Data processing agreement
Last updated: October 2, 2026
This agreement is part of our terms and conditions. It sets out how Greenwolf Holding B.V., trading as Vintoo, processes personal data on behalf of the customer, as required by article 28 of the GDPR, and which data we process as a controller ourselves.
1. Parties
This agreement is between the customer, the organization that uses Vintoo, and Greenwolf Holding B.V., Chamber of Commerce number 92298001, Nijmegen, the Netherlands (we). By accepting the terms, the customer also accepts this agreement. Where this agreement and the terms differ on personal data, this agreement prevails.
2. Roles
We distinguish three kinds of data:
- Customer data: everything the customer enters in Vintoo or receives from it: its offering and ideal customer profile, its prospects, notes and pipeline stages, its team members and the reports written for it. For customer data the customer is the controller and we are the processor. This agreement covers that processing.
- Public source data: public business information we collect to write reports, such as company websites, company pages, company posts and public professional profiles of employees. We decide which sources we use and keep this data for a short time, so that we do not have to collect it again for every report. For this we are an independent controller; see section 12.
- Account data: data about users of Vintoo, such as names and email addresses. For this we are the controller; our privacy statement explains how we handle it.
3. Subject, purpose and duration
We process customer data to provide Vintoo: to store the customer's prospects, to combine them with public source data, to write reports with AI models and to make them available through the dashboard, the API, the MCP server, webhooks and emails. The details are in the annex in section 18. We do this for as long as the customer uses Vintoo.
4. Instructions
We process customer data only on documented instructions of the customer. Using Vintoo, including the analysis options, the API, the MCP server and webhooks, counts as an instruction, as do written instructions from an owner. We do not use customer data for our own purposes, do not share it with other customers and do not use it to train AI models.
If we believe an instruction breaks the law, we inform the customer.
5. Obligations of the customer
The customer:
- has a legal basis for its own use of reports and contact details, and informs the people it contacts about that use, at the latest at the first contact;
- uses Vintoo only for business-to-business purposes and complies with the rules for unsolicited email and calls;
- does not enter special categories of personal data or data about criminal convictions;
- removes personal data from its workspace when we ask because the person concerned objected.
6. Confidentiality
Everyone who processes customer data on our behalf has a duty of confidentiality. If an authority asks us for customer data, we inform the customer, unless the law forbids this.
7. Security
We take appropriate technical and organisational measures, taking into account the state of the art and the risks of the processing. They include:
- encrypted connections to the website, the API and the other interfaces;
- passwords, API keys and access tokens for AI assistants stored as hashes;
- separation of data per organization, with access only for its members and read-only access for external members;
- access to production systems only for our own staff who need it;
- rate limits and protection of public forms against abuse.
8. Subprocessors
The customer gives general permission for the subprocessors in section 19. We impose the same data protection obligations on them as in this agreement and remain responsible for them.
We inform owners by email at least 30 days before we add or replace a subprocessor. An owner can object on reasonable grounds within 14 days. If we cannot find a solution, the customer can end the agreement before the change takes effect.
9. Transfers outside the EEA
Our servers and database are located in Amsterdam, the Netherlands. Several subprocessors are based in the United States or process data there. We transfer personal data there only with appropriate safeguards: the EU-US Data Privacy Framework for certified providers, otherwise the standard contractual clauses of the European Commission.
10. Requests and assistance
We help the customer respond to requests of people to access, correct, delete or receive their data, and to objections. The customer can export prospects and reports through the dashboard and the API. Requests about customer data that reach us directly, we forward to the customer within 5 working days.
We also help with a data protection impact assessment or a prior consultation of the Dutch Data Protection Authority, by providing information about our processing and our security.
11. Personal data breaches
We inform the customer without undue delay, and no later than 48 hours after discovery, of a personal data breach that affects customer data. We send the notification to the owners of the organization and share what we know: the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures we took. We send updates as we learn more.
The customer decides whether to report the breach to the Dutch Data Protection Authority and to the people concerned. We help where needed.
12. Public source data
For public source data we are an independent controller. We collect only public business information about companies and about people in their professional role, only for companies customers add, and keep temporary copies for at most 90 days.
We honour objections. When a company excludes itself through the opt-out form, we no longer write new reports about it for any customer.
When a report shows the contact details of a person, the customer is an independent controller for its own use of those details, for business-to-business purposes only.
13. Audit
On request we give the customer the information it needs to check that we comply with this agreement. If that is not enough, the customer may have an audit carried out by an independent expert, at most once a year, with at least 30 days' notice and under confidentiality. The customer bears the costs, unless the audit shows that we seriously breached this agreement.
14. Retention and deletion
Customer data remains available as long as the organization exists, also after a subscription ends. The customer can export it at any time. When an owner deletes the organization, we delete its prospects and reports right away.
Deleting a single prospect hides it in the dashboard. If it must also be removed from our systems, the customer can ask us by email.
15. Liability
The limitation of liability in our terms and conditions also applies to this agreement. Each party bears the fines imposed on it. Between the parties, article 82 of the GDPR applies to compensation of people concerned.
16. Duration and changes
This agreement applies as long as we process customer data. We may change it with at least 30 days' notice. If a change is materially worse for the customer, the customer can end the agreement before it takes effect.
17. Applicable law
Dutch law applies. Disputes are submitted to the District Court of Gelderland (Rechtbank Gelderland). Questions? Email info@vintoo.nl.
18. Annex: processing details
- People concerned: employees and representatives of prospect companies, users of the customer and people the customer mentions in notes.
- Personal data: name, job title and employer; public professional profile information such as headline, summary, work experience, skills and photo; public company posts; work email address and work phone number when the customer asks for them; notes and pipeline stages; names and email addresses of users.
- Purposes: writing and showing reports, monitoring prospects and delivering results through the interfaces.
- Retention: as long as the organization exists; see section 14.
- Location: servers and database in Amsterdam, the Netherlands; subprocessors as listed in section 19.
19. Annex: subprocessors
- DigitalOcean, LLC, United States, servers in Amsterdam: hosting of servers and database;
- Anthropic Ireland, Ltd, processing in the United States: AI models;
- OpenAI Ireland Ltd, processing in the United States: AI models;
- TypeSafe AI, Inc., United States: classification models;
- Apify Technologies s.r.o., Czech Republic, processing in the United States: collecting public LinkedIn information;
- SerpApi, LLC, United States: Google search results;
- Outscraper: Google Maps information;
- FullEnrich Corp, United States, storage in the EU: work email addresses and phone numbers;
- Resend (Plus Five Five, Inc.), United States: sending emails, such as monitoring results;
- Slack Technologies Limited, Ireland, processing in the United States: internal notifications for our team.