Acitinar
    How It WorksWho It's For
    PricingContact
    Sign InStart Free Trial
    Acitinar

    Turning business signals into commercial opportunities — helping you contact the right companies at the right time.

    Signals
    • Commercial Intelligence
    • Buying Signals
    • Sales Intelligence
    • Business Signals
    Use Case
    • Recruitment
    • Agencies
    • Accountants
    • Corporate Finance
    • Professional Services
    • Business Development Teams
    Company
    • Home
    • About Us
    • Blog
    • Sitemap
    • Contact
    Legal
    • Privacy Policy
    • Terms of Service
    • Cookie Policy
    • Acceptable Use Policy
    • Data Processing Addendum
    • AI & Signals Disclaimer
    • Website Disclaimer

    © 2026 Acitinar. All rights reserved.

    Data Processing Addendum

    The data processing terms between Acitinar Ltd and its customers under UK GDPR, covering roles, security, sub-processors, and data subject rights.

    Version 2.0Effective 13 July 2026

    On this page

    • 1. Introduction
    • 2. Definitions
    • 3. Roles of the Parties
    • 4. Customer Responsibilities
    • 5. Acitinar Obligations
    • 6. Subprocessors
    • 7. International Transfers
    • 8. Assistance With Data Subject Requests
    • Part 2 — Security, Compliance and Final Provisions
    • 9. Personal Data Breach Management
    • 10. Return and Deletion of Personal Data
    • 11. Audit Rights
    • 12. Confidentiality
    • 13. Processing Details
    • 14. Artificial Intelligence Processing
    • 15. Liability
    • 16. Changes to This DPA
    • 17. Governing Law
    • 18. Jurisdiction
    • 19. Contact Information

    1. Introduction

    This Data Processing Addendum ("DPA") forms part of the agreement between:

    Acitinar Ltd ("Acitinar", "we", "our", or "Processor")

    and

    the customer entity entering into an agreement for use of Acitinar Services ("Customer", "you", or "Controller").

    This DPA governs the processing of personal data by Acitinar on behalf of the Customer in connection with the Services.

    This DPA supplements the:

    • Acitinar Terms of Service;
    • Subscription Agreement (where applicable);
    • Privacy Policy.

    In the event of any conflict between this DPA and another agreement regarding personal data processing, this DPA shall prevail.

    2. Definitions

    For the purposes of this DPA:

    "Applicable Data Protection Laws"

    Means all applicable laws relating to privacy and personal data processing, including:

    • UK General Data Protection Regulation ("UK GDPR");
    • Data Protection Act 2018;
    • Privacy and Electronic Communications Regulations 2003 ("PECR");
    • any replacement or successor legislation.

    "Controller"

    Means the entity that determines the purposes and means of processing personal data.

    "Processor"

    Means the entity processing personal data on behalf of the Controller.

    "Personal Data"

    Has the meaning given under Applicable Data Protection Laws.

    "Processing"

    Includes any operation performed on Personal Data, including:

    • collection;
    • storage;
    • use;
    • access;
    • analysis;
    • deletion;
    • disclosure.

    "Subprocessor"

    Means any third party appointed by Acitinar to process Personal Data on behalf of the Customer.

    3. Roles of the Parties

    3.1 Customer as Controller

    The Customer acts as the Controller of Personal Data submitted to Acitinar through the Services.

    The Customer determines:

    • why Personal Data is processed;
    • what Personal Data is submitted;
    • how Personal Data is used.

    3.2 Acitinar as Processor

    Acitinar acts as Processor where it processes Customer Personal Data solely to provide the Services.

    Acitinar processes Personal Data only:

    • on documented instructions from the Customer;
    • as necessary to provide the Services;
    • as required by Applicable Data Protection Laws.

    3.3 Independent Processing

    Nothing in this DPA prevents Acitinar from processing information where it acts as an independent Controller.

    Examples may include:

    • account management;
    • billing;
    • fraud prevention;
    • security monitoring;
    • legal compliance;
    • improving the Platform using aggregated or anonymised information.

