This agreement forms part of the Terms of Service and applies whenever EVA DAVA EOOD, UIC 207945177, 9 Gen. Gurko Str., floor 1, 8000, Burgas, Bulgaria (the Processor), processes personal data on the instructions of a client (the Controller). It is entered into under Article 28(3) of Regulation (EU) 2016/679.
For the campaign data, the Controller is the client and the Processor is EVA DAVA EOOD. The Controller decides who is contacted and why. The Processor carries that decision out.
The Controller's decision is not implied, it is documented: the buyer profile, the qualification criteria, the seniority tier, the geography, the messaging and the exclusion list are signed off by the Controller in writing before the first message is sent, under clause 11 of the Terms of Service. Those documents are the instruction.
| Activity | EVA DAVA acts as |
|---|---|
| Sourcing and selecting prospects against the Controller's signed‑off buyer profile | Processor |
| Verifying that a business address is deliverable before sending to it | Processor |
| Sending outbound from the Controller's domain and mailbox | Processor |
| Handling replies received in the Controller's mailbox | Processor |
| Writing contacts, notes, meeting records and opt‑outs into the Controller's CRM | Processor |
| Booking meetings into the Controller's calendar | Processor |
| Keeping the permanent suppression list of people who asked never to be contacted again | Independent controller |
Each sub‑processor is named in writing to the Client before the engagement starts, and the current list is provided on request at any time. No sub‑processor is added or replaced without written notice to the Client and a period in which the Client may object; if the objection cannot be resolved, the Client may terminate without penalty and without paying for meetings not yet held. The list is not published here because it is part of how the work is done, not part of what is being sold.
The last row is the only exception and it is deliberate. A suppression list tied to one Controller would be deleted at the end of that engagement, and the same person would be contacted again for the next client. Keeping it separately, across all clients and beyond the end of any engagement, is the only way an objection can be permanent. EVA DAVA answers for it as a controller under its Privacy Notice, holds nothing in it beyond the address, the date and the fact of the request, and uses it for nothing but honouring the objection.
The Controller confirms that it has a lawful basis for the outbound activity it instructs. The balancing assessment under Article 6(1)(f) that supports it is set out in section 6 of the Privacy Notice, is repeated for the Controller's own profile, and is supplied to the Controller on request so that the Controller can rely on it and defend it.
Subject matter: identifying, contacting and qualifying business prospects, and booking meetings, on behalf of the Controller.
Duration: for as long as the engagement under the Terms of Service continues, and thereafter for the return or deletion period in clause 14.
Collection, organisation, structuring, storage, use, transmission, restriction and erasure.
Purpose: identifying, contacting and qualifying business prospects within the buyer profile the Controller has signed off, and booking meetings with those who agree to one. There is no other purpose. Personal data processed for one Controller is never used for another, and the Controller's lists, copy, hook and angle are never reused.
Employees, officers and representatives of companies falling inside the agreed buyer profile, and people who reply to a message sent under the Service.
No special categories of data under Article 9 are processed, and none may be introduced without a written amendment to this agreement. No data relating to children is processed. No personal email addresses are used. There is no automated decision‑making within the meaning of Article 22 and no profiling that produces legal or similarly significant effects.
The Processor processes personal data only on the documented instructions of the Controller. The documented instructions are:
Where Union or Bulgarian law requires the Processor to process beyond those instructions, it informs the Controller before processing unless that law prohibits it.
The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR, and does not carry it out until the point is resolved. This applies in particular to a request to send to a category the Processor excludes under clause 14 of the Terms of Service, and to a request to remove or weaken the opt‑out mechanism in an outbound message.
The Service is delivered by Alex Kuguk, the sole owner of the Processor, who is bound by the confidentiality clause of the Terms of Service (clause 20).
Any further person given access to the Controller's data is bound by an equivalent written confidentiality obligation before access is granted, and access is granted only to what that person's part of the work requires.
The Controller gives general written authorisation for the following sub‑processors.
| Sub‑processor | Purpose | Location |
|---|---|---|
| Google Ireland Limited | Google Workspace: mailboxes on the Controller's domains, calendar, meetings, documents | EU, transfers to the US |
| Microsoft Ireland Operations Limited | Microsoft 365 and Exchange Online: the second half of the mailbox pack | EU, transfers to the US |
| Domain registrar and DNS | Registration of the Controller's domains, DNS and network | United States, with EU edge |
| Website host | Hosting of the public website and its server logs | United States |
| Prospect data provider | Business contact data and outbound sequencing | United States |
| Email verification provider | Deliverability check on a business address before sending | Bangladesh |
Both mailbox vendors are used on every engagement, by design: the pack is split across Google and Microsoft so that neither of them can take all of it out with a single suspension. That is an operating rule under clause 12 of the Terms of Service and it is also why both appear here.
The Processor gives the Controller thirty days written notice before adding or replacing a sub‑processor. The Controller may object on reasonable data‑protection grounds, and if the objection cannot be resolved either party may terminate the affected part of the Service without penalty.
Each sub‑processor is engaged under a written contract imposing the same obligations as this agreement. The Processor remains fully liable to the Controller for the performance of its sub‑processors.
Measures appropriate to the risk under Article 32:
Transfers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), and on the EU–US Data Privacy Framework where the recipient is certified under it. A transfer impact assessment is available to the Controller on request.
The Processor does not transfer the Controller's personal data to any country or recipient outside those arrangements without the Controller's written instruction.
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller with:
The Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller's data.
The notification carries the facts known at that time: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Further information follows as it becomes known, without waiting for a complete picture, so that the Controller can meet its own 72‑hour duty under Article 33.
The Processor makes available the information needed to demonstrate compliance with Article 28, and allows for and contributes to audits by the Controller or an auditor it mandates.
During the engagement, the Processor retains prospect records for the period the Controller instructs. Where the Controller gives no instruction, the default is twelve months from the last contact, unless a conversation is still running, and it is recorded in the agreement either way.
On termination of the Service, at the Controller's choice, the Processor returns or deletes the personal data it holds and deletes existing copies, within thirty days. Written confirmation follows.
Two exceptions, both stated plainly rather than left in a schedule:
Data held in the Controller's own systems is not affected by any of this. It never left them.
The domains and the mailboxes are registered to the Controller's legal entity and remain the Controller's property when the engagement ends, under clause 9 of the Terms of Service.
This matters here and not only in the commercial terms: the mail, the sent history and the replies sit in accounts the Controller owns and controls. On termination the Processor's access is revoked and the data stays exactly where it was, with the Controller, without a migration and without a copy having to be handed over. There is no lock‑in of the data because there was never custody of it in the first place.
Liability under this agreement is subject to the limitations in the Terms of Service, except where the GDPR does not permit limitation.
Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement prevails. This agreement is governed by the law of the Republic of Bulgaria.
This agreement is accepted together with the Terms of Service and requires no separate signature. A countersigned copy on the Controller's own paper is provided on request — write to alex.kuguk@evadava.com.