Go to app
Back to home

DATA PROCESSING AGREEMENT | THE SALES NINJA

Morpheus Agency, Société par Actions Simplifiée (SAS), share capital €1,000
RCS Bordeaux, SIREN 943 590 182
16 rue des Quinconces, 33000 Bordeaux, France
(the "Provider")

The Sales Ninja is a trade name operated by Morpheus Agency.

Last updated: 17 August 2026

Governing language. This Data Processing Agreement is drafted in English and the English version is the binding version between the parties. It is governed by French law, consistent with the Terms of Service.


1. Purpose and scope

This Data Processing Agreement (the "DPA") sets out the terms on which the Provider processes personal data on behalf of the Customer, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR and the Swiss Federal Act on Data Protection.

It applies to all processing of Customer Personal Data — personal data that the Customer, or a person acting on its behalf, submits to or has processed through The Sales Ninja (the "Service") and for which the Customer is the controller.

It does not apply to personal data for which the Provider is itself the controller (Customer account administration, billing, support, website analytics, and the shared professional directory built from public LinkedIn pages). That processing is described in Part A of the Privacy Policy.

For the avoidance of doubt, that shared professional directory is built solely from LinkedIn pages accessible without a LinkedIn account and without logging in. It contains none of the Customer Personal Data described in Annex I — in particular no prospect list, no qualification decision, no message, no conversation, no note and no targeting criterion — and Section 4.1 accordingly does not apply to it. The Provider remains the controller of that directory and answers directly to the persons concerned, under Part A of the Privacy Policy.

1.1 Formation

This DPA forms an integral part of the Terms of Service. By subscribing to the Service, the Customer accepts this DPA on behalf of itself and, where applicable, its affiliates. No signature is required for it to take effect.

A counter-signed copy is available on request to support@thesales.ninja for customers whose internal procedures require one.

1.2 Order of precedence

In the event of any conflict on a data-protection matter, the following order applies:

  1. the Standard Contractual Clauses, where incorporated under Section 11;
  2. this DPA;
  3. the Privacy Policy;
  4. the Terms of Service.

2. Definitions

Terms not defined here have the meaning given to them in the GDPR or in the Terms of Service.

  • "Customer Personal Data" — personal data processed by the Provider on behalf of the Customer through the Service, as described in Annex I.
  • "End User" — a prospect or business contact of the Customer whose personal data is processed through the Service.
  • "Authorized User" — an individual authorized by the Customer to access the Service, including a person whose LinkedIn or mailbox account is connected to an Agent.
  • "Agent" — the automated conversational agent configured and operated by the Customer through the Service.
  • "Sub-processor" — a third party engaged by the Provider to process Customer Personal Data.
  • "SCCs" — the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.

3. Roles of the parties

The Customer is the controller and the Provider is the processor in respect of Customer Personal Data.

The Customer determines the purposes and means of the processing, in particular by defining its target audience, its messaging, its sending volumes and its qualification criteria within the Service.

3.1 Customer warranties

The Customer warrants that:

  • it has a valid legal basis for each processing operation carried out through the Service, including for the sending of prospecting messages;
  • it provides data subjects with the information required by Articles 13 and 14 GDPR;
  • it maintains an effective and readily accessible objection / opt-out mechanism;
  • it complies with applicable prospecting and electronic-communications law (GDPR, ePrivacy, CAN-SPAM, CASL and local equivalents);
  • its instructions to the Provider do not infringe applicable data-protection law.

3.2 Special categories of data

The Service is not designed to process special categories of personal data within the meaning of Article 9 GDPR, nor data relating to criminal convictions and offences. The Customer undertakes not to submit such data to the Service and acknowledges that the Provider's measures are not calibrated for it.


4. Processing on documented instructions

The Provider processes Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to a third country.

The following constitute the Customer's documented instructions:

  • this DPA, the Terms of Service and the Privacy Policy;
  • the Customer's configuration of the Service (targeting and qualification criteria, message content and cadence, connected accounts, automation settings and approval thresholds);
  • any instruction subsequently given in writing by an Authorized User through the Service or by email to support@thesales.ninja.

The Provider informs the Customer if, in its opinion, an instruction infringes the GDPR or another provision of Union or Member State data-protection law. The Provider may suspend the execution of the instruction concerned until it is confirmed, amended or withdrawn.

Where the Provider is required by Union or Member State law to process Customer Personal Data beyond the Customer's instructions, it informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

4.1 Artificial intelligence and model training

The Provider accesses large-language and embedding models through the application programming interfaces (APIs) of the model providers listed in Annex III, under terms which do not permit the use of submitted data for training or improving those providers' models.

