Last updated: June 2026
This Data Processing Agreement ("DPA") is entered into between Go2MarketCo ("Processor," "we," "us") and the entity or individual that has agreed to our Terms of Service ("Controller," "you"). This DPA supplements and forms part of our Terms of Service and sets out the terms under which we process personal data on your behalf.
This DPA governs the processing of Personal Data by the Processor on behalf of the Controller through the Controller's use of the AMP-MAP platform.
The Processor processes Personal Data for the purpose of providing the Service, including:
The Personal Data processed may include: names, email addresses, phone numbers, job titles, company names, physical addresses, IP addresses, engagement data (email opens, clicks), and any custom fields created by the Controller.
Data Subjects include the Controller's contacts, leads, customers, prospects, business partners, and any individuals whose data is uploaded or collected via the Service.
Processing continues for the duration of the Controller's subscription and for a reasonable period thereafter to fulfill data retention obligations as described in our Privacy Policy.
The Processor shall:
The Processor shall ensure that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory.
The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
The Controller provides general authorization for the Processor to engage the Sub-processors listed below to assist in providing the Service. A current list is also maintained at /legal/subprocessors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud infrastructure & hosting provider | Application hosting, compute, and database storage | United States / EU |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Twilio Inc. | SMS and messaging delivery | United States |
| Email delivery provider (SMTP) | Transactional and marketing email delivery | United States / EU |
| Salesforce, Inc. | CRM integration sync (only if connected by the customer) | United States |
| HubSpot, Inc. | CRM integration sync (only if connected by the customer) | United States |
| Google LLC | SSO, Calendar, and Google Ads integrations (only if connected) | United States |
| Microsoft Corporation | SSO and Calendar integrations (only if connected) | United States |
| Clay / data-enrichment provider | Contact and company data enrichment (only if enabled) | United States |
The Processor shall notify the Controller at least 30 days in advance before engaging a new Sub-processor. The Controller may object to a new Sub-processor by notifying the Processor within 14 days of receiving notice. If the Controller objects and the Processor cannot reasonably accommodate the objection, either party may terminate the affected portion of the Service.
The Processor shall ensure that each Sub-processor is bound by data protection obligations no less protective than those in this DPA. The Processor remains fully liable for the acts and omissions of its Sub-processors.
The Processor shall assist the Controller in responding to Data Subject requests to exercise their rights under Applicable Data Protection Laws, including requests for access, rectification, erasure, portability, restriction, and objection.
The Service provides built-in tools for the Controller to fulfill Data Subject requests, including:
Without prejudice to Section 3.3, the Processor shall:
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Data Breach affecting the Controller's Personal Data.
The notification shall include, to the extent available:
The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.
The Controller may export its data at any time using the Service's built-in export features.
Upon termination of the subscription, the Processor shall:
The Controller may audit the Processor's compliance with this DPA, subject to the following conditions:
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Processor may satisfy audit requests by providing relevant third-party audit reports or certifications.
Where Personal Data is transferred to countries outside the EEA that have not been deemed to provide an adequate level of data protection, the Processor shall ensure that appropriate safeguards are in place, including:
The Processor shall conduct transfer impact assessments as required under Applicable Data Protection Laws and make summaries available to the Controller upon request.
This DPA is effective from the date the Controller accepts the Terms of Service and shall continue until the end of the Processor's processing of Personal Data. The obligations under this DPA shall survive termination to the extent necessary to fulfill post-termination obligations.
For questions about this DPA, contact us: