LiReach Legal Data Processing Agreement

Data Processing
Agreement.

This Data Processing Agreement describes how LiReach processes personal data on behalf of customers when providing our platform and related services.

Last updated: 05/09/2026

1. Scope and applicability

This Data Processing Agreement ("DPA") forms part of the agreement between Qamringa Private Limited ("LiReach", "we", "us" or "our") and the customer identified in the applicable LiReach order, subscription or service agreement ("Customer").

This DPA applies where LiReach processes personal data on behalf of the Customer in connection with the LiReach platform or related services.

This DPA is intended to establish the responsibilities of the parties regarding the processing and protection of personal data.

This DPA supplements the LiReach Terms of Service and Privacy Policy .

If there is a conflict between this DPA and another agreement concerning the processing of personal data, this DPA will control to the extent of that conflict, unless the parties expressly agree otherwise in writing.

2. Definitions

For purposes of this DPA, the following terms have the meanings described below.

Personal Data
Information relating to an identified or identifiable individual, as defined under applicable data protection law.
Processing
Any operation performed on Personal Data, including collection, storage, use, organization, transmission, analysis or deletion.
Data Subject
The individual to whom Personal Data relates.
Subprocessor
A third-party service provider engaged by LiReach to process Personal Data on behalf of the Customer.

Terms not specifically defined in this DPA will have the meaning given to them under the applicable data protection laws governing the relevant processing.

3. Roles and responsibilities

Customer

Data Controller

Where applicable, the Customer determines the purposes and means of processing Personal Data submitted to LiReach.

LiReach

Data Processor

LiReach processes Personal Data on behalf of the Customer in accordance with the Customer's documented instructions and this DPA.

The parties acknowledge that their roles may differ depending on the nature of a particular processing activity and the applicable law.

Nothing in this DPA prevents LiReach from processing information for its own legitimate purposes where LiReach acts independently as a controller or equivalent entity under applicable law.

4. Processing instructions

LiReach will process Customer Personal Data only:

  • To provide and operate the LiReach services.
  • To perform documented instructions from the Customer.
  • As necessary to maintain security, reliability and functionality of the services.
  • As required by applicable law.

If LiReach reasonably believes that an instruction violates applicable data protection law, LiReach may notify the Customer before carrying out the instruction, unless prohibited by law.

Customer responsibility: The Customer is responsible for ensuring that its instructions to LiReach are lawful and that it has the necessary rights, notices, permissions and legal basis to process Personal Data through the service.

5. Categories of Personal Data

Depending on how the Customer uses LiReach, Personal Data processed through the platform may include:

Identity information
Names, professional titles, roles and similar business identity information.
Contact information
Business email addresses, phone numbers, professional contact information and similar data.
Professional information
Company, job role, industry, professional background and business-related information.
Outreach information
Campaign information, messages, responses, preferences and interaction history.
Account information
Information associated with users and accounts created to access LiReach.

Special categories of data

Unless expressly agreed in writing, the Customer should not use LiReach to intentionally process sensitive or special categories of Personal Data where prohibited by applicable law.

If the Customer requires LiReach to process a sensitive category of data, the parties should establish appropriate additional contractual, technical and organizational safeguards before such processing begins.

6. Confidentiality

LiReach will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

Personnel and service providers with access to Customer Personal Data will only access or process that information as necessary to perform their authorized responsibilities.

7. Security measures

LiReach will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration or disclosure.

Depending on the nature of the services and data, security measures may include:

  • Access controls and authentication mechanisms.
  • Restrictions on personnel access to data.
  • Security monitoring and operational controls.
  • Appropriate measures for protecting data during transmission and storage, where applicable.
  • Processes for identifying and responding to security incidents.
  • Backup and service continuity measures where appropriate to the service.

Security measures may evolve

LiReach may update its technical and organizational security measures as technology, risks and the LiReach service evolve, provided that the overall level of protection remains appropriate to the processing risks.

8. Subprocessors

LiReach may engage third-party service providers to assist in delivering the LiReach platform.

Where those providers process Customer Personal Data on behalf of LiReach, they will be treated as Subprocessors under this DPA.

LiReach will require applicable Subprocessors to provide appropriate protections for Personal Data consistent with the obligations applicable to LiReach.

Subprocessor changes

LiReach may add or replace Subprocessors as needed to operate and improve the service, subject to applicable legal requirements.

Where required by applicable law or agreed contract, LiReach will provide information or notice regarding relevant Subprocessor changes.