The Provider does not use Customer Personal Data to train, fine-tune or otherwise improve any model, nor to develop or improve the Service beyond what is necessary to provide it to the Customer, nor for any purpose of its own. The Provider does not sell Customer Personal Data and does not share it other than with the Sub-processors listed in Annex III.


5. Confidentiality

The Provider ensures that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, which survives the end of their engagement.

Access to Customer Personal Data is restricted to personnel who need it to provide, secure or support the Service, on a least-privilege basis.


6. Security

The Provider implements the technical and organizational measures set out in Annex II, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR.

The Provider may update those measures over time, provided that the level of security is not degraded. Material changes are published with the updated version of this DPA.


7. Sub-processors

7.1 General authorization

The Customer grants the Provider a general written authorization to engage Sub-processors. The Sub-processors engaged as at the date of this DPA are listed in Annex III.

7.2 Conditions

The Provider:

  • imposes on each Sub-processor, by written contract, data-protection obligations no less protective than those set out in this DPA;
  • remains fully liable to the Customer for the performance of each Sub-processor's obligations.

7.3 Changes

The Provider notifies the Customer by email of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance.

The Customer may object on reasonable grounds related to data protection within that period. Where an objection cannot be resolved, the Customer may terminate the affected portion of the Service without penalty, and is refunded any fees prepaid for the terminated portion in respect of the period after termination.


8. Assistance with data subject rights

Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organizational measures in fulfilling its obligation to respond to requests for the exercise of data subject rights under Chapter III GDPR.

The Service provides the Customer with the ability to access, export, correct and delete Customer Personal Data directly. Where a request cannot be satisfied through those functions, the Provider assists the Customer within a reasonable period and at no additional charge for requests of ordinary volume.

If a data subject addresses a request directly to the Provider, the Provider does not respond to it on the merits and forwards it to the Customer without undue delay.


9. Assistance with Articles 32 to 36

Taking into account the nature of the processing and the information available to it, the Provider assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, in particular security of processing, notification of personal data breaches, communication to data subjects, data protection impact assessments and prior consultation of the supervisory authority.


10. Personal data breach

The Provider notifies the Customer of any personal data breach affecting Customer Personal Data without undue delay, and in any event within seventy-two (72) hours of becoming aware of it.

The notification is sent by email to the Customer's administrative contact and includes, to the extent then available:

  • the nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address the breach and mitigate its effects;
  • the contact point for further information.

Where the information cannot be provided at the same time, it is provided in phases without further undue delay. The Provider documents each breach and makes that documentation available to the Customer on request.

Notification of a breach is not, in itself, an acknowledgment of fault or liability.


11. International transfers

11.1 Onward transfers to Sub-processors

Where the Provider transfers Customer Personal Data to a Sub-processor located outside the European Economic Area, that transfer is framed by:

  • an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for certified recipients; or
  • the SCCs, Module Three (processor to processor), which are deemed incorporated into this DPA by reference, supplemented where necessary by additional safeguards.

The transfer mechanism applicable to each Sub-processor is stated in Annex III.

11.2 Customers established outside the EEA

Where the Customer is established outside the EEA and Customer Personal Data is transferred to it by the Provider, the SCCs, Module Four (processor to controller) are deemed incorporated into this DPA by reference.

11.3 Completion of the SCCs

Where the SCCs apply:

  • the data exporter and data importer are the parties identified in Annex I, Section A;
  • the optional docking clause (Clause 7) applies;
  • for Clause 9, Option 2 (general written authorization) applies, with the thirty (30) day notice period set out in Section 7.3;
  • for Clause 11, the optional independent dispute-resolution mechanism does not apply;
  • for Clause 17, the SCCs are governed by French law;
  • for Clause 18(b), disputes are resolved before the courts of France;
  • Annexes I, II and III to this DPA serve as Annexes I, II and III to the SCCs.

11.4 United Kingdom and Switzerland

Where the UK GDPR applies, the SCCs are supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner's Office. Where the Swiss FADP applies, references to the GDPR are read as references to the FADP and the competent authority is the Federal Data Protection and Information Commissioner.

The Provider executes the SCCs, the UK Addendum or any successor mechanism on request to support@thesales.ninja.


12. Audit and information

The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by it.

