Data Processing Agreement
This Data Processing Agreement forms part of the Enrike Terms of Service when Higuera Ex Machina SL processes Customer Personal Data on a customer’s behalf.
Last updated: 30 July 20261. Parties and effect
This agreement is between the customer that accepted the Terms of Service (“Customer”) and Higuera Ex Machina SL, NIF B21770680, C/Escultor Llimona 15, 08031, Barcelona, Spain (“Higuera”). It applies automatically where Customer uses Enrike to process personal data and is effective for the duration of that processing.
Customer is the controller and Higuera is the processor for Customer Personal Data, unless Customer is itself a processor, in which case Higuera is its subprocessor. Terms such as controller, processor, personal data, processing, and data subject have the meanings given in the GDPR.
2. Scope of processing
- Subject matter
- Data enrichment and related account, API, file, support, and security operations.
- Duration
- The service term plus the limited retention and deletion periods described below.
- Nature
- Receiving, validating, transmitting, researching, analysing, inferring, structuring, returning, securing, and deleting data.
- Purpose
- Providing the Enrike service under Customer’s documented instructions.
- Data subjects
- Customer users, business contacts, leads, prospects, and other individuals represented in submitted records.
- Personal data
- Business email addresses; names and public professional context; company, role, location, language, gender, age, and salary estimates; postcodes; request metadata; and enrichment results.
Enrike is not designed for special-category data, criminal-conviction data, children’s data, or identity documents. Customer must not submit such data unless Higuera has expressly agreed in writing and the parties have implemented any additional required safeguards.
3. Customer instructions and responsibilities
The Terms, this agreement, Customer’s use of service settings, and written support requests are Customer’s documented instructions. Higuera will process Customer Personal Data only on those instructions, including for transfers, unless Union or Member State law requires otherwise. Where legally permitted, Higuera will inform Customer before processing required by law.
Customer is responsible for the lawfulness, accuracy, and source of Customer Personal Data; providing required notices; responding to data subjects; and ensuring its instructions comply with applicable law. Higuera will promptly inform Customer if, in its opinion, an instruction infringes applicable data-protection law.
4. Confidentiality and security
Higuera ensures that people authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed. Higuera maintains proportionate technical and organisational measures, including access controls, encryption in transit, protected server credentials, row-level database controls, pseudonymised lookup and usage keys, logging controls, rate limiting, and tested operational safeguards.
Customer is responsible for its account configuration, authorised users, API-key handling, endpoint security, and secure use of downloaded results.
5. Subprocessors
Customer gives Higuera general authorisation to use the subprocessors below where needed to provide Enrike:
Higuera will impose materially equivalent data-protection obligations on subprocessors and remains responsible for their performance to the extent required by applicable law. We will provide reasonable advance notice of a material new subprocessor through the service, by email, or by updating this page. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will work in good faith on a solution; if none is reasonably available, either party may terminate the affected service.
6. Assistance
Taking into account the nature of processing and information available to Higuera, we will provide reasonable assistance with data subject requests, security obligations, breach notifications, data protection impact assessments, and prior consultations. Customer remains responsible for deciding how to respond to requests and for meeting its own legal obligations.
7. Personal data breaches
Higuera will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include available information reasonably needed for Customer’s assessment and notifications. Higuera’s notice is not an admission of fault or liability.
8. International transfers
Where Customer Personal Data is transferred outside the EEA without an adequacy decision, Higuera will use an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses, and supplementary measures where appropriate. On request, Higuera will provide information reasonably available about the applicable mechanism.
9. Return and deletion
Customer can retrieve results through the service during processing. After termination, Higuera will delete or return Customer Personal Data processed solely on Customer’s behalf, unless applicable law requires retention. Deletion from backups and security records may occur during ordinary rotation cycles.
This section does not apply to account, billing, security, usage, or shared-cache data that Higuera processes as an independent controller under the Privacy Policy. Email enrichment results in the shared cache expire after four calendar months and postcode results after twelve calendar months; lookup values are held as SHA-256 keys and cached result objects omit the submitted input.
10. Information and audits
Higuera will make available information reasonably necessary to demonstrate compliance with this agreement. No more than once per year, unless required by a regulator or following a substantiated incident, Customer may request a remote audit on reasonable notice. Audits must protect confidentiality, avoid disruption, and use existing independent reports first where they provide sufficient assurance. Customer bears its audit costs.
11. Order of precedence and contact
If this agreement conflicts with the Terms on personal-data processing, this agreement controls. The remaining Terms, including liability and governing-law provisions, continue to apply. Privacy and DPA questions can be sent to enrike@higuera.ai.