Skip to main content
reconosint.
How it worksSample profileCompareStakeOutPricing
Sign inStart free

Data Processing Addendum

Last updated: July 11, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between reconosint. (“reconosint,” “we,” “Processor”) and the customer entity that has entered into the reconosint Terms of Service(the “Customer,” “Controller”) for the use of the reconosint services (the “Service”). It governs the processing of Personal Data that reconosint carries out on the Customer’s behalf.

Note on execution. This page is the standard, self-serve version of our DPA. Enterprise customers who require a countersigned copy for their procurement or vendor files can request one at any stage of a deal — see Request a signed DPAbelow. A signed DPA does not change the substantive terms on this page; it adds the parties’ signatures and Customer entity details.

Note on counsel review.This document is in “v1” form pending attorney review (scheduled). If you have a specific legal question, please contact us at privacy@reconosint.ai before relying on any part of this document.

1. Subject matter

The subject matter of the processing is reconosint’s provision of the Service: AI-powered technology-stack and decision-maker research about target companies, produced for the Customer. In providing the Service, reconosint processes Personal Data on the Customer’s behalf as a Processor, and the Customer acts as the Controller.

2. Duration

Processing continues for the duration of the Customer’s subscription to the Service and until deletion of Personal Data in accordance with Section 10 (Return and deletion) and the retention periods described in our Privacy Policy.

3. Nature and purpose of processing

reconosint processes Personal Data to operate, maintain, and deliver the Service, including: authenticating account holders; generating and storing research profiles requested by the Customer; collecting publicly available information about target companies and their personnel via licensed data partners; sending transactional communications; billing; and detecting and preventing fraud and abuse. reconosint does not use Customer Personal Data or profiled-individual data to train third-party large-language models.

4. Types of Personal Data

  • Account holders (Customer users): name, business email address, company, plan tier, authentication identifiers, billing identifiers, usage data, and technical data (IP address, user agent, approximate location derived from IP).
  • Profiled individuals (third parties researched by the Customer): name, job title, employer, professional tenure, public profile photo and link, and publicly stated skills, tools, and experience excerpts — collected from publicly accessible web sources.

reconosint does not intentionally process special categories of Personal Data (as defined under the GDPR) and the Service is not designed for such data.

5. Categories of data subjects

  • The Customer’s authorized users of the Service.
  • Employees and representatives of target companies that the Customer chooses to research.

6. Sub-processors

The Customer authorizes reconosint to engage the sub-processors listed at /legal/subprocessors, each of whom is bound by a written agreement imposing data-protection obligations no less protective than those in this DPA. That page is the source of truth for our current sub-processors, their purpose, the data they process, and their region. We will update it before adding a material new sub-processor, and, where appropriate, notify affected Customers by email so they may object.

7. Cross-border transfer mechanism

reconosint and its sub-processors are located primarily in the United States. Where the Customer transfers Personal Data of individuals in the European Economic Area, the United Kingdom, or Switzerland to reconosint, such transfers are made pursuant to the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable), which are incorporated into this DPA by reference. reconosint will assist the Customer in implementing appropriate supplementary measures where required.

8. Security measures

reconosint maintains technical and organizational measures appropriate to the risk, including:

  • Encryption of Personal Data in transit (TLS) and at rest where supported by our sub-processors.
  • Row-level security on application data and least-privilege access controls.
  • Regular review of access permissions and authentication requirements for personnel.
  • Logging and application error monitoring to detect and respond to incidents.
  • A zero-retention configuration for AI inference performed by our model provider.

9. Personal data breach notification

reconosint will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Customer’s Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and will be updated as more information becomes available.

10. Audit rights, assistance, return and deletion

  • Audit: reconosint will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable prior notice and subject to confidentiality.
  • Assistance: taking into account the nature of the processing, reconosint will assist the Customer in responding to data-subject requests and in meeting its obligations regarding security, breach notification, and data-protection impact assessments.
  • Return and deletion: on termination of the Service, reconosint will delete or return Personal Data in accordance with the retention periods in our Privacy Policy, except where retention is required by applicable law.

11. Request a signed DPA

Need a countersigned copy for your procurement or vendor-risk files? Email privacy@reconosint.ai with your Customer legal entity name and signatory, and we will return an executed DPA. We can typically turn this around at any stage of a deal.

Request signed DPA

Related

Privacy Policy · Terms of Service · Sub-processors · Privacy Request

reconosint.
PrivacyTermsSecuritySub-processorsAccessibilityStatusContact
© 2026 reconosint. · AI-powered sales intelligence