Data Processing Addendum

Last updated: June 11, 2026

In plain English

When you use Encrata, we may process personal data on your behalf, including information about your customers, users, employees, or other people you look up through our services.

You control the data you send to Encrata. We process it only to provide, secure, support, and improve the services you use. We do not sell it, we do not use it for unrelated purposes, and we protect it with appropriate technical and organizational safeguards.

Where data protection laws apply, Encrata acts as your processor or service provider. That means we handle personal data according to your instructions, use trusted subprocessors only where necessary, and take reasonable steps to help you meet your privacy and security obligations.

Your customers' data deserves the same care as your own. That is the point of this addendum.

If you have questions, contact us.

1. Scope

This Data Processing Addendum ("DPA") forms part of the agreement between Encrata ("Processor") and the customer ("Controller") and applies where Encrata processes personal data on behalf of the customer in connection with the Service, as required by the GDPR, UK GDPR, and CCPA.

2. Roles and Responsibilities

The customer acts as the data controller and determines the purposes and means of processing. Encrata acts as a data processor and processes personal data only on documented instructions from the customer, including with regard to international transfers, unless required otherwise by law.

3. Nature of Processing

  • Subject matter: provision of OSINT and data enrichment APIs
  • Duration: the term of the agreement
  • Categories of data: identifiers submitted for lookup (emails, phone numbers, domains, IPs, images) and account data
  • Data subjects: the customer's end users and lookup subjects

4. Confidentiality and Security

Encrata ensures persons authorized to process personal data are bound by confidentiality obligations. We implement appropriate technical and organizational measures, including encryption in transit (TLS 1.2+), encryption at rest, access controls, audit logging, and periodic security reviews.

5. Subprocessors

The customer provides general authorization for Encrata to engage subprocessors listed at encrata.com/legal/subprocessors. We will provide notice of changes and impose data protection obligations on subprocessors equivalent to those in this DPA.

6. International Transfers

Where personal data is transferred outside the EEA or UK, Encrata relies on the European Commission's Standard Contractual Clauses (SCCs) or other valid transfer mechanisms.

7. Data Subject Rights

Taking into account the nature of processing, Encrata will assist the customer with appropriate technical and organizational measures to respond to data subject requests (access, rectification, erasure, restriction, portability, objection).

8. Breach Notification

Encrata will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data, providing sufficient information to meet the customer's notification obligations.

9. Deletion and Return

Upon termination of the agreement, Encrata will delete or return all personal data processed on behalf of the customer within 30 days, unless retention is required by law.

10. Audits

Encrata will make available information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable notice and confidentiality.

11. Contact

To execute a signed copy of this DPA or for questions, contact privacy@encrata.com.