Last updated: 17 August 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Himo Tech (“Processor”, “we”) and the customer (“Controller”, “you”). It applies where we process personal data on your behalf in providing LeadsBullseye.
For the business-listing (lead) data you collect and the account content you submit, you are the Controller and we are the Processor. For our own account/billing records we act as an independent Controller (see the Privacy Policy).
We process personal data only to provide the Service and on your documented instructions (which include your configuration and use of the Service), unless required by law to do otherwise. This includes the on-demand contact enrichment feature: it executes only when you invoke it for a specific saved lead, which constitutes your documented instruction for that lead — we do not run it on our own initiative.
Personnel authorized to process personal data are bound by confidentiality obligations.
We implement appropriate technical and organizational measures, including encryption in transit, row-level tenant isolation, AES-256-GCM encryption of any API keys you supply, least-privilege access controls, and logging.
You authorize us to engage the subprocessors below. We impose data-protection terms on them no less protective than this DPA and remain responsible for their performance. We will give notice of intended changes and allow you to object.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, hosting of application data | EU / US regions |
| HeyCatch | Product analytics — page and feature usage, and account identifiers of signed-in users. Only for visitors who accept analytics cookies; see our Cookie Policy | United States |
| Stripe | Subscription billing and payments | US / global |
| Google (Maps Platform & Gemini API) | Business-listing data and AI qualification/generation, including on-demand contact enrichment via the Gemini API with Google Search grounding | US / global |
| Cloud hosting provider | Application server hosting | As configured at deployment |
Where we transfer EU/UK personal data outside the EEA/UK, we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism.
Taking into account the nature of processing, we will assist you with data-subject requests, security, breach notification, and data-protection impact assessments, as required by applicable law.
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with information reasonably available to us.
On termination, we will delete or return personal data processed on your behalf, except where retention is required by law. You may also delete leads and account data from within the Service.
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits consistent with confidentiality and security constraints.