Version 1.1, effective 14 September 2026.
This Data Processing Agreement (the "Agreement") supplements Emelia's Terms of Sale and governs the processing of personal data carried out by Bridgers SAS on behalf of its Customers, within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR").
It is entered into between:
Bridgers SAS, a French simplified joint stock company with share capital of EUR 1,000, registered with the Paris Trade and Companies Register under number 882 679 749, with its registered office at 149 avenue du Maine, 75014 Paris, France, publisher of the Emelia service, hereinafter the "Processor" or "Emelia",
and
the Customer, the natural or legal person holding an Emelia account, hereinafter the "Controller".
1WHY THIS DOCUMENT EXISTS, AND WHAT IT ADDS TO THE PRIVACY POLICY
Emelia processes two distinct sets of data, under two different legal capacities. Confusing the two is the single most common misunderstanding, so it is settled here.
Customer account data. Name, email address, billing information, connection logs, service usage. For this data Emelia acts as a controller: it determines the purposes and means of the processing. That processing is described in the privacy policy, and this Agreement does not cover it.
The data the Customer uploads, imports, enriches or has processed within Emelia, that is, the data of its prospects and recipients. For this data Emelia acts as a processor: it processes it only on the Customer's instructions, and the Customer remains solely responsible for it. That is the subject of this Agreement. This data is referred to below as "Customer Data".
The case of email and phone lookups. When the Customer asks the service to find a person's email address or phone number, the query comes from them, it is passed to the lookup providers listed in Annex 3, and the result is returned to that Customer alone and attached to their account. Emelia neither builds nor operates a contact database of its own: it does not publish the sources queried, and one Customer's lookups are never used to answer another's. Each lookup provider's role in relation to its own sources is governed by its own contractual framework, stated in Annex 3.
In accordance with Article 28(10) GDPR, if Emelia were to determine the purposes and means of a processing operation itself, it would be considered the controller of that processing, which would then fall outside this Agreement. That is already the case for the account data mentioned above.
A privacy policy cannot serve as a data processing agreement: it documents processing for which the publisher is the controller, whereas Article 28 requires a contract governing processing carried out on someone else's behalf. This document is that contract.
2ACCEPTANCE AND FORM
This Agreement is incorporated by reference into the Terms of Sale and applies automatically to any Customer as soon as they load Customer Data into the service. No signature is required for it to take effect.
A Customer who needs a signed copy for their own record of processing activities or for their legal department may request one at contact@emelia.io: Emelia will send it signed, with no change to the content below.
Emelia may amend this Agreement to reflect a change in the law or a change among its own sub-processors. Any material amendment is notified directly to the Customer by email at least thirty days before it takes effect, and does not take effect as against a Customer who objects in writing within that period on data protection grounds; the parties then seek a solution, failing which the Customer may terminate without penalty. Publishing a new version on this page does not, on its own, constitute notification.
Each version is dated and archived. Emelia keeps a record of the version applicable to each Customer.
3DESCRIPTION OF THE PROCESSING
As required by Article 28(3) GDPR, the processing is described as follows.
Subject matter. The provision of the Emelia service: hosting contact lists, finding and verifying email addresses, finding phone numbers, sending email sequences from the Customer's own mailboxes, performing LinkedIn actions from the Customer's own accounts, and tracking opens, clicks, replies and unsubscribes.
Duration. The processing lasts as long as the Customer's account is active, extended by the deletion periods set out in Article 12.
Nature and purpose. Collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure by transmission, alignment and erasure, for the sole purpose of enabling the Customer to run its own outbound sales campaigns.
Categories of data subjects. The prospects and recipients targeted by the Customer, and the individuals whose business contact details appear in the lists the Customer imports or builds.
Categories of data. Identity and business contact details: first name, last name, business email address, phone number, job title, seniority, company, industry, size, website, address, city, country, LinkedIn profile URL. Content of messages sent and replies received. Engagement data: opens, clicks, replies, bounces, unsubscribes, invitation acceptances. Any custom variable the Customer chooses to add to its lists.
Sensitive data. The service is not designed to process special categories of data within the meaning of Article 9 GDPR, nor data relating to criminal convictions. The Customer undertakes not to load any such data into the service.
4EMELIA'S OBLIGATIONS
Emelia undertakes, in accordance with Article 28(3) points (a) to (h) GDPR:
(a) To process Customer Data only on the Customer's documented instructions. The Customer's instructions consist of this Agreement, the Terms of Sale, and the Customer's use of the features of the service. If Emelia considers that an instruction infringes the GDPR or another Union or Member State data protection provision, it shall immediately inform the Customer. Where a legal obligation requires Emelia to carry out processing not covered by those instructions, it shall inform the Customer before processing, unless the applicable law prohibits that information on important grounds of public interest.
