Data Processing Addendum

Updated August 10, 2026

  1. BACKGROUND.

    1. ZenLeads Inc. (d/b/a Apollo.io) ("Apollo", "we", "our" or "us") entered into an Order Form and an agreement (the "Agreement") with the entity or organization named in the Agreement (“Customer", “you”, “your”, or “yours”) for the provision of our Services to you.

    2. This Data Processing Addendum (the "DPA") between you and Apollo (each a "Party" and collectively the "Parties") is incorporated into and will form part of the Agreement. Signatures of assent of the Parties to the Agreement will be deemed signature to, and acceptance and agreement of, this DPA and the Standard Contractual Clauses incorporated into this DPA.

    3. In the event of a conflict between any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail. Notwithstanding the foregoing, the limitations and exclusions of liability set out in the Agreement will continue to apply to this DPA and to the Standard Contractual Clauses, and each Party’s aggregate liability arising out of or relating to this DPA and the Standard Contractual Clauses will be subject to those limitations and exclusions.

    4. Sections 4 through 6 of this DPA apply solely where and to the extent Apollo is a Processor of Customer Personal Data. These Sections do not apply to the extent Apollo is a Controller of Personal Data, as described in Section 3(b) of this DPA.

  2. DEFINITIONS. Unless otherwise set out in this DPA, each capitalized term in this DPA will have the meaning set out in the Agreement, and the following capitalized terms used in this DPA will be defined as follows:

    1. "Controller" has the meaning given under the applicable Data Protection Laws that employ that term in designating between “processors” and “controllers” of personal data. Where applicable, “Controller” will also have the same meaning as “Business” for the purposes of the CCPA.

    2. "Customer Personal Data" means Personal Information included in the Customer Data that we Process on your behalf in connection with our provision of the Services. (For the avoidance of doubt, Customer Personal Data does not include any Personal Data as to which we act as a Controller.)

    3. "Data Privacy Framework" means the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. Data Privacy Framework self-certification programs (as applicable) operated by the U.S. Department of Commerce; as may be amended, superseded or replaced.

    4. Data Privacy Framework Principles” means the Principles and Supplemental Principles contained in the relevant Data Privacy Framework; as may be amended, superseded, or replaced.

    5. "Data Protection Laws" means, solely where and to the extent applicable to the Processing of Customer Personal Data under the Agreement, any applicable national or state implementing legislation regarding privacy, data protection, or data security (including, where applicable and without limitation: the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK Data Protection Act of 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act of 2018 (the “UK GDPR”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA”)), inclusive of any U.S. state law or other privacy, data protection, or data broker law, however it designates the parties to the Processing, and, in each case as amended, replaced or superseded from time to time and together with implementing regulations.

    6. "Data Subject" has the meaning given under the applicable Data Protection Law(s), and will also mean a “consumer” for purposes of Data Protection Laws using that term.

    7. "European Economic Area" or "EEA" means the Member States of the European Union together with Iceland, Norway, and Liechtenstein.

    8. Instructions” means your instructions to us to process the Customer Personal Data as provided under the Agreement, this DPA, through your use of the features and functionality of the Services or as otherwise mutually agreed by authorized signatories of both parties in writing.

    9. "Processing" has the meaning given under the applicable Data Protection Laws, and "Process" and its cognates will be interpreted accordingly.

    10. "Processor" has the meaning given under the applicable Data Protection Laws that employ that term in designating between “processors” and “controllers” of Personal Information. Where applicable, “Processor” will also have the same meaning as “Service Provider” for the purposes of the CCPA.

    11. Standard Contractual Clauses" means either or both of the following, as the context requires, along with any successor clauses thereto:

      1. The “EU SCCs”, meaning the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (located at http://data.europa.eu/eli/dec_impl/2021/914/oj) and completed as set forth herein.
      2. The “UK SCCs”, meaning the United Kingdom International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (located at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-DPA.pdf) and completed as set forth herein.
    12. "Subprocessor" means any Processor engaged by us who agrees to receive from us Customer Personal Data.

    13. "Supervisory Authority" will mean the data protection supervisory authority (including any cognate terms) as defined under the applicable Data Protection Laws.

