This Data Processing Addendum ("DPA") governs IV-Lead's processing of Customer Personal Data on behalf of a connected organisation.
Last updated: 31 August 2026
1. Scope and incorporation
This DPA forms part of the IV-LEAD Email Signatures Terms of Service. It applies where Chen Yehoshua, trading as IV-Lead ("IV-Lead"), processes Customer Personal Data on behalf of the organisation that connected the HubSpot app ("Customer").
This DPA does not apply to processing for which IV-Lead acts as an independent controller, including IV-Lead's own service administration, terms-acceptance evidence, security records, infrastructure security, support correspondence, and legal compliance, as described in the Privacy Notice.
2. Definitions
"Customer Personal Data" means personal data contained in the Customer's HubSpot roster or rollout records and processed by IV-Lead solely to provide the connected app. "Data Protection Law" means the privacy and data-protection law applicable to the relevant processing, including the GDPR or UK GDPR where applicable. "Controller", "processor", "personal data", "processing", and "personal data breach" have the meanings given by applicable Data Protection Law.
3. Roles and documented instructions
Customer is controller and IV-Lead is processor for Customer Personal Data. Customer instructs IV-Lead to process Customer Personal Data only as necessary to provide, secure, support, and terminate the connected app in accordance with the Terms, this DPA, Customer's authorised use of the Service, and any additional lawful written instruction accepted by IV-Lead.
IV-Lead will inform Customer if, in IV-Lead's reasonable opinion, an instruction infringes applicable Data Protection Law, unless law prohibits that notice. IV-Lead may suspend the affected processing while the parties resolve the issue.
Customer is responsible for the lawfulness of its instructions, its HubSpot data, its notices to workers, and its legal basis for the processing.
4. Processing details
| Subject matter | Providing a company-standard email-signature generator and rollout view connected to Customer's HubSpot account. |
|---|---|
| Duration | For the connection period and the limited deletion and security-retention periods stated in the Privacy Notice. |
| Nature and purpose | Retrieve the permitted HubSpot user roster; verify account membership and super-admin status; apply Customer's brand kit; store per-user rollout status under HubSpot user ID; show authorised rollout information; secure, troubleshoot, and terminate the connected service. |
| Data subjects | Customer's HubSpot users, typically employees and contractors. |
| Data categories | HubSpot user ID; work name and work email address processed transiently; language, template, renderer version, email-client choice, generated or confirmed state, confirmation time, and self-test status; account and team information needed to verify access. |
| Special-category or highly sensitive data | Not required or intended. Customer must not instruct IV-Lead to process such data through the Service. |
5. Confidentiality and personnel
IV-Lead will ensure that any person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality and receives access only as needed for the Service, security, support, or legal obligations.
6. Security
Taking account of the nature, scope, context, and purposes of the processing, IV-Lead will maintain reasonable technical and organisational measures designed to protect Customer Personal Data. The current measures include:
- HTTPS for data in transit;
- authenticated encryption of HubSpot OAuth tokens at rest;
- hashed, short-lived OAuth state and builder launch tokens, with single-use launch tokens;
- least-privilege HubSpot access using one read-only scope;
- server-side verification of account membership and super-admin status;
- tenant isolation based on the verified session rather than browser-supplied account input;
- sandboxed signature previews;
- security audit logging that is designed not to contain raw OAuth tokens or signature content; and
- automated testing of tenant isolation, including cross-tenant replay attempts.
IV-Lead may update security measures where the overall level of protection is not materially reduced.
7. Subprocessors
Customer gives general authorisation for IV-Lead to use the subprocessors listed below for Customer Personal Data:
| Subprocessor | Service | Processing location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, request handling, security observability, and database recovery | Cloudflare infrastructure, including global network routing and the configured database region |
HubSpot is Customer's selected platform and the source from which Customer directs the app to retrieve roster data. Google Workspace is used for support correspondence for which IV-Lead acts as controller; neither is listed above as a subprocessor of the core Customer Personal Data processing.
IV-Lead will require a subprocessor to protect Customer Personal Data under written terms that provide materially equivalent data-protection obligations. IV-Lead remains responsible for the subprocessor's performance of those obligations to the extent required by applicable law.
IV-Lead will provide at least 14 days' notice before appointing a new subprocessor that will process Customer Personal Data, through an in-app notice to connected accounts and an update to this page. Customer may object on reasonable data-protection grounds during that period. If the parties cannot resolve the objection, Customer may terminate the affected processing by disconnecting the app.
8. Assistance with data-subject requests and compliance
Taking account of the nature of the processing and information available to IV-Lead, IV-Lead will reasonably assist Customer with:
- responding to requests to exercise data-subject rights;
- security obligations, breach assessment and notification;
- data-protection impact assessments and prior consultation where legally required; and
- demonstrating compliance with applicable processor obligations.
If IV-Lead receives a request concerning Customer Personal Data, IV-Lead will direct the requester to Customer unless law requires IV-Lead to respond directly, and will notify Customer where permitted.
9. Personal data breaches
IV-Lead will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data and, where reasonably practicable, within 48 hours. The notice will include available information reasonably required for Customer to assess and meet its legal obligations. IV-Lead's notice is not an admission of fault or liability.
10. Deletion and return
On disconnect, IV-Lead destroys usable HubSpot OAuth credentials and blocks further HubSpot access. IV-Lead will delete Customer Personal Data from the live application database within the periods stated in the Privacy Notice, unless Customer requests earlier verified deletion or applicable law requires retention.
Cloudflare point-in-time recovery may contain earlier copies for up to 7 additional days after live deletion. Such copies are isolated for disaster recovery and age out automatically. IV-Lead does not provide a return export of transient roster names or work email addresses because those fields are not persisted; Customer retains the source data in HubSpot.
11. Audit information
On reasonable written request, IV-Lead will provide information reasonably necessary to demonstrate compliance with this DPA. Customer must first use available documentation and remote evidence. Any additional audit must:
- be limited to once in any 12-month period unless a confirmed breach or regulator requires otherwise;
- give at least 30 days' notice where practicable;
- occur during reasonable hours without disrupting the Service or exposing another customer's data or confidential information;
- be performed by an independent qualified auditor bound by confidentiality; and
- be paid for by Customer unless the audit identifies material non-compliance by IV-Lead.
12. International transfers
IV-Lead is established in Israel, which the European Commission recognises as providing an adequate level of data protection. Where Customer Personal Data is transferred onward to a country that requires an additional transfer mechanism, IV-Lead will rely on an applicable lawful safeguard, including relevant provider contractual safeguards and the European Commission's Standard Contractual Clauses where applicable.
13. Liability and order of precedence
The Terms' limitations and exclusions of liability apply to this DPA to the fullest extent permitted by law. Nothing in this DPA limits rights that cannot lawfully be limited.
If this DPA conflicts with the Terms on Customer Personal Data, this DPA controls. Mandatory Data Protection Law always controls.
14. Contact
Data-processing questions and instructions: support@iv-lead.com.