Skip to content
TOM — The Outreach Machine
Why TOM AI personalization How it works Deliverability Pricing FAQ DNS checker Start the beta

Legal · Data Processing

Data Processing Addendum

Version 2.0 — effective 27 September 2026 upon Customer's recorded acceptance

This Data Processing Addendum ("DPA") supplements the Terms of Service between Studio Synapse di Fabrizio Mainardi di Pescia, a sole proprietorship under Italian law, Via Coste di Lagolo 12, 38076 Madruzzo (TN), Italy, VAT No. IT13965140968 ("Studio Synapse" or "Processor"), and the business or other organisation identified in the Account or order ("Customer"). It applies only when and to the extent Studio Synapse processes Customer Personal Data on Customer's behalf through The Outreach Machine (the "Service").

Studio Synapse offers and accepts this DPA as part of the Service. It becomes binding between Studio Synapse and Customer when an authorised Customer representative affirmatively accepts this version in the Service's signup or account flow, or signs it in writing. The electronic record must identify the Customer legal entity, the authorised user/representative or Account, the accepted DPA version, and the date and time of the affirmative acceptance. If Customer acts as a processor for another controller, Customer confirms that it has authority to give the instructions in this DPA and appoint Studio Synapse as its subprocessor. This DPA applies to processing on Customer's behalf from the recorded acceptance onward; it does not retrospectively make earlier processing lawful.

1. Definitions and precedence

  • Applicable Data Protection Law means the data-protection and privacy laws that apply to the processing or a party's role, including, where applicable, the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, applicable U.S. state privacy laws, and equivalent laws in other countries.
  • Customer Personal Data means personal data contained in Customer Data that Studio Synapse processes on Customer's behalf.
  • Processing, Controller, Processor, Personal Data and Data Subject have the meanings given in the Applicable Data Protection Law that applies.
  • Subprocessor means a processor appointed by Studio Synapse to process Customer Personal Data on Customer's behalf.

If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls for that processing. The Terms continue to govern other aspects of the Service. Nothing in this DPA changes either party's legal role where that role is determined by the facts or applicable law.

2. Processing details and roles

The subject matter, duration, nature and purpose of processing, categories of data subjects, types of Personal Data and processing operations are set out in Schedule 1. Customer determines the purposes and essential means of its campaigns and is generally the Controller. If Customer itself acts as a Processor, it remains responsible for the upstream Controller's instructions and permissions. Studio Synapse acts as Processor only for operations it actually performs on Customer's documented instructions; it may act as an independent Controller for account, billing, security and other processing described in the Privacy Policy.

3. Customer's instructions and responsibilities

  • Customer instructs Studio Synapse to process Customer Personal Data to provide, secure and support the Service, including storing and organising contact data, reading websites Customer identifies, generating drafts using AI services, configuring and sending campaigns through connected infrastructure, processing bounces and replies, and applying opt-outs and suppression lists, as enabled by Customer.
  • Documented instructions consist of this DPA, the Terms, Customer's account and campaign settings, sending actions and written support instructions. Studio Synapse will notify Customer if it reasonably believes an instruction infringes Applicable Data Protection Law, unless law prohibits that notice.
  • Customer is responsible for the lawful source, accuracy, minimisation and retention of Customer Personal Data; selecting recipients; identifying and documenting the applicable legal basis and any channel-specific permission; providing required privacy notices; handling Data Subject requests and objections; and ensuring campaign content and sending instructions comply with law.
  • A GDPR legitimate-interest assessment, public availability of an email address, or use of the Service does not by itself provide permission to send marketing email where the recipient's local law requires prior consent. Customer must assess each recipient, channel and market, retain evidence, honour opt-outs before any later send, and maintain suppression lists.
  • For campaigns, Customer must consider the laws of the recipient's location, including, where applicable, EU/EEA ePrivacy rules and Italian Privacy Code Article 130, UK GDPR and PECR, U.S. federal and state rules, Canada's CASL, Australia's Spam Act and other local anti-spam laws. This DPA is not legal advice or an authorisation to contact any person.
  • AI personalisation is instructed to use information appearing on the public website Customer identifies for the relevant prospect. Customer must not add private, sensitive or unrelated personal information to an AI prompt.
  • Customer must not submit special-category personal data, data about criminal convictions or offences, or personal data relating to children. These categories are outside the agreed Service scope and are prohibited.