    14. Third Party” has the meaning given in the CCPA.

  3. DATA PROCESSING.

    1. When We Act as a Processor. To the extent that we Process Customer Personal Data solely to provide you with Services, such as to Process your Customer Personal Data in order to (i) match it to and provide you with Business Contact Information and other outputs of the Services, (ii) provide emailing, prospecting, recording, meeting, calendar or other similar Services to you, or (iii) provide enhanced Services with artificial intelligence capabilities, we are acting as a Processor and you are acting as a Controller. When we act as a Processor, we will only Process Customer Personal Data in accordance with your Instructions, and we will notify you in the unlikely event that Data Protection Law requires us to process Customer Personal Data other than pursuant to your Instructions (unless prohibited from doing so by applicable law). As a Processor, to the extent required by Data Protection Laws, we:

      1. acknowledge that Customer Personal Data is disclosed only for the limited and specified business purposes set forth under the Agreement (“Business Purposes”) and will not retain, use, or disclose Customer Personal Data outside of the direct business relationship between you and us, or for any purpose (including any commercial purpose) other than the Business Purposes or as otherwise permitted by Data Protection Law;
      2. will not “sell” any Customer Personal Data “share” Customer Personal Data or Process any Customer Personal Data for purposes of targeted advertising, as such terms are defined in Data Protection Laws;
      3. will comply with any applicable restrictions under the CCPA on combining Customer Personal Data with other data; and
      4. will provide the same level of protection for the Customer Personal Data subject to the CCPA as is required of Customer under the CCPA and comply with all applicable provisions of the CCPA. We will notify you in the event we determine that we can no longer comply with our obligations under the CCPA.
    2. When We Each Act as Controllers. We are each independent Controllers, and (for CCPA purposes), each a Business as to Personal Information included in Business Contact Information and Account Information when such Business Contact Information or Account Information, as the case may be, is in our respective possession. For the avoidance of doubt, this means that Apollo is an independent Controller of all Personal Information in its Contributor Database, including Personal Information that has been enriched and/or verified by Customer Data or otherwise contributed by you as set forth in the Agreement. You are an independent Controller when you provide such Personal Information to us.

    3. Required Notices and Consents. You will have sole responsibility and liability for the means by which you acquire Customer Personal Data and provide such data to us. In particular, where required by Data Protection Laws, you will ensure that you have provided/will provide all necessary notices and have obtained/will obtain all necessary consents for the Processing of Customer Personal Data as contemplated in the Agreement.

    4. Artificial Intelligence and Automated Decision-Making. To the extent the Services include artificial intelligence or automated decision-making technology features, you are solely responsible, as Controller and (where applicable) as deployer, for determining the lawfulness of your use of such features, including providing all required notices, obtaining all required consents, conducting any required assessments (including data protection impact assessments and any assessments required in connection with automated decision-making technology), responding to data subject rights relating to automated decision-making or profiling, and otherwise complying with Data Protection Laws and any applicable laws governing artificial intelligence. We will provide reasonable assistance solely to the extent and in the manner required of a Processor under Data Protection Laws. Nothing in this DPA causes us to act as a Controller or deployer with respect to your use of such features.

  4. SUBPROCESSORS.

    1. Authorized Subprocessors. You agree that we may use the Subprocessors listed at https://trust.apollo.io/ to Process Customer Personal Data.

    2. Adding New Subprocessors. We will notify you of any changes concerning the addition of a new Subprocessor at least thirty (30) days before the new Subprocessor commences its Processing of Customer Personal Data (the “Notice”). We will provide Notice by either:

      1. posting such Subprocessors at the following webpage: https://www.apollo.io/company/privacy-center or https://trust.apollo.io/, or
      2. sending an email to the last known email address we have on file.
    3. Objections to Subprocessors. If you object to a new Subprocessor on reasonable grounds related to the protection of Customer Personal Data, then without prejudice to any right to terminate the Agreement, the Parties will attempt to negotiate a resolution in good faith. If the Parties cannot agree on a resolution within 30 days of your objection to a new Subprocessor, then you may terminate the Agreement immediately upon written notice to us and you will be entitled to a refund of any prepaid fees for services unused as of the effective date of termination. This termination right and refund is your sole and exclusive remedy if you object to any new Subprocessor. If you do not object within thirty (30) days of receipt of the Notice, you are deemed to have accepted the new Subprocessor.

