ICP LensICP Lens
    DPA

    Data Processing Agreement

    Effective: June 7, 2026·FOP Khromushkin Kostiantyn Mykolajovych, Ukraine·privacy@icplens.com

    This Data Processing Agreement (DPA) applies to customers who upload personal data of EU/EEA data subjects when using ICP Lens, operated by FOP Khromushkin Kostiantyn Mykolajovych, registered in Ukraine (registration number 3273705914). It supplements our Terms of Service and Privacy Policy.

    Who needs a DPA

    If your CRM export contains personal data of individuals located in the EU or EEA — such as contact names, email addresses, or job titles — and your organisation is subject to GDPR, a DPA between you (the data controller) and ICP Lens (the data processor) may be required under Article 28 GDPR.

    In practice, ICP Lens parses and scores your uploaded file entirely in your browser — the original CSV or Excel file is never transmitted to our servers. What is sent to our servers is the derived result of that analysis, which includes account names, deal values, and job-title clusters used to populate your dashboard, shareable links, and PDF exports. We treat this stored derived data as personal data under GDPR and protect it with Row Level Security scoped to your account, encryption at rest and in transit, and EU-region hosting (Frankfurt, Germany).

    If your legal or compliance team requires a signed DPA, we are happy to provide one.

    How to request a DPA

    • Email privacy@icplens.com with subject line: DPA Request
    • Include your company name, registered country, and contact name
    • We will respond within 3 business days with a DPA document for review
    • The DPA is governed by Ukrainian law and incorporates the EU Standard Contractual Clauses (SCCs) for transfers of personal data outside the EEA

    What the DPA covers

    • Scope and subject matter of processing
    • Categories of personal data and data subjects
    • Confidentiality and security measures
    • Sub-processor arrangements and prior authorisation
    • Data subject rights and breach notification
    • Audit rights and termination obligations
    • International data transfer safeguards (SCCs)

    Sub-processors

    ICP Lens currently uses the following sub-processors:

    • Supabase Inc. — database and authentication infrastructure, EU region (Frankfurt, Germany). Stores the derived results of your analysis. DPA at supabase.com/legal/dpa
    • Paddle.com Market Ltd — payment processing as Merchant of Record. Processes billing and customer contact data only; has no access to your CRM data or analysis results.
    • Google LLC (Google Analytics) — website analytics, loaded only after cookie consent. Has no access to your CRM data or analysis results.

    Your original uploaded file is never stored by any sub-processor; all file parsing and scoring happens in your browser before any data reaches our servers. Stored derived data is treated as personal data under GDPR and is protected by Row Level Security, encryption at rest and in transit, and EU-region hosting.

    Contact

    ICP Lens
    Email: privacy@icplens.com
    Website: icplens.com
    Country of Registration: Ukraine
    Registration number: 3273705914