Last updated: January 1, 2025 · Operated by Germaine 50 Technologies (Lagos, Nigeria) · support@baddecision.app
This Data Processing Addendum ("DPA") forms part of the Germaine 50 Technologies ("Bad Decision", "Processor") Terms of Service. It applies to the extent you ("Customer", "Controller") process personal data through the Service.
This DPA reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Nigeria Data Protection Act (NDPA) 2023.
You are the Controller. You decide why and how lead data is processed. Bad Decision is the Processor. We process lead data only on your instructions, to provide the Service to you.
You are responsible for having a lawful basis (consent or legitimate interest) to process the leads you upload or find, and for honoring data subject rights requests.
We process the following on your behalf:
We process this data only to provide the Service. We never use your data to train our own models or sell it to anyone.
We use the following sub-processors to deliver the Service. Each is bound by a written agreement with equivalent data protection obligations. This list is current as of the last-updated date above; we maintain a live list at /subprocessors and notify customers at least 30 days before engaging any new sub-processor.
| Sub-processor | Purpose | Location |
|---|---|---|
| WorkOS, Inc. | Authentication and sign-in | United States |
| Supabase, Inc. | Postgres database and file storage | United States / EU |
| Flutterwave | Subscription and add-on payment processing | Global |
| Telnyx LC | SMS and AI voice calling | Global |
| Meta Platforms, Inc. | WhatsApp Business API message delivery | Global |
| Vercel, Inc. | Web application hosting | Global edge |
| Cloudflare, Inc. | CDN, DNS, and DDoS protection | Global edge |
| OpenAI, L.L.C. | AI message drafting and conversation | United States |
| Anthropic PBC | AI message drafting and conversation | United States |
| Google LLC (Gemini) | AI message drafting and conversation | Global |
| Resend, Inc. | Transactional and campaign email delivery | United States |
| Minimax (Hailuo) | Text-to-speech for AI voice calls | Global |
| Cal.com | Meeting scheduling and booking | Global |
We will notify you at least 30 days before engaging any new sub-processor. You may object by emailing us. If we cannot resolve your objection, you may terminate with a pro-rata refund.
Your data is stored with our database provider in the United States or EU, depending on your region. Backups are kept for 30 days. Your data may be transferred to other countries for processing. We comply with applicable data protection laws including NDPR (Nigeria) and GDPR (EU) for EU residents' data, and use Standard Contractual Clauses (or other appropriate transfer mechanisms) where personal data is transferred outside its region of origin.
We help you respond to data subject requests by providing:
We forward any data subject request we receive directly to you for response.
If a personal data breach happens, we will notify you without undue delay and in any case within 72 hours. The notice will describe the nature of the breach, the likely consequences, and the measures we are taking.
We will cooperate with you to meet your own breach notification obligations under GDPR Article 33.
When your subscription ends, we will delete or return all personal data within 30 days, at your choice. We may retain billing records for 7 years for tax compliance, and security logs for 12 months.
To request deletion or export, email us at support@baddecision.app with the subject "DPA request".