    4. Subprocessor Agreements. We will enter into a written agreement with each Subprocessor that imposes substantially similar data protection obligations on the Subprocessor with regard to their Processing of Customer Personal Data, as are imposed on us where we are acting as a Processor under this DPA.

    5. Liability of Subprocessors. We will be liable to you for the acts and omissions of any Subprocessor as if they were our acts and omissions, subject to the limitations and exclusions of liability set out in the Agreement.

  5. DATA SECURITY, AUDITS, AND SECURITY NOTIFICATIONS; DELETION AND RETENTION.

    1. Apollo Security Obligations. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures set out in Exhibit 2.

    2. Demonstrating Compliance. Upon your reasonable request, we will make available all information reasonably necessary to demonstrate our compliance with our obligations under Data Protection Law(s).

    3. Security Incident Notification. If we become aware of a confirmed Security Incident we will (i) notify you of the Security Incident without undue delay (and in any event within 72 hours of confirmation), (ii) investigate the Security Incident and provide you (and any law enforcement or regulatory official, as required by Data Protection Law) with reasonable assistance as required to investigate the Security Incident, and (iii) take steps to remedy any non-compliance with this DPA. Our notification of, or response to, a Security Incident under this Section will not be construed as an acknowledgment by us of any fault or liability with respect to the Security Incident.

    4. Apollo Employees and Personnel. We will treat the Customer Personal Data as confidential and will ensure that any employees or other personnel authorized to Process Customer Personal Data are subject to a binding duty of confidentiality with respect to the Customer Personal Data both during the term of their employment or engagement and thereafter.

    5. Audits. We will, upon your reasonable request and where and to the extent so required by Data Protection Law, allow for, cooperate with, and contribute to assessments and audits (including inspections, of our compliance with the applicable Data Protection Law, conducted by you (or a third party on your behalf and mandated by you) provided (i) such audits or inspections are not conducted more than once per year (unless requested by a Supervisory Authority); (ii) are conducted only during business hours; and (iii) are conducted in a manner that causes minimal disruption to Apollo’s operations and business.

    6. Remediation Right. Where and to the extent such a right is explicitly provided under the CCPA, you retain the right, upon reasonable notice to us, to take reasonable and appropriate steps to (i) ensure that we are using Customer Personal Data we collected pursuant to the Agreement in a manner consistent with your obligations under CCPA, and (ii) stop and remediate unauthorized use of Customer Personal Data.

    7. Deletion of Data. Subject to Section 5(h) below, we will, at your election within 90 (ninety) days of the date of termination of the Agreement:

      1. delete all Customer Personal Data Processed by us or any Subprocessors; or
      2. return a complete copy of all Customer Personal Data by secure file transfer in such a format as notified to us by you.
    8. Retention. We and our Subprocessors may retain Customer Personal Data to the extent required by applicable laws and only to the extent and for such period as required by applicable laws; provided that we ensure the confidentiality of all such Customer Personal Data and will ensure that such Customer Personal Data is only Processed as necessary for the purpose(s) specified in the applicable laws requiring its storage and for no other purpose.

  6. ACCESS REQUESTS AND ASSISTANCE WITH COMPLIANCE.

    1. Government Disclosure. We will notify you of any request for the disclosure of Customer Personal Data by a governmental or regulatory body or law enforcement authority (including any data protection supervisory authority) unless otherwise prohibited by law or a legally binding order of such body or agency.

    2. Assistance Generally. Solely to the extent and in the manner required under Data Protection Laws, we will provide reasonable assistance to you for your compliance with such laws, including, without limitation, as set forth in Section 6.

    3. Data Subject Rights. To the extent required under Data Protection Laws, and taking into account the nature of the Processing, we will use reasonable endeavors to assist you by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of your obligation to respond to requests for exercising Data Subject rights laid down in Data Protection Laws.

    4. Data Protection Impact Assessments; Prior Consultations. To the extent required under Data Protection Laws: (i) we will provide you with reasonably requested information regarding our Services to enable you to carry out data protection impact assessments (including any similar assessments under Data Protection Laws) or prior consultations with any Supervisory Authority, in each case solely in relation to Processing of Customer Personal Data and taking into account the nature of the Processing and information available to us; and (ii) we will provide reasonable assistance to you in the cooperation or consultation with a Supervisory Authority as it relates to the Processing of Customer Personal Data hereunder.

