ASTROLABE A Noble Base Product
Features Pricing
Try Demo Sign in Get Started
Features Pricing
Try Demo Sign in Get Started

Legal

Data Processing Addendum

Our responsibilities when we process personal information on your organization’s behalf.

Last updated

September 8, 2026

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Service providers

Contact Noble Base, Inc.

hello@noblebase.ai

600 W Peachtree St NW
Ste 1700 PMB 289
Atlanta, GA 30308

1. Scope and instructions

This DPA forms part of the Terms of Service between Noble Base, Inc. and the customer organization. It takes effect when those Terms are accepted; no separate signature is required.

Customer Personal Data means personal information we process on your behalf to provide the service, including customer-supplied records and the results processed on your instructions. Applicable Data Protection Law means the privacy and data-protection laws that apply to that processing, including applicable US state laws and, where applicable, the GDPR or UK GDPR.

For processing on your behalf, you act as controller or business and we act as processor or service provider. If you act for another controller, you must have authority to provide the instructions. These labels do not override roles imposed by law. Our separate account, billing, security, and other independent operations are described in the Privacy Policy; a provider's independent collection of its source database is not processing on your behalf under this DPA.

Your documented instructions consist of the agreement and your authorized use of the service, including requests for enrichment, prospect generation, analysis, and exports. We will process Customer Personal Data only on those instructions, unless law requires otherwise. Where permitted, we will inform you of that requirement before processing. We will inform you if we believe an instruction violates Applicable Data Protection Law.

2. Processing details

  • Purpose and activities: receiving, storing, matching, enriching, analyzing, organizing, retrieving, delivering, supporting, and deleting data for the requested audience-intelligence services.
  • People concerned: your customers, contacts, and prospects represented in supplied or requested data.
  • Data types: contact identifiers, customer activity, geographic and household attributes, demographic and interest information, business context, and generated reports and assignments. Exact fields depend on your instructions and plan.
  • Duration: provision of the service and the applicable retention and deletion periods in section 7. Provider sources have a shorter lifecycle than customer inputs and derived analysis.

The prohibited-data restrictions in the Terms apply. Do not instruct us to process those categories. You are responsible for required notices, lawful bases, permissions, and the legality of your instructions. We remain responsible for our own obligations under this DPA and applicable law.

3. Use restrictions and confidentiality

For Customer Personal Data processed as a service provider or contractor under the CCPA, we will not sell or share that data, retain, use, or disclose it outside the direct business relationship or the specified business purposes, or combine it with information from other sources except as permitted by the CCPA. Customer-requested enrichment must remain within those permitted purposes and applicable law. We will provide the same level of privacy protection required by the CCPA and notify you if we determine we can no longer meet these obligations. You may take reasonable steps to verify compliance and stop or remediate unauthorized use.

We will not use identifiable Customer Personal Data to train models for other customers or disclose your private uploads or reports to other customer organizations. Access by personnel is limited to authorized purposes and subject to confidentiality obligations. We will maintain appropriate technical and organizational security measures in light of the processing and its risks.

4. Assistance and incidents

Taking account of the nature of processing and the information available to us, we will reasonably assist you with individual rights requests, security obligations, data-protection impact assessments, and regulator consultations required by applicable law. We will inform you of requests concerning Customer Personal Data and will not independently fulfill a request on your behalf unless you authorize us or law requires it.

We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and meet applicable legal notification requirements. We will email an affected customer's account contact directly and provide available information about the nature of the breach, affected data, likely consequences, containment and remediation, and a contact for follow-up. Information may be provided in stages as it becomes available. Public incident updates, if available, do not replace direct notice.

We will take reasonable steps to contain and investigate the incident and cooperate with your required response. A notice is not by itself an admission of liability. Contact hello@noblebase.ai for privacy or security matters.

5. Service providers and changes

You give general authorization for the subprocessors identified on our service provider list to process Customer Personal Data for the described purposes. We will impose applicable data-protection obligations on subprocessors by contract and remain responsible for their performance of those obligations to the extent required by this DPA and law.

We will email affected customers at least 15 days before a new or replacement subprocessor begins handling their Customer Personal Data and update the public list. The notice will identify the provider, its purpose, the planned start date, and how to raise concerns. Separate affirmative customer approval is not required.

You may object on reasonable data-protection grounds by replying before the planned start date. We will discuss the concern and seek a reasonable resolution, such as avoiding the provider for the affected processing where feasible. We will not route your affected Customer Personal Data to the proposed subprocessor while a timely, reasonable objection remains unresolved. If no workable resolution is available, the parties may end the affected processing. This process does not limit objection or other rights required by applicable law.

6. International processing

Your instructions may involve providers processing information outside your country. We will comply with applicable requirements for international transfers of Customer Personal Data. Where a transfer requires standard contractual clauses or another safeguard, the appropriate mechanism must be put in place before that transfer. This DPA does not itself represent that transfer clauses have been signed or that every transfer is authorized. Contact us before instructing processing that requires an additional transfer arrangement.

7. Return and deletion

You may retrieve available data through authorized downloads during service access. Provider-result downloads expire 30 days after first readiness; repeated downloads and account termination do not renew that period. For accounts enrolled in automatic source deletion, after expiry our cleanup process removes provider source records and source-bearing files from active service storage. Failed or abandoned processing has a separate seven-day processing deadline. Customer inputs and derived reports and assignments remain separately available during ongoing service.

Automatic source deletion is enabled for new customer accounts and existing accounts that have completed our retention review. Other existing accounts are not yet enrolled: their expired provider sources may remain in active storage pending review and enrollment. The 30-day download limit applies even when automatic deletion has not been enabled. Contact us to check your account's status or request deletion.

When paid subscription access actually ends, Customer Personal Data in active service storage, including inputs, results, generated reports, saved prompts, and related analysis, is scheduled for deletion within 30 days. Reactivation can cancel pending deletion only before cleanup starts. For Wrapped, account closure, an earlier deletion request, or assistance returning still-available data, contact us. We will follow your lawful deletion or return instructions, unless law requires retention. There is no new download window for already expired sources.

Account, billing, usage, and acceptance records retained for our separate administration or legal obligations are governed by the Privacy Policy. Inaccessible backups may age out normally and remain isolated from ordinary use; applicable cleanup must precede restored access. Provider operational copies remain subject to applicable contractual and legal requirements. Customer-held downloads are outside our deletion process.

8. Compliance information and audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by you or a qualified auditor you appoint where required by applicable law. Coordinate reasonable scope, confidentiality, security, and timing with us. Existing documentation and independent reports may be used where sufficient; we do not claim to hold a certification we have not obtained. These arrangements do not restrict a regulator's powers or mandatory audit rights.

This DPA controls a conflict with the Terms concerning processing of Customer Personal Data. The Terms' liability provisions apply to the extent permitted by law and do not restrict an individual's or regulator's statutory rights.

Astrolabe

See who’s buying, not just what’s converting.

© 2026 Astrolabe. All rights reserved.

Product

  • Features
  • Pricing
  • FAQ

Company

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Service providers
  • hello@noblebase.ai