Last Updated: 21st September 2026
This Data Processing Agreement (the “DPA”) forms part of and is incorporated into the agreement between FUTUREBLINK Inc. and the customer identified in that agreement (the “Agreement”).
FUTUREBLINK Inc., a corporation incorporated under the laws of the State of Delaware, United States, Delaware file number 10627023, whose mailing address is 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States (“Processor”, “we”, “us”); and the customer identified in the Agreement (“Controller”, “you”).
Where a conflict arises between this DPA and the Agreement in respect of the processing of personal data, this DPA prevails.
Capitalised terms not defined here have the meaning given in the Agreement or in Applicable Data Protection Law.
Applicable Data Protection Law means Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR together with the Data Protection Act 2018. The California Consumer Privacy Act as amended by the CPRA (the “CCPA”) applies only as and where set out in section 12.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority have the meanings given in the GDPR, and the equivalent terms in the UK GDPR are construed accordingly.
Sub-processor means any third party engaged by us to process personal data on your behalf.
Standard Contractual Clauses means the clauses adopted by the European Commission in Decision 2021/914 and, for UK transfers, the UK International Data Transfer Addendum.
2.1 Roles. In respect of customer personal data, you are the controller and we are the processor. Where you are yourself a processor acting for a third-party controller, you warrant that you have the authority to appoint us as a sub-processor and to enter into this DPA.
2.2 Independent controller activities. We act as an independent controller in respect of account administration data, billing data, support correspondence, security and abuse-prevention logging, and product telemetry relating to your authorised users. That processing is governed by our Privacy Policy and not by this DPA.
2.3 Duration. The subject matter of the processing is the provision of the services. Processing continues for the term of the Agreement and for the retention and deletion periods in section 11.
2.4 Nature and purpose. We process personal data to host and operate the services, which comprise: storage and management of prospect and contact records; composition, scheduling and delivery of outbound email sequences; connection to and synchronisation with mailboxes you authorise; receipt, classification and routing of inbound replies; tracking of email opens, clicks and replies; mailbox warm-up and deliverability monitoring; email address verification; AI-assisted drafting of message content; scheduling of meetings; and integration with third-party systems you authorise.
2.5 Categories of data subject. Prospects and recipients contacted through the services; your authorised users and personnel; correspondents who reply to messages sent through the services; and invitees who book meetings through the services.
2.6 Categories of personal data.
2.7 Special categories. The services are not designed or intended for processing special categories of personal data within the meaning of Article 9 GDPR, personal data relating to criminal convictions and offences, or personal data of children. You must not upload or submit such data. Free-text message content is not filtered and may incidentally contain such data; we apply the measures in section 7 to all personal data regardless of category.
2.8 Your responsibilities. You warrant that you have a valid lawful basis for the processing you instruct, that you have given all required notices and obtained all required consents, that you have the right to transfer personal data to us, and that your use of the services complies with all applicable law governing electronic direct marketing, including GDPR Article 6(1)(f) and Recital 47, the ePrivacy Directive 2002/58/EC as implemented nationally, the UK Privacy and Electronic Communications Regulations 2003, and any equivalent regime applicable to the recipients you choose to contact. You are responsible for honouring opt-out and unsubscribe requests you receive.
3.1 We process personal data only on your documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we inform you before processing unless the law prohibits it on important grounds of public interest.
3.2 The Agreement, this DPA, your configuration of the services, and your use of the services' documented features together constitute your complete documented instructions.
3.3 We notify you without undue delay if, in our opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing pending resolution.
3.4 We ensure that persons authorised to process personal data are bound by an appropriate duty of confidentiality, are subject to background screening where lawful and proportionate, and receive periodic data protection and security training.
3.5 Access to personal data is restricted to personnel who require it, on a least-privilege and need-to-know basis, and is logged.
3.6 We do not sell or rent personal data, do not retain, use or disclose it for any purpose other than performing the services, and do not combine it with data from other sources except as necessary to perform the services. We do not use your personal data to train, fine-tune or otherwise improve any general-purpose machine learning model.
