Legal
Data processing addendum
Effective September 5, 2026
Scope and parties
This Data Processing Addendum (“DPA”) forms part of the OmniReach terms of use between Boolean and Bean, Victoria, Australia (“OmniReach”, “we”) and the customer that holds an OmniReach workspace (“Customer”, “you”). It applies whenever OmniReach processes Customer Personal Data on your behalf and whenever data-protection law such as the GDPR, the UK GDPR, the Australian Privacy Act 1988, or a U.S. state privacy law applies to that processing.
This DPA applies automatically to every Customer. No signature is required. If you need a countersigned copy for your records, email hello@omnireach.com and we will return one. If this DPA conflicts with the terms of use, this DPA prevails for the processing of Customer Personal Data; otherwise the terms of use prevail.
Definitions
Customer Personal Data means personal data that you or your users upload, import, discover, generate, or cause OmniReach to obtain through the Service — chiefly information about prospects, recipients, and the people who reply to your outreach. Account Data means information about you and your users that OmniReach needs to run the Service: sign-in details, workspace membership, billing, support history, security logs, and product analytics. Sub-processor means a third party we engage to process Customer Personal Data. “Controller”, “processor”, “data subject”, “personal data breach”, and “processing” have the meanings given in the GDPR; the equivalent terms in other laws (for example “business” and “service provider”) are read accordingly.
Roles
For Customer Personal Data, you are the controller (or business) and OmniReach is your processor (or service provider). We process it only on your documented instructions, which are: the terms of use, this DPA, your configuration of the Service, and the actions your users take in it. If we believe an instruction breaches applicable law we will tell you and may pause the affected processing.
For Account Data, OmniReach is an independent controller and the privacy policy governs. We are not joint controllers with you for either category.
Details of processing
- Subject matter and purpose. Operating a multi-channel outreach workspace: storing prospect lists, drafting and sending LinkedIn and email messages your users approve, receiving replies, applying caps and suppression, and providing discovery, AI drafting, and reporting features.
- Duration. The term of your subscription plus the deletion period below.
- Nature. Collection on your instruction, storage, organisation, transmission to connected platforms and recipients, AI-assisted transformation, retrieval, export, erasure.
- Data subjects. Prospects and leads; recipients of outreach; people who reply; your users’ contacts imported from integrations such as Apollo; and, for connected-account content, your own users.
- Categories of personal data. Name, job title, employer, LinkedIn URL and identifiers, business email address, public professional profile information, message content and replies, notes, campaign membership and status, do-not-contact entries, and fields you import.
- Special categories. The Service is not designed for special-category or sensitive data and you agree not to submit it unless strictly necessary and lawful. We do not intentionally collect it.
Your obligations
You are responsible for the lawfulness of the Customer Personal Data you process through the Service, including having a lawful basis for prospecting and outreach, providing any notices required to data subjects, honouring opt-outs, and ensuring your instructions to us comply with applicable law and with the rules of the platforms you connect. You will not instruct us to process data in a way that would cause us to breach applicable law.
Our obligations
- Process Customer Personal Data only on your instructions and only to provide the Service.
- Ensure people authorised to process it are bound by confidentiality obligations.
- Implement the security measures described below.
- Engage Sub-processors only under the conditions below.
- Help you respond to data-subject requests. If a prospect contacts us directly we will forward the request to you within 5 business days where we can identify your workspace, and we provide in-product tools to edit, export, suppress, and delete prospect records.
- Help you with data-protection impact assessments and regulator consultations that concern our processing, on reasonable request.
- Delete or return Customer Personal Data at the end of the Service as described below.
- Make available the information reasonably needed to demonstrate compliance with this DPA.
We will not sell or rent Customer Personal Data, share it for cross-context behavioural advertising, combine it with personal data from other customers except as needed to provide the Service, or use it to train a general-purpose model offered to other customers.