(b) To ensure that persons authorised to process Customer Data are bound by confidentiality. Emelia's employees and contractors with access to Customer Data are subject to a contractual confidentiality obligation that survives the end of their relationship with Emelia, and are granted access only to the extent their duties require.
(c) To implement the technical and organisational measures required by Article 32. Those measures are described in Annex 2, together with the conditions under which they may change.
(d) To engage sub-processors only on the conditions set out in Article 6 below.
(e) To assist the Customer in responding to data subject rights requests. The service allows the Customer to access, export, rectify and delete its lists directly, which covers most requests. Where a request goes beyond those features, Emelia provides the necessary assistance within timeframes compatible with the one month Article 12(3) GDPR allows the Customer to reply. Where a data subject contacts Emelia directly, Emelia tells them it is not the controller and forwards the request to the Customer without delay, without answering it itself.
(f) To assist the Customer in complying with its obligations under Articles 32 to 36, namely security of processing, notification of breaches, communication to data subjects, data protection impact assessments and prior consultation of the supervisory authority, taking into account the nature of the processing and the information available to Emelia.
(g) To delete or return Customer Data at the end of the provision of services, at the Customer's choice, on the conditions set out in Article 12.
(h) To make available to the Customer all information necessary to demonstrate compliance with this Article, and to allow for audits on the conditions set out in Article 11.
(i) To maintain the record required by Article 30(2) GDPR, listing the categories of processing activities carried out on behalf of its Customers, and to make it available to the supervisory authority on request. An extract relating to the Customer's processing is provided to them on written request.
5WHAT EMELIA DOES NOT DO WITH CUSTOMER DATA
The instruction-only obligation in Article 4(a) has the following consequences. They are spelled out here because these are the questions Customers ask most often.
- Emelia does not use Customer Data for its own commercial purposes. It does not sell it, does not rent it, and does not disclose it to anyone outside the sub-processors listed in Annex 3.
- Emelia does not feed any prospect database of its own with the lists its Customers import or the results of their lookups, and one Customer's personal data is never made accessible to another. Emelia does keep a technical cache of public company information, which contains no personal data and avoids querying the same source twice.
- Emelia does not train any artificial intelligence model on Customer Data, and imposes the same prohibition on the provider named in Annex 3.
- Aggregate measurements produced by the service, which identify neither a person nor a Customer, may be used to monitor and improve the service. They are no longer personal data.
This Article concerns Customer Data, that is, what the Customer loads into the service and has processed there. It says nothing about the account data itself: the person who opens an Emelia account is of course in Emelia's own records, for which Emelia is then the controller, as Article 1 explains and the privacy policy details. The two are not the same thing.
6SUB-PROCESSORS
The Customer gives Emelia general authorisation to engage sub-processors for the performance of the service, within the meaning of Article 28(2) GDPR.
The current list of sub-processors is set out in Annex 3 and kept up to date on this page.
Emelia informs the Customer of any addition or replacement of a sub-processor at least thirty days before that sub-processor accesses Customer Data, by email to the account address. The Customer has that period to object, in writing and on reasonable data protection grounds. If the Customer objects, the parties shall seek an alternative solution in good faith; failing that, the Customer may terminate its subscription without penalty and be refunded the unused portion of the period paid for.
Emelia contractually imposes on each sub-processor data protection obligations equivalent to those of this Agreement. In accordance with Article 28(4), Emelia remains fully liable to the Customer for the performance of the sub-processor's obligations.
7TRANSFERS OUTSIDE THE EUROPEAN UNION
Customer Data is hosted in the European Union, in France (AWS eu-west-3 region, Paris).
Annex 3 states, for each sub-processor, its country of establishment and the safeguard governing the transfer where there is one. Two of them are established in the United States.
Where the provider is established in the United States and listed under the EU-US Data Privacy Framework for the relevant category of data, the transfer relies on the European Commission's adequacy decision of 10 July 2023. Emelia verifies that the provider is effectively listed and the scope of that listing.
Absent a valid listing, the transfer relies on the standard contractual clauses of Implementing Decision (EU) 2021/914, module 3 (processor to processor), supplemented by a transfer impact assessment.
If a provider's Data Privacy Framework listing becomes inactive, or if an adequacy decision is invalidated, Emelia switches without delay to the standard contractual clauses for the transfer concerned, or stops using that provider.
The Customer may obtain a copy of the safeguards in place for a given transfer by writing to contact@emelia.io.
8PERSONAL DATA BREACHES
In accordance with Article 33(2) GDPR, Emelia notifies the Customer of any personal data breach affecting Customer Data without undue delay and no later than forty-eight hours after becoming aware of it.
The notification is sent by email to the account address and includes, to the extent the information is available at the time of sending: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and Emelia's point of contact. Missing information is provided as it becomes available, and gathering it does not delay the initial notification.