4.1 You grant us general written authorisation to engage sub-processors, subject to this section.
4.2 The sub-processors in force at the effective date are published at salesblink.io/sub-processors.
4.3 We give you at least thirty (30) days' notice before authorising a new sub-processor or replacing an existing one, by email to your designated notice address and by a dated changelog published alongside that list.
4.4 You may object on reasonable, documented data protection grounds within fifteen (15) days of notice. We will work in good faith to resolve the objection. Where no resolution is reached you may terminate the affected services without penalty, with a pro-rata refund of prepaid fees for the unused term.
4.5 Where a sub-processor must be replaced without notice to preserve the security or continuity of the services, we may do so and will notify you as soon as reasonably practicable.
4.6 We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remain fully liable to you for each sub-processor's performance.
4.7 Integrations you connect. Where you authorise the services to connect to a third-party system under your own account — including CRM platforms, workflow automation services, mailbox providers, chat platforms, and AI clients connecting via the Model Context Protocol — that third party is not our sub-processor. The transfer is made on your instruction and you are responsible for your own relationship with that provider.
5.1 We are established in the United States. We and our sub-processors process personal data in multiple regions, including the European Economic Area and the United States. The processing location for a given sub-processor depends on the region in which that sub-processor's services are provisioned. We will identify the processing region for any individual sub-processor on your reasonable request.
5.2 Because we are established in the United States, all processing of personal data originating in the EEA or the United Kingdom constitutes a restricted transfer. Each such transfer is made pursuant to the Standard Contractual Clauses, under which you are the data exporter and we are the data importer. Module Two (controller to processor) applies; Module Three (processor to processor) applies where you are yourself a processor; the docking clause applies; the general authorisation option in Clause 9(a) applies with the notice period in section 4.3; the governing law and forum are those of Ireland; for UK transfers the UK International Data Transfer Addendum applies to the same clauses.
5.3 We have conducted, and will maintain, a transfer impact assessment in respect of each such transfer, and will supply a copy on reasonable request.
5.4 If any transfer mechanism relied on is invalidated or superseded, the parties will in good faith adopt a replacement without undue delay.
6.1 Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability and objection.
6.2 The services let you search, export, correct and delete personal data within your account. You use that functionality in the first instance.
6.3 Where we receive a request from a data subject relating to personal data processed on your behalf, we do not respond to the substance other than to direct them to you, and we notify you without undue delay and in any event within five (5) business days.
6.4 Assistance under this section is provided at no additional charge, save that we may charge a reasonable fee for assistance that is manifestly unfounded, excessive or repetitive, having first notified you of the anticipated charge.
6.5 We provide reasonable assistance with data protection impact assessments and with any prior consultation with a supervisory authority.
7.1 We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons.
7.2 Those measures include, at minimum:
7.3 We may update our security measures from time to time, provided no update materially reduces the overall level of security.
7.4 Certifications. We do not currently hold a SOC 2 Type II attestation or ISO/IEC 27001 certification. We make our security documentation available on request under section 9.2.
8.1 We notify you without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting personal data processed on your behalf.
8.2 Notification is made to your designated security contact by email and in-product notice, and describes, to the extent known and supplemented as more information becomes available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the name and contact details of our data protection contact; the likely consequences; and the measures taken or proposed to address it and mitigate its effects.
8.3 We take reasonable steps to contain, investigate and remediate the breach, preserve relevant evidence, and provide you with the cooperation and information reasonably necessary to meet your own notification obligations.
8.4 We will not make any public statement or notification to data subjects or supervisory authorities identifying you without your prior written consent, unless legally compelled, in which case we notify you in advance where lawful.
8.5 Notification under this section is not an acknowledgement of fault or liability.
9.1 We make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.
9.2 Your audit right is satisfied in the first instance by our provision of current security documentation and a completed security questionnaire.
9.3 Where that information is insufficient, you may on thirty (30) days' written notice conduct an audit no more than once per calendar year, save where an audit is required following a personal data breach or by a supervisory authority. Audits are conducted during business hours, subject to confidentiality undertakings, in a manner that does not unreasonably disrupt our operations, and at your cost.
