Scout by Thinklytics LLC · Last Updated: July 6, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service and is effective on the Client's acceptance. (Supporting document prepared by Thinklytics LLC; pending review by counsel.)
1. Roles. For personal data Thinklytics LLC processes to provide the Service ("Client Personal Data"), the Client is the Controller and Thinklytics LLC is the Processor. Each party will comply with applicable data-protection laws ("Data Protection Laws," including the TDPSA, GDPR, UK GDPR, and CCPA/CPRA).
2. Processing details. Subject matter/nature: research, scoring, and preparation of outreach Deliverables. Purpose: performing the Service. Duration: the term of the Service plus the deletion periods in the Privacy Policy. Data subjects: the Client's prospects and target business contacts. Categories: name, business email, job title, employer, business phone, professional profile links, company firmographics, and publicly sourced professional signals. No special-category data.
3. Processor obligations. Thinklytics LLC will: (a) process Client Personal Data only on the Client's documented instructions (the Terms, the ICP, and configuration are instructions); (b) ensure personnel are bound by confidentiality; (c) implement appropriate technical and organizational security measures (Schedule 2); (d) assist the Client, taking into account the nature of processing, with data-subject requests and Articles 32-36 GDPR; (e) notify the Client without undue delay after becoming aware of a personal-data breach; and (f) at the Client's choice, delete or return Client Personal Data at the end of the Service, except copies required by law.
4. Controller obligations. The Client warrants it has a lawful basis and any required notices/consents to have the individuals researched and contacted, that its instructions are lawful, and that its use of Deliverables complies with anti-spam and data-protection law.
5. Subprocessors. The Client authorizes Thinklytics LLC to engage the subprocessors in Schedule 1. Thinklytics LLC imposes data-protection terms on each no less protective than this DPA and remains responsible for their performance. We will give notice of intended changes and allow a reasonable period to object.
6. International transfers. Where Client Personal Data is transferred across borders, the parties rely on a valid transfer mechanism such as the EU/UK Standard Contractual Clauses, incorporated by reference.
7. Audit. Thinklytics LLC will make available information reasonably necessary to demonstrate compliance and allow audits, subject to reasonable notice, confidentiality, and frequency limits.
8. Liability. Liability under this DPA is subject to the limitations in the Terms. 9. Conflict. If this DPA conflicts with the Terms on data protection, this DPA controls. 10. Governing law: State of Texas.
We engage the categories of subprocessors below. The specific named providers in each category are available to Clients on request under NDA.
| Category | Purpose | Location |
|---|---|---|
| Cloud hosting provider | Application hosting + database | US |
| Cloud storage provider | Deliverable storage | US |
| AI / large-language-model provider | Research synthesis + drafting | US |
| Web-search provider | Public web research | US |
| Email-verification provider | Deliverability checks | US |
| Licensed B2B contact-data provider | Contact + firmographic data | US |
| CRM / email-delivery platform | CRM + email delivery (only if Client enables) | US |
Access controls and least privilege; encryption in transit; hashed credentials; secrets stored by reference (never in the database); network isolation for the data store; rate limiting and lockout; audit logging; and vendor review of subprocessors.