    4. Customer Responsibilities

    The Customer is responsible for ensuring:

    • it has a lawful basis for processing Personal Data;
    • it provides appropriate privacy notices;
    • it obtains required permissions;
    • its instructions to Acitinar comply with Applicable Data Protection Laws.

    The Customer warrants that its use of the Services does not require Acitinar to process Personal Data unlawfully.

    5. Acitinar Obligations

    Acitinar shall:

    5.1 Process Personal Data Only on Instructions

    Acitinar shall process Personal Data only:

    • according to Customer instructions;
    • for providing the Services;
    • for purposes described in the agreement.

    5.2 Confidentiality

    Acitinar shall ensure that persons authorised to process Personal Data:

    • are subject to confidentiality obligations;
    • access information only where necessary;
    • receive appropriate guidance regarding data handling.

    5.3 Security Measures

    Acitinar implements appropriate technical and organisational measures designed to protect Personal Data.

    Measures may include:

    • access controls;
    • authentication requirements;
    • encryption during transmission;
    • restricted internal access;
    • security monitoring;
    • backup procedures.

    The Customer acknowledges that no online system can guarantee absolute security.

    6. Subprocessors

    6.1 Authorisation

    The Customer authorises Acitinar to appoint subprocessors where reasonably required to provide the Services.

    Subprocessors may include providers supporting:

    • cloud infrastructure;
    • payment processing;
    • AI functionality;
    • analytics;
    • security;
    • communications;
    • data enrichment.

    6.2 Current Subprocessors

    Acitinar may use subprocessors including:

    Subprocessor

    Purpose

    Stripe

    Payment processing

    OpenAI

    AI functionality

    Google Gemini

    AI functionality

    SerpAPI

    Search and data functionality

    HunterAPI

    Email and enrichment functionality

    6.3 Subprocessor Obligations

    Acitinar will require subprocessors to:

    • provide appropriate security protections;
    • process information only for agreed purposes;
    • comply with applicable contractual obligations.

    Acitinar remains responsible for its subprocessors' processing activities to the extent required by Applicable Data Protection Laws.

    7. International Transfers

    Where Personal Data is transferred outside the United Kingdom, Acitinar will ensure appropriate safeguards are implemented.

    These may include:

    • adequacy regulations;
    • UK International Data Transfer Agreements;
    • UK Addendums to Standard Contractual Clauses;
    • other lawful transfer mechanisms.

    8. Assistance With Data Subject Requests

    Where required by Applicable Data Protection Laws, Acitinar will provide reasonable assistance to help the Customer respond to requests from individuals exercising their rights.

    These may include requests relating to:

    • access;
    • correction;
    • deletion;
    • restriction;
    • objection;
    • portability.

    The Customer remains responsible for responding directly to individuals.

    Acitinar Ltd

    Data Processing Addendum

    Part 2 — Security, Compliance and Final Provisions

    9. Personal Data Breach Management

    9.1 Notification

    Acitinar maintains procedures designed to identify and respond to Personal Data Breaches.

    Where Acitinar becomes aware of a Personal Data Breach affecting Customer Personal Data, Acitinar will:

    • notify the Customer without undue delay where required by Applicable Data Protection Laws;
    • provide available information regarding the nature of the breach;
    • take reasonable steps to contain and mitigate the impact.

    9.2 Information Provided

    Where available, breach notifications may include:

    • the nature of the incident;
    • categories of Personal Data affected;
    • categories of individuals affected;
    • likely consequences;
    • measures taken or proposed to address the incident.

    Information may be provided progressively as investigations develop.

    9.3 Customer Responsibilities

    The Customer remains responsible for determining:

    • whether notification to regulators is required;
    • whether notification to affected individuals is required;
    • the content and timing of such notifications.

    Acitinar will provide reasonable cooperation where appropriate.

    10. Return and Deletion of Personal Data

    Upon termination or expiry of the Services, Acitinar will, at the Customer's request, delete or return Customer Personal Data processed on the Customer's behalf, unless:

    • retention is required by law;
    • retention is necessary for legitimate business purposes;
    • the information has been anonymised.

