1.1 The agreement. These Terms of Service ("Terms") are a binding agreement between you and Vonsel. They govern your access to and use of the Vonsel website at vonsel.com, the Vonsel browser extension, the Vonsel dashboard and CRM, and every related feature, interface and application (together, the "Service"). By creating an account, by installing or using the browser extension, or by otherwise accessing or using the Service, you agree to these Terms. If you do not agree, you must not use the Service.
These Terms include the following documents, which form part of them: Annex A, the Data Processing Addendum; our Privacy Policy at vonsel.com/privacy; and our Cookie Policy at vonsel.com/cookies.
In these Terms, "we", "our" and "us" mean Vonsel. "You" and "your" mean the business, sole trader or professional that accepts these Terms.
1.2 Definitions.
"AI Output" means any text, score, summary, classification, translation, transcription or suggestion generated by an artificial intelligence or machine learning model made available through the Service.
"Business Records" means information about businesses and commercial establishments that you capture, import or store in your Workspace, including contact details, location, category and publicly posted ratings and reviews.
"Connected Account" means an account you hold with a third party and choose to connect to the Service, including a mailbox, a calendar or a messaging or social account.
"Connected Service" means any third-party website, platform, social network, messaging service, email provider, calendar service, directory, map service, application or programming interface with which the Service interoperates at your initiative and under your control.
"Workspace" means the private area of the Service in which your account data, your Business Records and the content you create are stored.
1.3 The provider. The Service is provided by Luis Alberto de Haro GarcÃa, sole trader, holder of Spanish tax identification number 31027244Z, with address at Avenida de José Ortega y Gasset 124, 2º-23, 29006 Málaga, Spain, trading under the name "Vonsel" and contactable at luis@vonsel.com.
2.1 The Service is not offered to consumers. The Service is offered exclusively to companies, sole traders, self-employed professionals and other persons acting for purposes relating to their trade, business, craft or profession. The Service is not offered to consumers.
2.2 Your declaration. By registering for or using the Service, you represent and warrant that (1) you are acting in the course of your trade, business, craft or profession and not as a consumer; (2) any individual who accepts these Terms on your behalf is duly authorised to bind you; and (3) you will not use the Service for personal, family or household purposes.
2.3 Why this matters. We rely on that declaration when we grant you access, when we set our prices and when we agree to the allocation of risk in sections 7 to 17. If you are not acting in a business capacity, you must not register for or use the Service.
3.1 The browser extension. The Vonsel browser extension runs in your own browser, in your own browsing session, under your own identity and from your own internet connection. It lets you save into your Workspace the business listings displayed to you while you browse, and it can read publicly accessible pages of the websites those listings point to. The extension does not use proxies, does not rotate identities and does not act on behalf of any account other than yours. You perform the capture. We do not perform it for you and we do not perform it in advance.
What the extension saves is information that the business itself has published in order to be found and contacted: the entry the business created or claimed on a public map or directory service, and the contact details the business displays on its own public website. It is the trading name, the address, the category, the opening hours, the telephone number, the published email address, the website, the public social profile links and the ratings and reviews the service shows to anyone who looks. The extension does not create information, does not infer it, does not obtain it from any private source, and does not read anything that the business has not made publicly visible.
3.2 Your Workspace and the CRM. The Service provides a workspace in which you store, organise, annotate, segment, map, score and track the Business Records you capture or import. Your Workspace is private to you. Business Records are stored per customer account. We do not merge them into a shared corpus and we do not make one customer's records available to another.
3.3 Connected Accounts, inbox and outbound messaging. An optional module lets you connect Connected Accounts belonging to you, including mailboxes, calendars and messaging or social accounts, so that you can read and send messages inside the Service. Section 9 governs what you send. Section 10 governs the module and prevails over any general provision of these Terms in case of conflict.
3.4 Artificial intelligence features. The Service uses artificial intelligence models, operated by third-party providers, to draft outreach messages, analyse public reviews, score and classify records, transcribe voice notes and produce other suggestions. Section 11 governs these features.
3.5 Data sources. Business Records reach your Workspace one way: you capture them yourself with the extension and you save them into your Workspace. We do not supply you with business data, we do not sell you a list, and we do not maintain a directory of our own that you can search. Where we make an import interface available to you, what you bring in through it is data you already hold, and you are responsible for having the right to bring it in. In every case the records are your data and we hold them as your processor, as set out in section 12.
The information concerned is information that businesses publish about themselves so that customers can find and contact them. It is business contact information, published by the business, on channels the business chose, for the purpose of being contacted. That does not make it free of legal rules, and section 7.3 and section 12.4 set out that deciding whether your use of it is lawful is your responsibility, not ours.
3.6 What the Service is not. Because it affects how these Terms allocate responsibility:
3.7 Changes to the Service. We may add, modify or discontinue features at any time. Where a change materially reduces a feature you rely on, we will make reasonable efforts to notify active subscribers in advance. Section 19 governs changes to these Terms, which is a different matter.
4.1 Registration. You create your account yourself, from the extension or from our website, by providing an email address and confirming a verification code we send to it. Confirming that code is your acceptance of these Terms and of the documents listed in section 1.1, and we record it as described in section 19.7.
4.2 Accurate information. You must provide accurate, truthful and complete information and keep it up to date. Where the Service requires your legal name, business identification or postal address in order to comply with a legal obligation applicable to outbound communications, you must provide them and keep them current.
4.3 Credentials and security. You are responsible for keeping your credentials, API keys and access tokens confidential. They are personal to one named user and must not be shared with anyone, inside or outside your organisation, as section 8.4 provides. Notify us immediately if you become aware of unauthorised access to your account. You are responsible for all activity that occurs under your account, whether or not you authorised it.
4.4 Team members. If your plan allows you to invite team members, you are responsible for the permissions you grant them, for their compliance with these Terms, and for everything they do in your Workspace. Their acts and omissions are treated as yours.
4.5 Age and capacity. You represent and warrant that you are at least 18 years old and that you have full legal capacity to enter into these Terms. Where you accept these Terms on behalf of an entity, you further represent and warrant that you are duly authorised to bind it.
We do not verify age and we are under no obligation to do so. The Service is offered only to businesses and professionals under section 2, it is not directed to children, and it is neither designed nor marketed for use by anyone under 18. We rely entirely on the representation you give here, and the absence of an age check is not a representation that we permit, tolerate or have accepted use of the Service by any person under 18.
If that representation is untrue when given, we may treat these Terms as voidable on the ground of misrepresentation and may rescind or terminate them at our election, with immediate effect and without refund, close the account and delete its contents in accordance with section 13. You, and any person who caused the account to be opened, remain liable to us for all resulting loss, and section 17 applies.
4.6 Our discretion. We may refuse a registration, and we may suspend or terminate an account, in accordance with section 18.
5.1 Pricing. The fees for our plans are shown on our pricing page. Different plans offer different features and usage limits. We may change our prices with at least thirty (30) days' notice to existing subscribers. A price change does not affect the current billing period; it applies to subsequent renewals.
5.2 Payment. Fees are due when a subscription is activated and on each renewal. By providing payment details you authorise us, and our payment processor, to charge your chosen payment method for the applicable fees and any applicable taxes.
5.3 Billing cycles. Subscriptions are billed monthly or annually. Annual subscriptions are charged in full at the start of the annual period.
5.4 Auto-renewal. Unless you cancel before the end of the current billing period, your subscription renews automatically for an equivalent period at the then-current rate.
5.5 Free plans and trials. We may offer a free plan or a trial. They carry the same allocation of risk as paid plans, section 16.2 sets the cap that applies to them, and we may change or withdraw them at any time.
5.6 Taxes. Fees are exclusive of value added tax and equivalent indirect taxes, which we add where applicable. You are responsible for providing a valid tax identification number where one is required to determine the correct treatment, and for any tax arising in your own jurisdiction.
6.1 How to cancel. You may cancel at any time from your dashboard, or by writing to info@vonsel.com. To avoid being charged for the next period, cancel before the end of your current billing period.
6.2 Effect of cancellation. Your subscription stays active and fully functional until the end of the current paid period. No further charges apply after it ends, and access to paid features then stops. Section 13 governs what happens to your data.
6.3 Refunds. Except where these Terms or mandatory law provide otherwise, fees paid are non-refundable, including fees paid in advance for annual subscriptions and unused features or credits. Once you have used the Service in a billing period, no refund, credit or reimbursement is due for that period, whether or not you continue to use it, and we do not accept claims for reimbursement based on how much or how little use you made of it. These Terms expressly provide for a pro rata refund in three cases: section 12.6 (sub-processors), section 18.2 (termination by us without cause) and section 19.4 (you do not accept a material change).
