Data Processing Agreement
How ManyPI processes personal data on your behalf, under Article 28 GDPR.
Version 2.0 · Effective 5 September 2026
This agreement applies automatically to every ManyPI customer. You do not need to request it, sign it or negotiate it in order to be covered — it takes effect when you accept our Terms of Service.
If your procurement process needs a countersigned PDF, email legal@manypi.com and we will send one at no charge.
Two sections are worth reading even if you read nothing else: section 13, which describes the one place where data is shared across customers, and section 14, which sets out what you are responsible for as controller.
Contents
This Data Processing Agreement ("DPA") is concluded between:
(1) the Customer — the natural or legal person who has entered into the ManyPI Terms of Service, acting as controller; and
(2) ManyPI, Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Federal Republic of Germany, VAT ID DE335582063 ("ManyPI", "we"), acting as processor.
This DPA implements Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the equivalent provisions of the UK GDPR and the Swiss Federal Act on Data Protection.
How this DPA is concluded. This DPA forms an integral part of the Terms of Service and takes effect automatically when the Customer accepts those Terms or begins using the Service, whichever is earlier. No separate signature is required for it to bind us. If the Customer's procurement process requires a countersigned copy on paper or as a PDF, write to legal@manypi.com and we will provide one at no charge.
Order of precedence. In the event of a conflict, the order of precedence is: (i) the Standard Contractual Clauses in Annex IV; (ii) this DPA; (iii) the Terms of Service; (iv) any other document. Nothing in this DPA is intended to contradict or restrict the Standard Contractual Clauses.
Terms used in this DPA that are defined in the GDPR — including "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" — carry their GDPR meaning.
"Customer Personal Data" means personal data that ManyPI processes on the Customer's behalf in the course of providing the Service. It comprises, in particular:
- Contact and lead records that the Customer uploads, imports, creates, or instructs the Service to research and collect;
- CRM records — companies, deals, tasks, notes and activity history;
- Mail data — the content and metadata of messages sent through the Service and, where the Customer connects a mailbox, message headers and message bodies synchronised from that mailbox;
- Outreach records — campaign membership, delivery status, replies, unsubscribes and suppression entries;
- Files and datasets the Customer uploads for analysis;
- Results of web research that the Customer instructs the Service to perform.
Allocation of roles — please read this carefully.
The Customer is the controller of all Customer Personal Data. It is the Customer, not ManyPI, who decides which people to research, which contacts to import, which mailbox to connect, what to say to those people and on what legal basis. ManyPI has no relationship with the Customer's contacts and no independent purpose in respect of them.
ManyPI is the processor of Customer Personal Data.
ManyPI is separately an independent controller for a limited set of processing that it determines itself — account registration and administration, billing, security and abuse prevention, service telemetry, support correspondence, and the operational caches described in section 13. That processing is governed by our Privacy Policy, not by this DPA. Where ManyPI acts as controller, it does not do so on the Customer's instructions and does not use Customer Personal Data for those purposes.
Subject matter. The processing of Customer Personal Data necessary to provide the Service described in the Terms of Service.
Duration. This DPA applies for as long as ManyPI processes Customer Personal Data, and in any event for the duration of the Customer's subscription plus the deletion period set out in section 9.
Nature and purpose. Collection, recording, organisation, structuring, storage, retrieval, consultation, enrichment, analysis (including analysis by artificial intelligence), transmission, restriction, erasure and destruction, in each case for the purpose of providing the lead research, CRM, outreach, workflow automation, data extraction and analytics functions of the Service.
Types of personal data and categories of data subjects. Set out in Annex I.
Frequency. Continuous, for the duration of the subscription.
ManyPI shall process Customer Personal Data only on the Customer's documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law to which ManyPI is subject. In that case ManyPI shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
What constitutes an instruction. The Customer's instructions are given by: (i) this DPA and the Terms of Service; (ii) the Customer's configuration and use of the Service through its interface, API or MCP server — including which contacts to import, which research to run, which mailbox to connect, which campaigns to send and which automations to enable; and (iii) any further written instruction the Customer gives to legal@manypi.com.
ManyPI shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions. ManyPI may suspend execution of the instruction concerned until the Customer confirms or withdraws it.