It is for the Customer, as controller, to decide whether the supervisory authority must be notified and the data subjects informed, and to carry out that notification. Emelia does not notify the authority in the Customer's place.
9AUTHORITY ACCESS REQUESTS
If a public, administrative or judicial authority sends Emelia a binding request for access to Customer Data, Emelia:
- informs the Customer without delay, so that they can exercise their own rights, unless applicable law prohibits it;
- where such a prohibition exists, seeks to have it lifted and endeavours to obtain the right to share as much information with the Customer as possible, as quickly as possible, keeping a documented record of its efforts;
- challenges the request where it appears unlawful under applicable law, including by using the available remedies, and seeks suspension of its effects pending the proceedings;
- discloses only the minimum strictly required, on a reasonable interpretation of the request.
Emelia is a French company, established in the European Union, and is not subject to third-country legislation requiring it to hand data to that country's authorities.
10OBLIGATIONS AND RIGHTS OF THE CUSTOMER
The Customer warrants, as controller:
- That it has a valid legal basis for processing the Customer Data, and can demonstrate it. In business-to-business outbound sales, that basis is most often legitimate interest, which assumes the message sent relates to the recipient's professional role.
- That it informs data subjects as required by Article 14 GDPR where the data was not obtained from them, which is the case in outbound prospecting, giving them the identity of the controller, the purposes, the legal basis, the source of the data and their rights.
- That it provides in every message a simple and free means of objecting, and acts on it. Emelia provides an unsubscribe variable and a blocklist for that purpose, but cannot decide their use in the Customer's place.
- That the instructions it gives Emelia are lawful, and that it loads no data into the service that it has no right to process.
- That it maintains its own record of processing activities and, where applicable, the impact assessment provided for in Article 35.
Emelia does not verify the lawfulness of the lists the Customer imports and has no means of doing so: it has no knowledge of how the data was collected.
In return, the Customer has the following rights, exercisable at any time: to give and change its instructions within the limits of the service, to access and export its data, to obtain its rectification or deletion, to object to a new sub-processor on the conditions set out in Article 6, to carry out an audit on the conditions set out in Article 11, to obtain a copy of the safeguards governing a transfer, and to decide what happens to its data at the end of the contract.
11AUDIT AND DEMONSTRATION OF COMPLIANCE
On written request, Emelia makes available to the Customer the information necessary to demonstrate compliance with this Agreement: a description of the security measures, the current list of sub-processors, the location of the data, and the safeguards governing transfers.
The Customer may carry out an audit, itself or through an independent auditor bound by confidentiality and not a competitor of Emelia, once in any twelve-month period, on thirty days' written notice, during business hours and without disproportionate disruption to Emelia's operations. An additional audit may be carried out following a personal data breach affecting the Customer or a reasoned request from a supervisory authority.
The cost of the audit is borne by the Customer, unless the audit reveals a material failure by Emelia to comply with this Agreement, in which case Emelia bears it.
12WHAT HAPPENS TO THE DATA WHEN THE CONTRACT ENDS
On termination, the Customer may export its data from its account for as long as it retains access.
At the Customer's written choice, expressed within thirty days of the end of the contract, Emelia returns the Customer Data in a structured, commonly used format, or deletes it. Absent a choice within that period, Emelia deletes it.
Deletion takes place within thirty days of the end of the contract or of the Customer's request for production systems, and within ninety days for backups, which are overwritten on rotation rather than erased individually.
On written request, Emelia provides the Customer with a written deletion certificate stating the scopes deleted and the date of execution.
Emelia may retain Customer Data beyond those periods only to the extent Union or Member State law requires, and only for the duration of that obligation. Billing data, for which Emelia is the controller, is retained in accordance with applicable accounting and tax obligations.
13LIABILITY
Each party's liability under this Agreement is governed by the Terms of Sale, without prejudice to the mandatory provisions of Article 82 GDPR on data subjects' right to compensation.
14PRECEDENCE, SURVIVAL AND SEVERABILITY
In the event of a conflict between this Agreement and the Terms of Sale or any other contractual document binding the parties, including one entered into later, this Agreement prevails in everything concerning the processing of Customer Data. For the rest, the Terms of Sale continue to apply.
Obligations which by their nature must survive the end of the contract do so: confidentiality, security, deletion or return of the data and its certification, and cooperation on a breach relating to an earlier period.
If any provision of this Agreement is held void or unenforceable, the others remain in force, and the parties shall replace it with a valid provision pursuing the same object.
15GOVERNING LAW AND JURISDICTION
This Agreement is governed by French law. The courts of Paris have jurisdiction, subject to the mandatory rules of jurisdiction applicable to consumers and to the powers vested in supervisory authorities.
16CONTACT
For any question about this Agreement, the exercise of rights, an audit or a request for a signed copy: contact@emelia.io, or by post to Bridgers SAS, 149 avenue du Maine, 75014 Paris, France.