6.4 Complaints and claims. Send any complaint or claim about the Service, about a charge or about our performance to info@vonsel.com, in writing and with reasonable particulars. We will answer within thirty (30) business days of receipt. That period is our commercial commitment to you. It does not apply to, shorten, extend or replace any period fixed by law: requests to exercise data protection rights are answered within the period stated in our Privacy Policy, and any other statutory deadline prevails over this section. Section 16.3 sets the separate time limit within which a claim must be notified to us.
6.5 Payment disputes and chargebacks. If you dispute a charge, you agree to contact us first at info@vonsel.com and to allow us fifteen (15) days to resolve it before initiating a chargeback. Initiating a chargeback in respect of a charge due under these Terms is a breach of these Terms. We may suspend your account while a dispute is pending. Where a chargeback is resolved in our favour, or relates to a charge that was due, we may recover the amount charged back, any fee imposed on us by our payment provider, and our reasonable costs of recovery.
7.1 You decide. We provide software and technical facilities. You decide, at your own initiative and under your own control, which searches to run, which businesses to capture, which records to keep and for how long, which accounts to connect, whom to contact, through which channel, how often, with what content, and on what legal basis. We do not decide any of those things.
7.2 No general obligation to monitor. We do not control, and we have no general obligation to monitor, the data you collect, the content you store or the communications you send through the Service. We are not responsible for the manner in which you use it. We reserve the right, but assume no obligation, to review use of the Service in order to verify compliance with these Terms, investigate a complaint, respond to a request from an authority or a Connected Service, or protect the Service and its users.
7.3 No legal advice and no compliance assessment. We do not provide legal advice. We give no assurance that any particular use of the Service, or of any data obtained through it, is lawful in your jurisdiction or in the jurisdiction of any recipient you contact. You are solely responsible for determining the lawfulness of your own activity. You may not rely on any legal basis analysis, legitimate interests assessment, compliance statement or justification that we have prepared in relation to our own processing; those documents describe our activity, not yours. We strongly recommend that you obtain advice from legal counsel qualified in your jurisdiction, and in that of your intended recipients, before conducting prospecting or outreach using the Service.
7.4 What we provide is a professional service. We provide the Service in the exercise of our own professional activity as a provider of software as a service. Everything we do in connection with the Service, including its development, operation, maintenance, security, support and availability, and the data-handling functions it performs on your instruction, is an act or omission in the provision of those professional services, and any liability of ours in connection with the Service arises in that capacity. Nothing in this section alters section 7.1: you decide what you collect, whom you contact and on what legal basis.
7.5 Notices we give you. Where the Service shows you a warning, a limit, a recommendation or a compliance prompt, that notice is for your convenience. It does not transfer any responsibility to us, it is not a representation that an action is lawful, and its absence does not mean an action is permitted.
You may use the Service only for lawful purposes and in accordance with these Terms.
8.1 Unlawful and harmful activity. You must not use the Service in breach of any applicable law; to facilitate fraud, identity theft, impersonation or any criminal activity; to send communications that are threatening, harassing, deceptive, defamatory, obscene, discriminatory or otherwise unlawful; or to infringe the intellectual property, privacy, publicity, confidentiality or reputation rights of any person.
8.2 Prohibited data collection. You must not use the Service, or any data obtained through it, to:
This prohibition does not apply to a Connected Account of your own, which you access under section 10 with your own authorisation.
8.3 Communications. Everything you send through or with the assistance of the Service is governed by section 9, which prevails over this section 8 in case of conflict.
8.4 One account, one user. Access is personal to the individual to whom it is issued. A set of credentials may be used by one named individual only. If more than one person needs access, you must obtain a seat for each of them where your plan allows it. You must not share, lend, resell or make available your credentials, API keys, access tokens or session to any other person, whether inside or outside your organisation, and you must not operate a single account from several people, devices or locations at the same time in order to avoid paying for seats. Concurrent use of one set of credentials by more than one person is a material breach, and we may end the additional sessions, require a seat for each user, and suspend or terminate under section 18, without refund.
8.5 Misuse of the Service itself. You must not attempt to gain unauthorised access to our systems, networks, servers or databases; distribute malicious code or conduct denial-of-service attacks against us; reverse engineer, decompile or disassemble the Service, except to the extent that applicable law does not allow this restriction; access the Service, our dashboard or our APIs by any automated means other than the interfaces we document and authorise, or in a manner that circumvents any usage limit applicable to your plan; or resell, sublicense or redistribute the Service, or data obtained through it, without our prior written authorisation.
8.6 Competing products. You must not use the Service, or data obtained through it, to build, train, fine-tune or operate a competing product or service, or to train, fine-tune or evaluate any artificial intelligence or machine learning model.
8.7 Consequences. Breach of this section is a material breach. Section 18 sets out what we may do about it.
This is the most important allocation of responsibility in these Terms. Read it before you send anything.
The Service is not, and must not be used as, a bulk sending, mass mailing, blasting, campaign or automated sequencing platform, and it must not be used to send spam or any unsolicited communication that is unlawful in the hands of its recipient.
Every communication is sent one recipient at a time, from a Connected Account belonging to you, in response to a specific instruction you give for that communication. The Service has no mass send, no campaign engine, no automated follow-up sequence and no shared or central recipient list. Where you schedule a communication for later delivery, you determine its single recipient, its content and its send time in advance, and the Service does no more than transmit it at the time you set.
Where the Service applies a daily sending limit to a connected account, that limit exists to protect the standing of your own account with its provider. It is not a compliance control, it is not an approval, and it is not a representation that any volume below it is lawful, and its absence on a given channel is not a representation that no limit applies to you. The limits of each Connected Service apply to you in full, whether or not the Service displays or enforces them.
You must not use the Service, or any script, automation, integration, application programming interface or workaround, to reproduce the effect of a bulk sending or sequencing platform.
Lawful one-to-one business-to-business outreach conducted in accordance with this section 9 is a permitted use of the Service. The prohibition here is directed at bulk sending and at unlawful communications, not at lawful prospecting.
Where the Service transmits an email, a message or any other communication, you are the sender and the initiator of that communication for all legal purposes, and you are the controller of the recipient's personal data.
You acknowledge that, in respect of every such communication: (1) we do not initiate the transmission; (2) we do not select the recipient; (3) we do not select, review, approve, edit, modify or endorse the content; and (4) we do not send on our own behalf, in our own name, or from our own accounts. Where you use an AI feature to draft a communication, the draft is a suggestion produced at your request and for you alone. You review it, you may edit it, and you decide whether to send it and to whom, so the content remains yours and selected by you, as sections 11.2 and 11.3 provide.
Communications are transmitted from accounts, addresses, telephone numbers, domains and identities that you hold and connect, at times, in volumes, to recipients and with content that you alone determine and control. We act solely as a technical means of transmission.
Sole responsibility. As between you and us, you bear sole responsibility for every communication you send through or with the assistance of the Service and for every consequence of it, including any complaint, claim, investigation, enquiry, order, fine, penalty, sanction, blocklisting, restriction, suspension or termination that results from it, whether directed at you or at us. We are not liable for any such consequence.
You represent and warrant, on a continuing basis and in respect of each and every communication you send through or with the assistance of the Service, that:
A warning you should not ignore. Some jurisdictions require the recipient's prior consent for commercial communications sent by email or equivalent electronic means, including where the recipient is a legal person, subject to limited exceptions such as a pre-existing commercial relationship. Spain, where we are established, is one of them under Article 21 LSSI-CE. This warning is given for information only. It is not legal advice, it is not exhaustive, and section 7.3 applies to it in full.
These warranties are material terms. Breach of any of them is a material breach entitling us to suspend or terminate your access under section 18, without refund and without prior notice.
You must not use the Service to:
Sending on behalf of a third party is permitted only if you impose the obligations of this section 9 on that third party by written contract, verify that it has a valid lawful basis, and remain fully responsible to us for its compliance as if the communications were your own.
We may suspend, throttle, restrict or disable your access to the outbound messaging features, or to the Service as a whole, immediately, without prior notice and without refund, where we have reasonable grounds to suspect a breach of this section 9.
Indications alone are sufficient. We are not required to establish that a breach has occurred, to obtain proof, to conduct an investigation, or to give you an opportunity to respond before acting. Indications include a complaint from a recipient or any third party; a report, warning, enquiry, throttle or block from a Connected Service, an email provider, a hosting or infrastructure provider or a blocklist operator; an enquiry, order or sanction from a supervisory, regulatory or law enforcement authority; a spam-trap hit, or the appearance of a domain, address or number you use on a reputation blocklist; an abnormal rate of bounces, blocks, complaints or manual spam reports; a pattern of activity consistent with bulk sending, list purchase, identity concealment or circumvention of a limit; or the creation or connection of accounts, domains, numbers or Workspaces in a manner consistent with evading an earlier suspension.
Suspension under this section is a protective measure. It is not a breach by us, it is not a finding or an admission of anything against you, and it gives rise to no refund, credit, compensation, damages or liability of any kind. We will inform you as soon as reasonably practicable and, where we consider it appropriate, tell you what would be required for access to be restored. Repeated or serious breach entitles us to terminate immediately under section 18.2, without refund.
You must notify us in writing within five (5) business days of receiving any complaint, enquiry, request, warning, order or notice from a data protection or anti-spam authority, from a Connected Service, or from any individual, that relates to communications you have sent through the Service or to data you have processed in it.
If a supervisory authority, a court or a Connected Service makes an enquiry of us concerning your use of the Service, you will provide, promptly and at your own cost, all information and assistance we reasonably require in order to respond. Section 17.6 lists the records and sets the deadline.
Without limiting section 17, you indemnify, defend and hold us harmless against any claim, demand, complaint, investigation, regulatory enquiry, proceeding, order, award, settlement, damages, fine, penalty, sanction, loss, cost and expense arising out of or in connection with any communication you send through or with the assistance of the Service, including any allegation that it was unsolicited, unlawful, misleading, harassing or defamatory, and any claim, investigation or sanction under data protection, electronic communications, consumer protection or anti-spam law.
That obligation covers our reasonable costs of responding, the cost of any external legal, forensic or technical adviser we reasonably engage, and our own time at our then-current professional rates. As section 17.5 provides, your obligations under this section are not subject to the cap in section 16 and do not count towards it.
10.1 Scope. This section applies to every Connected Service and every Connected Account, and prevails over any general provision of these Terms in case of conflict.
10.2 No affiliation. We have no affiliation, partnership, sponsorship, endorsement or commercial relationship with any Connected Service. Any reference we make to one is made solely to identify the services with which the Service can interoperate, and all names, logos and trade marks of Connected Services belong to their respective owners. Your use of any Connected Service is governed by your own agreement with that third party, not by these Terms. We are not a party to that agreement and we do not act as anyone's agent under it.
10.3 Your accounts, your responsibility. Where the Service acts through a Connected Account, you act at your own initiative and under your own control. You represent and warrant that (1) you are the lawful holder of each Connected Account, or are duly authorised by its holder to connect and operate it; (2) you are in good standing with the relevant provider; (3) connecting and using that account through the Service is permitted under your agreement with that provider; and (4) you have read and will comply with the terms of service, acceptable use policies, automation restrictions and usage limits of every Connected Service you use. You remain solely responsible for all activity conducted through your Connected Accounts, including the volume, frequency, timing, recipients and content of everything sent from them.
10.4 How connections are made, and who makes them. Connections to Connected Accounts are established and maintained through Unipile SAS, a company incorporated in France, which we engage as a sub-processor (the "Connectivity Provider"). We name it here, and we describe our other sub-processors by category under section 12.6, for one reason: the credentials of your own accounts pass through it, and you cannot sensibly decide whether to connect an account without knowing who receives that authorisation. Its own terms of use and documentation are published by it and govern its service to us, not to you: you are not a party to our agreement with it and it owes you nothing. The following is relevant to your decision to connect an account:
10.5 Restriction and suspension of your accounts. A Connected Service decides, on its own criteria and outside our control, whether to allow, restrict or terminate any account.
You acknowledge that a Connected Service may issue a warning to you, or rate-limit, restrict, throttle, suspend, block, blacklist, disable, delete or permanently terminate an account, number, domain or address of yours, and that this may happen whether the activity concerned was carried out manually or through software. You further acknowledge that this risk is inherent to connecting any third-party account to any external tool, and that it is materially higher for cold outreach and for high volumes.
To the fullest extent permitted by law, we are not liable for, and cannot intervene in, any such warning, rate limit, restriction, suspension, blacklisting, deletion or termination, nor for any consequence of it, including loss of access, data, contacts, message history, sender or domain reputation, advertising accounts or business opportunities.
This applies in full where the account restricted is your own personal or business mailbox, telephone number, messaging account or social account, and it applies whether or not the restriction was caused by your use of the Service. A restriction imposed by a third party on an account of yours is not a failure of the Service, is not a defect, and gives rise to no refund, credit, compensation or liability of any kind. You are responsible for the conduct that led to it, you must stop that conduct, and section 17 applies to any claim brought against us in connection with it.
10.6 Availability, changes and our right to disable an integration. Connected Services may change, restrict, deprecate, degrade or withdraw their interfaces, policies, availability or data at any time, without notice to us. We are not liable for any interruption, degradation, delay, data inaccuracy or loss of functionality of the Service resulting from an act, omission, change or outage of a Connected Service or of the Connectivity Provider.
We may modify, suspend or discontinue support for any Connected Service at any time, in whole or in part, including where the provider of that Connected Service requests that we do so, or where we consider that continuing would place you or us at legal risk. Our only obligation is to notify you as soon as reasonably practicable.
The continued availability, completeness and functionality of any feature that depends on a Connected Service is not guaranteed. Its interruption, degradation or withdrawal is not a failure of the Service and does not entitle you to a refund, a credit or a reduction of fees. No service level, uptime commitment or response time applies to the messaging module or to any feature that depends on a Connected Service.
10.7 No guarantee of delivery. We do not warrant that any message will be sent, delivered, delivered on time, in order or only once, delivered to a recipient's main inbox rather than a spam or promotions folder, or accepted, read or acted on. Messages may fail, be delayed, be duplicated or be rejected for reasons outside our control. You are solely responsible for verifying, by independent means, any communication that is time-critical or commercially critical to you.
10.8 Third-party content. Data, ratings, reviews, images and other material originating from a Connected Service, or captured by you from a public source, are provided to you as found. We do not author, control, verify or endorse that material, and we make no representation as to its accuracy, completeness, currency, ownership or lawfulness.
10.9 Suspension of the module. If we have reasonable grounds to believe that your use of a Connected Account breaches this section, exposes other users to risk, or breaches an obligation we owe to a Connected Service or to the Connectivity Provider, we may suspend the module for your account immediately and without prior notice, and we will inform you as soon as reasonably practicable.
10.10 What the Connectivity Provider requires of us, and what you therefore owe us. Our agreement with the Connectivity Provider requires us to ensure that use of its service does not breach the terms, policies or technical restrictions of the platforms reached through it, and entitles it to suspend or terminate our access if that happens. That obligation runs upstream from us and we cannot transfer it, so we pass its substance to you as an obligation you owe to us. You therefore undertake, for every Connected Account and every message sent through it, that you will observe the terms of service, acceptable use policies, automation restrictions, rate limits and action limits of each platform concerned, that you will not use any Connected Account in a manner that a platform prohibits, and that you will stop immediately if we or the Connectivity Provider tell you that your use puts our access at risk. Breach of this section is a material breach for the purposes of section 18.
10.11 You assume the risk of this module, and you will not claim against us for it. You acknowledge that the messaging module depends on interfaces we do not control, provided by companies with which you have no contract and we have no influence, and that the risk of a warning, a limit, a restriction, a suspension, a block, a deletion or a permanent termination is inherent to connecting any account to any external tool, is materially higher for cold outreach and for high volumes, and cannot be eliminated by us.
Knowing that, and to the fullest extent permitted by law, you waive and will not bring any claim, demand or proceeding against us arising out of or in connection with: (1) any warning, rate limit, restriction, throttle, suspension, block, blocklisting, deletion or termination applied by a platform, by a provider or by the Connectivity Provider to any account, number, domain or address of yours; (2) any loss following from it, including loss of access, data, contacts, message history, sender or domain reputation, advertising accounts, revenue or business opportunity; (3) any interruption, degradation, delay, failure, duplication or non-delivery of a message; (4) any change, restriction, deprecation or withdrawal of an integration, whether by the platform, by the Connectivity Provider or by us; and (5) the suspension or discontinuation of the module, in whole or in part, including where we act at the request of a platform or of the Connectivity Provider or because we consider that continuing would place you or us at legal risk.
This waiver does not extend to our own wilful misconduct, and nothing in it excludes any liability that cannot lawfully be excluded. It does not affect any refund these Terms expressly provide, namely those in sections 12.6, 18.2 and 19.4. Section 16 applies to anything that survives it.
10.12 If your use costs us something. If the Connectivity Provider or a platform restricts, suspends, penalises or charges us, or brings any claim against us, because of your use of a Connected Account, you will reimburse us for every resulting cost, charge, penalty and expense, and section 17 applies. Where our access to a platform or to the Connectivity Provider is restricted or withdrawn for any reason, the affected features stop being available, that is not a failure of the Service, and section 10.6 governs it.
10.13 Survival. Sections 10.3, 10.5, 10.6, 10.7, 10.8, 10.10, 10.11 and 10.12 survive termination of these Terms and disconnection of any Connected Account.