Sub-processors
You authorise us to engage the Sub-processors below. We enter into written terms with each that impose data-protection obligations no less protective than this DPA, and we remain responsible for their performance.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | Configured region (currently United States) |
| Vercel | Application hosting and platform logs | United States / global edge |
| Unipile | LinkedIn and mailbox connection, sending, replies | European Union |
| Inngest | Background jobs (sends, drafting, sync) | United States |
| OpenAI | AI-assisted drafting and targeting suggestions | United States |
| Autobound | Signals discovery and recommendations | United States |
| Firecrawl | Public website extraction for seller context | United States |
| Resend | Transactional and invitation email | United States |
| Stripe | Billing (account data only; not prospect data) | United States |
| PostHog | Product analytics in the signed-in application | United States or European Union (configured host) |
| Upstash | Short-lived cache for public marketing demos | United States |
Customer-directed integrations you connect yourself (for example Apollo) and the platforms you send to (LinkedIn, mailbox providers) are not our Sub-processors; you engage them directly. A Sub-processor is used only when the relevant feature is enabled.
We will give at least 14 days’ notice by email or prominent in-product notice before adding or replacing a Sub-processor that will process Customer Personal Data. You may object on reasonable data-protection grounds within that period. If we cannot resolve the objection, you may terminate the affected feature or your subscription and we will refund any prepaid fees for the unused period.
International transfers
OmniReach operates from Australia and uses Sub-processors in the locations listed above. Where a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland requires a transfer mechanism, the parties rely on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, and Module Three, processor to processor, as applicable), which are incorporated into this DPA with OmniReach as data importer, and — for the United Kingdom — the UK International Data Transfer Addendum. Where a Sub-processor is certified under the EU–U.S. Data Privacy Framework we may rely on that certification for onward transfers. Ireland is the governing law and forum for the EU clauses; England and Wales for the UK Addendum. We will provide a completed copy of the clauses on request.
Where the Australian Privacy Act applies, we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.
Security measures
Our current measures, which we may improve but will not materially weaken, include:
- Encryption in transit (TLS 1.2 or higher) for all traffic between users, OmniReach, and Sub-processors.
- Encryption at rest for the database and storage provided by our hosting Sub-processors; integration credentials additionally encrypted at the application layer.
- Workspace isolation enforced with database row-level security, role-based permissions, and per-request authorisation checks.
- Connected LinkedIn and mailbox credentials handled by Unipile’s hosted connection flow; OmniReach does not store your LinkedIn or mailbox password.
- Secrets held in the hosting platform’s secret store, not in source code; API keys shown once and stored hashed.
- Rate limits, daily send caps, approval gates, and audit logging of API and agent activity.
- Least-privilege access to production for a small number of named staff, with multi-factor authentication on provider accounts.
- Provider-managed backups with automatic rotation; backups are not restored for ordinary product use after a verified deletion.
We do not currently hold ISO 27001 or SOC 2 certification. We will tell you if that changes.
Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data we will notify you without undue delay and, where feasible, within 72 hours, at the email address of your workspace owner. The notice will describe what we know about the nature of the breach, the data and data subjects likely affected, the likely consequences, and the measures taken or proposed, and we will update it as we learn more. We will reasonably cooperate with your own notifications to regulators and data subjects.
Deletion and return
During the subscription you can export and delete prospect records and campaign data in the product. When your subscription ends or you request deletion, we will delete Customer Personal Data within 30 days, or return it in a portable format first if you ask before that period ends. We may retain a minimal do-not-contact record to honour opt-outs, and information we must keep to comply with law or resolve a dispute, which we will isolate from further processing. Copies in provider backups are removed on their normal rotation schedule.
Audit
On written request, no more than once a year unless required by a regulator or following a breach, we will provide the documentation reasonably needed to verify our compliance with this DPA — including this page, our security description, and relevant Sub-processor certifications. If that is insufficient to meet a legal obligation, you may conduct or commission an audit at your cost, on at least 30 days’ notice, during business hours, under confidentiality, and without unreasonable disruption. We may object to an auditor who is a competitor or not suitably qualified.
Liability
Each party’s liability under this DPA is subject to the exclusions and the cap in the terms of use, read as a single cap across the terms and this DPA. Nothing in this DPA limits liability that cannot lawfully be limited or a data subject’s rights under applicable law.
Changes
We may update this DPA to reflect changes in law, guidance, or the Service. We will give reasonable notice of a material change by email or prominent in-product notice. A change will not reduce the protections in this DPA for the remainder of a prepaid period without your agreement.
Contact
Data-protection questions, data-subject requests, and breach reports: hello@omnireach.com.