Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between the Customer and Kristiyan Tsvetanov, trading as Warmerly ("Warmerly", "we", "us"). It supplements our Terms of Service and applies where Warmerly processes personal data on your behalf as a processor under UK GDPR and EU GDPR.
1. Definitions
Terms not defined here have the meaning set out in the UK GDPR and EU GDPR. "Customer" means the entity that has signed up to Warmerly. "Personal Data" means information relating to an identified or identifiable person. "Warmerly" means Kristiyan Tsvetanov, trading as Warmerly, a UK sole trader (not a limited company), of 318 Shady Lane, Birmingham, B44 9EB, England, United Kingdom.
2. Subject matter and duration
The subject matter is Warmerly's processing of Customer data for the purpose of providing email warmup, outreach campaigns, the unified inbox, lead and email discovery, and deliverability tooling. Duration is the term of the Customer's subscription, plus the retention periods set out in section 11 and in our Privacy Policy.
3. Nature and purpose of processing
- Authentication, and encrypted storage of mailbox OAuth tokens and IMAP/SMTP credentials.
- Sending and receiving warmup mail through the Customer's authorised mailboxes.
- Sending outreach campaigns through the Customer's authorised mailboxes and connected accounts, and recording delivery, open, click, reply, bounce, and unsubscribe events.
- Reading, storing, and displaying the contents of the Customer's connected mailboxes and connected LinkedIn / WhatsApp / Instagram accounts in the Warmerly inbox.
- Submitting message extracts, campaign context, and business-contact information to a third-party AI provider in order to classify messages, draft replies, and generate personalised campaign content.
- Computing health and deliverability metrics, and providing the dashboard.
- Support access by Warmerly administrators, where required to resolve a Customer issue or investigate a credible abuse report. Such access is audit-logged and time-limited.
4. Categories of data and data subjects
- Customer account holders and team members: name, email, hashed password, role, billing info, IP, user-agent.
- Warmup participants: the mailbox addresses in the From/To headers of warmup mail, used solely to send and receive warmup messages.
- Campaign recipients: name, business email address, employer, job title, any custom fields the Customer uploads, message content sent to them, and their engagement with it (opens, clicks, replies, bounces, unsubscribes).
- Correspondents in the Customer's mailboxes and connected accounts: anyone who appears in the Customer's Inbox or Sent folder, or in their LinkedIn / WhatsApp / Instagram conversations — including their name, address or handle, and the full content of those messages. This category is broad and is not limited to people connected with Warmerly.
- Business contacts in the lead database: company-level information and business contact addresses compiled from public sources. Warmerly is the controller for this dataset; see our Prospect Privacy Notice.
The Customer must not use Warmerly to process special category data (Article 9) or criminal offence data (Article 10). The service is not designed for it.
5. Sub-processors
Warmerly uses the following sub-processors. The full list, with data categories, location, and the date each was added, is also published on its own page: Sub-processors.
- Hetzner Online GmbH (Germany/Finland) — application and database hosting.
- Cloudflare, Inc. (US, with EU data localisation where applicable) — DDoS protection, CDN, and R2 object storage for uploaded avatars and logos.
- Stripe Payments Europe, Ltd. (Ireland, with US parent) — billing and payment processing.
- Resend, Inc. (US) — transactional and broadcast email delivery for Warmerly's own service notifications.
- OpenRouter, Inc. (US) — routing of AI requests to model providers, for inbox classification, reply drafting, campaign personalisation, and the support assistant.
- Google LLC / Google Ireland Ltd. — Gemini models accessed for the AI features above, and Google Analytics 4 (consent-gated).
- Unipile SAS (France) — LinkedIn and WhatsApp account connection and message sync.
- Meta Platforms, Inc. (US) — Instagram account connection and messaging, where the Customer connects an Instagram account.
- Whop, Inc. (US) — conversion measurement on our marketing site (consent-gated; no Customer data).
- Webshare Software Company (US) — proxy infrastructure used by our crawling and verification workers. No Customer content passes through it.
We will provide 30 days' notice of any new sub-processor. You may object in writing; if your objection cannot be resolved, you may terminate the affected portion of the service.
6. International transfers
Application data is stored and processed in the European Economic Area. Several sub-processors listed above are established outside the UK/EEA, or transfer data to the United States — in particular our AI provider, payment provider, transactional email provider, and analytics provider. For those transfers we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with encryption in transit and data minimisation as supplementary measures.
7. Security
- OAuth tokens and mailbox credentials encrypted with AES-256-GCM at rest.
- Passwords hashed with Argon2id.
- All traffic encrypted with TLS 1.2+.
- Role-based access control within workspaces, with administrative access audit-logged.
- Database and administrative ports firewalled off the public internet, reachable only over a private network.
- Rate limiting on authentication and other abuse-sensitive endpoints.
Warmerly is a small business and states its security posture accurately: we do not currently hold SOC 2, ISO 27001, or any other third-party certification, and we do not currently commission annual third-party penetration testing. We will update this section if that changes.
8. Personal data breaches
We will notify the Customer without undue delay (and within 72 hours where feasible) of becoming aware of a personal data breach affecting Customer data, with sufficient detail to enable the Customer to meet its own notification obligations.
9. Data subject requests
Warmerly will assist the Customer in responding to data subject requests within statutory timeframes, either through self-service tooling or via support request to privacy@warmerly.com.
10. Audit
Customers on Agency or higher plans may request a remote audit of Warmerly's security posture once per calendar year, by giving 30 days' notice. We will answer a pre-agreed security questionnaire and provide reasonable written evidence of the measures in section 7. We cannot provide certification reports we do not hold.
11. Deletion
On termination, Warmerly will delete Customer data on the schedule set out in section 8 of our Privacy Policy — in summary, mailbox credentials immediately on disconnect, synced mailbox contents within 30 days of disconnect, and remaining account data within 90 days — except where retention is required by law, and except for suppression and unsubscribe records, which are retained so that opt-outs continue to be honoured. A deletion confirmation is available on request.
12. Contact
Warmerly is operated by Kristiyan Tsvetanov, trading as Warmerly, 318 Shady Lane, Birmingham, B44 9EB, England, United Kingdom. For DPA questions or to request a signed copy, email privacy@warmerly.com.