Data Processing Addendum

Last updated 13 July 2026

About this addendum

This Data Processing Addendum (the DPA) forms part of the Terms of Service between you or your organisation (Customer) and Clarity RevOps (we, us, our), operator of HypeSync (the Service). It applies where we process personal data on the Customer's behalf. If it conflicts with the Terms, this DPA governs for data protection matters.

Roles

The Customer is the controller of the personal data processed through the Service (or, where the Customer is itself a processor, the processor). We act as the Customer's processor. We process personal data only on the Customer's documented instructions, which include the Customer's configuration and use of the Service, unless we are required to do otherwise by law.

Nature and purpose of processing

We process personal data to provide the Service: reading the Customer user's own LinkedIn inbox, triaging conversations as work or personal, matching work conversations to the correct CRM record, and logging them to the Customer's connected CRM at the Customer's direction. Processing continues for the duration of the Terms.

Categories of data and data subjects

Data subjects: the Customer's users, and the participants in those users' own LinkedIn conversations. Personal data: names, professional headline, title, company, LinkedIn profile URL and photo, message metadata, and a minimised preview of message content, together with the account and contact identifiers written to the CRM.

We do not intend to process special categories of personal data, and the Customer will not use the Service to do so.

Our obligations

We will: process personal data only on the Customer's instructions; ensure that persons authorised to process it are bound by confidentiality; implement appropriate technical and organisational security measures; assist the Customer, taking into account the nature of processing, with data subject requests and with its security, breach notification, and impact assessment obligations; and, at the Customer's choice, delete or return personal data at the end of the Service, except where retention is required by law.

Sub-processors

The Customer authorises us to engage the sub-processors listed in our Privacy Policy, currently authentication (Clerk), database and hosting (Neon and Vercel), AI conversation triage (Anthropic), payments (Stripe), and the Customer's chosen CRM (Salesforce or HubSpot), to process personal data to provide the Service.

We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give notice of any intended change of sub-processor so that the Customer can object on reasonable data protection grounds.

Security

We maintain measures appropriate to the risk, including encryption of connection tokens at rest, encryption of data in transit, access controls, data minimisation, and scoping access to the user's own inbox. We do not automate any action on the Customer's behalf on any third-party platform.

Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide the information reasonably available to us to help the Customer meet its own notification obligations.

International transfers

Where personal data is transferred across borders, we and our sub-processors rely on appropriate safeguards, such as the Standard Contractual Clauses or an equivalent mechanism, to protect it.

Data subject requests and records

We will assist the Customer in responding to requests from data subjects to exercise their rights, and, on reasonable request and notice, make available the information necessary to demonstrate compliance with this DPA, subject to confidentiality and to the security of other customers' data.

Deletion

On termination of the Service, or on the Customer's request, we will delete or return the Customer's personal data within a reasonable period, except for limited records we are required to retain by law.

US state privacy laws

Where US state privacy laws apply, we act as a service provider or processor: we process the Customer's personal data only to provide the Service and for the limited purposes those laws permit, we do not sell it, we do not share it for cross-context behavioural advertising, and we do not retain, use, or disclose it outside our direct business relationship with the Customer.

Contact

Data protection questions: privacy@tryhypesync.com. HypeSync is operated by Clarity RevOps.