11.1 Nature of AI Output. Certain features use artificial intelligence and machine learning models, including large language models operated by third-party providers, to produce AI Output. AI Output is generated automatically and probabilistically from inputs you supply or select. It is not reviewed, verified, approved or endorsed by any person at Vonsel before it reaches you.
AI Output may be inaccurate, incomplete, outdated, biased, offensive or misleading. It may state as fact matters that are false. It may attribute to a person or a business characteristics, conduct, statements or opinions that are inaccurate or damaging. It may resemble or reproduce material in which a third party holds rights, and it may differ between runs on identical inputs. Scores, signals and rankings are estimates, not findings.
11.2 Your review obligation. You must review, verify and where necessary correct all AI Output before you send it, publish it, share it, store it as a record or otherwise act on it.
11.3 You are the author and the publisher. As between you and us, any AI Output you send, publish or otherwise disseminate is your content and your statement. You are its author and its publisher for all legal purposes, including the law of defamation, unfair commercial practices, advertising, consumer protection and intellectual property. You must not represent to any recipient or third party that AI Output has been verified, checked, approved or endorsed by us.
11.4 Prohibited uses of AI features. Do not use AI Output as the sole basis for any decision producing legal effects, or similarly significant effects, concerning an individual, including decisions relating to credit, employment, housing, insurance or access to essential services. Do not use AI Output as legal, financial, tax, medical or other professional advice, or present it to a third party as such. Do not use AI features to generate content that is unlawful, defamatory, harassing, deceptive, discriminatory or infringing, or to impersonate any person or organisation. Do not submit to AI features any special category personal data within the meaning of Article 9 GDPR, health data, financial account data, government identifiers, or any data you are not entitled to disclose to a processor. Do not use AI features to develop, train, fine-tune, benchmark or improve a competing model or service.
11.5 Third-party model providers. To deliver AI features we transmit the inputs you provide, which may include Business Records, review text and text you have entered, to third-party model providers acting as our sub-processors. Some of them process data outside the European Economic Area, including in a country for which the European Commission has not adopted an adequacy decision. The categories of provider, the countries of processing and the transfer safeguards are set out in Annex 3 to Annex A, and section 12.6 governs how you can obtain their identity. If you do not wish your data to be processed in this way, do not use the AI features.
11.6 No warranty for AI Output. AI features and AI Output are provided "as is" and "as available", with no warranty that any AI feature will remain available, will continue to use any particular model or provider, or will produce consistent results. Sections 9, 15, 16 and 17 apply to them in full.
12.1 We act in two different capacities. For the purposes of the GDPR and any equivalent law:
We act as an independent controller in respect of (a) the account, registration, authentication, billing, tax, support, security and fraud prevention data that identifies you or your personnel; (b) the usage, telemetry, diagnostic and website analytics data generated by operating the Service and our website. That processing is described in our Privacy Policy.
We act as your processor in respect of (a) any Business Record you capture, import, save, edit, enrich, annotate, segment or otherwise store in your Workspace; (b) the notes, tags, pipeline data, tasks and other content you create in it; (c) the contents of the Connected Accounts you connect, and the messages you send and receive through the Service; and (d) every recipient you contact through the Service. In that capacity you are the controller.
12.2 The dividing line. A business record becomes Customer Personal Data under Annex A the moment you capture, import or save it into your Workspace. From that moment we hold it only as your processor, and our controller role over the data listed in section 12.1 does not extend to the contents of your Workspace.
12.3 You determine the purposes and the means. You alone determine which contacts are collected, which fields are retained, for how long, which recipients are contacted, through which channel, with what content and for what purpose. We do not determine any of those matters, and we do not process the contents of your Workspace for our own purposes. In particular, we do not sell, rent, share or aggregate Customer Personal Data across customers, and we do not use it to train machine learning models or to build or enrich any dataset or product of ours.
12.4 Your responsibilities as controller. You are responsible for determining, documenting and evidencing a valid legal basis for your processing and your outreach; for the information duties of Articles 13 and 14 GDPR, including the source of the data; for answering data subject requests, including the unconditional right to object to direct marketing under Article 21(3) GDPR and the right to erasure under Article 17 GDPR; for your own record of processing under Article 30 GDPR; for any data protection impact assessment your activities require; and for notifying the competent authority and the individuals concerned of any breach affecting data you control. Section A2.6 sets out the same obligations as warranties.
12.5 No joint control intended. Nothing in these Terms constitutes the parties as joint controllers. Where a supervisory authority or a court nevertheless determines that we act as joint controllers in respect of any processing, the parties agree that, as between them, you bear responsibility for the lawfulness of your outreach, for the information duties owed to the individuals you contact, and for responding to their requests, and section 17 applies accordingly.
12.6 The Data Processing Addendum and our sub-processors. The detailed terms governing our processing as your processor are set out in Annex A, the Data Processing Addendum, which forms part of these Terms. It is incorporated by reference and no separate signature is required, although we will countersign a copy on request.
How we describe them. To provide the Service we engage sub-processors. Annex 3 to Annex A sets out, for each category of sub-processor, its purpose, the categories of data it processes, the country or countries of processing and the transfer mechanism that applies. We describe them by category rather than by name in this published document, because the identity and composition of our suppliers is confidential commercial information about our infrastructure. The one exception is the Connectivity Provider named in section 10.4, which we identify because your own account credentials pass through it and you cannot decide whether to connect an account without knowing that.
How you obtain their names. We will give you the current list of our sub-processors by name, free of charge and within five (5) business days of a written request to privacy@vonsel.com, and before you are required to commit to the Service if you ask before subscribing. If we fail to provide it within that period, you may terminate the affected part of the Service without penalty and we will refund the unused portion of any prepaid fees. Section A6.5 sets out what the list contains and how it operates as Annex III to the Standard Contractual Clauses.
Notice of changes and your right to object. We will give you at least thirty (30) days' notice, by email to the address on your account, before a new sub-processor begins processing Customer Personal Data. You may object within those thirty days on reasonable and documented data protection grounds. If we cannot agree a solution in good faith, you may terminate the affected part of the Service without penalty, with a refund of the unused portion of any prepaid fees. Silence for thirty days is acceptance. Section A6.3 applies.
Our liability for them. Where a sub-processor fails to fulfil its data protection obligations, we remain fully liable to you for the performance of its obligations, in accordance with Article 28(4) GDPR.
12.7 If a business asks to be removed. A business whose published details sit in a Workspace, or the individual behind it, may write to privacy@vonsel.com asking us to act on those details. Where the request concerns data we hold as controller under section 12.1, we answer it ourselves. Where it concerns a Business Record in your Workspace, you are the controller and the decision is yours, so we acknowledge the request, tell the person that we act as a processor, and pass it to you without undue delay and in any event within five business days. You must then answer that person and act on the request within the periods that data protection law places on a controller, and you must tell us what you decided if we ask. We do not control the map, directory or website from which the details were published, and we cannot change or remove anything there.
12.8 Unlawful instructions. We will inform you immediately if, in our opinion, an instruction you give us infringes data protection law. We are not liable where, having been so informed, you maintain and apply that instruction.
13.1 You control your Workspace. You and the users you authorise control its content. Every action taken in it, including deleting records, notes, tags, areas, pipelines, Connected Accounts or the entire Workspace, and including actions taken in bulk, by import or through an API, is taken by you and at your risk, whether performed by you, by a user you have authorised, or by any person using credentials issued to your account.
13.2 Deletion is permanent. Deletion is immediate and irreversible. We do not operate a recycle bin, an undo facility or a customer-facing restore service, and we do not maintain backups for the purpose of restoring data you have chosen to delete. Any operational backup we maintain exists solely for our own disaster recovery and business continuity. It creates no right for you to have data restored and no obligation on us to attempt a restore. Where we agree, entirely at our discretion, to attempt recovery, we do so as a discretionary accommodation, without warranty that it will succeed or be complete, and we may charge our reasonable costs.
13.3 Retention periods are not a service commitment. Retention periods stated in our Privacy Policy describe how long we keep data for our own legal, accounting and operational purposes. They do not constitute a service commitment to preserve, restore or make available any data to you.
13.4 Your backup obligation. The Service provides export functionality in structured, commonly used, machine-readable formats. You are responsible for maintaining your own current and independent copies of any data whose loss would harm you, and you acknowledge that this allocation of responsibility is a condition of the price at which the Service is offered. To the fullest extent permitted by law, and save in case of our wilful misconduct, we are not liable for the loss, corruption, deletion or inaccessibility of your data, and our sole obligation in respect of data loss is to use commercially reasonable efforts to restore the Service itself.