9.4 An audit does not extend to the premises, systems or data of our other customers, nor to information whose disclosure would breach our obligations to third parties.
10.1 Where you use AI-assisted features, prompt content — which may include contact records, company information and prior message content — is transmitted to the AI sub-processors identified in the sub-processor list, currently OpenAI and OpenRouter.
10.2 We contract with those sub-processors on terms that prohibit the use of your data for training or improvement of their models. This section 10.2 applies to our default configuration only; where you exercise either option in section 10.3, that section governs instead.
10.3 The services permit you to select a model of your own choosing through the routing sub-processor, and to supply your own API key for that sub-processor.
10.4 We do not use your personal data to train, fine-tune or evaluate any model of our own.
11.1 We retain personal data for the duration of the Agreement and in accordance with the following retention periods:
11.2 On termination or expiry of the Agreement you may, within thirty (30) days, export your personal data using the export functionality of the services or request a copy from us.
11.3 On your written request at any time, we delete or return all personal data processed on your behalf and delete existing copies, at your election, without waiting for the periods in section 11.1 to elapse, unless law requires continued storage.
11.4 Personal data residing in backups is deleted in accordance with our backup rotation schedule, and in any event within thirty (30) days of deletion under section 11.1 or 11.3. Pending expiry of that period such data remains subject to this DPA and is not restored to production systems except as part of a disaster recovery event affecting the services as a whole.
11.5 We may retain personal data to the extent and for the period required by law, or in aggregated and anonymised form from which data subjects cannot be identified.
11.6 We certify deletion in writing on your written request.
12.1 This section applies only where, and for so long as, we process personal information (as defined in the CCPA) on behalf of a customer that is a “business” within the meaning of the CCPA. It does not extend the scope of Applicable Data Protection Law defined in section 1 for any other purpose. In respect of such processing we act as a “service provider”.
12.2 We do not sell or share personal information; do not retain, use or disclose it for any purpose other than performing the services specified in this DPA or as otherwise permitted by the CCPA; do not retain, use or disclose it outside the direct business relationship between the parties; and do not combine it with personal information received from other sources, except as permitted by the CCPA.
12.3 We certify that we understand the restrictions in section 12.2 and will comply with them.
12.4 You may take reasonable and appropriate steps to ensure that we use personal information in a manner consistent with your obligations under the CCPA, and to stop and remediate any unauthorised use.
12.5 Where a conflict arises between this section and the remainder of this DPA in respect of personal information subject to the CCPA, this section prevails to the extent of the conflict.
13.1 Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement.
13.2 Section 13.1 does not limit either party's liability to a data subject under Article 82 GDPR, nor liability that cannot lawfully be limited.
14.1 Term. This DPA takes effect on the effective date of the Agreement and continues until all personal data has been deleted or returned in accordance with section 11.
14.2 Amendment. We may amend this DPA on thirty (30) days' notice where necessary to reflect a change in Applicable Data Protection Law, a decision of a supervisory authority or court, or a change in the services, provided the amendment does not materially reduce the protections afforded to personal data.
14.3 Severance. If any provision is held invalid or unenforceable, the remainder continues in full force and the parties will substitute a valid provision of equivalent commercial effect.
14.4 Governing law. This DPA is governed by the law stated in the Agreement, save where Applicable Data Protection Law or the Standard Contractual Clauses require otherwise.
Populated by sections 2.3 to 2.6 above.
Competent supervisory authority: the supervisory authority of the EU Member State in which our Article 27 representative is established, or, where you are established in the EEA, the supervisory authority competent for you.
Our data protection contact: Sushant Shekhar, Founder — dpo@salesblink.io
Our EU representative under Article 27 GDPR: Sushant Shekhar — dpo@salesblink.io
Our UK representative under Article 27 UK GDPR: Sushant Shekhar — dpo@salesblink.io
Populated by section 7 above.
Populated by the list published at salesblink.io/sub-processors.
If you need a countersigned copy of this DPA, or have questions about how we process personal data, contact dpo@salesblink.io or write to us.