- Home
- Legal
- Joint Controllership
Arrangement between Joint Controllers
Effective from
This arrangement is an annex to the Terms and Conditions and is concluded upon their acceptance. It describes the allocation of obligations between us and the Customer in relation to the data of Authors of Entries, for which we are joint controllers within the meaning of Article 26 GDPR. Its essential content is publicly available at the same address, and an Author may exercise their rights against either of us regardless of how we have allocated the tasks (Article 26(3) GDPR). Capitalised terms have the meaning given to them in the Terms and Conditions.
Contents
- § 1. Parties and subject matter
- § 2. Nature, purpose, types of data and categories of persons
- § 3. Allocation of obligations (Article 26(1) GDPR)
- § 4. VERTOM measures and obligations
- § 5. Processors and data sources
- § 6. Verification and audit
- § 7. Transfers of data outside the EEA
- § 8. Author objection and exclusion list
- § 9. End of processing
- § 10. Final provisions
Contents
- § 1. Parties and subject matter
- § 2. Nature, purpose, types of data and categories of persons
- § 3. Allocation of obligations (Article 26(1) GDPR)
- § 4. VERTOM measures and obligations
- § 5. Processors and data sources
- § 6. Verification and audit
- § 7. Transfers of data outside the EEA
- § 8. Author objection and exclusion list
- § 9. End of processing
- § 10. Final provisions
§ 1. Parties and subject matter
1. The joint controllers of the Authors’ data are: VERTOM AI sp. z o.o., ul. Żurawia 45, 00-680 Warszawa, KRS 0001248500 (hereinafter: “VERTOM”) and the Customer.
2. The joint controllership covers the reading of public Entries in the specified Sources, their assessment, preparation of a reply draft, storage of Leads and sending notifications.
3. The joint controllership does not cover what the Customer does with a Lead after receiving it: contacting the Author, recording data in its own systems and further correspondence. In this respect, the Customer is an independent controller and is solely responsible for this.
4. The arrangement applies for the duration of the agreement for use of the Service and until the data are deleted in accordance with § 9.
§ 2. Nature, purpose, types of data and categories of persons
1. Nature of processing: automated collection, recording, organisation, storage, content analysis, disclosure to the Customer and erasure.
2. Purpose: identification of public Entries in which the Author expresses a need for the Customer’s product or service, in order to enable the Customer to establish contact.
3. Types of data: the Author’s first and last name or profile name, a link to the profile if it is public, the content of the Entry, the publication date, the Source address, public reaction and comment counts, the result of the Entry assessment together with the justification generated by the Service, the content of the reply draft and the Lead status assigned by the Customer.
4. Categories of persons: Authors of public Entries in Sources specified by the Customer, on Facebook, Reddit and X services.
5. We do not intentionally process special categories of data. VERTOM determines the catalogue of prohibited Sources (Terms and Conditions § 7(3)), which applies regardless of the Customer’s wishes. If an Entry nevertheless contains such data, they are processed solely as an element of the Entry content, without separate analysis, and are subject to the same deletion period as the remainder.
§ 3. Allocation of obligations (Article 26(1) GDPR)
1. VERTOM determines and carries out: the method of reading Entries, the scope of recorded fields, the retention period, the model used for assessment, the removal of identifying data from content submitted to the model, the catalogue of prohibited Sources and technical and organisational measures (§ 4).
2. The Customer determines and carries out: the list of Sources, assessment criteria, Scan schedule, notification channels, and the purpose and method of using a Lead after receiving it.
3. VERTOM fulfils the information obligation towards Authors (Article 14 GDPR). The information is published at useleadscanner.com/legal/notice-for-authors, in every language in which the Service is available. The Customer provides this address to an Author who asks about the source of their data.
4. The contact point for Authors within the meaning of the third sentence of Article 26(1) GDPR is VERTOM: [email protected]. VERTOM receives and handles Authors’ requests (§ 8), including where they concern data in the Customer’s Organisation. A Customer that receives a request directly forwards it without delay to this address.