No independent use. ManyPI shall not sell Customer Personal Data, shall not use it for its own marketing, shall not disclose it to third parties except as provided in this DPA, and shall not combine it with data from other customers except in the operational caches expressly described in section 13.
Government and law enforcement requests. If ManyPI receives a legally binding request from a public authority for disclosure of Customer Personal Data, it shall — unless legally prohibited — notify the Customer without undue delay, challenge requests that appear unlawful or overbroad, and disclose only the minimum lawfully required.
ManyPI shall ensure that any person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement.
ManyPI operates as a sole proprietorship. Access to production systems is limited to the owner and, where engaged, individually named contractors who have signed a written confidentiality undertaking before being granted access.
Administrative access. ManyPI maintains an internal administration interface capable of viewing aggregated and, in defined circumstances, individual workspace records for support, billing and abuse-prevention purposes. Access to it is restricted by a credential held outside the application database; every access is logged with actor, path, IP address, user agent and timestamp; and every write operation additionally requires a one-time code delivered through a separate channel. Logs of that access are available to the Customer on request.
ManyPI shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons.
The measures in force at the effective date of this DPA are set out in Annex II. ManyPI may update them from time to time provided the level of security is not materially reduced.
The Customer has reviewed the measures in Annex II and considers them appropriate to the risk presented by the Customer Personal Data it chooses to process through the Service. The Customer remains responsible for its own security practices, including the strength and confidentiality of its credentials, its management of user accounts and roles within its organisation, and its decision as to which categories of data to place in the Service.
General authorisation. The Customer grants ManyPI a general written authorisation to engage sub-processors, subject to the conditions in this section.
Current sub-processors are listed in Annex III and maintained at all times at https://manypi.com/legal/sub-processors.
Flow-down. ManyPI shall impose on each sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA. Where a sub-processor is located outside the EEA, ManyPI shall put in place a valid transfer mechanism under Chapter V GDPR.
Full liability. Where a sub-processor fails to fulfil its data protection obligations, ManyPI remains fully liable to the Customer for the performance of that sub-processor's obligations.
Changes and right to object. ManyPI shall give the Customer at least thirty (30) days' notice before adding or replacing a sub-processor. Notice is given by updating the sub-processors page and by email to Customers who have subscribed to change notifications there. The Customer may object on reasonable data-protection grounds within that period by writing to legal@manypi.com. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
Where a change is necessary to address an urgent security risk, ManyPI may make it immediately and give notice as soon as possible thereafter.
Customer-configured integrations. The Service allows the Customer to connect third-party systems of its own choosing — for example a CRM, a project tracker or a custom MCP server. Those providers are not ManyPI sub-processors. The Customer authorises and directs those connections and is the controller in respect of them; the Customer is responsible for having its own lawful basis and, where required, its own agreement with each such provider.
Taking into account the nature of the processing, ManyPI shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising a data subject's rights under Chapter III GDPR.
Self-service first. The Service provides functions with which the Customer can, without ManyPI's involvement, search for a person across its workspace, view every record held about them, correct or delete those records, export them in a structured, commonly used and machine-readable format, and add an address to a permanent suppression list. The Customer shall use these functions in the first instance.
Requests received by ManyPI. If ManyPI receives a request directly from one of the Customer's data subjects, it shall not respond to it on the merits, shall promptly forward it to the Customer, and shall inform the data subject that the request has been forwarded to the responsible controller — unless applicable law requires otherwise.
Further assistance. Where a request cannot be answered using the self-service functions, ManyPI shall provide reasonable additional assistance without undue delay and at no charge, save that manifestly unfounded or excessive requests for assistance may be charged at ManyPI's then-current professional-services rate, notified in advance.
Notification to the Customer. ManyPI shall notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within forty-eight (48) hours of becoming aware of it. Notification shall be sent to the email address on the Customer's account and, where the breach is material, additionally by direct contact.
The notification shall describe, to the extent known at the time and supplemented as further information becomes available:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address it and to mitigate its adverse effects;
- the name and contact details of a point of contact at ManyPI.
ManyPI shall not delay an initial notification in order to complete its investigation. An incomplete notification within the deadline is preferred to a complete one after it.
