This Data Processing Agreement (the "DPA") sets out the terms under which Individual Entrepreneur Evgenii Salamatov processes personal data on behalf of the customers of gtm-api.com, an MCP-first GTM API that lets AI agents run LinkedIn automation, email outreach, and data enrichment through a single unified interface, with built-in per-account sending safety limits and observability. This DPA forms part of, and is governed by, the gtm-api.com Terms of Service between you (the "Customer") and Individual Entrepreneur Evgenii Salamatov (the "Provider", "we", or "us").
Effective date: 2026-06-22
gtm-api.com and Individual Entrepreneur Evgenii Salamatov operate independently of LinkedIn Corporation, with no partnership or endorsement between them. Where this DPA refers to LinkedIn, it does so only to describe how Customers use that platform through the Service, and implies no relationship with LinkedIn Corporation. LinkedIn is a trademark of its owner.
1. Parties and roles
For the personal data that the Customer targets, transmits, or otherwise puts through the gtm-api.com platform, that is, the B2B prospect and contact data the Customer chooses to act on, the Customer is the controller and Individual Entrepreneur Evgenii Salamatov is the processor. The Customer decides whose data is collected, why, on what lawful basis, and what messages are sent; we act only to execute those instructions on the Customer's behalf.
Separately, Individual Entrepreneur Evgenii Salamatov acts as an independent controller for the account-level data it collects to run the service (account identity, API keys, billing data, usage and server logs, support correspondence, and cookies). That controller-side processing is governed by our Privacy Policy, not by this DPA.
Provider details: Individual Entrepreneur Evgenii Salamatov, identification number 324080203, country of Georgia. Registered office: Abi (down the lake), Akhaltsikhe District, Georgia.
As an individual entrepreneur established in Georgia, Individual Entrepreneur Evgenii Salamatov is not required under the GDPR to appoint a Data Protection Officer and has not appointed one; data-protection queries may be directed to the contact in Section 10.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" carry the meanings given to them in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). "Data Protection Laws" means the GDPR, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and any other privacy or data protection law applicable to the processing. "SCCs" means the Standard Contractual Clauses adopted by the European Commission on 4 June 2021. "UK IDTA" means the UK International Data Transfer Addendum to the SCCs.
3. Subject matter, duration, nature and purpose
Subject matter. Processing of personal data necessary to provide the gtm-api.com service to the Customer.
Duration. Processing continues for as long as the Customer's account is active and the Customer uses the service, plus any short retention or deletion windows described in Section 9.
Nature and purpose. We collect, store, structure, transmit, and act on prospect and contact data so that the Customer's AI agents and workflows can run multichannel B2B outbound, sending LinkedIn connection requests and messages, dispatching email outreach, enriching records, and observing delivery and safety metrics, all strictly to deliver the service the Customer has configured. We do not use prospect or contact data for our own independent purposes, and we do not train machine-learning models on Customer prospect data.
4. Categories of data subjects and personal data
Data subjects: the Customer's prospects and business contacts, typically employees, decision-makers, and other professionals at the organizations the Customer targets.
Categories of personal data: names, job titles, employer and company details, public LinkedIn profile URLs, business email addresses, and the content of outreach messages and replies. The Customer must not submit special-category data (Article 9 GDPR) through the service, and is responsible for the contents of any free-text message fields it configures.
5. Processor obligations
5.1 Documented instructions
We process Customer personal data only on the Customer's documented instructions, including the instructions embodied in this DPA, in the Terms of Service, and in the configuration choices the Customer makes through the API and dashboard. We will tell the Customer if we believe an instruction infringes Data Protection Laws, and we will not transfer data outside the configured scope unless required by law, in which case we will notify the Customer first unless the law prohibits it.
5.2 Confidentiality
Anyone we authorize to process Customer personal data is bound by an appropriate duty of confidentiality and is granted access only on a need-to-know basis.
5.3 Security (Article 32)
We implement and maintain the technical and organizational measures described in Annex II, appropriate to the risk presented by the processing.
5.4 Sub-processing
The Customer grants a general authorization for us to engage sub-processors to help deliver the service. The current sub-processors are listed in Annex III. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to the Customer for their performance. We will give the Customer advance notice of any intended addition or replacement of a sub-processor, by updating Annex III and/or notifying the account contact, so the Customer has a reasonable opportunity to object on legitimate data protection grounds before the new sub-processor begins processing.
5.5 Assisting with data-subject requests
Taking into account the nature of the processing, we will assist the Customer, by appropriate technical and organizational measures, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts us directly about data we process for a Customer, we will refer them to the Customer.
5.6 Assisting with Articles 32-36
We will provide reasonable assistance to the Customer with security obligations, personal data breach notifications, data protection impact assessments, and prior consultations with supervisory authorities, taking into account the information available to us.
5.7 Audits and information
We will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits must be scheduled with reasonable advance notice, conducted during business hours, no more than once per year (unless required by a supervisory authority or following a breach), and must not unreasonably disrupt our operations or compromise the confidentiality of other customers. Where available, we may satisfy audit requests by providing existing third-party audit reports or penetration-testing summaries.
