1. Parties & Effective Date
This Data Processing Agreement ("DPA") is entered into between:
- Processor: ForexBrokerLead ("we", "us", "Processor")
- Controller: The client purchasing leads from us ("you", "Client", "Controller")
This DPA is effective as of the date of your first Order and supplements our Terms & Conditions. In case of conflict, this DPA prevails on data protection matters.
Why this matters: When you buy leads from us and load them into your CRM, you become the "Controller" (you decide how to contact them) and we are the "Processor" (we delivered the data to you). GDPR Article 28 requires a written contract between Controller and Processor — that's this document.
Note: For the leads themselves (the individuals whose data is in the lists we deliver), you are the Controller and we were the Controller at the sourcing stage. We transfer our Controller obligations to you at delivery time.
2. Scope & Purpose
This DPA covers the processing of personal data that ForexBrokerLead delivers to you as part of your Order, including but not limited to:
- Lead names, email addresses, phone numbers
- Lead country, lead type, deposit history (where applicable)
- Lead consent records (timestamp, source URL, IP at opt-in)
- Any supplementary fields requested as custom filters
The duration of processing is the duration of your license to use the Leads (24 months from delivery, per our Terms), unless terminated earlier.
3. Roles of the Parties
For personal data of Leads (the individuals whose data is in the lists we deliver):
- ForexBrokerLead was the Controller at the sourcing stage (we determined what data to collect and how).
- You (Client) become the Controller at delivery stage (you determine how to contact them, what offers to send, etc.).
For personal data of Client (your data, e.g. your name, email, payment info):
- You (Client) are the Controller.
- ForexBrokerLead is the Processor.
4. ForexBrokerLead's Obligations as Processor
ForexBrokerLead agrees to:
- Process Client personal data only on documented instructions from the Client, including with regard to transfers of personal data to a third country (GDPR Art. 28(3)(a)).
- Ensure that personnel authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Take all technical and organizational measures required pursuant to GDPR Article 32 (security of processing).
- Respect the conditions referred to in paragraphs 2 and 4 for engaging another processor.
- Assist the Client in ensuring compliance with obligations pursuant to GDPR Articles 32 to 36 (security, breach notification, DPIA, prior consultation).
- Delete or return all personal data to the Client after the end of the services, at the Client's choice.
- Make available to the Client all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits.
5. Subprocessors
ForexBrokerLead uses the following subprocessors to deliver its services:
- Web hosting: cPanel shared hosting (data center: EU/US, varies by availability).
- Email delivery: PHP mail() via hosting provider's MTA, or PHPMailer via SMTP if configured.
- Payment processing: Stripe, PayPal, Coinbase Commerce (depending on payment method chosen).
- Analytics: Google Analytics 4, Microsoft Clarity (anonymous, aggregated data only).
We will notify you in advance of any intended addition or replacement of a subprocessor, giving you the opportunity to object. To receive subprocessor change notifications, email support@forexbrokerlead.com with subject "Subprocessor notifications".
6. Security Measures
Technical and organizational measures we maintain:
- TLS 1.3 encryption for all traffic in transit.
- AES-256 encryption for personal data at rest.
- MFA required for all team member access to personal data.
- Role-based access control with quarterly access reviews.
- Daily encrypted backups retained for 30 days.
- Quarterly security reviews and annual penetration tests.
- Written breach response plan with 72-hour notification commitment.
- Annual staff data protection training.
7. Personal Data Breach Notification
In the event of a personal data breach affecting Client data, ForexBrokerLead will:
- Notify the Client without undue delay and within 24 hours of becoming aware of the breach.
- Provide a description of the breach, the likely consequences, and the measures taken or proposed.
- Cooperate with the Client in any required notification to supervisory authorities and data subjects.
For the avoidance of doubt: a "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
8. International Data Transfers
If personal data is transferred outside the EU/EEA/UK, we rely on:
- European Commission's Standard Contractual Clauses (SCCs).
- UK International Data Transfer Addendum (for UK-origin data).
- EU-US Data Privacy Framework (for US subprocessors who are certified).
Copies of these mechanisms are available on request.
9. Data Return & Deletion
At the end of your license period (24 months from delivery, or earlier termination of your account), you have the choice to:
- Return all personal data we delivered to you (we'll send a confirmation that no copies remain in your systems), or
- Delete all personal data we delivered (we'll provide a deletion certificate on request).
ForexBrokerLead will, on its side, delete or anonymize all personal data we hold about you (the Client) within 30 days of account termination, subject to legal retention requirements (tax records kept 7 years).
10. Audit Rights
The Client may audit ForexBrokerLead's compliance with this DPA, subject to:
- Providing 30 days' written notice.
- Conducting the audit during business hours, without unreasonable disruption to our operations.
- Limiting the audit to once per calendar year (unless a breach has occurred).
- Signing our standard NDA before accessing any non-public systems.
Alternatively, we can provide a recent third-party audit report (e.g. SOC 2 Type II, ISO 27001 certificate) in lieu of an on-site audit, where available.
11. Contact
For any questions about this DPA or to request a countersigned copy:
- Email: support@forexbrokerlead.com
- Data Protection Officer: dpo@forexbrokerlead.com