Documentation. ManyPI shall document every personal data breach, including the facts, its effects and the remedial action taken, and shall make that documentation available to the Customer on request.
No admission. A notification under this section is not, and shall not be construed as, an acknowledgement of fault or liability.
Further assistance. ManyPI shall assist the Customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR — security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation — taking into account the nature of processing and the information available to ManyPI. In particular, ManyPI shall provide the information reasonably required for a data protection impact assessment concerning the Service.
On termination or expiry of the Customer's subscription, and at the Customer's choice, ManyPI shall delete or return all Customer Personal Data and delete existing copies, unless Union or Member State law requires continued storage.
Export window. For thirty (30) days after termination the Customer may export its data through the Service's export functions. The Customer is responsible for exporting within that window.
Deletion. After the export window expires, or immediately upon the Customer's written instruction, ManyPI shall delete Customer Personal Data from its production systems.
Backups. Encrypted backups are retained on a rolling cycle for disaster-recovery purposes and are overwritten in the ordinary course. Data deleted from production remains in backups until those backups expire, and in any event no longer than ninety (90) days after deletion from production. During that period the data is not accessible in the ordinary course of operations and is not processed for any purpose other than restoration of the service.
Statutory retention. ManyPI may retain data where required by law — in particular invoices and accounting records, which German commercial and tax law (§ 257 HGB, § 147 AO) requires to be retained for up to ten years. Data retained on that basis is processed only for that purpose and is deleted when the period expires.
Certification. ManyPI shall certify deletion in writing on request.
Operational caches. The limited cross-customer caches described in section 13 are not Customer Personal Data and are governed by that section rather than by this one.
ManyPI shall make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
The parties agree the following practical arrangement, which is intended to make that right usable rather than theoretical:
Tier 1 — documentation. ManyPI shall provide, on request and at no charge, its current technical and organisational measures, its sub-processor list and the corresponding transfer safeguards, and any third-party assessment reports it holds.
Tier 2 — questionnaire. ManyPI shall complete a reasonable written security and data-protection questionnaire once per twelve-month period, at no charge, within thirty (30) days of receipt.
Tier 3 — inspection. Where the Customer reasonably demonstrates that Tiers 1 and 2 are insufficient — in particular following a personal data breach or a substantiated regulatory inquiry — the Customer may conduct an on-site or remote inspection, subject to: at least thirty (30) days' prior written notice; conduct during normal business hours; no more than once per twelve-month period, unless required by a supervisory authority or following a breach; execution of a confidentiality undertaking by the auditor; the auditor not being a competitor of ManyPI; and no access to data belonging to other customers.
Costs. The Customer bears its own audit costs and ManyPI's reasonable costs of supporting a Tier 3 inspection, unless the inspection reveals a material breach by ManyPI of this DPA, in which case ManyPI bears its own costs.
Supervisory authorities. Nothing in this section limits the powers of a competent supervisory authority.
Where the data sits. Your account data, CRM records, lead records and synchronised mail are stored on servers located in the European Union. The primary database is hosted in the European Union (Supabase, EU region), and background processing infrastructure is located in Germany and Finland (Hetzner Online GmbH). Storage and processing of Customer Personal Data in the ordinary course therefore involves no transfer outside the EEA.
Transfers that do occur. Certain sub-processors listed in Annex III are established outside the EEA — principally in the United States and in Israel. Personal data is transferred to them only to the extent necessary for the function they perform.
Safeguards. For each such transfer ManyPI relies on:
- an adequacy decision of the European Commission where one covers the recipient — this applies to Israel; or
- the EU-US Data Privacy Framework, where the recipient is certified under it; and in every case, as an independent fallback,
- the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated into this DPA as Annex IV.
We rely on the Standard Contractual Clauses as a standing safeguard rather than depending on the adequacy of the EU-US Data Privacy Framework alone, because the validity of that framework is subject to pending litigation before the Court of Justice of the European Union. If an adequacy decision is invalidated, the Standard Contractual Clauses continue to apply without any further action by the parties.
Transfer impact assessments. ManyPI has assessed the laws and practices of the destination countries for each transfer and has documented supplementary measures where appropriate, including encryption in transit and at rest, minimisation of the data transmitted, and contractual commitments on government access. That documentation is available under section 10.
