BD
Bad Decision
How it worksProductsIntegrationsPricingCase studies
Sign inStart free
BD
Bad Decision

One platform to find, reach, and book.

Product

  • How it works
  • Products
  • Integrations
  • Pricing
  • Case studies
  • Blog
  • FAQ
  • Guarantee

Company

  • About
  • Contact
  • Affiliates
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Cookie Policy
  • DPA

© 2026 Germaine 50 Technologies. All rights reserved.

One platform to find, reach, and book.

Data Processing Addendum (DPA)

Last updated: January 1, 2025 · Operated by Germaine 50 Technologies (Lagos, Nigeria) · support@baddecision.app

This Data Processing Addendum ("DPA") forms part of the Germaine 50 Technologies ("Bad Decision", "Processor") Terms of Service. It applies to the extent you ("Customer", "Controller") process personal data through the Service.

This DPA reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Nigeria Data Protection Act (NDPA) 2023.

1. Roles

You are the Controller. You decide why and how lead data is processed. Bad Decision is the Processor. We process lead data only on your instructions, to provide the Service to you.

You are responsible for having a lawful basis (consent or legitimate interest) to process the leads you upload or find, and for honoring data subject rights requests.

2. What We Process

We process the following on your behalf:

  • Lead data (name, email, phone, company, social links).
  • Email content and engagement data (opens, clicks, replies).
  • WhatsApp and SMS message content and delivery status.
  • AI voice call recordings, transcripts, and outcomes.
  • Scheduling and booking data.
  • Automation flow definitions and execution logs.

We process this data only to provide the Service. We never use your data to train our own models or sell it to anyone.

3. Sub-Processors

We use the following sub-processors to deliver the Service. Each is bound by a written agreement with equivalent data protection obligations. This list is current as of the last-updated date above; we maintain a live list at /subprocessors and notify customers at least 30 days before engaging any new sub-processor.

Sub-processorPurposeLocation
WorkOS, Inc.Authentication and sign-inUnited States
Supabase, Inc.Postgres database and file storageUnited States / EU
FlutterwaveSubscription and add-on payment processingGlobal
Telnyx LCSMS and AI voice callingGlobal
Meta Platforms, Inc.WhatsApp Business API message deliveryGlobal
Vercel, Inc.Web application hostingGlobal edge
Cloudflare, Inc.CDN, DNS, and DDoS protectionGlobal edge
OpenAI, L.L.C.AI message drafting and conversationUnited States
Anthropic PBCAI message drafting and conversationUnited States
Google LLC (Gemini)AI message drafting and conversationGlobal
Resend, Inc.Transactional and campaign email deliveryUnited States
Minimax (Hailuo)Text-to-speech for AI voice callsGlobal
Cal.comMeeting scheduling and bookingGlobal

We will notify you at least 30 days before engaging any new sub-processor. You may object by emailing us. If we cannot resolve your objection, you may terminate with a pro-rata refund.

4. Data Location

Your data is stored with our database provider in the United States or EU, depending on your region. Backups are kept for 30 days. Your data may be transferred to other countries for processing. We comply with applicable data protection laws including NDPR (Nigeria) and GDPR (EU) for EU residents' data, and use Standard Contractual Clauses (or other appropriate transfer mechanisms) where personal data is transferred outside its region of origin.

5. Data Subject Rights

We help you respond to data subject requests by providing:

  • A data export tool that produces lead data in CSV or JSON.
  • An account deletion tool that permanently removes data within 30 days.
  • Reasonable cooperation for complex requests at no charge for the first 5 per year.

We forward any data subject request we receive directly to you for response.

6. Breach Notification

If a personal data breach happens, we will notify you without undue delay and in any case within 72 hours. The notice will describe the nature of the breach, the likely consequences, and the measures we are taking.

We will cooperate with you to meet your own breach notification obligations under GDPR Article 33.

7. Deletion on Termination

When your subscription ends, we will delete or return all personal data within 30 days, at your choice. We may retain billing records for 7 years for tax compliance, and security logs for 12 months.

To request deletion or export, email us at support@baddecision.app with the subject "DPA request".

Questions about this policy?
Email us at support@baddecision.app and we will get back to you within 24 hours.