Skip to main content
Leverpoint.Book a review
Legal

Data processing addendum

Who is responsible for what, which providers touch the data, and what happens when an engagement ends.

Scope

This addendum forms part of the terms of service between Leverpoint (Pty) Ltd (registration 2026/672248/07) and its client. It applies to personal information processed in the course of an engagement, and is read alongside our privacy notice.

Terms used here carry the meaning given in POPIA. Where UK or EEA data subjects are involved, the equivalent UK GDPR concepts apply: responsible party corresponds to controller, and operator to processor.

Roles are allocated by activity, not by label

Under POPIA the responsible party is whoever determines the purpose and means of processing. That is not the same party for every activity in an outbound engagement, so this addendum allocates it activity by activity rather than applying one blanket label.

  • Client campaign data. Where the client defines the ICP, the targeting criteria and the message, and Leverpoint executes on the client’s documented instructions, Leverpoint acts as operator and the client as responsible party.
  • Leverpoint’s own prospecting. Data we gather to find our own clients is ours. We determine its purpose and means, so Leverpoint is the responsible party and this addendum does not apply to it.
  • Our research and harvesting tooling. The methods, sources and signal data behind our account research are determined by us. Leverpoint is the responsible party, subject to the terms of the sources we draw on.

Where in practice both parties materially shape purpose and means, the parties will record that in the statement of work and allocate obligations accordingly rather than relying on this default.

What we process, and why

Business contact information — name, business email address, job title, employer, and publicly available business context such as a published job posting. Processed for the sole purpose of performing the agreed outbound campaign. We do not process special personal information or the information of children, and we do not use client campaign data to market our own services.

Our obligations as operator

  • Process only on the client’s documented instructions, unless law requires otherwise — in which case we tell the client first where we lawfully can.
  • Keep appropriate technical and organisational security measures, including access control and encryption in transit.
  • Bind everyone with access to confidentiality.
  • Assist the client with data subject requests, and with security, breach notification and impact assessments, so far as is reasonable.
  • Notify the client without undue delay on becoming aware of a security compromise affecting their data.
  • Make available the information reasonably needed to demonstrate compliance, and allow audit on reasonable written notice, no more than once a year unless a regulator requires otherwise.

The client’s obligations

  • Ensure there is a lawful basis for the outreach instructed, including a documented legitimate interest assessment where UK or EEA recipients are targeted.
  • Ensure the ICP and targeting instructions given to us are lawful.
  • Provide any privacy notice its own regulatory position requires.
  • Tell us promptly of any objection, opt-out or data subject request received directly.

Sub-processors

We use third parties to deliver the service. Each is bound by written terms no less protective than this addendum. The current categories are:

  • Email sending and deliverability platforms
  • Email verification providers
  • Business data and enrichment providers
  • Cloud hosting and infrastructure
  • Productivity and communication tooling

We will tell clients before adding or replacing a sub-processor that handles their campaign data. A client may object on reasonable data protection grounds, and if we cannot resolve it either side may end the affected service.

Cross-border transfers

Leverpoint operates from South Africa and its providers are largely outside it, so personal information will be transferred across borders. We transfer only where the recipient is subject to a law, binding agreement or corporate rules affording protection substantially similar to POPIA, and we put appropriate safeguards in place for UK and EEA data.

Opt-outs and suppression

Every campaign carries a working opt-out. Opt-outs are actioned promptly and within ten business days at the latest. Suppression records are kept permanently and deliberately: deleting them would risk contacting someone who asked us not to. This is a legitimate and necessary retention, and it survives termination.

Retention, return and deletion

We keep client campaign data for the engagement and for a short period afterwards to deal with queries. On written request at or after termination we return it in a portable format and then delete our copies, except suppression records and anything we must keep by law.

Contact

Data protection queries, including requests to exercise rights or to report a concern, go to hello@leverpoint.co.za. Complaints may also be made to the Information Regulator in South Africa, or the Information Commissioner’s Office in the United Kingdom.

Last updated 25 August 2026.