Implest

Data Processing Addendum

The data-processing terms that apply when Implest processes personal data on a customer’s behalf.

Last updated: 6 October 2026

1. Scope and parties

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and Komaneca SL, trading as Implest ("Implest"), where Implest processes personal data on behalf of Customer in connection with the Implest service.

Customer acts as controller, or as a processor that is authorised to appoint Implest as a subprocessor, for Customer Personal Data. Implest acts as processor or subprocessor for that data. Each party remains independently responsible for processing for which it determines its own purposes and means.

2. Customer instructions

Implest will process Customer Personal Data only on documented instructions from Customer, including the agreement, configured integrations, Missions, execution modes, workspace settings and other instructions submitted through the service, unless processing is required by applicable law.

A Mission may record the purpose, target, territory, channel, restrictions and execution mode requested by Customer. Customer is responsible for ensuring its instructions are lawful and for providing any notices or obtaining any lawful basis required for its processing.

3. Nature, purpose and categories of processing

Processing may include collection, recording, organisation, storage, retrieval, analysis, enrichment, AI inference, prioritisation, generation, transmission, messaging, qualification, scheduling, logging, restriction, deletion and other operations needed to provide the contracted service.

Data subjects may include Customer personnel, users, prospects, professional contacts, CRM contacts, meeting participants and other individuals whose data Customer lawfully submits or instructs Implest to process.

Personal data may include business identity and contact data, employer and role information, professional profile identifiers, CRM data, conversation content, meeting and calendar metadata, campaign status, customer instructions, technical identifiers and other data submitted by Customer. Customer must not intentionally use Implest to process special-category data or criminal-conviction data unless the parties have expressly reviewed and agreed the use case.

4. Confidentiality and personnel

Implest will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where needed for their role.

Implest will maintain appropriate AI and data-protection awareness for personnel involved in operating the service, taking account of their role and the risks of the processing.

5. Security measures

Implest will implement technical and organisational measures appropriate to the risk, including encrypted transport, access controls, server-side secret management, least-privilege access, Row Level Security where appropriate, logging and auditability, credential rotation, backups, environment separation and incident-response procedures.

Customer acknowledges that security measures may evolve as technology, risks and the service change, provided that the overall level of protection is not materially reduced.

6. Subprocessors

Customer grants Implest general authorisation to engage subprocessors needed to provide the service. The current list is maintained on the Subprocessors & Third-Party Services page. Implest will impose data-protection obligations on subprocessors that are materially consistent with the obligations applicable to Implest for the relevant processing.

Implest may update its subprocessors. Where required by applicable law or contract, Implest will provide reasonable advance notice of a material new subprocessor so that Customer may raise a reasonable data-protection objection.

7. International transfers

Where Customer Personal Data is transferred from the European Economic Area to a country without an applicable adequacy decision, Implest will ensure that an appropriate transfer mechanism is in place. Where relevant, the European Commission Standard Contractual Clauses are incorporated for the applicable controller-to-processor or processor-to-processor relationship, together with any required supplementary measures.

Where an authorised subprocessor relies on another lawful transfer mechanism, such as an adequacy decision or the EU-U.S. Data Privacy Framework, that mechanism may be used for the relevant transfer.

8. Assistance to Customer

Taking into account the nature of the processing and information available to Implest, Implest will reasonably assist Customer with data-subject requests, security obligations, personal-data breach obligations, data-protection impact assessments and consultations with supervisory authorities where required by applicable data-protection law.

If Implest receives a request from a data subject concerning Customer Personal Data for which Customer is the controller, Implest may refer the request to Customer and will not respond as controller unless required or authorised by law.

9. Personal data breaches

Implest will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data where notification is required under applicable law. The notice will include available information reasonably needed for Customer to assess its obligations, and Implest may provide information in phases as the investigation develops.

Implest will take reasonable steps to contain, investigate and remediate the incident and will document material security incidents in accordance with its internal procedures.

10. Return and deletion

On termination of the relevant service, and at Customer’s choice where required by applicable law, Implest will return or delete Customer Personal Data, unless applicable law requires continued retention. Deletion may be subject to reasonable technical backup cycles and preservation of minimum records required for security, suppression, legal obligations or the establishment, exercise or defence of legal claims.

Suppression information may be retained where necessary to honour an objection or prevent unlawful re-contact.

11. Audit information

Implest will make available information reasonably necessary to demonstrate compliance with its processor obligations. Where appropriate, this may include current security documentation, relevant certifications or summaries, subprocessors information and responses to reasonable security questionnaires.

Any on-site or additional audit must be legally required or reasonably necessary, coordinated to minimise disruption, protect other customers and confidential information, and may be subject to reasonable cost allocation where permitted by law.

12. Priority and governing terms

If this DPA conflicts with the Terms of Service on matters concerning the processing of Customer Personal Data, this DPA prevails for those matters. Defined terms not stated here have the meaning given in the applicable agreement or data-protection law.

This DPA is governed by the law governing the main agreement, without prejudice to mandatory rights and the operation of any incorporated Standard Contractual Clauses.

Questions or requests: msegura@implest.com.

Back to Implest