UK and Switzerland. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies. For transfers subject to Swiss law, the Standard Contractual Clauses apply with the amendments identified by the Swiss Federal Data Protection and Information Commissioner.
The Service uses artificial intelligence to research leads, draft messages, extract structured data from web pages, classify inbound replies and answer questions about uploaded datasets. Delivering those functions requires Customer Personal Data to be transmitted to our AI sub-processor.
What is transmitted. Depending on the function used: the content of the Customer's instructions; lead records supplied as context for drafting; excerpts of inbound reply bodies for sentiment and intent classification; the content of files the Customer uploads for analysis; and excerpts of web pages retrieved during research.
No training on Customer Personal Data. ManyPI does not use Customer Personal Data to train, fine-tune or improve any artificial-intelligence model, whether its own or a third party's. ManyPI has contracted with its AI sub-processor on terms that prohibit the use of data submitted through the interface used by the Service for training that provider's models. This prohibition is passed down as a binding instruction under section 3.
Human oversight. Output generated by artificial intelligence is probabilistic and may be inaccurate, incomplete or misleading. It is provided to assist the Customer's judgement, not to replace it. The Customer is responsible for reviewing output before acting on it, and in particular before sending any message generated with its assistance.
No automated decision-making with legal effect. The Service scores and ranks leads to help the Customer prioritise its own outreach. That scoring produces no legal effects concerning the data subject and does not similarly significantly affect them within the meaning of Article 22 GDPR. The Customer shall not configure the Service to make decisions of that kind.
We describe this processing explicitly because it is the one respect in which the Service does not keep every customer's data wholly separate, and a Customer conducting a data-protection review is entitled to know that before signing.
To avoid repeatedly retrieving the same publicly available information and repeatedly querying the same mail servers — which would burden third-party infrastructure and slow the Service for everyone — ManyPI maintains two operational caches that are shared across customers:
- a cache of contact information published on a company's own website, keyed by domain, holding published email addresses, telephone numbers, named roles and social profile links; and
- a cache of email address deliverability results, keyed by address, holding whether a mailbox was found to exist, the reason, and the responding server's code.
In respect of these caches ManyPI acts as an independent controller, not as the Customer's processor. The legal basis is Article 6(1)(f) GDPR — our legitimate interest, and the legitimate interest of the operators of the systems we would otherwise query repeatedly, in not performing the same lookup many times over. We have carried out and documented a balancing assessment for this processing.
Safeguards. Entries expire and are purged on a defined retention cycle. The deliverability cache is not readable by any customer account and is accessible only to internal service processes, so that it cannot be used to test whether arbitrary addresses exist. Neither cache records who looked a record up, and neither is used to build profiles of individuals.
Rights. A person may object to this processing or request erasure of their entry at privacy@manypi.com, and we will act on it. Because we act as controller here, this right is exercised against ManyPI directly and does not depend on any Customer.
This section is central to the allocation of risk under this DPA. The Service is capable of collecting personal data about people who have no relationship with the Customer, and of sending them messages. Whether that is lawful depends entirely on decisions the Customer makes and that ManyPI cannot see.
The Customer warrants and undertakes that:
- it is and remains the controller of all Customer Personal Data, and has determined the purposes and means of the processing it instructs;
- it has a valid legal basis under Article 6 GDPR for every category of processing it instructs, including collection, enrichment, storage and contact;
- it complies with its information obligations under Articles 13 and 14 GDPR towards every data subject whose data it processes through the Service — including, where data was not obtained from the data subject, providing the information required by Article 14 within one month or at the time of first communication, whichever is earlier, and identifying the source;
- it complies with all applicable electronic marketing law in every jurisdiction it contacts, including Directive 2002/58/EC as implemented nationally, § 7 UWG in Germany — which requires prior express consent for commercial email, including in a business-to-business context — the CAN-SPAM Act in the United States, and CASL in Canada;
- it honours opt-outs, objections and erasure requests from its contacts without undue delay;
- it has the right to connect any mailbox it connects, and where that mailbox belongs to an organisation, that it is authorised by that organisation to grant access to its contents;
- it does not instruct the processing of special categories of personal data under Article 9 GDPR, or data relating to criminal convictions and offences under Article 10, through the Service, unless it has first agreed this with ManyPI in writing and the parties have implemented appropriate additional safeguards;
- it does not use the Service to process the personal data of children;
- it complies with the Acceptable Use Policy, which forms part of the Terms of Service.