In practice:

  • the Provider responds to written security questionnaires and requests for documentation within a reasonable period, at no charge, up to once per twelve (12) month period;
  • the Customer may conduct an on-site or remote inspection once per twelve (12) month period, subject to at least thirty (30) days' prior written notice, during business hours, without unreasonable disruption to the Provider's operations, and subject to confidentiality undertakings by the Customer and any mandated auditor. The auditor must not be a competitor of the Provider;
  • the Customer bears the costs of any inspection it conducts, unless the inspection reveals a material breach of this DPA by the Provider, in which case the Provider bears its own costs and reimburses the Customer's reasonable costs;
  • the frequency limits above do not apply where an inspection is required by a supervisory authority or follows a personal data breach affecting the Customer.

13. Retention, return and deletion

Customer Personal Data is retained for the duration of the Agreement.

On termination or expiry, at the Customer's choice:

  • the Customer has thirty (30) days to request the return of Customer Personal Data, which is provided in a structured, commonly used, machine-readable format; and
  • Customer Personal Data is permanently deleted from active systems within thirty (30) days of that period expiring or of the Customer's deletion request, whichever is earlier.

Encrypted backups may retain Customer Personal Data until the end of the backup rotation cycle, of a maximum of ninety (90) days, during which it remains subject to this DPA and is not accessed for any other purpose.

The Provider may retain Customer Personal Data where required to do so by Union or Member State law, for the duration and to the extent so required. The Provider certifies deletion in writing on request.


14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits the rights of data subjects under the GDPR or under the SCCs.


15. Term

This DPA takes effect on the date the Customer subscribes to the Service and remains in force for as long as the Provider processes Customer Personal Data on the Customer's behalf, notwithstanding any expiry or termination of the Terms of Service.


16. Changes

The Provider may update this DPA to reflect changes in law, in the Service or in its technical stack. Any material change is notified by email to Authorized Users thirty (30) days in advance and published at https://thesales.ninja/dpa with the new last-updated date.


17. Contact

Morpheus Agency
16 rue des Quinconces, 33000 Bordeaux, France
Email: support@thesales.ninja



ANNEX I — DESCRIPTION OF THE PROCESSING

A. List of parties

Data exporter (controller) — the Customer, being the business entity that subscribed to the Service, as identified in its subscription and billing records. Contact: the Authorized User designated as administrator of the Customer's account. Activities relevant to the transfer: use of the Service for B2B sales prospecting.

Data importer (processor) — Morpheus Agency, SAS, 16 rue des Quinconces, 33000 Bordeaux, France. Contact: support@thesales.ninja. Activities relevant to the transfer: provision of The Sales Ninja platform.

B. Categories of data subjects

  • End Users — prospects and business contacts targeted or contacted by the Customer through the Service;
  • Authorized Users — the Customer's personnel who access the Service or whose LinkedIn or mailbox account is connected to an Agent;
  • individuals appearing in messages, replies or notes recorded in the Service.

C. Categories of personal data

CategoryExamples
Identification and contact dataFirst and last name, business email address, LinkedIn profile URL, telephone number where provided
Professional dataEmployer, job title, seniority, industry, company size, professional location
Message contentMessages sent and received, replies, notes, drafts generated by the Agent
Engagement metadataSend, delivery, read and reply timestamps, connection-request status, campaign and sequence identifiers
Public activity dataPublicly visible LinkedIn posts, comments and reactions used to personalize outreach
Authorized User account credentialsLinkedIn session cookies and mailbox authorization tokens of Authorized Users who connect an account, together with the identifiers of the connected account

The Provider does not knowingly process special categories of personal data (Section 3.2).

D. Nature and purpose of the processing

Provision of an automated B2B sales-prospecting platform on the Customer's behalf, comprising: identification and sourcing of prospects matching the Customer's criteria; enrichment of professional contact data; generation of personalized outreach messages; sending of connection requests and messages through the Customer's connected accounts; receipt and handling of replies; and reporting on outcomes.

E. Frequency of the processing

Continuous, for the duration of the Agreement.

F. Duration of the processing

The term of the Agreement, followed by the retention and deletion periods set out in Section 13.

G. Sub-processors

See Annex III. The subject matter, nature and duration of each Sub-processor's processing are limited to the role stated for it in that Annex.



ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES

The measures below are those actually implemented as at the last-updated date of this DPA.

The Provider does not currently hold a SOC 2 or ISO/IEC 27001 certification, and does not represent otherwise. Customers requiring an independent attestation should take this into account in their assessment.

1. Access control

  • Multi-factor authentication or single sign-on is enforced on all internal access to production systems, including the database, application hosting, deployment infrastructure and payment platform.
  • Access to production is limited to personnel who require it, on a least-privilege basis, and is reviewed when a person's role changes or their engagement ends.
  • Authorized Users authenticate to the Service with individual credentials. Administrative functions are separated from ordinary user functions.