4. Studio Synapse's processor commitments

Studio Synapse will, to the extent required by Applicable Data Protection Law:

  • process Customer Personal Data only on documented instructions, including instructions about international transfers, except where Union, Member State or other applicable law requires processing;
  • not use Customer Personal Data for Studio Synapse's own marketing, advertising, sale, enrichment, unrelated analytics, product training or general model training, and not combine it with other customer data for such purposes; not sell or disclose it except to authorised Subprocessors for the purposes of this DPA or as required by law; security, service operation and abuse-prevention processing is limited to what is needed to provide and protect the Service under this DPA;
  • ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide or secure the Service;
  • implement and maintain the technical and organisational measures in Schedule 2, taking account of the nature of the processing and the risks to Data Subjects;
  • assist Customer, taking account of the nature of processing, with requests to exercise Data Subject rights and with security, breach, DPIA and prior-consultation obligations;
  • notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, provide information reasonably available to assist Customer's legal reporting duties, and cooperate with mitigation and investigation;
  • notify Customer if a Data Subject or authority sends a request or complaint concerning Customer Personal Data, and not respond on Customer's behalf except on Customer's instructions or where legally required;
  • make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as described in section 8; and
  • not sell or share Customer Personal Data for cross-context behavioural advertising (as those terms are defined in applicable U.S. state privacy laws), use it for targeted advertising, or use it to train or fine-tune any general-purpose AI model. For TOM's OpenRouter connection, Studio Synapse will keep OpenRouter's prompt/completion logging and product-improvement use disabled and route requests only to model endpoints configured not to train on Customer Personal Data. OpenRouter may process request metadata needed for routing, billing, security and abuse prevention; the selected model provider receives the prompt to generate the response and may process it under that provider's published retention and security terms. Studio Synapse will not select an endpoint that permits training on Customer Personal Data or has an undisclosed/unacceptable data policy; endpoint choices may vary, and current provider policies are available through the OpenRouter provider-policy information in Schedule 2. If an acceptable endpoint is unavailable, AI personalisation of identifiable Customer Personal Data will not be performed.

5. Subprocessors

Customer gives general written authorisation for the Subprocessors and limited categories of provider set out in Schedule 2, subject to this section. Studio Synapse will enter into and maintain written processing terms with each Subprocessor as required by applicable law, including the obligations required by GDPR Article 28(4) where applicable, and remains responsible for its Subprocessors to the extent required by law. Customer may request the current provider and transfer-safeguard information by emailing team@theoutreachmachine.com.

Studio Synapse will give Customer at least 30 days' notice before adding or replacing a direct Subprocessor, an upstream provider used through Mailpool, or an individual endpoint provider on the approved AI-provider list, by email or an accessible notice in the Service. Customer may object within 15 days after notice on reasonable data-protection grounds. The parties will work in good faith to address the objection; if they cannot, Customer may stop using the affected feature and terminate the affected portion of the Service, subject to applicable law and the Terms. Model selection may vary among endpoint providers already on the current approved list; Studio Synapse will maintain that list and provide it to Customer on request. A newly appearing endpoint is not treated as approved merely because it is available through OpenRouter: it will not receive identifiable Customer Personal Data until its no-training and retention policies have been reviewed and the notice/objection period has passed. Studio Synapse will require Mailpool to notify it of upstream-provider changes in time to provide this notice or will suspend the affected Mailpool processing.

6. Security and Personal Data Breaches

Studio Synapse will maintain the measures in Schedule 2 and review them periodically. No security measure eliminates all risk. Customer is responsible for configuring the Service, protecting its credentials, limiting authorised users and deciding whether the Service's safeguards are appropriate for its data and purposes. Studio Synapse's breach notice is not an admission of fault and does not determine whether Customer must notify a regulator or Data Subject.

7. International transfers

The Service may process Customer Personal Data in the EEA and in other countries identified in Schedule 2, including the United States. Customer authorises these transfers only to the extent necessary to provide the Service and permitted by the law applicable to the relevant transfer. Studio Synapse is responsible for identifying and putting in place the transfer mechanism required for each restricted transfer it makes or instructs through its Subprocessors before the transfer occurs. An adequacy decision may be used where applicable; otherwise Studio Synapse will ensure the appropriate standard contractual clauses or other lawful safeguard and any required transfer-risk assessment and supplementary measures are in place. If no valid mechanism is available for a transfer, Studio Synapse will suspend that transfer or the affected feature until it can be made lawfully.

  • For a restricted transfer governed by the GDPR, the exporter and importer must use the applicable mechanism under Applicable Data Protection Law. Where EU Standard Contractual Clauses are required, the appropriate module of Commission Implementing Decision (EU) 2021/914 must be completed and entered into by the parties to that transfer. A processor-to-subprocessor transfer normally requires Module Three; a controller-to-processor transfer requires Module Two.
  • For a restricted transfer governed by UK law, the parties will use the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as appropriate, with completed tables and any required risk assessment.
  • For a transfer governed by Swiss law, the parties will use a recognised mechanism, including EU clauses with the Swiss adaptations required by the FDPIC where appropriate.
  • For other countries, the parties will put in place the transfer mechanism and supplementary measures required by that country's law before the transfer begins.