Indemnity. The Customer shall indemnify ManyPI against claims, proceedings, fines and reasonable legal costs brought by a third party, a data subject or a supervisory authority to the extent they arise from the Customer's breach of this section.
Suspension. Where ManyPI has a reasonable and substantiated belief that a Customer's processing is unlawful, it may suspend the affected function and shall inform the Customer of the grounds without undue delay, giving the Customer a reasonable opportunity to respond.
The liability of the parties under this DPA is governed by the limitations and exclusions in the Terms of Service, which apply to this DPA as if set out here in full.
Nothing in this DPA or in the Terms of Service limits or excludes:
- liability arising from intent or gross negligence;
- liability for injury to life, body or health;
- liability under the German Product Liability Act (Produkthaftungsgesetz);
- liability that cannot be limited or excluded under applicable data protection law; or
- the liability of either party towards a data subject under Article 82 GDPR.
Article 82 GDPR governs the parties' liability towards data subjects and their respective rights of recourse against one another. A limitation of liability agreed between the parties does not affect a data subject's claims.
Term. This DPA takes effect on the earlier of the Customer's acceptance of the Terms of Service and first use of the Service, and remains in force until all Customer Personal Data has been deleted or returned in accordance with section 9.
Changes. ManyPI may amend this DPA where necessary to reflect a change in applicable law, a decision or guidance of a supervisory authority, a change in the Standard Contractual Clauses, or a material change to the Service. ManyPI shall give the Customer at least thirty (30) days' notice of a material amendment. If the amendment materially reduces the Customer's rights or ManyPI's obligations, the Customer may terminate the affected subscription without penalty before the amendment takes effect and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
Severability. If any provision of this DPA is held invalid, the remainder continues in force and the invalid provision shall be replaced by a valid one that most closely reflects the parties' intention.
Governing law and jurisdiction. This DPA is governed by the law of the Federal Republic of Germany, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods. Exclusive place of jurisdiction, to the extent permissible, is Berlin, Germany. This choice of law does not affect the governing law of the Standard Contractual Clauses in Annex IV, which is determined by those clauses themselves.
A. List of parties
Data exporter (controller): the Customer, as identified in its ManyPI account and billing records.
Data importer (processor): ManyPI, Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Federal Republic of Germany. Contact: privacy@manypi.com.
B. Categories of data subjects
- The Customer's own personnel — employees, contractors and other authorised users of the Customer's workspace.
- Business contacts and prospective customers of the Customer, including individuals whose business contact details the Customer uploads, imports, or instructs the Service to research and collect from publicly accessible sources.
- Individuals who correspond with the Customer by email, where the Customer connects a mailbox — including senders and recipients who are not themselves leads, whose message headers are read in order to determine relevance.
- Individuals named in files, datasets or web pages the Customer submits for analysis.
C. Categories of personal data
- Identity and contact data: full name, job title, business email address, telephone number, business location, professional social media profile URL.
- Employment data: employer name, employer domain, employer size and industry, seniority.
- Correspondence content: subject lines, message bodies in plain text and HTML, sender and recipient addresses including copied recipients, timestamps, threading identifiers, and whether attachments were present.
- Derived and inferred data: relevance scores, fit rationale, AI-generated sentiment and intent classifications, AI-generated summaries, and custom research fields defined by the Customer.
- Engagement data: delivery status, bounce classification, message-open counts, replies, unsubscribes and suppression entries.
- Deliverability data: whether an address was found to be valid, the responding mail server and its response code.
- Free-text data: notes, tasks and any other content the Customer chooses to record.
D. Special categories of personal data
None is intended, instructed or permitted. The Customer undertakes in section 14 not to submit data falling within Articles 9 or 10 GDPR. The parties acknowledge that free-text fields and synchronised message bodies are capable of containing such data if the Customer places it there; ManyPI does not seek it, does not index for it and does not process it as such.