  7. ARTIFICIAL INTELLIGENCE AND AUTOMATED DECISION-MAKING.

    1. Roles. Where the Services include features that use artificial intelligence or machine learning ("AI Features"), the Party that develops and makes the AI Feature available acts as the "provider" and the Party that uses the AI Feature under its own authority acts as the "deployer," each as those or analogous terms are used under applicable Data Protection Laws and AI-specific laws (including Regulation (EU) 2024/1689 (the "EU AI Act")). Nothing in this Section alters the controller/processor allocations set out in Section 3.

    2. Cooperation. Taking into account the nature of the AI Features and the information available to us, we will provide you with information reasonably necessary to enable you to (i) provide any pre-use notices, (ii) respond to access or opt-out requests, and (iii) conduct any risk assessment or data protection impact assessment, in each case to the extent required of you under applicable Data Protection Laws governing automated decision-making technology, including the CCPA regulations on automated decision making technology. You remain responsible for determining whether your use of the AI Features results in any "significant decision" and for your own compliance obligations as a deployer or controller.

    3. Transparency. Each Party will comply with applicable AI transparency obligations, including any obligation to disclose interaction with an AI system or to mark AI-generated content under Article 50 of the EU AI Act, in relation to the AI Features it makes available or deploys.

  8. CONTROLLER OBLIGATIONS.

    1. In the course of acting as a Controller (and/or Third Party), such Party will:

      1. Limit its use of Personal Information received from the other Party to the limited and specific purposes set forth in the Agreement or any applicable Order Form, and (without limitation of the foregoing) to purposes that it reasonably believes an average consumer would reasonably expect.
      2. Comply with its own obligations under Data Protection Laws applicable to it as a Controller, including (without limitation) as to any Data Subject rights to deletion, access, and “opt-out” of “sale” or “sharing” of Personal Information (as such terms are defined in Data Protection Laws).
      3. Notify the other Party about all valid opt-out, deletion, or other data subject requests, as and to the extent required by Data Protection Laws. You will cooperate and comply with any such notification made by Apollo to you with respect to Business Contact Information in a timely manner. Apollo will make removal and opt-out requests available through the Removal Requests list (Settings > Removal Requests) or such other mechanism as Apollo may designate in writing. Customer agrees to review this list no less than once every thirty (30) days. Within thirty (30) days of Apollo making a request available Customer will either: (a) permanently delete the affected individual's data from all systems within Customer's control, including CRM systems, enrichment workflows, API outputs, AI integrations, and other downstream repositories where data obtained through the Services may reside; or (b) document and retain a separate, independent legal basis for continued processing. Suppression or cessation of active use does not satisfy the deletion obligation under (a).
      4. To the extent Apollo qualifies as a "data broker" under applicable Data Protection Laws, Apollo will maintain all required registrations and process consumer deletion and opt-out requests received through any state-administered accessible deletion mechanism (including California's DELETE Request and Opt-Out Platform) within the timeframes required by law, and will direct its Subprocessors to give effect to such requests in accordance with Section 4 (Subprocessors). Apollo will make such requests available to Customer in accordance with Section 8(iii).
      5. As to any Personal Information received from the other Party, implement and maintain reasonable security procedures, as appropriate to the level of sensitivity and confidentiality applicable to such Personal Information.
      6. Upon request, provide the other Party with reasonable assurances, in writing, as may be necessary to permit the other Party to ensure that it has employed Personal Information subject to the Agreement as contemplated by the Agreement.
      7. For Personal Information subject to the CCPA, provide the same level of protection to the Personal Information as the Party providing the Personal Information is required to provide under the CCPA, and notify the other Party if it determines that it is no longer able to comply with its CCPA obligations.
    2. Solely where and to the extent the CCPA applies to such Processing, the Party providing the Personal Information retains the right, upon reasonable notice, to (i) take reasonable and appropriate steps to ensure that the other Party uses Personal Information consistent with the CCPA, and (ii) stop and remediate any unauthorized Processing of Personal Information made available to the other Party.

  9. DATA TRANSFERS.

    1. Transfers Mechanism. To the extent that the Processing of Personal Information involves the transmission of such Personal Information to a country or territory outside the country from which such Personal Information was provided to the Party receiving the data (the “data importer”), the Parties will comply with any requirements under Data Protection Laws regarding such transfers. To the extent required by Data Protection Laws, the data importer will ensure that a lawful data transfer mechanism is in place prior to engaging in any onward transfers of Personal Information from one country to another.

