Effective date: August 15, 2026 Last updated: July 30, 2026 Version: 2.1

This Data Processing Agreement ("DPA") is entered into between Growth Leaps ("Processor" / "Needlz") and the Customer ("Controller") and forms part of the Terms & Conditions. It governs processing of personal data by Needlz on the Customer's behalf under Article 28 GDPR, equivalent UK GDPR provisions, Brazil's LGPD (Lei 13.709/2018), and comparable data protection laws in the territories where we offer the Platform.

1. Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given in the GDPR (Regulation (EU) 2016/679), UK GDPR, or LGPD as applicable. Under the LGPD, "Controller" corresponds to controlador and "Processor" to operador.

2. Roles

The Customer is Controller of personal data it inputs into or processes via the Platform. Needlz is Processor of such data, acting on the Customer's documented instructions.

Agency and multi-brand customers: where the Customer uses the Platform on behalf of clients, the Customer is Controller (or the client's processor, as their arrangement provides) for that client data, and Needlz is Processor. The Customer warrants it has the authority and lawful basis to submit that data and to instruct Needlz in respect of it.

Needlz acts as an independent Controller for its own account, billing, security, and service-improvement data, as described in the Privacy Policy.

3. Scope and Subject Matter

Item Detail
Subject matter Provision of the Needlz Platform services
Duration Subscription term plus any legally required retention
Nature of processing Storage, retrieval, analysis, AI model inference, measurement, report generation, display, deletion
Purpose AI visibility measurement, community engagement, AI content suggestions, outcome reporting
Categories of data User and account data; brand configuration data; measurement and engagement records; brand-voice samples; content submitted to the Platform; publicly available content analysed for measurement
Data subjects The Customer's personnel and authorised users; the Customer's clients' personnel where an agency uses the Platform; authors of publicly available content analysed for measurement

4. Needlz Obligations as Processor

  • Process personal data only on documented Controller instructions, unless required by law (and then, where permitted, with prior notice).
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures per GDPR Art. 32 and LGPD Art. 46 — encryption in transit and at rest, tenant isolation, least-privilege access, server-side enforcement of account boundaries, and regular security review.
  • Engage sub-processors only under the authorisation below, and impose equivalent obligations on them.
  • Assist the Controller with data subject requests and with security, breach notification, impact assessment, and prior consultation obligations.
  • At the Controller's choice, delete or return all personal data on termination (unless retention is legally required).
  • Make available information necessary to demonstrate compliance; allow and contribute to audits, no more than once per year absent a security incident or regulator requirement, on reasonable notice and subject to confidentiality.
  • Not sell personal data, and not use Controller personal data for its own purposes except as permitted in Section 4.1.

4.1 Service Improvement

Needlz may generate aggregated and de-identified information from processing (for example, statistics on which kinds of suggestion perform better) and use it to operate, secure, and improve the Service. Such information must not identify the Controller, any Managed Brand, any client, or any Data Subject, and must not be used to train models for the benefit of other customers using Controller content in identifiable form.

5. Sub-Processors

General authorisation is granted for the following categories. The current list of sub-processors is available on request to contact@needlz.ai:

  • Cloud infrastructure and storage (Google Cloud / Firebase — US-East region).
  • AI model providers used to generate AI Suggestions and to analyse answers.
  • Payment processing (Stripe, and any merchant-of-record or local payment provider appointed for a territory).
  • Search- and answer-measurement providers.
  • Messaging providers used to deliver WhatsApp and SMS messages.
  • Email delivery and analytics/monitoring tools.

Needlz will give at least 14 days' notice of intended sub-processor changes, with the opportunity to object on reasonable data-protection grounds. If an objection cannot be resolved, the Controller may terminate the affected service.

6. International Transfers

Needlz's infrastructure is hosted in the United States. Transfers of personal data are made under appropriate safeguards:

  • EEA / UK: EU Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum, incorporated by reference, with transfer risk assessments where required.
  • Brazil: the ANPD's standard contractual clauses under Resolution CD/ANPD No. 19/2024, incorporated by reference, or another lawful mechanism under LGPD Chapter V.
  • Other territories: the transfer mechanism required by the applicable national law.

7. Personal Data Breach Notification

Needlz will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a breach affecting the Controller's personal data, including (as then known): nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed. Needlz will cooperate with the Controller's own notification obligations to supervisory authorities and data subjects.

8. Governing Law

This DPA is governed by the same law as the Terms & Conditions — currently the District of Columbia, United States (see Terms & Conditions, Section 20.5) — except that where mandatory data protection law of the Controller's jurisdiction requires otherwise, that law applies to the data-protection obligations. Where this DPA conflicts with the Terms, this DPA prevails on data-protection matters only.


Version History

Version Date Summary
1.0 July 22, 2026 Initial DPA
2.0 August 15, 2026 Added agency/multi-brand controller-processor roles; LGPD controlador/operador mapping; expanded data categories (measurement, engagement, brand-voice, public content); service-improvement limits; audit frequency; sub-processor objection and termination right; Brazil transfers under ANPD Resolution 19/2024; mandatory-law carve-out in governing law
2.1 July 30, 2026 Reconciled with the Terms & Conditions as the reference generation: the governing law now defers to the single choice stated in the Terms rather than naming a jurisdiction independently; the sub-processor list is provided on request, and messaging providers were added to the authorised categories; internal cross-references now point at published routes