Version 1.0. Effective: May 13, 2026. Published at https://2ctsalesco.com/dpa.
This Data Processing Agreement ("DPA") forms part of the agreement between 2CanTalks LLC, a Wyoming limited liability company trading as 2CT Sales Co. ("Processor", "we"), and the client identified in a signed Service Order or Master Services Agreement that references this DPA ("Controller", "you"). This DPA applies whenever we process personal data on your behalf in the course of providing the Services. Capitalised terms not defined here have the meanings given in your Service Order or in the applicable data protection law.
1. Scope and roles
For all personal data processed under your Service Order, you act as Controller (or processor on behalf of a third-party controller) and we act as Processor. We process personal data only on your documented instructions, which are set out in your Service Order and in this DPA. We will inform you if, in our opinion, an instruction infringes applicable data protection law.
2. Subject matter, nature, and purpose
Subject matter: provision of outbound prospecting, inbound qualification, appointment setting, and related sales development services.
Nature and purpose: contacting prospects via phone, email, and LinkedIn on your behalf to set qualified sales meetings.
Duration: the term of the applicable Service Order plus any post-termination retention period required by law.
Categories of data subjects: your prospects, customers, and contacts that you provide to us or instruct us to target.
Categories of personal data: business contact data (name, job title, employer, business email, business phone, LinkedIn URL), engagement records (call notes, email correspondence, meeting outcomes), and any additional fields you choose to provide. We do not process special categories of personal data unless expressly agreed in writing.
3. Processor obligations
We will: (a) process personal data only on your documented instructions; (b) ensure that personnel authorised to process personal data are subject to confidentiality undertakings; (c) implement appropriate technical and organisational measures consistent with the risk (see Section 5); (d) assist you in fulfilling data subject rights requests, security obligations, and data protection impact assessments, taking into account the nature of processing and the information available to us; (e) at your choice, delete or return all personal data after the end of the provision of Services, except where retention is required by applicable law; and (f) make available to you the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as set out in Section 7.
4. Sub-processors
You give us a general authorisation to engage sub-processors for the Services. We will inform you of any intended addition or replacement of sub-processors at least ten (10) business days in advance, giving you an opportunity to object on reasonable grounds. If you object, we will work in good faith to find a workable resolution; if none is found, you may terminate the affected Service Order on written notice.
Current sub-processors include: cloud hosting and infrastructure providers; CRM, dialler, and email delivery platforms used to operate the Services; identity and access management providers; analytics and observability providers; and customer-data tooling. A current list is available on written request to justin@2ctsalesco.com.
We remain liable to you for the acts and omissions of our sub-processors as if they were our own.
5. Security measures
We implement and maintain technical and organisational measures appropriate to the risk, including: (a) access control (least-privilege, MFA on administrative accounts, role-based access); (b) encryption of personal data in transit using TLS and at rest where supported by the underlying platform; (c) network controls (firewalls, segmentation, monitored egress); (d) endpoint security (managed devices, disk encryption, anti-malware); (e) logging and monitoring of access to systems holding personal data; (f) personnel measures (background checks where permitted by law, security training, confidentiality undertakings); (g) physical security at our facilities; (h) backup and restore procedures with documented recovery objectives; and (i) a documented incident response process.
6. Personal data breach notification
We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting personal data processed under your Service Order. Our notification will include, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects. We will provide further information as it becomes available.
7. Audits
We will make available to you, on reasonable written request, the information necessary to demonstrate compliance with this DPA, including the most recent third-party assurance reports and security questionnaires we hold. Where you reasonably require further verification, you may conduct an audit (including inspections) once per twelve-month period, on at least thirty (30) days' prior written notice, during normal business hours, at your own cost, and subject to reasonable confidentiality and security requirements. We may, in our reasonable discretion, require that an audit be conducted by an independent third-party auditor. The audit scope is limited to the processing carried out for you under your Service Order.
8. International transfers
You acknowledge that we operate from South Africa and that personal data may be transferred to and processed in South Africa and other jurisdictions where we or our sub-processors operate. Where transfers from the European Economic Area, the United Kingdom, or Switzerland are involved, the Parties agree that the Standard Contractual Clauses approved by the European Commission (and, as applicable, the UK International Data Transfer Addendum) are incorporated into this DPA by reference and apply to those transfers. Where transfers from South Africa are involved, we will comply with POPIA requirements for cross-border transfers, including ensuring adequate safeguards.
9. Data subject requests
If we receive a request from a data subject in respect of personal data we process on your behalf, we will, where lawful, refer the request to you without undue delay. We will provide reasonable assistance to enable you to respond to data subject rights requests under applicable law, including rights of access, rectification, erasure, restriction, portability, and objection.
10. Return and deletion
On termination or expiry of your Service Order, we will, at your choice and at your written request: (a) return personal data to you in a commonly used machine-readable format; or (b) securely delete personal data from our active systems. Backups will be overwritten in the ordinary course. We may retain personal data to the extent and for the period required by applicable law, subject to ongoing confidentiality.
11. Liability
Each Party's liability under this DPA is subject to the limitation of liability in the applicable Service Order or, if absent, Section 12 of the Operational Terms. Nothing in this DPA limits a Party's liability where such limitation is not permitted by applicable data protection law.
12. Governing law and order of precedence
This DPA is governed by the laws of the State of Wyoming, subject to mandatory provisions of applicable data protection law. In the event of conflict between this DPA and the Operational Terms or a Service Order, this DPA controls for the subject of personal data processing.
13. Contact
Data protection contact: justin@2ctsalesco.com
2CanTalks LLC, 1309 Coffeen Avenue, STE 1200, Sheridan, WY 82801, USA
EIN: 33-2287125