5. Regardless of the above allocation, an Author may exercise their rights against each joint controller (Article 26(3) GDPR), and each of them is liable to the Author under Article 82 GDPR.
6. If VERTOM considers that a setting introduced by the Customer infringes data protection legislation, it informs the Customer thereof and may suspend Scans until the matter is clarified.
§ 4. VERTOM measures and obligations
1. VERTOM ensures that persons authorised to process data have undertaken to maintain confidentiality, and that only persons for whom it is necessary have access to Authors’ data; every access to Authors’ data by a Service operator outside the ordinary operation of the Service is recorded in the audit log.
2. It implements technical and organisational measures appropriate to the risk, in particular: encryption of connections, encryption at rest of integration secrets, isolation of each Organisation’s data using unpredictable identifiers, two-factor authentication for operator accounts, a limit on the number of login attempts, automatic deletion of data upon expiry of the retention period, backups in the European Economic Area, and removal of identifying data from content submitted to the language model before it is sent.
3. It handles Authors’ requests centrally (§ 8) and informs the Customer about them where possible. VERTOM handles a request addressed to the Customer within 7 days of its forwarding.
4. It makes available to the Customer the information necessary to demonstrate compliance with the obligations under Articles 26 and 32–36 GDPR, to the extent that they concern the part of processing carried out by VERTOM.
5. It informs the Customer of a personal data breach concerning Authors’ data without undue delay, no later than within 48 hours after becoming aware of the breach, providing the circumstances known to it, the categories and approximate number of persons, and the measures taken. VERTOM submits notifications to the supervisory authority in respect of the processing referred to in § 3(1).
6. It enables the Customer to verify performance of this arrangement in accordance with § 6.
§ 5. Processors and data sources
1. VERTOM uses the processors listed at useleadscanner.com/legal/subprocessors, within the scope described there. The Customer gives general authorisation for this.
2. The same list identifies the data sources: entities making public content from Reddit and X services available. They do not act on our instructions—they themselves determine how they collect that content and act as independent controllers in relation to Authors’ data. They are not processors and we do not enter into data processing agreements with them under Article 28 GDPR; we list them because Authors’ data originate from them and the Customer has the right to know from where.
3. VERTOM informs the Customer by email of its intention to add or change a processor or data source at least 30 days in advance. The Customer may object within that period, stating justified data-protection grounds. If the parties do not reach an agreement, the Customer may terminate the agreement for use of the Service with effect from the date the change is introduced, and the fee for the unused period shall be refunded proportionately.
4. VERTOM imposes on each processor, by contract, the same data-protection obligations that apply to it, and is liable to the Customer for that processor’s fulfilment of those obligations.
§ 6. Verification and audit
1. The Customer may verify performance of this arrangement by requesting information and documents, including audit results and processor certificates. VERTOM responds within 14 days.
2. If the information under paragraph 1 is insufficient, the Customer may conduct an audit, itself or through an auditor bound by confidentiality, no more than once a year, unless a personal data breach has occurred, upon at least 14 days’ prior notice, during business hours and in a manner that does not disrupt the operation of the Service or breach the confidentiality of other customers’ data. The Customer bears the audit costs unless the audit demonstrates a material breach of the arrangement.
§ 7. Transfers of data outside the EEA
1. Authors’ data are stored on servers in the European Economic Area.
2. Transfers of data outside the EEA are made exclusively to the processors indicated in the list in § 5(1), on the basis of a European Commission adequacy decision (including under the EU-U.S. Data Privacy Framework), and in the absence of such a decision or if it is repealed—on the basis of standard contractual clauses adopted by the Commission, supplemented by a transfer impact assessment.
3. The provider of the language model used in AI Mode is OpenAI Ireland Ltd (EEA), under OpenAI’s data processing agreement. Queries to the model are processed on OpenAI servers in the United States; the basis for this transfer is the standard contractual clauses incorporated into that agreement. Content submitted through the API is not used to train models. The content of the Entry submitted to the model is first stripped of names and surnames, email addresses, telephone numbers and links to profiles.
4. The provider of access to public content from the Reddit and X services is established outside the EEA, but the direction of the flow here is the reverse of that in paragraphs 2 and 3. We do not disclose Authors’ data to it: we send the name of the Source and a search phrase, and receive public content together with data of its Authors. Receiving data from a source outside the EEA is data collection, not a transfer within the meaning of Chapter V of the GDPR, and is subject to the same rules as any other collection described in this arrangement.
5. One flow does, however, go outside and may identify a person: where the Source is a specific public account on the X service, its name leaves the EEA. The name is public, we send it solely in order to retrieve that account’s public entries, and we do not combine it with any other data. The legal classification of this single flow is the subject of legal consultation; we will enter its outcome here. Apart from this, personal data may not leave the EEA by this route, which is why § 7(2)(e) of the Terms and Conditions prohibits the Client from using personal data as a search phrase.
6. The assessment of the lawfulness of the source within the meaning of EDPB Opinion 28/2024 for both of these sources is being prepared. Until it is prepared, we use them while consciously accepting the risk described in § 5(2) and in this paragraph; we will make this assessment available to the Client upon request once it has been completed.
§ 8. Author objection and exclusion list
1. An Author who objects to processing or requests deletion of data may contact VERTOM at [email protected]—as the contact point of the joint controllers (§ 3(4))—or contact the Customer directly. VERTOM then deletes the Author’s data from all Organisations, including the Customer’s Organisation, and records an irreversible hash of the Author’s identifier on the exclusion list, through which subsequent Scans omit their Entries.
2. The Customer acknowledges that an Author’s objection is implemented without the Customer’s separate consent and that, due to the local nature of the identifier, it may not always be possible to determine which Organisation it concerned; where possible, VERTOM informs the Customer about the deletion.
3. The exclusion list is a record that VERTOM maintains independently as controller, based on Article 6(1)(c) GDPR (the obligation to fulfil data subjects’ rights) and Article 6(1)(f) GDPR (legitimate interest in effectively implementing an objection). The list contains only hashes from which the Author’s data cannot be reconstructed and is maintained indefinitely, because its deletion would mean collecting again the data of a person who does not wish this.
§ 9. End of processing
1. Authors’ data are automatically deleted upon expiry of the retention period resulting from the Plan (Terms and Conditions § 5(6)), and Entries that have not been assessed as a Lead—in the same manner and no later than Leads.
2. Upon termination of the agreement for use of the Service, after a 30-day grace period, VERTOM deletes all Authors’ data processed in connection with the Customer’s Organisation, together with their copies, except for the exclusion list (§ 8) and data whose retention is required by Union or Member State law.
3. Before the agreement ends, the Customer may download a copy of the Leads in an open format through the panel. From the moment of downloading, the Customer is an independent controller in relation to that copy and determines its retention period itself.
§ 10. Final provisions
1. Each joint controller is liable to the Author for damage caused by processing under Article 82 GDPR; the Author may seek a claim from either of them. Settlements between the parties on this account follow the allocation of obligations in § 3. The limitation of liability under § 10 of the Terms and Conditions applies in relation to a Customer that is not a privileged Customer, unless this is contrary to mandatory provisions of law.
2. In matters not regulated, the Terms and Conditions and the GDPR apply. This arrangement may be amended in accordance with the procedure for amending the Terms and Conditions.
3. This arrangement has been drawn up in seven languages; in the event of discrepancies, the Polish version is binding. It applies from 7 September 2026. It replaced the Personal Data Processing Agreement of 2 September 2026, which was based on the incorrect assumption that the Customer alone was the controller of Authors’ data.