing in ordinary logs and revoke or replace compromised credentials.
  • Workspace boundaries: apply authorization checks so that a user or integration receives only the workspace data it is entitled to access; validate requested actions at the service boundary.
  • Operational security: maintain relevant security logs, monitor and investigate errors and suspected misuse, control production changes, address vulnerabilities in proportion to risk and keep an incident response process with assigned responsibilities.
  • Resilience: maintain suitable recovery arrangements for stored customer data and assess the ability to restore availability after an incident; protect recovery copies and restrict their use. No particular recovery-time or recovery-point objective is created here.
  • Data lifecycle: minimize unnecessary copies and disclosures; restrict support access to the relevant request; apply return, retention and deletion instructions, including to restored backups.
  • Accountability and suppliers: bind authorized personnel to confidentiality; assess providers appropriate to their role, document necessary processing and transfer arrangements, and periodically evaluate the effectiveness of these safeguards.

Annex C. Provider inventory and roles

The following inventory identifies the listed providers, data categories and functions. A provider is a subprocessor under this DPA only to the extent it actually processes Customer Personal Data on Breakcold’s behalf to deliver an instructed service. Some functions, including Breakcold’s own billing, product administration and marketing conversion measurement, may instead concern controller data under the privacy policy. A provider may also be an independent controller for a separate purpose. The inventory is not an instruction to disclose CRM or mailbox contents for advertising.

ProviderData categoriesPurpose of processing
ConvexAccount data, CRM data, contacts, communications, tasks, notes, files, media metadata, AI outputs, and billing references.Core database, backend, and file storage.
Cloudflare Workers/KVAPI requests, authentication data, session and token data, request metadata, and API payloads.API infrastructure.
VercelApplication requests, session context, browser and device data, IP and network data, and technical logs.Application hosting.
WorkOS AuthKitIdentity data, contact details, organization membership, authentication credentials, sessions, and security metadata.Authentication.
StripeBilling identity, subscription data, invoices, payment data, tax information, and transaction metadata.Billing.
ResendSender and recipient contact data, email content, email metadata, and delivery events.Transactional email.
CrispUser identity and contact data, support messages, attachments, and support-session metadata.Customer support.
TinybirdWorkspace identifiers, usage data, product events, record and pipeline metadata, and operational analytics.Product analytics.
OpenRouterUser prompts, CRM data, email and message content, transcripts, website content, AI outputs, and technical request metadata.AI gateway.
OpenAIAudio data, transcription content, summary inputs and outputs, and technical request metadata.AI processing.
FirecrawlCustomer-provided website URLs, publicly available website content, page metadata, and scraping request metadata.Website scraping.
Google PlacesLocation searches, address data, place identifiers, and request metadata.Location lookup.
Logo.devCompany names and domains, logo requests, and image-request metadata.Company branding.
GravatarEmail-derived identifiers, avatar requests, and technical request metadata.Avatar lookup.
Google Favicon serviceCompany domains, favicon requests, and technical request metadata.Favicon lookup.
Google Tag Manager / Google AdsBrowser identifiers, device data, online activity, page events, and conversion data.Marketing analytics.
LinkedIn Conversions APIHashed contact identifiers, account identifiers, and subscription and conversion event data.Conversion tracking.

Not every provider receives every customer’s data. AI, scraping, location and image lookup depend on the relevant feature or request. The table does not establish processing countries, downstream recipients or transfer mechanisms; those must be documented for the applicable processing. Optional landing-site tools and consent categories are separately described in the Cookie Policy. Contact support@breakcold.com for relevant provider details or change notices.