Data Processing Addendum 

1. Scope and Role of the Parties
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Tomba Technology Web Service LLC ("Tomba") and applies whenever Tomba processes Personal Data on Customer's behalf.
Capitalised terms not defined here have the meaning given in the Terms of Service. "Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Supervisory Authority" have the meanings given in the GDPR.
The Two Distinct Roles
Tomba acts in two different capacities, and it matters which one applies:
A. Tomba as Controller — our own contact database. Tomba independently compiles business contact information from publicly available sources. For that database, Tomba is the Controller and determines the purposes and means of processing. Our handling of that data is described in the Privacy Policy, not in this DPA.
B. Tomba as Processor — Customer Data. When Customer uploads, submits, or transmits data to the Service — for example a list of domains or contacts for bulk processing or verification — Tomba processes that Personal Data on Customer's behalf and on Customer's documented instructions. For that processing, Customer is the Controller and Tomba is the Processor. This DPA governs that processing.
Where Customer uses data obtained from Tomba's database for its own outreach, Customer is an independent Controller of that data and is solely responsible for establishing a lawful basis and complying with Section 5 of the Terms of Service.
2. Details of Processing
| Subject matter | Provision of the Tomba email discovery, enrichment, and verification Service |
| Duration | The term of the Terms of Service, plus the retention period in Section 10 |
| Nature and purpose | Hosting, storage, matching, enrichment, verification, and return of results; support and security |
| Types of Personal Data | Business contact details: name, business email address, business phone number, job title, employer, professional profile URLs, and any other data Customer chooses to submit |
| Categories of Data Subjects | Customer's prospects, leads, contacts, and business partners; Customer's own personnel who use the Service |
| Special categories | None. Customer must not submit special category data as defined in Article 9 GDPR |
3. Customer's Obligations as Controller
Customer represents and warrants that:
- It has a valid lawful basis under Article 6 GDPR (and, where relevant, the UK GDPR) for the processing it instructs, and has completed any legitimate interests assessment required
- It has provided all notices and obtained all consents required to lawfully transfer Personal Data to Tomba and for Tomba to process it as described
- Its instructions comply with applicable data protection law
- It will not submit special category data, data relating to children, or data outside the scope described in Section 2
- It will comply with its obligations as Controller, including responding to Data Subject requests it receives
Customer is responsible for the accuracy, quality, and legality of Customer Data and the means by which it acquired that data.
4. Tomba's Obligations as Processor
Tomba will:
- Process Personal Data only on Customer's documented instructions, including the Terms of Service, this DPA, and Customer's use of the Service, unless required otherwise by law — in which case Tomba will notify Customer before processing, unless that law prohibits notice
- Ensure that personnel authorised to process Personal Data are bound by an appropriate duty of confidentiality
- Implement the technical and organisational measures described in Section 6
- Not sell Personal Data, and not retain, use, or disclose it for any purpose other than performing the Service
- Immediately inform Customer if, in its opinion, an instruction infringes applicable data protection law
5. Sub-processors
Customer provides general written authorisation for Tomba to engage Sub-processors.
Tomba will:
- Impose data protection obligations on each Sub-processor that are no less protective than those in this DPA
- Remain fully liable to Customer for each Sub-processor's performance
- Maintain a current list of Sub-processors, available on request from privacy@tomba.io
- Give Customer at least thirty (30) days' notice before adding or replacing a Sub-processor
Customer may object on reasonable data protection grounds within that notice period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused term.
6. Security Measures
Tomba maintains appropriate technical and organisational measures under Article 32 GDPR, including:
- Encryption — TLS 1.3 in transit; AES-256 at rest
- Access control — role-based access on a least-privilege basis, multi-factor authentication for administrative access, and prompt revocation on role change or departure
- Network security — firewalling, network segmentation, and intrusion monitoring
- Resilience — backups, tested restoration procedures, and documented business continuity plans
- Testing — regular vulnerability scanning, penetration testing, and review of the effectiveness of these measures
- Secure development — code review, dependency scanning, and change management
Further detail is in our Security Policy. Tomba may update these measures provided the level of protection is not reduced.
