GDPR / Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Controller") and Kaada Nordic MarTech (the "Processor") for the processing of personal data under the EU General Data Protection Regulation (GDPR).

1. Roles and Scope

  • Controller: You (the OmniScout account holder) determine the purposes and means of processing lead data and outreach content.
  • Processor: Kaada Nordic MarTech processes data on your behalf to provide the OmniScout platform.
  • Scope: This DPA applies to all personal data processed through OmniScout, including lead contact information and audit data.

2. Data We Process on Your Behalf

  • Business contact information (name, phone, email, address) from Google Places API.
  • Website content fetched during audits (publicly available pages).
  • Review data from Google Business Profile.
  • Advertising data from Meta Ads Library.
  • Outreach emails generated on your instructions.

3. Processing Instructions

We process personal data only on your documented instructions — through the OmniScout interface — and for the purpose of providing the platform. We will not process your data for our own purposes, sell it, or share it with third parties except as required by law or as described in this DPA.

4. Sub-Processors

We engage the following sub-processors to deliver the service:

  • Cloud hosting: Supabase (database, auth, storage) — EU data region.
  • AI processing: Lovable AI Gateway — processes outreach email generation and audit summaries.
  • Email delivery: For sending viewing alerts and outreach emails.
  • Google Places API: For lead search data.

All sub-processors are bound by written agreements that provide at least the same level of data protection as this DPA. We will notify you in advance of any new sub-processor.

5. Data Security Measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Password hashing with bcrypt.
  • Row-level security (RLS) on all database tables — each account can only access its own data.
  • Access controls and least-privilege principle for internal systems.
  • Regular security reviews and penetration testing.
  • Incident response plan with 72-hour breach notification to controllers.

6. Data Subject Rights

We assist you in responding to data subject requests (access, rectification, erasure, portability, objection) by providing tools within OmniScout to export or delete lead data. Contact us at privacy@omniscout.ai for assistance.

7. International Data Transfers

Data is primarily stored in the EU (Supabase EU region). Where data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and supplementary technical measures.

8. Data Retention and Deletion

We retain personal data only as long as your account is active. You can delete individual leads, reports, or your entire account at any time. Upon account deletion, all data is permanently removed within 30 days.

9. Breach Notification

We will notify you of any personal data breach within 72 hours of becoming aware of it, including the nature of the breach, likely consequences, and measures taken.

10. Contact

For GDPR or data protection questions, contact our Data Protection Officer at dpo@omniscout.ai or by post at the address listed in our imprint.