17ANNEX 1: PROCESSING AT A GLANCE
| Item | Content |
|---|---|
| Controller | The Customer |
| Processor | Bridgers SAS (Emelia) |
| Subject matter | Provision of the Emelia multichannel outbound service |
| Duration | The term of the subscription, extended by the deletion periods in Article 12 |
| Nature | Hosting, enrichment, sending, tracking of interactions |
| Purpose | Enabling the Customer to run its own outbound campaigns |
| Data subjects | Prospects and recipients targeted by the Customer |
| Categories of data | Business contact details, message content, engagement data, custom variables |
| Special categories | None. Loading them is contractually prohibited |
| Location | European Union, France (AWS eu-west-3, Paris) |
18ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES
Measures implemented by Emelia under Article 32 GDPR.
Encryption and transport. Exchanges between the Customer and the service, and between the components of the service, are encrypted in transit with TLS. Data at rest is encrypted at the storage layer managed by the hosting provider.
Access control. Access to production systems is individually named, restricted to people whose duties require it, and revoked on departure. Application secrets and API keys are stored outside the source code. The Customer's API keys can be revoked at any time from the account.
Segregation. Each Customer's data is tied to their account and application access is filtered on that identifier. Production and development environments are separate.
Logging. Access to production systems and administrative actions are logged and retained.
Backups. Databases are backed up automatically by the hosting provider, with retention allowing restoration to an earlier point in time.
Development. Code is version controlled and every change is tracked and attributed to its author. Changes are delivered through merge requests, and those affecting the processing of Customer Data are reviewed before deployment.
Hosting security. Emelia relies on the physical and environmental measures of its hosting provider AWS, whose certifications (ISO/IEC 27001, SOC 2) are public and cover the eu-west-3 region.
Personnel. People with access to Customer Data are bound by confidentiality and trained in data protection.
Incident management. Emelia maintains a procedure for qualifying and handling security incidents, including the notification provided for in Article 8 of this Agreement.
Review. These measures are reviewed periodically and following any significant security incident.
They may evolve with the state of the art. Emelia will not implement any change that reduces the overall level of security without informing the Customer beforehand, who may object on the conditions set out in Article 2.
19ANNEX 3: SUB-PROCESSORS
Sub-processors that may process Customer Data, as at the date of this version. The legal entities below are the ones that contract with Emelia; several differ from the trading name of the service.
| Provider | Legal entity | Role | Establishment | Transfer outside the EU and safeguard |
|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services EMEA SARL | Hosting, storage, database | Luxembourg | No. Processing in the Paris region (eu-west-3) |
| Unipile | Unipile SAS, SIREN 885 265 595 | Connecting the Customer's LinkedIn accounts and performing LinkedIn actions | France | No |
| Enrow | Schrute Farms SARL, SIREN 981 316 300 | Email address finding and verification | France | No. Hosting declared within the European Union |
| Icypeas | Vloum SAS, SIREN 919 561 266 | Email address finding | France | No. Hosting declared in France |
| Piloterr | WebAPI Group SAS, Toulouse register 984 275 917 | Retrieval of public company and profile information | France | No |
| PostHog | PostHog, Inc. | Product usage measurement and session replay, which may capture screens displaying Customer Data | United States | European instance, data hosted in Germany. Provider certified under the EU-US Data Privacy Framework, certification active |
| Anthropic | Anthropic Ireland, Limited, Dublin | AI message generation, only if the Customer uses that feature | Ireland | Contract entered into with the Irish entity. The provider is not certified under the EU-US Data Privacy Framework: processing carried out in the United States is governed by the standard contractual clauses, modules 2 and 3, incorporated into its data processing addendum |
| Webshare | Webshare Software | Proxy provision for LinkedIn actions | United States | Yes. Provider not certified under the EU-US Data Privacy Framework: transfer governed by the standard contractual clauses |
On the message generation feature. It is called only when the Customer triggers it. The provider contractually undertakes not to train its models on the content submitted, and states that inputs and outputs are deleted within thirty days for its standard interface and twenty-nine days for its batch interface. A Customer who does not want its prospect data sent to that provider simply does not use the feature.
On session replay. The usage measurement tool records browsing sessions inside the application, which may include screens displaying Customer Data. Password fields are masked.
Providers that process only the Customer's account data, and not Customer Data, fall outside this Agreement: they are listed in the privacy policy. This is the case for the payment provider and the support tool.
20VERSION HISTORY
| Version | Date | Changes |
|---|---|---|
| 1.1 | 14 September 2026 | Added the qualification of email and phone lookups, the article on what we do not do with the data, authority access requests, the Article 30(2) record, the deletion certificate, the precedence clause and this history |
| 1.0 | 14 September 2026 | First publication |