    2. Data Privacy Framework. At the time of the execution of the Agreement, Apollo participates in and certifies compliance with the Data Privacy Framework. As required by the Data Privacy Framework, Apollo will: (i) provide at least the same level of privacy protection as is required by the Data Privacy Framework Principles; (ii) notify Customer if Apollo makes a determination it can no longer meet its obligation to provide the same level of protection as is required by the Data Privacy Framework Principles (in which event Apollo will cease such processing or take other reasonable and appropriate steps to remediate. Where and to the extent that the Data Privacy Framework applies, Apollo will use the Data Privacy Framework to lawfully receive Customer Personal Data and/or Personal Information in the United States.

    3. EU SCCs. To the extent legally required (for example, if the Data Privacy Framework does not cover the transfer to Apollo and/or the Data Privacy Framework is invalidated), the Parties are deemed to have entered into and signed the EU SCCs and its Annexes, which form part of this DPA and take precedence over the rest of this DPA to the extent of any conflict. Except as described in Sections 9(d) and 9(e) below, the EU SCCs are deemed completed as follows:

      1. Module 1 applies to transfers of Personal Information where both Parties are independent Controllers (as described in Section 3(b) of this DPA). Module 2 of the EU SCCs applies to transfers of Customer Personal Information from Customer (the Controller) to us (the Processor).
      2. Clause 7 (the optional docking clause) is included.
      3. Clause 9 of Module 2 (Use of sub-processors): The Parties select Option 2 (General written authorization). The initial list of Subprocessors and the procedures for updating such list are set forth in Sections 4.1 and 4.2 of this DPA.
      4. Clause 11 (Redress): The optional language requiring that data subjects be permitted to lodge a complaint with an independent dispute resolution body is not included.
      5. Clause 17 (Governing law): The Parties choose Option 1 (the law of an EU Member State that allows for third-party beneficiary rights) and select the law of Ireland.
      6. Clause 18 (Choice of forum and jurisdiction): The Parties select the courts of Ireland.
      7. Annex I is completed as set forth in Exhibits 1A, 1B and 1C of this DPA. For Annex I(C), the Parties select the Irish Data Protection Commission. Annex II is completed as set forth in Exhibit 2 of this DPA. Annex III is not applicable because the Parties have chosen General Authorization under Clause 9.
    4. UK SCCs. To the extent legally required, by entering into this DPA, the Parties are deemed to have entered into and signed the UK SCCs, which form part of this DPA and take precedence over the rest of this DPA as set forth in the UK SCCs. The Tables within the UK SCCs are deemed completed as follows:

      1. Table 1: The Parties’ details will be the Parties and their affiliates to the extent any of them is involved in such transfer, and the Key Contact will be the contacts set forth in Exhibits 1A, 1B and 1C of this DPA, as applicable.
      2. Table 2: The Approved EU SCCs referenced in Table 2 will be the EU SCCs as executed by the Parties and completed above, except that: (1) Clause 17 (Governing law): The Parties choose the law of England and Wales; (2) Clause 18 (Choice of forum and jurisdiction): The Parties select the courts of England and Wales and (3) Annex 1C and Clause 13 the Parties select the UK Information Commissioner.
      3. Table 3: Annex I is set forth in Exhibits 1A, 1B and 1C of this DPA. Annex II is set forth in Exhibit 2 of this DPA. Annex III is inapplicable.
      4. Table 4: We may end this DPA as set out in Section 19 of the UK SCCs.
    5. Swiss Data. For transfers of Personal Information that are subject to the Swiss Federal Act on Data Protection (“FADP”), the EU SCCs form part of this DPA as set forth above, but with the following differences to the extent required by the FADP:

      1. References to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR. The revised FADP, effective September 1, 2023, applies only to the Personal Information of natural persons.
      2. The term “member state” in the EU SCCs will not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs.
      3. The relevant supervisory authority is the Swiss Federal Data Protection and Information Commissioner (for transfers subject to the FADP and not the GDPR), or both such Commissioner and the supervisory authority identified in the EU SCCs (where the FADP and GDPR apply, respectively).
      4. The EU SCCs will be modified as follows: (1) Clause 17 (Governing law): The Parties choose the law of Switzerland; (2) Clause 18 (Choice of forum and jurisdiction): The Parties select the courts of Switzerland and (3) Annex 1C and Clause 13 the Parties select the Swiss Federal Data Protection and Information Commissioner.

