exporta.ai
Book a demoLog inStart free
Legal noticePrivacyCookiesTermsData processingUse of AISecurity
Legal

Data processing agreement

How Exporta.ai processes, on behalf of its customers, the personal data they store on the platform (Article 28 GDPR).

Last updated: 24 September 2026

01

Parties, purpose and acceptance

This agreement is entered into between the Customer, as controller, and Tarraconsulting International S.L. (tax ID (NIF) B43758671, "Exporta.ai"), as processor. It forms part of the General terms and conditions and is accepted by accepting them, including on the Free plan. In matters of data protection, it prevails over them. Its purpose is to govern the processing of the personal data that the Customer enters into the Platform or that are obtained at its request, for the sole purpose of providing the contracted service.

02

Description of the processing

• Data subjects: the Customer's business contacts (customers, prospective customers, distributors, importers, suppliers, exhibitors and trade fair visitors) and, where applicable, the Customer's Users. • Categories of data: identification and professional data (name, job title, company, country, city), business contact details (email, phone, LinkedIn profile), notes, tasks, opportunities, attachments, voice notes and their transcription, photographs of business cards, message drafts and the content of conversations with the assistant about those contacts. The processing of special categories of data is not envisaged. • Operations: collection, recording, organisation, structuring, storage, consultation, enrichment, verification, transcription, translation, AI analysis, export and erasure. • Duration: that of the main contract.

03

Obligations of Exporta.ai

• To process the data only on the documented instructions of the Customer, which are those of this agreement and those the Customer gives when using the Platform, and to inform the Customer if it considers that an instruction infringes the legislation. • Not to use the data for its own purposes, except for aggregated and anonymised usage data to improve the service, nor to train artificial intelligence models. • To ensure that persons authorised to process the data are bound by confidentiality. • To apply the security measures of Article 32 GDPR described in the Information security policy. • To access the content of the Customer's account only when necessary to provide support or resolve an incident, with a recorded reason, on a temporary basis and leaving a record in the audit log. • To assist the Customer, insofar as possible, in responding to data subjects' rights, carrying out impact assessments and prior consultations, and complying with its security and notification obligations. • To keep a record of the processing activities carried out on behalf of the Customer.

04

Obligations of the Customer

• To ensure that it has a legal basis for processing the data it enters or obtains through the Platform and for the communications it sends, and that it has informed the data subjects where appropriate (Arts. 13 and 14 GDPR). • To assess whether it needs an impact assessment before using large-scale enrichment or prospecting features, and to apply its conclusions. • Not to enter special categories of data or data relating to minors. • To supervise the processing and give lawful instructions.

05

Data subjects' rights

If a data subject contacts Exporta.ai to exercise their rights over the Customer's data, Exporta.ai will forward the request to the Customer within two business days at most and will not respond to it on its own account, unless instructed by the Customer. The Platform offers tools to consult, rectify, export and erase data, and to add people to the Customer's suppression list.

06

Personal data breaches

Exporta.ai will notify the Customer, without undue delay and within 48 hours at most of becoming aware of it, of any security breach affecting its data, with the information available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a contact point. The information may be provided in phases.

07

Sub-processors

The Customer gives Exporta.ai general authorisation to engage the following sub-processors: • Supabase Inc. — database, authentication and file storage (Ireland region, EU). • Vercel Inc. — hosting and running of the application (Dublin region, EU). • OpenRouter Inc. — access to AI models (USA) and, through it, the providers of the models in use (including Google, Anthropic, OpenAI, DeepSeek and Xiaomi). • Apollo.io and FullEnrich — search for companies and people and finding business email addresses (USA). • looot.ai and, through it, Icypeas and Hunter — search for companies and people, finding business email addresses and reading public web pages. • Dropcontact — finding business email addresses (France, EU). • MillionVerifier — email verification. • DeepL SE — document translation (Germany, EU). • Firecrawl — reading public web pages (USA). • Resend — sending transactional emails, such as invitations (USA). • PostHog — product analytics and error logging (EU). Exporta.ai will inform the Customer of the addition or replacement of sub-processors at least 15 days in advance, by publishing the updated list on this page and notifying the administrators by email. The Customer may object on reasonable grounds; if no solution is reached, it may terminate the contract. Exporta.ai imposes equivalent data protection obligations on its sub-processors and remains liable for them.

08

International transfers

Where a sub-processor processes data outside the European Economic Area, the transfer is based on an adequacy decision (such as the EU-U.S. Data Privacy Framework) or on standard contractual clauses of the European Commission, with any supplementary measures that may be appropriate. If a mechanism ceases to be valid, Exporta.ai will adopt an alternative within a reasonable period.

09

Audits

Exporta.ai will make available to the Customer the information necessary to demonstrate compliance with this agreement. The Customer may carry out, at its own expense and with 30 days' notice, one audit per year, unless there has been a security breach in the preceding 12 months or an authority so requires. The audit will not give access to other customers' data, to confidential information of Exporta.ai or to elements that would compromise security.

10

End of the processing

On termination of the contract, the Customer may export its data from the Platform. Once the account has been closed, Exporta.ai will erase the personal data processed on the Customer's behalf, unless the law requires them to be kept, in which case it will keep them blocked. Backups held by the infrastructure provider are deleted in its ordinary rotation cycle. At the Customer's request, Exporta.ai will certify the erasure.

11

Liability

Each party is liable for its breaches of this agreement and of the legislation, subject to the limits set out in the General terms and conditions. If Exporta.ai were to process the data for purposes other than those entrusted to it, it will be considered a controller in respect of that processing.

For any questions about data processing, write to hola@exporta.ai.