E. Nature and purpose of the processing
Lead research and enrichment; contact and customer relationship management; email outreach and reply handling; mailbox synchronisation; workflow automation; extraction of structured data from web pages; analysis of uploaded datasets; and the hosting, security, backup and support necessary to provide those functions.
F. Frequency of the transfer
Continuous, for the duration of the subscription.
G. Duration of processing
For the duration of the subscription, plus the export and deletion periods in section 9.
H. Competent supervisory authority
Where the Standard Contractual Clauses apply and ManyPI is the exporter, the competent authority is the Berlin Commissioner for Data Protection and Freedom of Information. Where the Customer is the exporter, the competent authority is that of the Customer's own establishment.
The following measures are in force at the effective date of this DPA.
Encryption
- All data in transit is protected with TLS. Certificates on infrastructure operated by ManyPI are issued and renewed automatically.
- Data at rest is encrypted at the storage layer by our hosting providers.
- Credentials for third-party systems — mailbox passwords, OAuth access and refresh tokens, and integration tokens — are additionally encrypted at the application layer using AES-256-GCM with a key held only in the runtime environment and never committed to source control. The application refuses to start in production if that key is absent, rather than falling back to a default.
- Passwords for customer-supplied database connections are held in a dedicated secrets vault, separate from the application database, and are removed automatically when the connection is deleted.
Access control and tenant isolation
- Row-level security is enabled on the application database and enforced at the database engine, so that a query executed with a customer's credentials cannot return another customer's rows even if the application layer is bypassed.
- Tables holding operationally sensitive data are additionally closed by revoking access at the grant level, so that two independent controls must fail before they are exposed.
- The deliverability cache is not readable by any customer-level role, specifically so that it cannot be used to enumerate whether arbitrary email addresses exist.
- Administrative access is gated by an identifier held in the runtime environment rather than as a database field, so that no database write can grant it and no change to a user's own email address can escalate privilege.
- Administrative write operations require a one-time code delivered out of band.
- Authentication supports federated sign-in and enforces session expiry.
Logging and accountability
- Every administrative access is logged with actor, path, IP address, user agent and timestamp.
- Every administrative mutation is logged separately with the acting identity.
- Workspace-level activity is recorded in an event log available to the Customer.
- Outreach open tracking records a counter only; it does not record the recipient's IP address or user agent.
Data minimisation by design
- Mailbox synchronisation reads only folders on an allowlist, by default the inbox and sent items.
- A message body is downloaded and stored only where a correspondent resolves to a contact already present in the Customer's workspace. All other messages advance the synchronisation watermark and are discarded without the body being retrieved.
- Attachments are never stored.
- Where the research agent retrieves a web page, the page body is processed on our own infrastructure and only the relevant excerpts are passed to the AI provider.
- Robots exclusion files are parsed and respected, and sites that decline automated collection are honoured. A maintained block list prevents collection from sources where it would be inappropriate.
Resilience and recovery
- Managed, encrypted backups with point-in-time recovery are maintained by our database provider.
- Background processing runs on redundant infrastructure and jobs are retried on failure.
- Long-running operations are watchdogged and failed safely rather than left in an indeterminate state.
Organisational measures
- Access to production is limited to the owner and individually named contractors under written confidentiality undertakings.
- A documented credential rotation procedure is maintained.
- Sub-processors are assessed before engagement and bound by written data-protection terms.
- Suspicious-activity detection is in place for account and payment abuse.
Measures the Customer controls
The Customer is responsible for the strength and confidentiality of its own credentials, for managing membership and roles within its organisation, for the security of the mailbox it connects, and for its choice of which data to place in the Service. Note in particular that records synchronised from a connected mailbox are visible to every member of the Customer's organisation in that workspace; the Customer should take that into account when adding members.
The following sub-processors are approved as at 5 September 2026. The authoritative and current version of this list is published at https://manypi.com/legal/sub-processors, where a Customer may also subscribe to change notifications.
