Legal

Data Processing Agreement

GDPR-compliant data-processing terms governing how Instalent (Sacore AB) processes personal data as a processor on behalf of its customers.

Last updated · July 18, 2026

This Data Processing Agreement ("DPA") forms part of the Instalent Terms of Service and governs the processing of personal data carried out by Sacore AB ("Instalent", the "Processor") on behalf of the Customer (the "Controller") in accordance with the General Data Protection Regulation (GDPR) EU 2016/679 and other applicable data-protection laws.

Scope note. This DPA applies only where the Customer is the controller and Instalent acts as a processor — for example, when the Customer runs outreach campaigns, uploads or selects contacts, or saves profiles into its own workspace. Where Instalent acts as a controller in its own right (for example, when sourcing and enriching professional data for the search index), that processing is governed by our Privacy Policy, not this DPA.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person processed through the Services on the Controller's behalf.
  • "Data Subject" means an individual whose personal data is processed.
  • "Controller" means the Customer, who determines the purposes and means of processing.
  • "Processor" means Instalent, processing personal data on the Controller's behalf.
  • "Sub-processor" means any third party engaged by Instalent to process Personal Data.

2. Scope and Purpose of Processing

Instalent processes Personal Data on the Controller's documented instructions solely to provide the Services, including:

  • multi-channel outreach campaign management;
  • storage and management of contacts the Controller selects or saves;
  • communication tracking and analytics; and
  • CRM and data-source integrations the Controller enables.

Duration: for the term of the subscription and up to 30 days after termination, unless longer retention is required by law.

3. Types of Personal Data and Data Subjects

Categories of Personal Data: contact information (names, business email addresses, phone numbers, professional profile links); professional information (job titles, companies, work history); communication data (message content, open/click and response data); connected-account data (authorisation and connection identifiers, managed through Unipile rather than stored by Instalent directly); and technical data (IP address, device, usage).

Categories of Data Subjects: job candidates and prospects, business contacts and leads, and the Controller's employees and users.

The Controller must not instruct Instalent to process special categories of personal data through the Services.

4. Controller Obligations

The Controller represents and warrants that it:

  • has a valid lawful basis (such as consent or legitimate interests) for the processing it instructs;
  • complies with all applicable data-protection laws;
  • has provided appropriate privacy notices to, and will honour the rights of, the relevant Data Subjects;
  • provides only lawfully obtained Personal Data; and
  • is responsible for the accuracy and legality of the data it submits and the instructions it gives.

5. Processor Obligations

Instalent shall:

  • process Personal Data only on the Controller's documented instructions, including for transfers, unless required otherwise by law (in which case it will inform the Controller unless prohibited);
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement the technical and organisational security measures in Section 6;
  • engage Sub-processors only in accordance with Section 7;
  • assist the Controller, taking into account the nature of processing, with Data Subject requests and with its security, breach-notification, and impact-assessment obligations;
  • delete or return Personal Data as set out in Section 11; and
  • make available the information necessary to demonstrate compliance and allow for audits under Section 9.

6. Security Measures

Instalent implements appropriate technical and organisational measures, including: encryption in transit (TLS) and at rest (AES-256); role-based access controls and multi-factor authentication; secure, tier-certified cloud infrastructure; monitoring and intrusion detection; encrypted backups with tested recovery; regular security review and testing; and staff confidentiality and security-awareness training.

7. Sub-processors

The Controller provides general authorisation for Instalent to engage Sub-processors to provide the Services. Instalent imposes data-protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for their performance.

Current Sub-processors include:

| Sub-processor | Purpose | Location | | --- | --- | --- | | Amazon Web Services / Google Cloud | Cloud hosting and infrastructure | EU (with safeguards for any non-EEA processing) | | Unipile | Multi-channel communication integration | EU | | Email delivery provider(s) | Sending and deliverability | EU / safeguarded | | Contact-enrichment and verification providers | Contact-data enrichment | Varies / safeguarded | | Analytics provider (privacy-friendly) | Product and website analytics | EU | | Payment provider(s) | Billing and payment | Safeguarded | | Customer-support tooling | Support | Safeguarded |

A current named list is available on request at jon@instalent.io. We will give the Controller advance notice of any intended addition or replacement of a Sub-processor, and the Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected Service.

8. Data Subject Rights

Instalent will assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, and objection). Data Subjects should address requests to the Controller; if Instalent receives a request directly, it will forward it to the Controller without undue delay and within 2 business days, and will not respond directly except on the Controller's instruction or as required by law.

9. Audits and Inspections

Instalent will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, by the Controller or a mandated auditor, on at least 30 days' notice, subject to confidentiality and to reasonable limits on frequency and scope. Instalent may charge reasonable fees for extensive audit support.

10. Personal Data Breach Notification

Instalent will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Controller's data, including the nature of the breach and affected data categories, likely consequences, measures taken or proposed, and a contact point for more information.

11. International Data Transfers

Instalent processes Personal Data primarily within the EEA. Where Personal Data is transferred outside the EEA or UK, Instalent relies on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses together with any additional safeguards required.

12. Data Retention and Deletion

On termination or expiry of the Services: the Controller may export its data for 30 days; after that, Instalent will securely delete the Personal Data, including from backups in the ordinary course, unless retention is required by law; and Instalent will confirm deletion on request.

13. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. The Controller will indemnify Instalent against claims arising from the Controller's breach of data-protection law, its unlawful instructions, or its failure to maintain a valid lawful basis.

14. Connected Accounts and Third-Party Integration

Where the Controller connects third-party accounts through Unipile, Instalent accesses connected-account data only to operate the features the Controller uses, does not use it for any unrelated purpose, does not access account contents beyond what is necessary, and does not transfer it other than to Unipile and Sub-processors as needed to provide the Services or as required by law. Further information is in the Unipile Privacy Policy.

15. Governing Law

This DPA is governed by the laws of Sweden, together with the GDPR and applicable EU member-state data-protection law, consistent with the governing-law provision of the Terms of Service.

16. Contact

For data-protection matters and Data Subject requests: jon@instalent.io.