    Deletion processes may take reasonable time due to technical, security, and operational requirements.

    11. Audit Rights

    11.1 Compliance Information

    Acitinar will provide reasonable information necessary to demonstrate compliance with this DPA.

    11.2 Customer Audits

    The Customer may request an audit where:

    • required by Applicable Data Protection Laws;
    • there are reasonable grounds to believe Acitinar is materially failing to comply with this DPA.

    Audits must:

    • be requested with reasonable notice;
    • occur during normal business hours;
    • avoid unreasonable disruption;
    • protect confidential information.

    11.3 Audit Limitations

    The Customer may not:

    • access information relating to other customers;
    • compromise security;
    • conduct intrusive testing without approval;
    • request audits unnecessarily.

    Acitinar may satisfy audit obligations by providing:

    • security documentation;
    • compliance information;
    • relevant questionnaires;
    • third-party assurance materials where available.

    12. Confidentiality

    Acitinar shall treat Customer Personal Data as confidential information.

    Acitinar will not:

    • sell Customer Personal Data;
    • disclose Customer Personal Data except as permitted by agreement or law;
    • use Customer Personal Data for unrelated purposes.

    This obligation continues after termination of the Services.

    13. Processing Details

    The following describes the categories of processing covered by this DPA.

    13.1 Subject Matter of Processing

    Processing of Personal Data necessary to provide the Acitinar Services.

    13.2 Duration of Processing

    Processing continues for the duration of the Customer's subscription and any additional period required for:

    • legal compliance;
    • security;
    • dispute resolution;
    • legitimate business purposes.

    13.3 Nature of Processing

    Processing activities may include:

    • collection;
    • storage;
    • organisation;
    • retrieval;
    • analysis;
    • generation of insights;
    • support activities;
    • deletion.

    13.4 Categories of Data Subjects

    Depending on Customer usage, data subjects may include:

    • Customer employees;
    • Customer Users;
    • business contacts;
    • prospective customers;
    • professional contacts.

    13.5 Categories of Personal Data

    Depending on Customer usage, Personal Data may include:

    • names;
    • business email addresses;
    • job titles;
    • company information;
    • professional profile information;
    • Customer-provided business contact information.

    13.6 Special Category Data

    Acitinar does not intend to process special category data.

    Customers must not upload special category data unless expressly authorised and legally permitted.

    Special category data includes information relating to:

    • health;
    • race or ethnicity;
    • political opinions;
    • religious beliefs;
    • trade union membership;
    • biometric data;
    • genetic data;
    • sexual orientation.

    14. Artificial Intelligence Processing

    The Customer acknowledges that certain Platform functionality may involve artificial intelligence technologies.

    AI processing may assist with:

    • analysis;
    • summarisation;
    • classification;
    • generation of Commercial Insights.

    Acitinar does not use Customer Personal Data to make decisions producing legal or similarly significant effects on individuals.

    AI outputs may require human review and should not be treated as guaranteed factual conclusions.

    15. Liability

    Each party's liability relating to this DPA shall be subject to the limitations and exclusions contained in the Acitinar Terms of Service unless otherwise required by law.

    Nothing in this DPA limits liability that cannot legally be excluded.

    16. Changes to This DPA

    Acitinar may update this DPA where necessary to reflect:

    • changes in applicable laws;
    • changes to processing activities;
    • changes to technology providers;
    • improvements to security practices.

    Where changes materially affect Customer rights, Acitinar will provide reasonable notice.

    17. Governing Law

    This DPA and any dispute arising from it shall be governed by the laws of England and Wales.

    18. Jurisdiction

    The courts of England and Wales shall have exclusive jurisdiction regarding disputes relating to this DPA.

    19. Contact Information

    For questions regarding this DPA:

    Acitinar Ltd

    Registered Office:

    24, Rydal Street, Leigh, WN7 4DR

    Email:

    info@acitinar.com

    Acitinar Ltd

    © Acitinar Ltd. All rights reserved.


    This document (version 2.0) is effective 13 July 2026. If you have questions, contact us at info@acitinar.com.