EnrikeBack to Enrike ↗
Legal
Terms of ServicePrivacy PolicyLegal NoticeCookie PolicyData Processing Agreement

Questions?enrike@higuera.ai

GDPR processor terms

Data Processing Agreement

This Data Processing Agreement forms part of the Enrike Terms of Service when Higuera Ex Machina SL processes Customer Personal Data on a customer’s behalf.

Last updated: 30 July 2026

1. Parties and effect

This agreement is between the customer that accepted the Terms of Service (“Customer”) and Higuera Ex Machina SL, NIF B21770680, C/Escultor Llimona 15, 08031, Barcelona, Spain (“Higuera”). It applies automatically where Customer uses Enrike to process personal data and is effective for the duration of that processing.

Customer is the controller and Higuera is the processor for Customer Personal Data, unless Customer is itself a processor, in which case Higuera is its subprocessor. Terms such as controller, processor, personal data, processing, and data subject have the meanings given in the GDPR.

2. Scope of processing

Subject matter
Data enrichment and related account, API, file, support, and security operations.
Duration
The service term plus the limited retention and deletion periods described below.
Nature
Receiving, validating, transmitting, researching, analysing, inferring, structuring, returning, securing, and deleting data.
Purpose
Providing the Enrike service under Customer’s documented instructions.
Data subjects
Customer users, business contacts, leads, prospects, and other individuals represented in submitted records.
Personal data
Business email addresses; names and public professional context; company, role, location, language, gender, age, and salary estimates; postcodes; request metadata; and enrichment results.

Enrike is not designed for special-category data, criminal-conviction data, children’s data, or identity documents. Customer must not submit such data unless Higuera has expressly agreed in writing and the parties have implemented any additional required safeguards.

3. Customer instructions and responsibilities

The Terms, this agreement, Customer’s use of service settings, and written support requests are Customer’s documented instructions. Higuera will process Customer Personal Data only on those instructions, including for transfers, unless Union or Member State law requires otherwise. Where legally permitted, Higuera will inform Customer before processing required by law.

Customer is responsible for the lawfulness, accuracy, and source of Customer Personal Data; providing required notices; responding to data subjects; and ensuring its instructions comply with applicable law. Higuera will promptly inform Customer if, in its opinion, an instruction infringes applicable data-protection law.

4. Confidentiality and security

Higuera ensures that people authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed. Higuera maintains proportionate technical and organisational measures, including access controls, encryption in transit, protected server credentials, row-level database controls, pseudonymised lookup and usage keys, logging controls, rate limiting, and tested operational safeguards.

Customer is responsible for its account configuration, authorised users, API-key handling, endpoint security, and secure use of downloaded results.

5. Subprocessors

Customer gives Higuera general authorisation to use the subprocessors below where needed to provide Enrike:

SubprocessorService
SupabaseAuthentication, database, usage records, and enrichment cache
Google CloudApplication hosting, request processing, security, and operational logs
OpenRouter and routed model or retrieval providersModel inference and web-assisted enrichment
Brave SearchFallback public-web research where configured

Higuera will impose materially equivalent data-protection obligations on subprocessors and remains responsible for their performance to the extent required by applicable law. We will provide reasonable advance notice of a material new subprocessor through the service, by email, or by updating this page. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will work in good faith on a solution; if none is reasonably available, either party may terminate the affected service.

6. Assistance

Taking into account the nature of processing and information available to Higuera, we will provide reasonable assistance with data subject requests, security obligations, breach notifications, data protection impact assessments, and prior consultations. Customer remains responsible for deciding how to respond to requests and for meeting its own legal obligations.

7. Personal data breaches

Higuera will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include available information reasonably needed for Customer’s assessment and notifications. Higuera’s notice is not an admission of fault or liability.

8. International transfers

Where Customer Personal Data is transferred outside the EEA without an adequacy decision, Higuera will use an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses, and supplementary measures where appropriate. On request, Higuera will provide information reasonably available about the applicable mechanism.

9. Return and deletion

Customer can retrieve results through the service during processing. After termination, Higuera will delete or return Customer Personal Data processed solely on Customer’s behalf, unless applicable law requires retention. Deletion from backups and security records may occur during ordinary rotation cycles.

This section does not apply to account, billing, security, usage, or shared-cache data that Higuera processes as an independent controller under the Privacy Policy. Email enrichment results in the shared cache expire after four calendar months and postcode results after twelve calendar months; lookup values are held as SHA-256 keys and cached result objects omit the submitted input.

10. Information and audits

Higuera will make available information reasonably necessary to demonstrate compliance with this agreement. No more than once per year, unless required by a regulator or following a substantiated incident, Customer may request a remote audit on reasonable notice. Audits must protect confidentiality, avoid disruption, and use existing independent reports first where they provide sufficient assurance. Customer bears its audit costs.

11. Order of precedence and contact

If this agreement conflicts with the Terms on personal-data processing, this agreement controls. The remaining Terms, including liability and governing-law provisions, continue to apply. Privacy and DPA questions can be sent to enrike@higuera.ai.

© 2026 Higuera Ex Machina SLC/Escultor Llimona 15, 08031, Barcelona, Spain