Alex Kuguk Data Processing Agreement Back to the offer

Data Processing Agreement

Version 1.0 · in force from August 23, 2026

This agreement forms part of the Terms of Service and applies whenever EVA DAVA EOOD, UIC 207945177, 9 Gen. Gurko Str., floor 1, 8000, Burgas, Bulgaria (the Processor), processes personal data on the instructions of a client (the Controller). It is entered into under Article 28(3) of Regulation (EU) 2016/679.

1Roles

The allocation, in one line

For the campaign data, the Controller is the client and the Processor is EVA DAVA EOOD. The Controller decides who is contacted and why. The Processor carries that decision out.

The Controller's decision is not implied, it is documented: the buyer profile, the qualification criteria, the seniority tier, the geography, the messaging and the exclusion list are signed off by the Controller in writing before the first message is sent, under clause 11 of the Terms of Service. Those documents are the instruction.

ActivityEVA DAVA acts as
Sourcing and selecting prospects against the Controller's signed‑off buyer profileProcessor
Verifying that a business address is deliverable before sending to itProcessor
Sending outbound from the Controller's domain and mailboxProcessor
Handling replies received in the Controller's mailboxProcessor
Writing contacts, notes, meeting records and opt‑outs into the Controller's CRMProcessor
Booking meetings into the Controller's calendarProcessor
Keeping the permanent suppression list of people who asked never to be contacted againIndependent controller

Each sub‑processor is named in writing to the Client before the engagement starts, and the current list is provided on request at any time. No sub‑processor is added or replaced without written notice to the Client and a period in which the Client may object; if the objection cannot be resolved, the Client may terminate without penalty and without paying for meetings not yet held. The list is not published here because it is part of how the work is done, not part of what is being sold.

The last row is the only exception and it is deliberate. A suppression list tied to one Controller would be deleted at the end of that engagement, and the same person would be contacted again for the next client. Keeping it separately, across all clients and beyond the end of any engagement, is the only way an objection can be permanent. EVA DAVA answers for it as a controller under its Privacy Notice, holds nothing in it beyond the address, the date and the fact of the request, and uses it for nothing but honouring the objection.

The Controller confirms that it has a lawful basis for the outbound activity it instructs. The balancing assessment under Article 6(1)(f) that supports it is set out in section 6 of the Privacy Notice, is repeated for the Controller's own profile, and is supplied to the Controller on request so that the Controller can rely on it and defend it.

2Subject matter and duration

Subject matter: identifying, contacting and qualifying business prospects, and booking meetings, on behalf of the Controller.

Duration: for as long as the engagement under the Terms of Service continues, and thereafter for the return or deletion period in clause 14.

3Nature and purpose of processing

Collection, organisation, structuring, storage, use, transmission, restriction and erasure.

Purpose: identifying, contacting and qualifying business prospects within the buyer profile the Controller has signed off, and booking meetings with those who agree to one. There is no other purpose. Personal data processed for one Controller is never used for another, and the Controller's lists, copy, hook and angle are never reused.

4Categories of data subject

Employees, officers and representatives of companies falling inside the agreed buyer profile, and people who reply to a message sent under the Service.

5Categories of personal data

No special categories of data under Article 9 are processed, and none may be introduced without a written amendment to this agreement. No data relating to children is processed. No personal email addresses are used. There is no automated decision‑making within the meaning of Article 22 and no profiling that produces legal or similarly significant effects.

6Instructions

The Processor processes personal data only on the documented instructions of the Controller. The documented instructions are:

Where Union or Bulgarian law requires the Processor to process beyond those instructions, it informs the Controller before processing unless that law prohibits it.

The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR, and does not carry it out until the point is resolved. This applies in particular to a request to send to a category the Processor excludes under clause 14 of the Terms of Service, and to a request to remove or weaken the opt‑out mechanism in an outbound message.

7Confidentiality

The Service is delivered by Alex Kuguk, the sole owner of the Processor, who is bound by the confidentiality clause of the Terms of Service (clause 20).

Any further person given access to the Controller's data is bound by an equivalent written confidentiality obligation before access is granted, and access is granted only to what that person's part of the work requires.

8Sub‑processors

The Controller gives general written authorisation for the following sub‑processors.

Sub‑processorPurposeLocation
Google Ireland LimitedGoogle Workspace: mailboxes on the Controller's domains, calendar, meetings, documentsEU, transfers to the US
Microsoft Ireland Operations LimitedMicrosoft 365 and Exchange Online: the second half of the mailbox packEU, transfers to the US
Domain registrar and DNSRegistration of the Controller's domains, DNS and networkUnited States, with EU edge
Website hostHosting of the public website and its server logsUnited States
Prospect data providerBusiness contact data and outbound sequencingUnited States
Email verification providerDeliverability check on a business address before sendingBangladesh

Both mailbox vendors are used on every engagement, by design: the pack is split across Google and Microsoft so that neither of them can take all of it out with a single suspension. That is an operating rule under clause 12 of the Terms of Service and it is also why both appear here.

The Processor gives the Controller thirty days written notice before adding or replacing a sub‑processor. The Controller may object on reasonable data‑protection grounds, and if the objection cannot be resolved either party may terminate the affected part of the Service without penalty.

Each sub‑processor is engaged under a written contract imposing the same obligations as this agreement. The Processor remains fully liable to the Controller for the performance of its sub‑processors.

9Security

Measures appropriate to the risk under Article 32:

10International transfers

Transfers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), and on the EU–US Data Privacy Framework where the recipient is certified under it. A transfer impact assessment is available to the Controller on request.

The Processor does not transfer the Controller's personal data to any country or recipient outside those arrangements without the Controller's written instruction.

11Assistance to the Controller

Taking into account the nature of the processing and the information available to it, the Processor assists the Controller with:

12Personal data breach

The Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller's data.

The notification carries the facts known at that time: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Further information follows as it becomes known, without waiting for a complete picture, so that the Controller can meet its own 72‑hour duty under Article 33.

13Audit

The Processor makes available the information needed to demonstrate compliance with Article 28, and allows for and contributes to audits by the Controller or an auditor it mandates.

14Return and deletion

During the engagement, the Processor retains prospect records for the period the Controller instructs. Where the Controller gives no instruction, the default is twelve months from the last contact, unless a conversation is still running, and it is recorded in the agreement either way.

On termination of the Service, at the Controller's choice, the Processor returns or deletes the personal data it holds and deletes existing copies, within thirty days. Written confirmation follows.

Two exceptions, both stated plainly rather than left in a schedule:

Data held in the Controller's own systems is not affected by any of this. It never left them.

15Infrastructure after the end

The domains and the mailboxes are registered to the Controller's legal entity and remain the Controller's property when the engagement ends, under clause 9 of the Terms of Service.

This matters here and not only in the commercial terms: the mail, the sent history and the replies sit in accounts the Controller owns and controls. On termination the Processor's access is revoked and the data stays exactly where it was, with the Controller, without a migration and without a copy having to be handed over. There is no lock‑in of the data because there was never custody of it in the first place.

16Liability and law

Liability under this agreement is subject to the limitations in the Terms of Service, except where the GDPR does not permit limitation.

Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement prevails. This agreement is governed by the law of the Republic of Bulgaria.

Signature

This agreement is accepted together with the Terms of Service and requires no separate signature. A countersigned copy on the Controller's own paper is provided on request — write to alex.kuguk@evadava.com.