AMP‑MAP

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement ("DPA") is entered into between Go2MarketCo ("Processor," "we," "us") and the entity or individual that has agreed to our Terms of Service ("Controller," "you"). This DPA supplements and forms part of our Terms of Service and sets out the terms under which we process personal data on your behalf.

1. Definitions

2. Scope and Purpose

2.1 Subject Matter

This DPA governs the processing of Personal Data by the Processor on behalf of the Controller through the Controller's use of the AMP-MAP platform.

2.2 Nature and Purpose of Processing

The Processor processes Personal Data for the purpose of providing the Service, including:

2.3 Types of Personal Data

The Personal Data processed may include: names, email addresses, phone numbers, job titles, company names, physical addresses, IP addresses, engagement data (email opens, clicks), and any custom fields created by the Controller.

2.4 Categories of Data Subjects

Data Subjects include the Controller's contacts, leads, customers, prospects, business partners, and any individuals whose data is uploaded or collected via the Service.

2.5 Duration

Processing continues for the duration of the Controller's subscription and for a reasonable period thereafter to fulfill data retention obligations as described in our Privacy Policy.

3. Obligations of the Processor

3.1 Lawful Processing

The Processor shall:

3.2 Confidentiality

The Processor shall ensure that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory.

3.3 Technical and Organizational Measures

The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

4. Sub-processors

4.1 Authorization

The Controller provides general authorization for the Processor to engage the Sub-processors listed below to assist in providing the Service. A current list is also maintained at /legal/subprocessors.

Sub-processorPurposeLocation
Cloud infrastructure & hosting providerApplication hosting, compute, and database storageUnited States / EU
Stripe, Inc.Payment processing and subscription billingUnited States
Twilio Inc.SMS and messaging deliveryUnited States
Email delivery provider (SMTP)Transactional and marketing email deliveryUnited States / EU
Salesforce, Inc.CRM integration sync (only if connected by the customer)United States
HubSpot, Inc.CRM integration sync (only if connected by the customer)United States
Google LLCSSO, Calendar, and Google Ads integrations (only if connected)United States
Microsoft CorporationSSO and Calendar integrations (only if connected)United States
Clay / data-enrichment providerContact and company data enrichment (only if enabled)United States

4.2 Notification of Changes

The Processor shall notify the Controller at least 30 days in advance before engaging a new Sub-processor. The Controller may object to a new Sub-processor by notifying the Processor within 14 days of receiving notice. If the Controller objects and the Processor cannot reasonably accommodate the objection, either party may terminate the affected portion of the Service.

4.3 Sub-processor Obligations

The Processor shall ensure that each Sub-processor is bound by data protection obligations no less protective than those in this DPA. The Processor remains fully liable for the acts and omissions of its Sub-processors.

5. Data Subject Rights

5.1 Assistance

The Processor shall assist the Controller in responding to Data Subject requests to exercise their rights under Applicable Data Protection Laws, including requests for access, rectification, erasure, portability, restriction, and objection.

5.2 Self-Service Tools

The Service provides built-in tools for the Controller to fulfill Data Subject requests, including:

6. Security Measures

Without prejudice to Section 3.3, the Processor shall:

7. Data Breach Notification

7.1 Notification Timing

The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Data Breach affecting the Controller's Personal Data.

7.2 Notification Content

The notification shall include, to the extent available:

7.3 Cooperation

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.

8. Data Return and Deletion

8.1 During the Subscription

The Controller may export its data at any time using the Service's built-in export features.

8.2 Upon Termination

Upon termination of the subscription, the Processor shall:

9. Audits

9.1 Audit Rights

The Controller may audit the Processor's compliance with this DPA, subject to the following conditions:

9.2 Audit Reports

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Processor may satisfy audit requests by providing relevant third-party audit reports or certifications.

10. International Data Transfers

10.1 Transfer Mechanisms

Where Personal Data is transferred to countries outside the EEA that have not been deemed to provide an adequate level of data protection, the Processor shall ensure that appropriate safeguards are in place, including:

10.2 Transfer Impact Assessments

The Processor shall conduct transfer impact assessments as required under Applicable Data Protection Laws and make summaries available to the Controller upon request.

11. Term and Termination

This DPA is effective from the date the Controller accepts the Terms of Service and shall continue until the end of the Processor's processing of Personal Data. The obligations under this DPA shall survive termination to the extent necessary to fulfill post-termination obligations.

12. Contact

For questions about this DPA, contact us: