Data Processing Agreement
Effective December 17th, 2025
1. Scope and Application
This Data Processing Agreement ('DPA') forms part of the agreement between the customer ('Customer') and Segment8 Ltd. ('Segment8') governing use of the Segment8 service. It applies where Segment8 processes Personal Data on behalf of Customer in providing the service.
If this DPA conflicts with another part of the agreement on the protection or processing of Personal Data, this DPA controls to the extent of that conflict.
2. Definitions
'Applicable Data Protection Law' means the privacy and data protection laws that apply to the processing covered by this DPA, including the UK GDPR, the Data Protection Act 2018, and the EU GDPR where applicable.
'Controller', 'Data Subject', 'Personal Data', 'Personal Data Breach', 'processing', 'Processor', and 'Subprocessor' have the meanings given in Applicable Data Protection Law. 'Customer Data' means Personal Data submitted to or collected through the service on Customer's behalf.
3. Roles and Customer Instructions
Customer is the Controller and Segment8 is the Processor of Customer Data, except where either party acts as an independent Controller under Applicable Data Protection Law.
Segment8 will process Customer Data only on Customer's documented instructions, including the instructions set out in the agreement and Customer's use and configuration of the service. Segment8 may process Customer Data where required by law and, unless legally prohibited, will inform Customer of that requirement before processing.
Customer is responsible for ensuring that its instructions and use of the service comply with Applicable Data Protection Law and that it has a valid basis for providing Customer Data to Segment8.
4. Processing Details
The subject matter of the processing is the provision, security, support, and maintenance of the Segment8 service. Processing continues for the term of the agreement and any limited period during which Customer Data remains in managed deletion or backup cycles.
The nature and purpose of processing may include collecting, storing, organising, retrieving, analysing, transmitting, and deleting Customer Data as needed to provide the features Customer chooses to use.
- Data Subjects may include Customer users, personnel, prospects, customers, interview or survey participants, and other people whose information Customer submits to the service.
- Personal Data may include account and contact details, professional information, communications, CRM and deal information, research or interview material, uploaded content, usage information, and technical identifiers.
- Customer should not submit special-category or highly sensitive Personal Data unless its use is supported by the agreement and lawful instructions.
5. Confidentiality and Personnel
Segment8 will ensure that personnel authorised to process Customer Data are subject to confidentiality obligations and receive access only where needed for their role. Access may be provided for service delivery, support, maintenance, security, or legal compliance.
Segment8 remains responsible for the performance of its personnel under this DPA.
6. Security
Segment8 will maintain appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures are selected with regard to the nature of the processing and the risks to Data Subjects.
These measures include encryption in transit and at rest, logical tenant separation, role-based access controls, authentication controls, infrastructure monitoring, vulnerability management, backup and recovery measures, and procedures for responding to security incidents. Further information is available in the Security Policy.
Customer is responsible for using the service securely, managing its users and permissions, protecting credentials, and configuring integrations appropriately.
7. Subprocessors
Customer gives Segment8 general authorisation to appoint Subprocessors needed to provide the service. Segment8 will require each Subprocessor to protect Customer Data through written obligations appropriate to the services it performs.
Segment8 remains responsible for its Subprocessors' performance of the data protection obligations assigned to them. The current Subprocessor list, including processing purpose and location, is published on the Subprocessors page.
Segment8 will provide notice of a material new Subprocessor before it begins processing Customer Data. Customer may raise a reasonable, documented data protection objection. The parties will work in good faith to address the concern.
8. International Transfers
Primary application data is hosted in Frankfurt, Germany. Where Customer Data is transferred to a country that does not benefit from an applicable adequacy decision, Segment8 will use a lawful transfer mechanism required by Applicable Data Protection Law.
Where applicable, this may include the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures appropriate to the transfer.
9. Data Subject Requests
Taking into account the nature of the processing, Segment8 will provide reasonable assistance to help Customer respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
If Segment8 receives a request relating to Customer Data directly from a Data Subject, Segment8 will direct the requester to Customer where appropriate and will not respond on Customer's behalf unless authorised by Customer or required by law.
10. Assistance and Personal Data Breaches
Segment8 will provide reasonable assistance with Customer's obligations relating to security, Personal Data Breach notifications, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to Segment8.
Segment8 will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. Notification will include available information reasonably needed for Customer to meet its notification obligations. Segment8's notice is not an admission of fault or liability.
11. Return and Deletion
During the term, Customer may access and export Customer Data through the service where the applicable feature supports it. On termination or expiry, Segment8 will delete or return Customer Data in accordance with the agreement and Customer's lawful instructions, unless retention is required by law.
Customer Data may remain for a limited period in protected backups or recovery systems until the relevant deletion cycle completes. During that period, it will remain protected and will not be used for another purpose.
12. Information and Audit Rights
Segment8 will make available information reasonably necessary to demonstrate compliance with this DPA. Customer should first use current policies, security documentation, and independent assurance material made available by Segment8.
Where that information is not sufficient, Customer may request an audit relating to processing under this DPA. Audits must be proportionate, protect other customers and Segment8's confidential information, avoid unreasonable disruption, and be subject to reasonable advance notice and confidentiality requirements.
13. AI Processing
Where a Customer-selected feature uses an AI provider, Segment8 processes Customer Data only to provide that feature. Customer Data is not used by Segment8 to train machine-learning models.
AI providers used to deliver service features are treated as Subprocessors and are subject to contractual restrictions governing their processing of Customer Data.
14. Contact
Questions or notices relating to this DPA can be sent to [email protected] or by post to Segment8 Ltd., 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.