EXHIBIT 1A
Controller/Exporter (Customer) to Processor/Importer (Apollo)

  1. LIST OF PARTIES.
    1. Data Exporter(s).
      1. Name: The Customer identified in the Agreement or Order Form.
      2. Address: As set forth in the Agreement or Order Form.
      3. Contact person’s name, position and contact details: As set forth in the Agreement and Order Form, or as otherwise agreed to by the parties.
      4. Activities relevant to the data transferred under these Clauses: Processing in connection with the receipt of the Services provided by the data importer in accordance with the Agreement and the DPA.
      5. Signature and date: See signature and/or electronic acceptance date to the Agreement.
      6. Role (controller/processor): Controller
    2. Data Importer.
      1. Name: ZenLeads Inc. (d/b/a Apollo.io)
      2. Address: 440 N Barranca Ave #4750, Covina, CA 91723
      3. Contact person’s name, position, and contact details: Legal Department; privacy@apollo.io or such other person designated by Apollo.
      4. Activities relevant to the data transferred under these Clauses: Processing in connection with providing, maintaining and improving the Services in accordance with the Agreement and the DPA.
      5. Signature and date: See signature and/or electronic acceptance date to the Agreement.
      6. Role (controller/processor): Processor
  2. DESCRIPTION OF TRANSFER.
    1. Categories of data subjects whose personal data is transferred. Data subjects may include data exporter’s employees (or other end-users of the Services), prospects, customers, business partners and vendors.
    2. Categories of personal data transferred. Customer Personal Data which may include, but is not limited to the following categories:
      1. First and last name
      2. Title
      3. Employer
      4. Contact information (company, email, phone, physical business address)
      5. IP address
      6. Video and audio recordings
    3. The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). Continuously for the duration of the Agreement.
    4. Nature of the processing. Data importer Processes Customer Personal Data to provide the Services pursuant to the Agreement, which includes, without limitation, receiving, storing, analyzing, and deleting Customer Personal Data.
    5. Purpose(s) of the data transfer and further processing. Data importer’s provision of Services to the data exporter pursuant to the Agreement between data exporter and data importer.
    6. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period. As further set forth under the Agreement and the DPA.
    7. For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing. Same as above.

EXHIBIT 1B
Controller/Exporter (Customer) to Controller/Importer (Apollo)

  1. LIST OF PARTIES.

    1. Data Exporter(s).
      1. Name: The Customer identified in the Agreement or Order Form.
      2. Address: As set forth in the Agreement or Order Form.
      3. Contact person’s name, position and contact details: As set forth in the Agreement and Order Form, or as otherwise agreed to by the parties.
      4. Activities relevant to the data transferred under these Clauses: Processing in connection with providing, maintaining, improving and enriching the Services in accordance with the Agreement and the DPA.
      5. Signature and date: See signature and/or electronic acceptance date to the Agreement.
      6. Role (controller/processor): Controller
    2. Data Importer.
      1. Name: ZenLeads Inc. (d/b/a Apollo.io)
      2. Address: 440 N Barranca Ave #4750, Covina, CA 91723
      3. Contact person’s name, position, and contact details: Legal Department; privacy@apollo.io or such other person designated by Apollo.
      4. Activities relevant to the data transferred under these Clauses: Processing in connection with providing, supporting, maintaining, improving and enriching the Services in accordance with the Agreement and the DPA.
      5. Signature and date: See signature and/or electronic acceptance date to the Agreement.
      6. Role (controller/processor): Controller
  2. DESCRIPTION OF TRANSFER.

    1. Categories of data subjects whose personal data is transferred. Data subjects include data exporter’s employees (and other end-users of the Services), prospects, customers, business partners and vendors.

    2. Categories of personal data transferred.

      1. First and last name
      2. Title
      3. Employer
      4. Contact information (company, email, phone, physical business address)
      5. IP address
      6. Any other categories of Personal Information provided by Customer.

      In each case where and to the extent such Personal Information is included in the Account Information or Customer Data Processed by data importer in its role as a data controller.

