Legal
Data Processing Addendum
Last updated August 29, 2026 · TryGTM
This page describes the processing terms we offer and, more usefully, where the controller line actually falls, which is the question most DPAs answer badly because the honest answer is inconvenient.
01The part most DPAs get wrong
A tool that only sends the list you uploaded is your processor: you decided who to contact, it acted on your instruction. GTM is not only that. Because it sources leads itself, against a licensed corpus and through your connected LinkedIn account, it decides what data to collect and why for that population. That makes it a controller in its own right for that data.
That is a deliberate choice with a real cost, and it is why the product carries per-field provenance, retention anchored to collection, a per-row pre-send check and two-scope suppression as architecture rather than as settings. A processor could have skipped all four.
For the data you bring. Your uploaded lists, your connected accounts, your workspace content. We are your processor and act on your instructions.
02Scope
These terms apply where we process personal data on your behalf in connection with the service. They form part of the agreement created by our Terms of Service.
03Roles, split by data set
- Your workspace content. Accounts, settings, templates, campaigns, uploaded contacts, conversation history. You are the controller. We are the processor.
- Leads we source. Records obtained from the licensed prospect corpus or from public LinkedIn activity. We are a controller for the act of collecting them, and a processor for what you subsequently do with them in your workspace.
- Service telemetry. Run ledgers, credit charges, error traces. We are the controller. Operational reports use event codes and identifiers. Product records and model requests can include personal data needed to perform the requested work; processing and retention depend on the applicable provider terms and configuration.
04What we do with it
- Process it only to provide the service and on your documented instructions.
- Impose confidentiality obligations on people with access.
- Delete or return workspace data on termination, subject to the suppression exemption below.
- Assist with data subject requests, and with security and impact assessments.
05Retention, and the one exemption
Retention windows are computed from the date a record was collected, never from when it was last updated. That distinction is not pedantry: anchoring to last-updated means an actively used record never expires, and it is the exact finding that produced a €240,000 fine for one lead-generation company.
Suppression records are exempt from every purge, at both workspace and platform scope. A suppression list a deletion can empty is a list that eventually mails somebody who asked you not to, so we keep the minimum needed to honour that request. The address or profile and the fact of the request, and nothing else.
06Subprocessors
We use a small number of providers to deliver the service. The categories and what each one is for are published at /subprocessors. Enterprise customers receive the named list under NDA, and we notify before adding a subprocessor that touches customer data.
07Location
Data is stored in the United States, in us-east-2, chosen explicitly rather than defaulted into. We serve the US today and say so rather than implying EU readiness; an EU deployment is a migration and a conversation, not a checkbox.
08Security
Row-level security on every table from its first migration, scoped access tokens that carry the authorising person’s own permissions and are re-checked on every call, content-free operational alerts, and a pre-send compliance check enforced by a database constraint rather than by application code. Our SOC 2 programme is underway and we say where it stands on /security rather than implying a badge we do not hold.
Model processing may include relevant contact details and conversation content. See Subprocessors for the data flow and request the applicable provider retention and processing terms before sending restricted data.
09Getting a signed copy
Email support@trygtm.com and we will send the executable version. Enterprise customers can bring their own paper; we would rather negotiate a DPA drafted by your counsel than have you sign around ours.