14.1 Our property. The Service, including its software, algorithms, design, interfaces, text, graphics, logos, icons, images and documentation, is our exclusive property and is protected by intellectual property law. We grant you a limited, non-exclusive, non-transferable, revocable licence to use the Service in accordance with these Terms, for the term of your subscription. That licence does not include any right to modify, copy, distribute, display or create derivative works based on the Service.
14.2 Your content. You retain ownership of the content you upload to or create in your Workspace. You grant us a worldwide, non-exclusive, royalty-free licence to host, store, process and transmit it solely in order to provide the Service to you and in accordance with Annex A.
14.3 AI Output. As between you and us, AI Output you retain, send or publish is your content for the purposes of sections 14.2, 14.4 and 11.3. We make no representation that AI Output is original, that it can be protected by intellectual property rights, or that it does not resemble material of a third party.
14.4 Your content is confidential. The contents of your Workspace, including your Business Records, your notes, your pipeline data and the messages you send and receive through the Service, are your confidential information. We treat them as confidential, we disclose them only to the personnel and sub-processors who need them to provide the Service, and we do not use them for any purpose of our own. Annex A governs them where they contain personal data, and section 3.6 states what we do not do with them.
14.5 Feedback. If you give us feedback, suggestions or ideas about the Service, we may use them without obligation or compensation to you. Feedback is treated as non-confidential and non-proprietary.
15.1 As is. The Service is provided "as is" and "as available", without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy or non-infringement. We make no representation that the Service will be available at all times, uninterrupted, timely, secure or error-free, that it will meet your requirements, or that any defect will be corrected within a particular period.
15.2 No verification of business data. Business data made available through the Service is collected from public sources at the moment of capture and is provided to you as found. Unless a specific feature is expressly described as performing a validation and states the method it uses, we do not verify, validate, confirm, cleanse or test any business name, address, telephone number, email address, website, social profile, opening hours, rating, review or category.
Where the Service, our website or our marketing material describes data as "verified", that word means only that the value was found at the public source indicated, in the format indicated. It does not mean the value has been tested against any mail server, telephone network or other system. It is not a representation that the value is correct or in use, and it is not a representation about the identity of any person associated with it.
Public data changes. Businesses update listings, change numbers, relocate and close. We do not guarantee that any information is current at the moment you access it.
15.3 Deliverability and sender reputation. We do not warrant any delivery rate, inbox placement rate, open rate, response rate, bounce rate or conversion rate. Deliverability depends on factors outside our control, including your domain and IP reputation, your authentication records, your sending volume and cadence, your content, recipient filtering, and the policies of intermediate providers. You are solely responsible for the configuration, authentication, warm-up and reputation of every domain, mailbox, telephone number and account from which you send, and for every consequence of their degradation, blocklisting, throttling or suspension.
15.4 No guarantee of results. The Service is a tool. We make no representation as to the commercial results you will obtain from it, including any number of leads, replies, meetings, customers or amount of revenue. Any figure, example, benchmark, case study, screenshot or testimonial on our website or in our materials is illustrative only and is not a promise of comparable results.
15.5 Your verification obligation. You must verify, before use and at your own cost, that any data obtained through the Service is accurate, current, lawfully usable by you and suitable for your purpose. You accept that a proportion of any dataset collected from public sources will be inaccurate or out of date, that this is inherent to data of this kind, and that it is reflected in the price of the Service.
16.1 Excluded losses. To the fullest extent permitted by law, we are not liable for any indirect, incidental, special, consequential or punitive loss, nor for any loss of profit, revenue, anticipated savings, data, contacts, message history, sender or domain reputation, business opportunity, contract or goodwill, nor for any fine, penalty or sanction imposed on you by any authority, court or Connected Service, whether or not we were advised of the possibility of such loss.
16.2 Aggregate cap. Our total aggregate liability to you for all claims arising out of or related to the Service or these Terms, whether in contract, tort (including negligence), breach of statutory duty, restitution or otherwise, shall not exceed the greater of (a) the total amount you actually paid us for the Service in the twelve (12) months immediately preceding the first event giving rise to the claim, and (b) one hundred euros (EUR 100). Where the Service, or the feature to which the claim relates, is provided free of charge, our total aggregate liability shall not exceed one hundred euros (EUR 100). The existence of more than one claim does not increase this cap, and all claims arising from the same event, or from a connected series of events, constitute a single claim for the purposes of this section.
16.3 Time limit for claims. Any claim arising out of or related to the Service or these Terms must be notified to us in writing, with reasonable particulars, within twelve (12) months of the date on which you first became aware, or ought reasonably to have become aware, of the circumstances giving rise to it. To the fullest extent permitted by law, claims notified after that period are excluded.
16.4 Basis of the bargain. You acknowledge that the allocation of risk in sections 7, 9, 10, 11, 13, 15, 16 and 17 is a fundamental element of the basis on which we provide the Service, that our prices are set in reliance on it, and that we would not provide the Service on the same terms without it.
16.5 Exceptions. Nothing in these Terms excludes or limits our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, for wilful misconduct, or for any other liability that cannot lawfully be excluded or limited under the law governing these Terms.
17.1 Your indemnity. You agree to indemnify, defend and hold harmless Vonsel and its owners, officers, directors, employees, contractors and agents (each an "Indemnified Party") from and against any claims, demands, investigations, regulatory enquiries, proceedings, liabilities, awards, settlements, damages, fines, penalties, losses, costs and expenses (including reasonable legal, forensic and expert fees, and the costs of responding to an authority or a Connected Service at our then-current professional rates) arising out of or in connection with:
17.2 Article 82(5) GDPR. Where we have paid full compensation for damage suffered under Article 82 GDPR, and that damage is attributable in whole or in part to your processing, you shall reimburse us that part of the compensation corresponding to your part of the responsibility for the damage, in accordance with Article 82(5) GDPR.
17.3 Fines. To the fullest extent permitted by law, this indemnity extends to administrative fines and penalties imposed on an Indemnified Party that are attributable to your breach. Where applicable law prevents the recovery of a fine, this section remains fully effective in respect of all associated defence costs, investigation costs, compensation payable to third parties and any other recoverable loss, and the unenforceable element shall be severed without affecting the remainder.
17.4 Conduct of claims. We will notify you in writing without undue delay after becoming aware of a claim covered by this section. We may, at our option and at your expense, either allow you to assume the defence with counsel reasonably acceptable to us, or retain sole control of the defence and settlement, in which case you will cooperate fully, provide all information and assistance we reasonably request, and reimburse all costs as incurred and within thirty (30) days of invoice.
You may not settle, compromise or admit liability in respect of any claim in a way that imposes any obligation, admission, payment or restriction on an Indemnified Party without our prior written consent. We will not settle a claim in a way that imposes an obligation on you without your consent, such consent not to be unreasonably withheld, conditioned or delayed. Failure or delay in notifying you relieves you of your obligations only to the extent that you are actually and materially prejudiced by it.
17.5 Not subject to the cap. Section 16 limits our liability to you. It does not limit your obligations under this section 17, under section 9.7 or under section 20.6, none of which is subject to any cap or counts towards it.
17.6 Cooperation and records. Within ten (10) business days of a written request, and at your own cost, you will provide us with all records reasonably required to respond to an authority, a Connected Service or a third-party claim, including your legitimate interests assessment, your Article 30 records, evidence of the lawful basis relied on for the recipients concerned, your suppression list and evidence of the opt-out mechanism used.
17.7 Survival. This section survives the expiry or termination of these Terms and of your account, and continues to apply to any claim arising from your use of the Service before that date, for as long as such a claim may be brought under applicable law.
18.1 By you. You may terminate your account at any time using the cancellation procedure in section 6.1.
18.2 By us. We may terminate your subscription for cause, with immediate effect and without refund, where: you breach these Terms, and in particular sections 8, 9 or 10.3; you fail to pay fees when due, or you initiate a chargeback contrary to section 6.5; we reasonably suspect fraudulent, abusive or unlawful activity; we receive a credible complaint, a regulatory enquiry, or a notice from a Connected Service or an infrastructure provider concerning your use; or your conduct is, in our reasonable judgement, harmful to other users, to our reputation, or to the operation of the Service.
We may also terminate your subscription without cause on thirty (30) days' notice, in which case we will refund the unused portion of any fees you have paid in advance for the period after termination.
18.3 Immediate suspension. We may suspend or throttle your access, or any part of it, with immediate effect and without prior notice, where we have reasonable grounds to believe that any of the circumstances in section 18.2 exists, or where suspension is necessary to protect the Service, other users, a Connected Service or us. Section 9.5 applies to suspension for suspected breach of section 9. Suspension under this section is not a breach by us and gives rise to no refund, credit or liability. We will inform you as soon as reasonably practicable.