On request, Studio Synapse will provide Customer with available information about the destination, recipient and safeguard relied on for a Customer Personal Data transfer. This DPA does not purport to replace any separate transfer instrument that the relevant exporter and importer must execute. The Commission's Article 28 processor clauses (Decision (EU) 2021/915) and the international-transfer clauses (Decision (EU) 2021/914) are distinct instruments.

8. Assistance, records and audits

Taking account of the processing and information available to Studio Synapse, Studio Synapse will reasonably assist Customer with Data Subject requests, Personal Data Breaches, DPIAs and consultations with supervisory authorities. Customer remains responsible for deciding and making notifications or responses unless the parties separately agree otherwise.

On reasonable written notice, no more than once in a 12-month period unless a Personal Data Breach or a regulator requires more, Customer may audit information relevant to this DPA. The parties will first use available documentation, security summaries and remote review; any on-site audit must be during business hours, protect other customers' confidentiality and system security, and be at Customer's expense. The parties will agree a reasonable scope and schedule. Nothing prevents a regulator from exercising its statutory powers.

9. U.S. state privacy laws

Where Customer Personal Data is subject to a U.S. state privacy law and Studio Synapse qualifies as a processor, service provider or contractor, Studio Synapse will process it only for the limited business purposes set out in this DPA and the Terms; will not sell it, share it for cross-context behavioural advertising, or use it for targeted advertising; will not retain, use or disclose it outside the permitted business relationship except as the law allows; and will not combine it with other data except as permitted by law. Studio Synapse will provide the level of privacy protection required by the applicable law, assist Customer with consumer requests, notify Customer if it can no longer meet its obligations, and allow Customer to take reasonable steps to verify and remediate unauthorised use. Customer will notify Studio Synapse of applicable restrictions and instructions.

10. Return and deletion

Customer may export Customer Data while the Account is active and, on request, during the 30 days after account closure. Before deletion, Customer may request return/export of Customer Personal Data in a commonly used format; if Customer does not request return, Studio Synapse will delete Customer Personal Data from TOM active systems and instruct its Subprocessors to delete it within 30 days after closure, unless applicable law requires retention. Backup copies are protected and are overwritten or deleted on a rolling cycle no later than 30 days after deletion from active systems. Technical and security logs are retained for no more than 90 days from creation and then deleted or irreversibly anonymised; those logs are limited to operational/security information and are not a substitute archive of campaign content. These periods do not automatically close a separately maintained mailbox/domain subscription or erase message copies held in a mailbox account that remains active; Customer controls that separate account and may instruct Studio Synapse to request deletion through the applicable provider. Billing, tax and other records Studio Synapse must retain as an independent Controller are handled separately under the Privacy Policy and applicable law.

11. Liability and third-party rights

The liability provisions in the Terms apply to this DPA only to the extent permitted by Applicable Data Protection Law. Nothing in this DPA limits a Data Subject's rights, a regulator's powers, or liability that cannot lawfully be limited or transferred. This DPA does not prevent a Data Subject or authority from bringing a claim against either party.

Schedule 1 — Details of processing

Subject matterCustomer's use of TOM to organise sales-engagement campaigns and related contact data.
DurationFor the Service term. Export is available during the Account term and for 30 days after closure. Customer Personal Data is deleted from TOM active systems and deletion is instructed to Subprocessors within 30 days after closure; backups are deleted on a rolling cycle no later than 30 days after active-system deletion. Technical/security logs are retained for up to 90 days from creation. Separate, still-active mailbox/domain accounts and their stored copies follow the account/provider terms described in section 10.
Nature and purposeCollection and storage of campaign data; reading a public prospect website identified by Customer; generating AI-assisted drafts from that website and Customer's instructions; managing domains/mailboxes through connected providers; campaign scheduling and transmission; handling delivery, bounces and replies; recording and applying opt-outs and suppression instructions; support, service operation and security.
Data SubjectsCustomer's prospects, business contacts and email recipients; Customer's authorised users and senders whose details appear in campaign messages.
Personal DataNames, email addresses, public website URLs and content, publicly stated job roles and company details, AI prompts limited to relevant information appearing on the identified public prospect website, generated drafts, sender details, sent message content, replies, delivery/bounce events, unsubscribe and suppression records, and limited campaign/service metadata.
Special categories and criminal dataProhibited. Customer must not submit special-category personal data under GDPR Article 9, personal data relating to criminal convictions/offences, or children's personal data.
Processing frequencyContinuous during the Service term, as initiated or configured by Customer.
Customer instructionsThis DPA, the Terms, Customer's account and campaign settings, website URLs provided by Customer, and Customer's written support instructions.

