Data Processing Addendum
Last updated: June 11, 2026
In plain English
When you use Encrata, we may process personal data on your behalf, including information about your customers, users, employees, or other people you look up through our services.
You control the data you send to Encrata. We process it only to provide, secure, support, and improve the services you use. We do not sell it, we do not use it for unrelated purposes, and we protect it with appropriate technical and organizational safeguards.
Where data protection laws apply, Encrata acts as your processor or service provider. That means we handle personal data according to your instructions, use trusted subprocessors only where necessary, and take reasonable steps to help you meet your privacy and security obligations.
Your customers' data deserves the same care as your own. That is the point of this addendum.
If you have questions, contact us.
1. Scope
This Data Processing Addendum ("DPA") forms part of the agreement between Encrata ("Processor") and the customer ("Controller") and applies where Encrata processes personal data on behalf of the customer in connection with the Service, as required by the GDPR, UK GDPR, and CCPA.
2. Roles and Responsibilities
The customer acts as the data controller and determines the purposes and means of processing. Encrata acts as a data processor and processes personal data only on documented instructions from the customer, including with regard to international transfers, unless required otherwise by law.
3. Nature of Processing
- Subject matter: provision of OSINT and data enrichment APIs
- Duration: the term of the agreement
- Categories of data: identifiers submitted for lookup (emails, phone numbers, domains, IPs, images) and account data
- Data subjects: the customer's end users and lookup subjects
4. Confidentiality and Security
Encrata ensures persons authorized to process personal data are bound by confidentiality obligations. We implement appropriate technical and organizational measures, including encryption in transit (TLS 1.2+), encryption at rest, access controls, audit logging, and periodic security reviews.
5. Subprocessors
The customer provides general authorization for Encrata to engage subprocessors listed at encrata.com/legal/subprocessors. We will provide notice of changes and impose data protection obligations on subprocessors equivalent to those in this DPA.
6. International Transfers
Where personal data is transferred outside the EEA or UK, Encrata relies on the European Commission's Standard Contractual Clauses (SCCs) or other valid transfer mechanisms.
7. Data Subject Rights
Taking into account the nature of processing, Encrata will assist the customer with appropriate technical and organizational measures to respond to data subject requests (access, rectification, erasure, restriction, portability, objection).
8. Breach Notification
Encrata will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data, providing sufficient information to meet the customer's notification obligations.
9. Deletion and Return
Upon termination of the agreement, Encrata will delete or return all personal data processed on behalf of the customer within 30 days, unless retention is required by law.
10. Audits
Encrata will make available information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable notice and confidentiality.
11. Contact
To execute a signed copy of this DPA or for questions, contact privacy@encrata.com.