Continuum API

Data Processing Agreement

Version 1.0 — Effective August 28, 2026

This Data Processing Agreement ("DPA") is entered into between Signalpulse Technologies LLC ("Continuum", "Processor") and the customer entity that has agreed to the Terms of Service ("Customer", "Controller"). It forms part of the agreement between the parties and governs the processing of personal data by Continuum on behalf of Customer.

This DPA is based on the Bonterms Data Processing Agreement v1.0 (incorporated by reference) and supplements it with the details below.

1. Definitions

"Personal Data" means any information that relates to an identified or identifiable natural person submitted to the Continuum API for processing. "Processing" has the meaning in applicable data protection law (GDPR, UK GDPR, CCPA, and equivalents). Capitalized terms not defined here have the meanings given in the Bonterms DPA.

2. Scope and purpose of processing

  • Categories of data subjects: contacts whose email addresses, phone numbers, or IP addresses Customer submits for verification or monitoring.
  • Categories of personal data: email addresses, phone numbers, IP addresses, and associated metadata returned by the API (MX records, deliverability signals, carrier data, geolocation).
  • Purpose: email and phone verification, deliverability monitoring, and bulk validation as requested by Customer via the API.
  • Duration: for the term of Customer's account plus any retention period required by applicable law or specified in the Privacy Policy.

3. Customer obligations

Customer is responsible for ensuring it has a lawful basis to submit personal data to the Continuum API and for providing any required notices to data subjects. Customer must not submit sensitive personal data (as defined under GDPR Article 9) to the API.

4. Continuum obligations

Continuum will:

  • Process personal data only on Customer's documented instructions and as permitted by applicable law.
  • Ensure personnel authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures as described in the Security Exhibit.
  • Notify Customer without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach affecting Customer data.
  • Assist Customer in responding to data subject rights requests, to the extent technically feasible.
  • On termination, delete or return Customer personal data within 30 days unless retention is required by law.

5. Subprocessors

Customer authorizes Continuum to engage the subprocessors listed at continuumapi.com/legal/subprocessors. Continuum will give Customer at least 10 days' notice before adding or replacing a subprocessor. Customer may object in writing within that period on reasonable grounds.

6. International transfers

Continuum stores and processes data in the United States (AWS us-east-1 via Supabase and Railway). For transfers from the EEA, UK, or Switzerland, Continuum relies on Standard Contractual Clauses (Controller-to-Processor) as approved by the European Commission (Decision 2021/914) or the UK ICO as applicable.

7. Audit rights

Continuum will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by Customer or a mandated third-party auditor, subject to reasonable notice (minimum 30 days) and confidentiality obligations. Continuum may satisfy audit requests by providing its most recent SOC 2 report in lieu of an on-site audit.

8. Limitation of liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.

9. Governing law

This DPA is governed by the same law as the Terms of Service (Delaware, United States).

10. Contact

Data protection inquiries: privacy@continuumapi.com. For formal data subject requests, please include "Data Subject Request" in the subject line.