7. Personal Data Breach
Tomba will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Data.
The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where information is not available at once, Tomba will provide it in phases without undue further delay.
Tomba will provide reasonable assistance to Customer in meeting its own notification obligations to Supervisory Authorities and Data Subjects. Tomba's notification is not an acknowledgement of fault or liability.
8. Assistance to Customer
Taking into account the nature of the processing and the information available to it, Tomba will provide reasonable assistance to Customer with:
- Data Subject requests — responding to requests to exercise rights of access, rectification, erasure, restriction, portability, and objection. If Tomba receives such a request directly relating to Customer Data, it will not respond substantively but will redirect the Data Subject to Customer without undue delay.
- Data protection impact assessments and prior consultation with Supervisory Authorities under Articles 35 and 36 GDPR
- Security of processing under Article 32 GDPR
Where a Data Subject asks Tomba to remove their details from Tomba's own database (Tomba acting as Controller), Tomba will handle that request directly under Section 6 of the Terms of Service.
9. International Transfers
Personal Data may be transferred to and processed in the United States and other countries where Tomba or its Sub-processors operate.
Where Personal Data originating in the EEA, United Kingdom, or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission Standard Contractual Clauses (Decision 2021/914), which are incorporated into this DPA by reference:
- Module Two (Controller to Processor) applies to transfers under this DPA
- Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation) applies with the notice period in Section 5; Clause 11 optional independent dispute resolution does not apply; Clause 17 is governed by the law of Ireland; Clause 18(b) designates the courts of Ireland
- For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies, with Tables 1–4 completed by reference to this DPA
- For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority
Tomba will conduct transfer impact assessments where required and will notify Customer if it becomes unable to comply with these clauses.
10. Retention, Return, and Deletion
Tomba will retain Customer Data only as long as necessary to provide the Service.
On termination or expiry, Tomba will, at Customer's election, return or delete Customer Data within ninety (90) days, except to the extent retention is required by law or necessary for the establishment, exercise, or defence of legal claims. Data retained under an exception remains subject to this DPA. Backup copies are deleted in the ordinary course of the backup cycle.
Customer may export Customer Data before termination takes effect.
11. Audit
Tomba will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.
Audits are subject to: reasonable prior written notice of at least thirty (30) days; no more than once in any twelve (12) month period unless required by a Supervisory Authority or following a Personal Data Breach; conduct during business hours without unreasonable disruption; and a confidentiality undertaking from the auditor, who must not be a competitor of Tomba. Tomba may satisfy an audit request by providing current third-party certifications, penetration test summaries, or completed security questionnaires.
12. California and Other US State Privacy Laws
For Personal Data subject to the California Consumer Privacy Act as amended ("CCPA") and comparable state laws, Tomba acts as a Service Provider (or Processor, as those laws define it).
Tomba will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than performing the Service specified in the Terms of Service, or as otherwise permitted by the CCPA; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with Personal Data received from another source, except as permitted by the CCPA.
Tomba certifies that it understands and will comply with these restrictions. See also our Privacy Notice for California Residents.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in Section 15 of the Terms of Service. Nothing in this DPA limits any liability that cannot be limited under applicable data protection law, including liability to Data Subjects under Article 82 GDPR.
14. Order of Precedence and Term
This DPA takes effect when Customer accepts the Terms of Service and continues until Tomba ceases all processing of Customer Data.
In the event of a conflict between this DPA and the Terms of Service concerning the processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
15. Contact
Privacy and data protection: privacy@tomba.ioLegal notices: legal@tomba.io
Mail: Tomba Technology Web Service LLC 2803 Philadelphia Pike Suite B #1228 Claymont, Delaware 19703 United States
If you require a countersigned copy of this DPA for your records, contact privacy@tomba.io.