    3. The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). Continuously for the duration of the Agreement.

    4. Nature of the processing. Data importer Processes Personal Information as further set forth under the Agreement and in data importer’s privacy policy, including Processing to verify, enrich and grow the Contributor Database and improve the Services, which includes, without limitation, receiving, storing, analyzing, and deleting Personal Information.

    5. Purpose(s) of the data transfer and further processing. Such purposes as further set forth under the Agreement and in data importer’s privacy policy, including Processing by data importers to verify, enrich and grow the Contributor Database and improve the Services.

    6. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period. Where data importer is a Controller: As further set forth under the data importer’s privacy policy.

    7. For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing. Same as above.

EXHIBIT 1C
Controller/Exporter (Apollo) to Controller/Importer (Customer)

  1. LIST OF PARTIES.
    1. Data Exporter(s).
      1. Name: ZenLeads Inc. (d/b/a Apollo.io)
      2. Address: 440 N Barranca Ave #4750, Covina, CA 91723-1722
      3. Contact person’s name, position and contact details: Legal Department; privacy@apollo.io or such other person designated by Apollo.
      4. Activities relevant to the data transferred under these Clauses: Providing the Services (including Business Contact Information) to the data importer in accordance with the Agreement and the DPA.
      5. Signature and date: See signature and/or electronic acceptance date to the Agreement.
      6. Role (controller/processor): Controller
    2. Data Importer.
      1. Name: The Customer identified in the Agreement.
      2. Address: As set forth in the Agreement.
      3. Contact person’s name, position, and contact details: As set forth in the Agreement and Order Form or otherwise agreed to by the parties.
      4. Activities relevant to the data transferred under these Clauses: Receiving the Services (including Business Contact Information) provided by the data exporter in accordance with the Agreement and the DPA.
      5. Signature and date: See signature and/or electronic acceptance date to the Agreement.
      6. Role (controller/processor): Controller
  2. DESCRIPTION OF TRANSFER.
    1. Categories of data subjects whose personal data is transferred. Data subjects include individuals whose data has been contributed to the Contributor Database.
    2. Categories of personal data transferred. Business Contact Information which includes (without limitation) the following categories of Personal Information:
      1. First and last name
      2. Title
      3. Employer
      4. Contact information (company, email, phone, physical business address)
    3. The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). Continuously for the duration of the Agreement.
    4. Nature of the processing. For the data importer’s use subject to the terms and license restrictions of the Agreement.
    5. Purpose(s) of the data transfer and further processing. Data importer’s receipt of Services (including Business Contact Information) provided by data exporter under the Agreement.
    6. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period. Data importer will retain the Business Contact Information in accordance with the Agreement.
    7. For transfers to (sub-) processors, also specify the subject matter, nature and duration of the processing. Same as above.

EXHIBIT 2
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Data importer will implement and maintain the Technical and Organizational Measures described in Annex II. Notwithstanding any provision to the contrary otherwise agreed to by Data exporter, Data importer may modify or update these Technical and Organizational Measures at its discretion provided that such modifications and updates do not result in the degradation of the overall security of the Services. All capitalized terms not otherwise defined herein will have the meanings as set forth in the Agreement.

  1. ACCESS CONTROL.

    1. Preventing Unauthorized Product Access.
      1. Outsourced processing. Apollo hosts its Service with outsourced, US-based data center providers. Additionally, Apollo maintains contractual relationships with vendors in order to provide the Service. Apollo relies on contractual agreements, privacy policies, and vendor compliance programs in order to assure the protection of data processed or stored by these vendors.
      2. Physical and environmental security. Apollo hosts its product infrastructure with multi-tenant, outsourced data center providers. The physical and environmental security controls are audited for SOC 2 Type II compliance.
      3. Authentication. Apollo implemented a uniform password policy for its customer products. Customers who interact with the products via the user interface must authenticate before accessing non-public customer data.
      4. Authorization. Customer data is stored in multi-tenant storage systems accessible to Customers via only application user interfaces and application programming interfaces. Customers are not allowed direct access to the underlying application infrastructure. The authorization model in each of Apollo’s products is designed to ensure that only the appropriately assigned individuals can access relevant features, views, and customization options. Authorization to data sets is performed through validating the user’s permissions against the attributes associated with each data set.
      5. Application Programming Interface (API) Access. Public product APIs may be accessed using an API key or through Oauth authorization.
    2. Preventing Unauthorized Product Use.
      1. Apollo implements industry-standard access controls and detection capabilities for the internal networks that support its products.
      2. Access controls: Network access control mechanisms are designed to prevent network traffic using unauthorized protocols from reaching the product infrastructure.
      3. Static code analysis: Security reviews of code stored in Apollo’s source code repositories are performed, checking for coding best practices and identifiable software flaws.
    3. Limitations of Privilege & Authorization Requirements.
      1. Product access: A subset of Apollo’s employees have access to the products and to customer data via controlled interfaces. The intent of providing access to a subset of employees is to provide effective customer support, troubleshoot potential problems, and detect and respond to security incidents. Access is enabled through “just in time” requests for access; all such requests are logged. Employees are granted access by role, and reviews of high-risk privilege grants are initiated daily. Employee roles are reviewed at least once every six months.
  2. TRANSMISSION CONTROL.