2. Tenant isolation

  • Customer Personal Data is segregated by organization at the database level, using PostgreSQL row-level security policies evaluated on every read and write. Isolation does not depend on application-layer filtering alone.
  • Each Agent runtime authenticates with credentials scoped to a single Customer organization.

3. Encryption

  • In transit — all traffic between Authorized Users, the Service, and its Sub-processors is encrypted with TLS 1.2 or above. The Service is not reachable over unencrypted connections.
  • At rest — the database, file storage and backups are encrypted at rest by the infrastructure providers listed in Annex III.
  • Connected-account credentials (LinkedIn session cookies, mailbox tokens) are stored encrypted, are never exposed to other customers, and are transmitted only to the connector Sub-processor identified in Annex III for the purpose of executing the actions instructed by the Authorized User.

4. Secrets and key management

  • Application secrets and API keys are held in environment-scoped secret stores of the hosting providers, are not committed to source control, and are rotated when a person with access departs or on suspicion of compromise.

5. Segregation of environments

  • Production, staging and development environments are logically separated and hold separate credentials. Customer Personal Data is not copied into non-production environments.

6. Logging and traceability

  • Every automated action performed by an Agent on a connected account is recorded with its timestamp, the acting agent, the target and the outcome, providing an auditable trail of processing carried out on the Customer's behalf.
  • Application errors and anomalies are captured by the monitoring Sub-processor listed in Annex III.

7. Resilience and backups

  • Customer Personal Data is stored on managed infrastructure providing automated, encrypted backups.
  • The Service is designed to fail closed on authorization and to fail open on non-essential telemetry, so that a failure of an ancillary component does not result in unauthorized processing.

8. Organizational measures

  • Personnel with access to Customer Personal Data are bound by written confidentiality obligations (Section 5).
  • Sub-processors are engaged only under written data-processing agreements imposing obligations no less protective than this DPA (Section 7.2).
  • Personal data breaches are notified to the Customer within seventy-two (72) hours of the Provider becoming aware of them (Section 10).
  • Data-protection questions and requests are handled at support@thesales.ninja.

9. Measures to be provided by the Customer

The Customer is responsible for: managing its Authorized Users and revoking access promptly on departure; the lawfulness of its targeting and message content; and the security of the third-party accounts it connects to the Service.



ANNEX III — SUB-PROCESSORS

Up to date as at the last-updated date of this DPA. Changes are notified in accordance with Section 7.3.

A. Infrastructure and platform

Sub-processorRoleLocationTransfer mechanism
Supabase Inc.Database, authentication, file storageEuropean Union (Frankfurt region)N/A (EU)
Railway Corp.Application infrastructure hostingEuropean UnionN/A (EU)
Vercel Inc.Web application hostingUnited StatesEU-US Data Privacy Framework

B. Artificial intelligence

Sub-processorRoleLocationTransfer mechanism
OpenAI, L.L.C.Language-model API for message generation and analysisUnited StatesEU-US Data Privacy Framework / SCCs
OpenRouter, Inc.Language-model and embedding API access, including embeddings for the shared professional directoryUnited StatesStandard Contractual Clauses
Brave Software, Inc.Web search performed by AgentsUnited StatesStandard Contractual Clauses

C. Prospecting and outreach

Sub-processorRoleLocationTransfer mechanism
UnipileLinkedIn and mailbox connector for automated actionsFrance (hosted on Scaleway, France)N/A (EU)
ZenLeads Inc. d/b/a Apollo.ioB2B professional contact-data enrichmentUnited StatesStandard Contractual Clauses
FullEnrich CorpB2B professional contact-data enrichmentUnited States (data stored in the EU)Standard Contractual Clauses
SideGuide Technologies, Inc. (Firecrawl)Extraction of public web-page content for researchUnited StatesStandard Contractual Clauses
Resend, Inc.Transactional and notification email deliveryUnited StatesEU-US Data Privacy Framework (and UK Extension)

D. Operations and support

Sub-processorRoleLocationTransfer mechanism
Stripe, Inc.Payment and billingUnited StatesEU-US Data Privacy Framework
Functional Software, Inc. (Sentry)Application error monitoringUnited StatesStandard Contractual Clauses
PostHog, Inc.Product analytics (US Cloud region)United StatesStandard Contractual Clauses
Slack Technologies, LLC (Salesforce)Internal customer-success and operational notificationsUnited StatesStandard Contractual Clauses