18.4 Effect of termination. On termination your right to access the Service ceases; you may export your data for thirty (30) days, after which we delete it in accordance with Annex A; section 13 applies to data you have already deleted; and no refund is due except where these Terms expressly provide for one.
18.5 Survival. Sections 6.4, 6.5, 7, 8, 9, 10, 11.3, 12, 13, 14, 15, 16, 17, 18.5, 19.6, 19.7, 20 and 21, and Annex A, survive termination, together with any other provision that by its nature should survive.
19.1 Dates and versions. These Terms are dated and versioned. This page shows the date on which the current version was last updated, and the archive at vonsel.com/legal lists every published version with its identifier and the date it took effect.
19.2 Material and non-material changes. We may amend these Terms. A change is material if it reduces your rights, increases your obligations, expands the purposes for which we process personal data, or alters our liability, our fees, or the governing law and jurisdiction. A change is non-material if it corrects a typographical error, clarifies a provision without altering its meaning, updates contact details, or is required by law or by an emergency security measure. Non-material changes take effect when the updated version is published.
19.3 Notice of material changes. For material changes we will give you at least thirty (30) days' prior notice, by email to the address associated with your account and by a notice inside your dashboard, stating the effective date of the new version and where it can be read. The change takes effect on the date stated in that notice.
19.4 If you do not agree. If you do not agree with a material change, you may terminate your subscription without penalty by notifying us before the effective date. Your subscription then ends on that date and we will refund the unused portion of any fees paid in advance for the period after it. If you do not terminate and you continue to use the Service after the effective date, you accept the new version.
19.5 Re-acceptance. We may require you to accept an updated version of these Terms in a specified manner before you may continue to use the Service, in which case the Service will ask you to confirm your acceptance when you next sign in.
19.6 Archive of previous versions. Every version of these Terms that we have published remains available at vonsel.com/legal, with the date it took effect, and each version is served at its own permanent address, reachable from that page. The version in force at the time of a given event governs the relationship between us in respect of that event.
19.7 Record of your acceptance. When you accept these Terms, we record the identity of the accepting account, the email address used, the date and time in UTC, the originating IP address and user agent, the documents and exact version identifiers shown to you, and a cryptographic digest of the text of each document as published at that moment. We keep that record for the duration of the relationship and for six (6) years afterwards, for the establishment, exercise and defence of legal claims. We will provide you with a copy of your record, and of the exact text you accepted, on request.
20.1 Governing law. These Terms, and any non-contractual obligation arising out of or in connection with them, are governed by the law of the Kingdom of Spain, without regard to its conflict of law rules and without regard to the United Nations Convention on Contracts for the International Sale of Goods.
20.2 Where the Service is provided. The Service is developed, operated and provided from Spain. Our obligations under these Terms are performed in Spain, the fees are payable in Spain, and these Terms are concluded in Spain at the moment your acceptance is recorded under section 19.7. Your own location, and the location of any recipient you contact, do not change the place of performance.
20.3 Talk to us first, and this is a condition. Before commencing any proceeding you must send us a written complaint under section 6.4 and allow the period stated there to expire. Compliance with this section is a condition precedent to any proceeding, and a proceeding commenced without it is premature and must be dismissed or stayed until it has been complied with.
20.4 Exclusive forum. Any dispute, claim or controversy arising out of or relating to these Terms, to the Service, or to any non-contractual obligation connected with either, shall be submitted to the exclusive jurisdiction of the courts of the city of Málaga, Spain. That jurisdiction is exclusive and not merely permissive. You accept this clause as a business and you acknowledge the declaration you gave in section 2.2. It is agreed by electronic means and recorded durably as described in section 19.7, and we will produce that record on request.
20.5 You will not sue elsewhere. You agree not to commence, join, fund or maintain any proceeding against us in any forum other than the one designated in section 20.4. You irrevocably waive any objection to that forum, including any objection based on venue, convenience or the doctrine of forum non conveniens, and you irrevocably consent to the dismissal, stay or transfer of any proceeding you bring elsewhere. You further agree that this clause may be produced in any such proceeding as conclusive evidence of your consent.
20.6 If you sue elsewhere anyway, you pay for it. If you commence or maintain a proceeding in breach of sections 20.4 or 20.5, you shall reimburse us, on demand, every cost we incur in obtaining its dismissal, stay or transfer, including local counsel, court fees, translation, sworn translation, service of process, travel and our own time at our then-current professional rates, whether or not that proceeding is ultimately dismissed. As section 17.5 provides, this obligation is not subject to the cap in section 16 and does not count towards it.
20.7 Waivers that apply only where a foreign court keeps the case. To the fullest extent permitted by the law of any forum in which a proceeding is nevertheless entertained, you waive any right to trial by jury, and you may bring a claim only in your individual capacity and not as a claimant or class member in any purported class, collective, consolidated, representative or mass action. This section is severable: if the waiver in it is held unenforceable in a given forum, the remainder of these Terms, and in particular sections 20.4 to 20.6, continue to apply in full.
20.8 Urgent measures. Nothing in this section prevents either party from applying to the courts designated in section 20.4 for urgent interim or protective relief, or prevents us from applying to any competent court for urgent relief to restrain an actual or threatened infringement of our intellectual property or unauthorised access to the Service.
20.9 Survival. This section survives the expiry or termination of these Terms and applies to any claim arising from your use of the Service before that date.
21.1 Entire agreement. These Terms, together with Annex A, the Privacy Policy and the Cookie Policy, constitute the entire agreement between you and us regarding the Service, and supersede all prior agreements, understandings, negotiations and representations, written or oral.
21.2 Order of precedence. In case of conflict: (1) Annex A, in respect of the processing of Customer Personal Data; (2) the body of these Terms; (3) the Privacy Policy and the Cookie Policy. The Standard Contractual Clauses referenced in Annex A prevail over Annex A in respect of international transfers.
21.3 Severability. If any provision is held invalid, illegal or unenforceable, the remaining provisions continue in full force, and the invalid provision is modified to the minimum extent necessary to make it valid while preserving its original intent.
21.4 Waiver. Our failure to exercise or enforce any right or provision is not a waiver of it, and a waiver of any term is not a continuing waiver of that or any other term.
21.5 Assignment. You may not assign or transfer these Terms without our prior written consent. We may assign them to an affiliate or in connection with a merger, acquisition or transfer of all or substantially all of our assets.
21.6 Force majeure. We are not liable for any failure or delay in performance due to causes beyond our reasonable control, including natural disasters, acts of government, pandemics, industrial action, telecommunications failures, power outages, cyber attacks, and interruptions of third-party services on which the Service depends.
21.7 Notices. We give notices to the email address associated with your account, by notice inside the Service, or by publication on our website where these Terms so provide. You give notices to info@vonsel.com, or to privacy@vonsel.com for data protection matters. Notices are deemed received on the next business day after they are sent.
21.8 Language. These Terms are drafted in English. The English version prevails. We may publish translations for convenience. In the event of any discrepancy, ambiguity or conflict between the English version and any translation, the English version governs, except where mandatory law in your jurisdiction requires otherwise.
21.9 No partnership. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between you and us.
The Service is provided by Vonsel.
This Data Processing Addendum ("DPA") forms an integral part of the Vonsel Terms of Service (the "Agreement") and applies whenever we process Personal Data on behalf of the Customer. By accepting the Agreement, the Customer enters into this DPA on its own behalf and, to the extent required under Data Protection Law, in the name and on behalf of its authorised affiliates.
The parties are (a) Vonsel, identified in section 1.3 of the Agreement ("Vonsel", "Processor"); and (b) the natural or legal person that has accepted the Agreement (the "Customer", "Controller"). A signed counterpart is available on request at privacy@vonsel.com and, where signed, prevails over this online version.
A1.1 "Data Protection Law" means Regulation (EU) 2016/679 ("GDPR"), Spanish Organic Law 3/2018 ("LOPDGDD"), Directive 2002/58/EC as implemented nationally, and any other applicable data protection or privacy legislation, as amended or replaced. "Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in Article 4 GDPR.
A1.2 "Customer Personal Data" means Personal Data that Vonsel Processes on behalf of the Customer in providing the Service, as described in Annex 1. "Service" has the meaning given in the Agreement.
A1.3 "SCCs" means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, or any successor clauses. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018.
A2.1 With respect to Customer Personal Data, the Customer acts as Controller and Vonsel acts as Processor. The Customer determines the purposes and means of the Processing, and Vonsel Processes Customer Personal Data only on the Customer's documented instructions.
A2.2 Vonsel as independent Controller. Vonsel acts as an independent Controller, and this DPA does not apply, with respect to (a) account, registration, authentication, billing, tax, support, security and fraud prevention data relating to the Customer and its users; (b) usage, telemetry, security, diagnostic and website analytics data generated by operating the Service. That Processing is described in the Vonsel Privacy Policy.