Sub-processors marked as conditional are engaged only where the Customer uses the corresponding function.
| Sub-processor | Legal entity | Purpose | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Supabase, Inc. | Primary database, authentication, file storage and serverless functions. The ManyPI project is provisioned in an EU region. | Singapore (company seat); data stored in the European Union | EEA — no transfer |
| Hetzner | Hetzner Online GmbH | Virtual servers running the background job worker, the email verification engine and the web data collection gateway. | Germany and Finland | EEA — no transfer |
| Netlify | Netlify, Inc. | Application and website hosting, content delivery, TLS termination. | United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| OpenAI | OpenAI, L.L.C. | All AI model inference: research agent reasoning, drafting assistance, structured extraction, and classification of inbound replies. OpenAI is contractually prohibited from training on data submitted through the API. | United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| Bright Data | Bright Data Ltd. | Web search, page retrieval and proxy infrastructure used to collect publicly accessible business information. | Israel | Adequacy decision |
| Polar | Polar Software Inc. | Merchant of record, checkout, subscription management, customer billing portal and metered overage billing. | United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| Lemon SqueezyLegacy subscribers only | Lemon Squeezy LLC | Legacy merchant of record. Engaged only for subscribers who purchased before our migration to Polar and have not since re-subscribed. | United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| Resend | Plus Five Five, Inc. | Delivery of transactional, service and lifecycle email that ManyPI sends to you, and maintenance of the corresponding contact list. Resend does not deliver the outreach you send to your own contacts — that leaves your own mailbox. | United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| GoogleSign-in with Google, or a connected Gmail mailbox | Google Ireland Limited / Google LLC | Sign-in with Google. Separately, where you choose to connect a Gmail or Google Workspace mailbox, access to that mailbox over SMTP and IMAP using OAuth. | Ireland / United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| MicrosoftOnly if you connect a Microsoft mailbox | Microsoft Ireland Operations Limited / Microsoft Corporation | Where you choose to connect an Outlook or Microsoft 365 mailbox, access to that mailbox over SMTP and IMAP using OAuth. | Ireland / United States | EU-US Data Privacy Framework and, as a fallback, EU Standard Contractual Clauses |
| TWIPLAOnly with your analytics consent | TWIPLA GmbH | Website and in-app analytics. Loaded only after you accept the analytics category in our cookie banner, and never before. | Germany | EEA — no transfer |
| Simple Analytics | Simple Analytics B.V. | Aggregate, cookieless traffic measurement for the marketing website. Sets no cookies and stores nothing on your device. | Netherlands | EEA — no transfer |
| Contentful | Contentful GmbH | Content management for the marketing website and blog. Holds no customer data. | Germany | EEA — no transfer |
Where ManyPI transfers Customer Personal Data to a sub-processor established in a third country that is not covered by an adequacy decision, the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA by reference and apply to that transfer.
Modules. Module Two (controller to processor) applies where the Customer is the exporter and ManyPI the importer. Module Three (processor to processor) applies where ManyPI is the exporter and its sub-processor the importer.
Elections made by the parties
- Clause 7 (docking clause): applies.
- Clause 9 (use of sub-processors): Option 2, general written authorisation, with a notice period of thirty (30) days as provided in section 6.
- Clause 11 (redress): the optional independent dispute resolution paragraph does not apply.
- Clause 17 (governing law): the law of the Federal Republic of Germany.
- Clause 18(b) (choice of forum): the courts of the Federal Republic of Germany.
- Annex I.A (parties), I.B (description of transfer) and I.C (competent supervisory authority): as set out in Annex I of this DPA.
- Annex II (technical and organisational measures): as set out in Annex II of this DPA.
- Annex III (list of sub-processors): as set out in Annex III of this DPA.
United Kingdom. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is incorporated, with the Standard Contractual Clauses as the Approved EU SCCs, Tables 1 to 3 completed by reference to the Annexes above, and Table 4 specifying that neither party may end the Addendum as set out in section 19.
Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the following amendments: references to the GDPR are to be understood as references to the Swiss Act; the competent supervisory authority is the Federal Data Protection and Information Commissioner; and the term "Member State" shall not be interpreted so as to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence.
Precedence. In the event of any conflict between the Standard Contractual Clauses and this DPA, the Standard Contractual Clauses prevail.
Contact
Data protection enquiries: privacy@manypi.com
Contractual and legal enquiries: legal@manypi.com
Security reports: security@manypi.com
ManyPI, Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Federal Republic of Germany