9. Assistance with data protection obligations

Taking into account the nature of the processing and information available to LiReach, we will provide reasonable assistance to the Customer where required by applicable data protection law.

Such assistance may include reasonable cooperation concerning:

  • Data subject requests.
  • Security assessments.
  • Regulatory or supervisory authority requirements.
  • Information reasonably necessary to demonstrate compliance with applicable processor obligations.

The Customer remains responsible for responding to Data Subject requests and determining the appropriate legal response unless applicable law provides otherwise.

10. Personal Data incidents

If LiReach becomes aware of a confirmed Personal Data breach affecting Customer Personal Data, LiReach will notify the Customer without undue delay, subject to applicable law.

Where reasonably available and legally permitted, the notification may include information concerning:

  • The nature of the incident.
  • The categories of Personal Data affected.
  • The likely consequences of the incident.
  • Measures taken or proposed to address the incident.

LiReach will take reasonable steps to investigate, contain and address a confirmed incident and will cooperate with the Customer as reasonably necessary.

Customer notification responsibility

The Customer remains responsible for determining whether notification to individuals, regulators or other parties is required and for making those notifications where applicable.

11. Return and deletion of Personal Data

Upon termination or expiration of the applicable services, LiReach will delete or return Customer Personal Data in accordance with the Customer's instructions and applicable legal requirements, unless retention is required by law.

Where technically and legally appropriate, LiReach may retain limited information for purposes such as legal compliance, security, fraud prevention, dispute resolution or legitimate business records.

Backup copies may remain for a limited period as part of standard backup and disaster recovery processes before being securely overwritten or deleted.

12. International data transfers

Customer Personal Data may be processed in countries other than the country in which the Customer or relevant Data Subject is located.

Where applicable law requires safeguards for international transfers, LiReach will implement appropriate transfer mechanisms or safeguards required by that law.

Transfer mechanism: The parties should confirm the appropriate international transfer mechanism based on the countries involved and the laws applicable to the processing.

13. Audits and compliance information

Upon reasonable request, LiReach will make available information reasonably necessary to demonstrate compliance with applicable processor obligations under this DPA, subject to confidentiality, security and other reasonable restrictions.

Where applicable law requires an audit, the parties will cooperate in good faith to establish a reasonable scope, timing and method for the audit.

Audits must not unreasonably interfere with LiReach's operations, compromise the security of other customers or require disclosure of confidential information unrelated to the Customer's processing activities.

Any reasonable costs associated with an audit may be allocated according to the parties' applicable agreement or, where no agreement exists, as permitted by applicable law.

14. Customer responsibilities

The Customer is responsible for:

  • Determining the purposes and lawful basis for processing where required.
  • Providing appropriate privacy notices to Data Subjects.
  • Obtaining any required consent or authorization.
  • Ensuring that Personal Data supplied to LiReach is collected and provided lawfully.
  • Configuring and using LiReach in accordance with applicable privacy and data protection requirements.
  • Responding appropriately to requests from Data Subjects.
LiReach provides processing tools — it does not determine your legal obligations. Customers should evaluate their specific legal, regulatory and contractual obligations before using LiReach to process Personal Data.

15. Term and termination

This DPA will remain in effect for as long as LiReach processes Customer Personal Data on behalf of the Customer under the applicable services agreement.

Obligations relating to confidentiality, security, deletion, retention and other provisions that by their nature should survive termination will continue for the period required by applicable law or the relevant agreement.

16. Liability

The liability of each party arising from this DPA will be subject to the liability provisions contained in the applicable LiReach agreement, except to the extent that applicable data protection law requires otherwise.

Nothing in this DPA is intended to exclude or limit liability that cannot legally be excluded or limited.

17. Changes to this DPA

LiReach may update this DPA where reasonably necessary to reflect changes in the LiReach services, applicable data protection requirements, technology or security practices.

Where a change materially affects the Customer's obligations or rights, LiReach will provide appropriate notice where required.

18. Governing law

This DPA will be governed by the governing law and dispute-resolution provisions contained in the applicable LiReach agreement, unless applicable law requires otherwise.

Complete before publishing

Confirm the legal entity, applicable jurisdiction, data protection laws, international transfer mechanism and contractual liability structure before treating this DPA as a binding legal agreement.

19. Contact us

For questions regarding this Data Processing Agreement or data processing arrangements with LiReach, please contact us.

Questions about data processing?

Contact the LiReach team regarding privacy, data processing, security or DPA requests.

Support@lireach.tech →

Your data.
Handled responsibly.

Learn more about how LiReach approaches privacy, security and responsible data processing.

Read Privacy Policy →