A2.3 The dividing line. Business records become Customer Personal Data under this DPA once the Customer captures, imports, saves, edits, enriches or otherwise stores them within its own account in the Service.
A2.4 No independent use. Vonsel does not sell, rent, share, aggregate across Customers, or use Customer Personal Data for its own purposes, including to train machine learning models or to build or enrich any Vonsel dataset or product.
A2.5 Article 28(10) GDPR. Nothing in the Agreement or this DPA authorises Vonsel to determine the purposes and means of Processing Customer Personal Data. If Vonsel were to do so, it would be considered a Controller in respect of that Processing.
A2.6 Customer responsibilities. The Customer warrants that it has a valid legal basis under Article 6 GDPR for the Processing it instructs, including for any direct marketing, cold outreach or commercial communication carried out through the Service; that it has given all notices and, where required, obtained all consents required under Data Protection Law and Directive 2002/58/EC as implemented nationally, including for email open and click tracking where enabled; that its instructions comply with Data Protection Law; and that it complies with the terms and acceptable use policies of every Connected Account it connects and remains solely responsible for the content, volume, frequency and recipients of the communications it sends.
A3.1 Vonsel Processes Customer Personal Data only on the Customer's documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law to which Vonsel is subject, in which case Vonsel informs the Customer of that requirement before Processing unless that law prohibits it on important grounds of public interest.
A3.2 The Customer's documented instructions consist of the Agreement, this DPA, the Customer's configuration and use of the features of the Service, and any further written instructions agreed by the parties. Additional written instructions outside the ordinary functionality of the Service may be subject to a reasonable fee agreed in advance.
A3.3 Article 28(3), final paragraph. Vonsel shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is confirmed, amended or withdrawn. Vonsel is not liable where, having been so informed, the Customer maintains and applies that instruction.
Customer Personal Data and the contents of the Customer's Workspace are the Customer's confidential information, and Vonsel treats them as such. Vonsel ensures that persons authorised to Process Customer Personal Data, including employees and contractors, have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is limited to personnel who need it to provide, secure or support the Service, under role-based access controls and least-privilege principles. These obligations survive termination of the Agreement.
Vonsel implements and maintains the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to the rights and freedoms of natural persons. Vonsel may update those measures from time to time, provided the overall level of security is not materially reduced. The Customer is responsible for the security of its own credentials, API keys, Connected Accounts and devices, and for the access it grants to its team members.
A6.1 General authorisation. The Customer grants Vonsel general written authorisation, within the meaning of Article 28(2) GDPR, to engage Sub-processors within the categories listed in Annex 3.
A6.2 Flow-down and liability. Vonsel imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA. Where a Sub-processor fails to fulfil its data protection obligations, Vonsel remains fully liable to the Customer for the performance of that Sub-processor's obligations, in accordance with Article 28(4) GDPR.
A6.3 Changes and objection. Vonsel gives the Customer at least thirty (30) days' prior notice, by email to the address on the Customer's account, of the addition or replacement of a Sub-processor. The Customer may object on reasonable, documented data protection grounds within that period, and the parties will discuss the objection in good faith. If no reasonable alternative is available, the Customer may terminate the affected part of the Service without penalty, with a pro rata refund of prepaid fees for the unused remainder of the term.
A6.4 Customer-authorised integrations. Where the Customer connects a Connected Account it controls, including a calendar, a mailbox or a messaging or social account, the provider of that account is not a Vonsel Sub-processor. Vonsel accesses it solely under the authorisation granted by the Customer, stores the corresponding credentials encrypted, and ceases access on revocation.
A6.5 Identity of Sub-processors. Annex 3 identifies Sub-processors by category of service, with the purpose, the categories of data, the country or countries of Processing and the transfer mechanism for each category. Vonsel does not publish the names of its suppliers, which are confidential commercial information about its infrastructure.
Vonsel will provide the Customer, free of charge and within five (5) business days of a written request to privacy@vonsel.com, with the current list of Sub-processors by name, stating for each its legal entity, purpose, location of Processing and applicable transfer mechanism, and will provide it to a prospective Customer before that Customer is required to commit to the Service. Vonsel may require the list to be kept confidential. The list so provided constitutes Annex III to the SCCs for the purposes of section A7, and is updated in accordance with section A6.3. If Vonsel fails to provide it within that period, the Customer may terminate the affected part of the Service without penalty, with a pro rata refund of prepaid fees for the unused remainder of the term.
A7.1 Where Processing of Customer Personal Data involves a transfer to a country outside the European Economic Area that is not subject to an adequacy decision of the European Commission, the transfer is governed by the SCCs, which are incorporated into this DPA by reference and are deemed executed by the parties on acceptance of the Agreement.
A7.2 The applicable module is Module Two (Controller to Processor) between the Customer and Vonsel, and Module Three (Processor to Processor) between Vonsel and its Sub-processors. For the purposes of the SCCs: (a) the data exporter is the Customer and the data importer is Vonsel or the relevant Sub-processor; (b) Clause 7 (docking clause) applies; (c) under Clause 9, Option 2 (general written authorisation) applies, with the notice period in section A6.3; (d) under Clause 11, the optional independent dispute resolution body does not apply; (e) under Clause 17, the governing law is the law of Spain; (f) under Clause 18(b), the forum is the courts of Spain; (g) Annexes I and II to the SCCs are populated by Annexes 1 and 2 to this DPA, and Annex III by the named list provided under section A6.5.
A7.3 Where a transfer is subject to UK data protection law, the UK Addendum applies to the SCCs. Where a transfer is subject to Swiss law, the SCCs apply with the amendments required by the Swiss Federal Data Protection and Information Commissioner.
A7.4 Clause 14 of the SCCs applies to each transfer identified in Annex 3, and the parties are bound by it. On written request, Vonsel provides the Customer with the destination, the transfer mechanism and the safeguards relied on for any such transfer.
A8.1 Forwarding. If Vonsel receives a request from a Data Subject relating to Customer Personal Data, Vonsel does not respond to it on the merits. Vonsel acknowledges receipt, informs the Data Subject that it acts as a Processor, and forwards the request to the Customer without undue delay and in any event within five (5) business days.
A8.2 Self-service tools. Taking into account the nature of the Processing, Vonsel assists the Customer primarily by making available, at no additional charge, functionality enabling the Customer to respond to Data Subject requests itself: search and retrieval of stored records by name, email address or telephone number, in support of Article 15; editing and correction of stored records, in support of Article 16; deletion of individual records, of selections of records, and of the Customer's entire account and its contents, in support of Articles 17 and 21; and export of the Customer's data in structured, commonly used, machine-readable formats, in support of Article 20.
A8.3 Limits of those tools. Deletion removes the record from the Customer's Workspace. It does not prevent the Customer, or a user it has authorised, from capturing or importing the same business again. As Controller, the Customer is responsible for ensuring that a record deleted in response to a Data Subject request is not re-captured or re-imported, and for maintaining and applying its own suppression list under section 9.3 of the Agreement.
A8.4 Additional assistance. Where a request cannot reasonably be fulfilled through the functionality in A8.2, Vonsel provides such further assistance as is technically possible and proportionate. Assistance requiring significant manual engineering effort may be charged at Vonsel's then-current professional services rates, agreed in advance. Vonsel does not charge for forwarding requests under A8.1 or for the functionality in A8.2.
A8.5 Limits of Vonsel's role. Vonsel does not verify the identity of Data Subjects, assess the merits of requests, determine the legal basis for the Customer's Processing, or communicate with supervisory authorities on the Customer's behalf. Those are the Controller's responsibilities.
A9.1 Vonsel notifies the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within seventy-two (72) hours of becoming aware of it. The notification includes, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Where information is not available at once, it may be provided in phases without further undue delay.
A9.2 Notification of a Personal Data Breach is not, and shall not be construed as, an acknowledgement by Vonsel of fault or liability. Notification to a supervisory authority under Article 33(1) and to Data Subjects under Article 34 is the Customer's responsibility as Controller.
A9.3 Taking into account the nature of the Processing and the information available to it, Vonsel provides reasonable assistance with data protection impact assessments (Article 35) and prior consultations (Article 36), limited to information concerning Vonsel's own Processing operations, security measures and Sub-processors.
A10.1 Vonsel makes available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. That right is satisfied in the first instance by Vonsel providing the security documentation described in Annex 2, the transfer information described in section A7.4, the named Sub-processor list under section A6.5, and any third-party certification or audit report it holds.
A10.2 Where that documentation is insufficient to address a specific, documented concern, the Customer may conduct an on-site or remote audit, subject to the following, which the parties agree are reasonable: (a) no more than once in any twelve (12) month period, except where required by a supervisory authority or following a Personal Data Breach affecting the Customer; (b) at least thirty (30) days' prior written notice; (c) during normal business hours and without disrupting the Service or the confidentiality of other Customers' data; (d) subject to a written confidentiality agreement; (e) the auditor must not be a competitor of Vonsel; and (f) the Customer bears its own costs and Vonsel's reasonable costs of supporting the audit.