6. Customer obligations and acceptable use
As controller of the prospect data it acts on, the Customer is responsible for:
- Establishing a valid lawful basis for collecting and contacting each prospect, and for providing any required notices to data subjects.
- Configuring outreach volumes and automation responsibly. Our built-in per-account safety limits reduce risk but do not guarantee that a LinkedIn account or mailbox will avoid restriction, throttling, or a ban; the Customer remains responsible for managing its sending volume and conduct.
- Using the service in compliance with the terms of any third-party platform it operates through, including the LinkedIn User Agreement and Professional Community Policies and any email provider terms. Automating activity on third-party platforms carries inherent risk that the Customer accepts. We are not liable for account restrictions, blocks, bans, deliverability failures, or for changes or interruptions in third-party platforms.
- Not using the service to violate any third-party platform's terms of service, to bypass authentication or billing controls, to reverse-engineer or probe the platform's infrastructure, or to misrepresent ownership of infrastructure.
- Ensuring the accuracy of, and lawful basis for, the prospect data it submits, and validating enriched data before relying on it; enrichment results depend on external sources, provider updates, and rate limits and are provided without warranty of accuracy.
We do not store LinkedIn account passwords as part of the unified API. Where the service maintains an authenticated session, each account is isolated within its own environment.
7. International transfers
Where we transfer Customer personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference. Module Two (controller-to-processor) applies between the Customer and us; Module Three (processor-to-processor) applies between us and our sub-processors. For transfers subject to the UK GDPR, the UK IDTA supplements the SCCs. Where the SCCs require a choice, the data importer's identity and contact details are those of the relevant party in this DPA and Annex III, the optional docking clause applies, and the governing law and dispute forum follow Section 10 except where the SCCs mandate an EU Member State.
8. Personal data breach notification
If we become aware of a personal data breach affecting Customer personal data, we will notify the Customer without undue delay and provide the information reasonably available to us, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed, so the Customer can meet its own notification obligations. We will cooperate with the Customer to investigate and remediate.
9. Return and deletion
On termination or expiry of the service, the Customer may export its data through the available interfaces. We will delete or return Customer personal data within thirty (30) days of the account being closed, except where applicable law requires us to retain it. Residual copies held in backups are deleted in the ordinary course of our backup rotation and remain protected by this DPA until then.
10. Governing law and how this DPA is accepted
This DPA is incorporated into the gtm-api.com Terms of Service by reference and is accepted when the Customer accepts those Terms or uses the service. Except where the SCCs require otherwise, this DPA is governed by the laws of the country of Georgia, and the courts of Georgia have jurisdiction. Before commencing litigation, the parties will attempt to resolve any dispute amicably for a period of sixty (60) days. Questions may be directed to [email protected] or [email protected].
Annex I, Details of processing
| Item | Detail |
|---|---|
| Controller | The Customer (the gtm-api.com account holder) |
| Processor | Individual Entrepreneur Evgenii Salamatov, ID no. 324080203, country of Georgia |
| Subject matter | Provision of the gtm-api.com MCP-first GTM API |
| Duration | For the term of the service, plus the deletion window in Section 9 |
| Nature and purpose | Storing, transmitting, and acting on prospect/contact data to run LinkedIn automation, email outreach, enrichment, and multichannel B2B outbound configured by the Customer |
| Categories of data subjects | The Customer's B2B prospects and business contacts |
| Categories of personal data | Names, job titles, employer/company, public LinkedIn profile URLs, business email addresses, message content and replies |
| Special-category data | None permitted |
| Frequency | Continuous, for the duration of the service |
Annex II, Technical and organizational measures
We maintain measures appropriate to the risk, including:
- Encryption. Data encrypted in transit (TLS) and at rest.
- Access control. Role-based access on a need-to-know basis, unique credentials, and least-privilege administration; API access authenticated by per-account API keys.
- Account isolation. Per-account isolation of authenticated sessions and processing environments.
- Network protection. CDN, web application firewall, and DNS protection at the edge.
- Monitoring and logging. Centralized observability, logging, and tracing to detect and investigate anomalies, with built-in per-account sending safety limits.
- Resilience. Regular backups and recovery procedures.
- Organizational measures. Confidentiality obligations for personnel, change management, and a documented incident-response process.
- Vendor management. Data protection terms imposed on all sub-processors.
These measures may be updated over time, provided the level of protection is not materially reduced.
Annex III, Approved sub-processors
As of 2026-06-22, and subject to change in accordance with Section 5.4, we engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, web application firewall, DNS | United States |
| DigitalOcean LLC | Cloud hosting | United States |
| Hetzner Online GmbH | Cloud hosting | Germany |
| Paddle.com Market Ltd | Payments / merchant of record | United Kingdom |
| Twilio Inc., SendGrid | Transactional email delivery | United States |
| Grafana Labs | Observability, logs and traces | United States |
The analytics, advertising, and marketing providers listed in our Privacy Policy, including Google, Meta, Amplitude, and Encharge, process Customer account and website-visitor data as described there. They do not process the Customer prospect data covered by this DPA and are therefore not listed as sub-processors above.
An up-to-date list is available on request from [email protected]. For general support, contact [email protected].