    1. In-transit. Apollo makes HTTPS encryption (also referred to as SSL or TLS) available on every one of its login interfaces and for free on every customer site hosted on the Apollo products. Apollo’s HTTPS implementation uses industry-standard algorithms and certificates.
    2. At-rest. Apollo encrypts Customer Personal Data at rest using industry-standard encryption algorithms, and manages encryption keys in accordance with industry-standard key-management practices. User passwords are stored using salted one-way hashing consistent with at least industry-standard practices for security.
  3. INPUT CONTROL.

    1. Detection. Apollo designed its infrastructure to log extensive information about the system behavior, traffic received, system authentication, and other application requests. Internal systems aggregate log data and alert appropriate employees of malicious, unintended, or anomalous activities. Apollo personnel, including security, operations, and support personnel, are responsive to known incidents.
    2. Response and Tracking. Apollo maintains a record of known security incidents that includes description, dates and times of relevant activities, and incident disposition. Suspected and confirmed security incidents are investigated by security, operations, or support personnel; and appropriate resolution steps are identified and documented. For any confirmed incidents, Apollo will take appropriate steps to minimize product and Customer damage or unauthorized disclosure.
    3. Communication. If Apollo becomes aware of unlawful access to Customer data stored within its products, Apollo will without undue delay: 1) notify the affected Customers of the incident; 2) provide a description of the steps Apollo is taking to resolve the incident; and 3) provide status updates to the Customer contact, as reasonably necessary. Notification(s) of incidents, if any, will be delivered to one or more of the Customer’s contacts in a form Apollo selects, which may include via email or telephone.
  4. JOB CONTROL.**

    1. The Apollo Product provides a solution for Customers to conduct their marketing and sales activities. Customers control the data types collected by and stored within their portals. Apollo never sells personal data to any third party.
    2. Terminating Customers. Customer Data in active (i.e., primary) databases are purged upon a customer’s written request, or for our web-based application available at https://www.apollo.io, 90 days after a customer terminates all agreements for such products with Apollo. Marketing information stored in backups, replicas, and snapshots is not automatically purged but instead ages out of the system as part of the data lifecycle; during that period such information remains subject to access controls, is not used for any active Processing, and is placed on a suppression list so that it is not re-collected, re-shared, or sold following a valid deletion or opt-out request, including any request received through DROP. Apollo reserves the right to alter the data purging period in order to address technical, compliance, or statutory requirements.
  5. AVAILABILITY CONTROL.

    1. Infrastructure availability. The data center providers use commercially reasonable efforts to ensure a minimum of 99.9% uptime. The providers maintain a minimum of N+1 redundancy to power, network, and HVAC services.
    2. Fault tolerance. Backup and replication strategies are designed to ensure redundancy and fail-over protections during a significant processing failure. Customer data is backed up to multiple durable data stores and replicated across multiple data centers and availability zones.
    3. Online replicas and backups. Where feasible, production databases are designed to replicate data between no less than 1 primary and 1 secondary database. All databases are backed up and maintained using at least industry-standard methods.
    4. Apollo’s products are designed to ensure redundancy and seamless failover. The server instances that support the products are also architected with a goal of preventing single points of failure. This design assists Apollo operations in maintaining and updating the product applications and backend while limiting downtime.
  6. SEPARATION IN PROCESSING. Apollo’s collection of personal data from its Customers is to provide and improve our products. Apollo does not use that data for other purposes that would require separate processing.