On termination or expiry of the Agreement, the Customer may export Customer Personal Data using the functionality of the Service for thirty (30) days. After that period Vonsel deletes Customer Personal Data, and procures that its Sub-processors delete it, except where Union or Member State law requires storage, in which case Vonsel informs the Customer and Processes the retained data only for the purpose and duration of that obligation. Backups containing Customer Personal Data are deleted in the ordinary course of Vonsel's backup rotation, and in any event within ninety (90) days of termination; until deletion, retained data remains subject to this DPA. On written request made within the export period, Vonsel certifies in writing that deletion has been carried out.
A12.1 Vonsel's liability under this DPA is subject to the limitations and exclusions in the Agreement. The Customer's obligations under sections 9.7, 10.12, 17 and 20.6 of the Agreement are not subject to any cap and do not count towards it, as section 17.5 provides. Nothing in this DPA limits either party's liability (a) to a Data Subject under Article 82 GDPR; (b) for administrative fines imposed on that party by a supervisory authority; (c) for wilful misconduct or fraud; or (d) for any liability that cannot lawfully be limited.
A12.2 Indemnity. The Customer shall indemnify and hold Vonsel harmless against any claim, fine, penalty, loss or expense, including reasonable legal fees, arising from (a) the Customer's breach of section A2.6, (b) instructions that infringe Data Protection Law, or (c) the Customer's use of Customer Personal Data for communications for which it lacked a valid legal basis.
A12.3 Where both parties are liable for the same damage under Article 82(4) GDPR, each may claim back from the other the part of the compensation corresponding to that other party's part of the responsibility, in accordance with Article 82(5) GDPR.
This DPA takes effect on acceptance of the Agreement and continues until Vonsel has ceased all Processing of Customer Personal Data. Vonsel may update it on thirty (30) days' prior notice where required by Data Protection Law, by a supervisory authority, or to reflect a change of Sub-processor under A6.3; no update will materially reduce the protections afforded to Customer Personal Data, and superseded versions remain available at vonsel.com/legal. In the event of conflict, this DPA prevails over the Agreement in respect of the Processing of Customer Personal Data, and the SCCs prevail over this DPA in respect of transfers. This DPA is governed by the law of Spain and the courts designated in section 20.4 of the Agreement have exclusive jurisdiction, without prejudice to Clauses 17 and 18 of the SCCs. Data protection enquiries: privacy@vonsel.com.
(SCC Annex I.B)
Subject matter. Provision of the Vonsel Service: a business-to-business sales intelligence and CRM platform through which the Customer captures, stores, organises, enriches, analyses and contacts its own business prospects.
Duration, frequency and retention. The term of the Agreement, plus the retention periods in section A11. Transfers are continuous for the duration of the Agreement.
Nature of the Processing. Collection on the Customer's instruction, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, analysis by artificial intelligence models, transmission of communications, erasure and destruction, all by automated means.
Purpose. To enable the Customer to manage its business prospecting and customer relationships, including lead management, pipeline tracking, geographic visualisation, artificial intelligence assisted analysis and scoring, calendar scheduling, and outbound email and messaging initiated by the Customer.
Categories of Data Subjects. Business owners, sole traders, self-employed professionals and named employees of the businesses the Customer stores as prospects, where those records identify a natural person; individuals who authored publicly posted reviews of those businesses, to the extent that review text is stored or analysed; recipients and senders of communications sent or received through the Service; and the Customer's own users and invited collaborators, in respect of activity records the Customer controls.
Categories of Personal Data.
Special categories of data. None are requested or required. The Service is not designed for, and the Customer must not use it to Process, data of the categories listed in Article 9(1) GDPR or data relating to criminal convictions and offences under Article 10 GDPR. Free-text fields are not monitored, and the Customer is responsible for what it enters into them.
(SCC Annex II, Article 32 GDPR)
Encryption in transit. Transport layer encryption on all connections to the application, its interfaces and the database. HTTPS is enforced.
Encryption at rest. Passwords are stored only as salted, one-way hashes produced by a computationally hard hashing function. Authorisation tokens for connected mailboxes, calendars and messaging accounts are stored encrypted under a dedicated application key held separately from the database. Database storage is encrypted at the infrastructure layer.
Tenant isolation. Every record containing Customer Personal Data is bound to a single Customer identifier and is retrievable only through it, with cascading deletion. There is no shared or cross-Customer store of prospect records.
Access control. Authentication by hashed password or federated identity, with session tokens. Role-based access for team members. Administrative access restricted to named personnel and granted on a least-privilege basis.
Application hardening. A restrictive, allowlist-based content security policy limits the sources from which content may be loaded or contacted.
Abuse and fraud prevention. Rate limiting on authentication and interface endpoints, an automated challenge on registration, and reputation checks on the originating network address.
Logging and auditability. Application and access logs retained for security monitoring and incident investigation. An in-application activity log records changes to Customer records, including actor, field and previous value.
Backups. Any backup of the production database exists for our own disaster recovery and business continuity and, as section 13.2 of the Agreement provides, creates no right to have data restored. Section 13.4 places the obligation to keep independent copies on the Customer.
Incident response. Personal Data Breaches are identified, contained, assessed and notified in accordance with section A9.1, and the actions taken are recorded.
Change management. Version-controlled source code, reviewed changes, and separated development, staging and production environments with distinct credentials.
Personnel. Confidentiality undertakings for all personnel with access to Customer Personal Data, and data protection awareness appropriate to role.
(SCC Annex III)
The Customer's general written authorisation under section A6.1 extends to the categories below. The identity of each Sub-processor within a category is provided to the Customer on request under section A6.5, free of charge and within five business days, and that named list, as provided, populates Annex III to the SCCs.
| # | Category of service | Purpose | Categories of data | Country of Processing | Transfer mechanism |
|---|---|---|---|---|---|
| 1 | Cloud infrastructure and database hosting | Hosting of the application and of the production database | All Customer Personal Data stored in the Service | European Economic Area or United States, depending on the region in which the production environment is hosted | Where Processing takes place outside the EEA: SCCs Module Three and the provider's own data processing terms |
| 2 | Unified messaging and mailbox connectivity, identified in section 10.4 of the Agreement | Connection, synchronisation and transmission for the Customer's Connected Accounts | Message content and metadata, contact identifiers, connected account credentials | European Union | None required. Processing within the EEA |
| 3 | Artificial intelligence model provider: review analysis and lead signals | Analysis of publicly posted reviews, generation of lead signals and scores | Business name and category, public review text, lead context | Singapore | No adequacy decision. SCCs Module Three, with Clause 14 applying to the transfer |
| 4 | Artificial intelligence model providers: drafting, assistance, transcription and routing | Drafting of outreach messages, in-product assistant, transcription of voice notes, and routing of requests to models on an allowlist configured by Vonsel | Prompt content, business name and category, review text, lead context, voice audio and transcripts | United States, with European Union Processing where the provider offers it | SCCs Module Three plus the provider's data processing terms. Downstream model providers restricted to an allowlist configured by Vonsel. Interface data excluded from model training |
| 5 | Transactional email delivery for our own service messages | Delivery of the messages we send you as a customer, such as verification codes, security alerts and billing notices. Email you send to your own recipients leaves through your Connected Account under category 2 | Your email address, subject, message body | United States | SCCs Module Three plus the provider's data processing terms |
| 6 | Outbound and transactional email delivery, fallback relay | Delivery of email where the primary provider is unavailable | Recipient email address, subject, message body | European Union | None required. Processing within the EEA |
| 7 | Map rendering | Display of Customer records on a map | Geographic coordinates of Customer records, end-user network address | United States | SCCs Module Three plus the provider's data processing terms |
Disclosed because customers ask about them. They are not Sub-processors under this DPA.
| Category of service | Purpose | Capacity | Country of Processing |
|---|---|---|---|
| Payment processing | Payments, subscriptions and tax | Independent controller in respect of payment data. Does not access the Workspace | European Economic Area, with a United States parent |
| Website and product analytics | Measurement of how our website and our interface are used. Session replay runs on our public pages only | Processor for Vonsel as controller of website visitor data | United States and European Union |
| Bot challenge, content delivery and network reputation | Automated challenge on registration, cache control, and reputation checks on the originating network address | Processor for Vonsel as controller | United States, and the United Kingdom under an adequacy decision |
Third-party services the Customer connects under its own account, including calendar providers, mailbox providers, and messaging and social platforms, are accessed under the Customer's own authorisation and are not engaged by Vonsel. Section A6.4 applies.