Schedule 2 — Security measures and Subprocessors

Technical and organisational measures

  • TLS/HTTPS encryption for data in transit;
  • access controls and authentication requirements for internal systems;
  • logging and monitoring for service operations and security;
  • secure cloud hosting and application infrastructure; and
  • regular backups, with backup copies retained for no more than 30 days after deletion from active systems.

These are the current measures disclosed by Studio Synapse. No certification or particular security standard is represented. Studio Synapse may update measures, provided it does not materially reduce the overall level of protection for Customer Personal Data.

Authorised Subprocessors and processing locations

Processor / providerPurposeLocation / transfer information
Cloudflare, Inc.Cloudflare Pages, Workers and DNS; website/application hosting, edge delivery and request processingUnited States and global edge network. Restricted transfers, if any, are subject to the safeguards required by applicable law.
Supabase, Inc.Application database and authenticationCustomer project primary region: AWS eu-west-1 (Ireland, EEA). Support access and onward subprocessor processing may occur elsewhere subject to the applicable transfer safeguards.
Hetzner Online GmbHApplication workloads and related hostingFinland (EEA). Backups retained for no more than 30 days.
Snowlight Ventures OÜ (Mailpool; Estonian registry no. 16370638)Mailpool API, email infrastructure, and mailbox/domain provisioning and managementPrimarily Estonia and countries where Mailpool's service providers operate. Depending on the mailbox/domain configured, its upstream providers may include Google Workspace, Microsoft 365, SMTP providers and domain registrars. Mailpool's published Privacy Policy lists Google Cloud Storage (Ireland), Webflow, Sentry, SendGrid/Twilio, Customer.io, Intercom, Segment/Twilio and Paddle among providers used for its services; access to TOM Customer Personal Data is limited to providers involved in the Mailpool service TOM uses.
OpenRouter, Inc. and approved model endpoint providersAI inference to generate personalised drafts from the public prospect website identified by CustomerOpenRouter is based in the United States; the selected endpoint provider's location may vary by model/route. OpenRouter prompt/completion logging and product-improvement use are disabled for TOM, so prompt/completion content is not retained by OpenRouter; request metadata may still be processed for routing, billing, security and abuse prevention. The endpoint provider receives the prompt to generate an output, is not authorised to train on Customer Personal Data, and may retain request content only for the period disclosed by its provider policy. Studio Synapse will not route identifiable Customer Personal Data to an endpoint whose training policy permits training or whose retention policy is unknown. The current provider policy information is published by OpenRouter.
Google Ireland Limited / Google LLCGoogle Workspace only where provisioned as a Mailpool upstream provider; website Google Analytics and Google Fonts are described separately in the Privacy and Cookie Policies and are not used to process campaign data for Studio Synapse's own purposesIreland / United States; transfers subject to applicable safeguards.

Stripe processes account, order and payment information under its own terms and is not authorised to receive Customer Personal Data about prospects or campaign recipients. No other SMTP or domain-registrar provider is directly appointed by Studio Synapse for Customer Data; such infrastructure is provisioned through Mailpool and its upstream providers as listed above. Mailpool's currently published Terms state that its Article 28 DPA is available on request; Studio Synapse will maintain the written processing terms required for Mailpool and its downstream providers as a condition of their access to Customer Personal Data. The list above describes direct Subprocessors and provider categories currently used; a specific replacement or material addition is subject to the advance notice and objection procedure in section 5. Updated names, exact routes and country-level details are available from Studio Synapse on request.

12. Contact

For DPA requests, privacy matters or to exercise a right: team@theoutreachmachine.com. Abuse reports: abuse@theoutreachmachine.com.

Data Processing Addendum version 2.0, effective 27 September 2026 upon Customer's recorded acceptance.

TOM — The Outreach Machine

Guided outreach: infrastructure, warmup, AI personalization and sending under control.

Why TOM AI personalization How it works Deliverability Pricing FAQ Blog
Terms of Service Data Processing Addendum Privacy Policy Refund Policy Cookie Policy Contact

© 2026 TOM — The Outreach Machine · theoutreachmachine.com

PERMISSION-BASED OUTREACH ONLY · THIS PAGE USES GOOGLE ANALYTICS

Studio Synapse di Fabrizio Mainardi di Pescia — ditta individuale · VAT No. IT13965140968 · Via Coste di Lagolo 12, 38076 Madruzzo (TN), Italy · team@theoutreachmachine.com