This Data Processing Agreement (“DPA”) forms part of the Terms of Service between ARIA INTELLIGENCE PTE. LTD. (“Processor,” “Top Prospect,” “we”) and the business customer using the Service (“Controller,” “Customer”). It applies when Processor handles Connected-Source Personal Data on Controller's behalf.
1. Roles of the Parties
For personal data contained in Telegram sources that Customer deliberately connects to the Service (“Connected-Source Personal Data”):
- Customer is the Controller. Customer determines the sources to connect, the purpose and criteria for processing, who may review results, and what action to take.
- Top Prospect is the Processor. Processor acts on Customer's documented instructions in the Terms, this DPA, and Customer's product configuration.
Top Prospect acts separately as controller for its own customer-account, billing, website, security, and support data, as explained in the Privacy Policy.
2. Subject Matter, Duration, Nature, and Purpose
- Subject matter: processing content and metadata from Telegram groups, supergroups, or channels selected through Customer's authorized connected account.
- Duration: any period in which Processor handles Connected-Source Personal Data for Customer, including a trial and paid term, plus the time reasonably needed to complete an instructed deletion, ordinary backup rotation, or a legally required retention.
- Nature: collection, transmission, filtering, merging, deduplication, classification, scoring, summarization, storage, display, and delivery through notification channels enabled by Customer.
- Purpose: to organize candidate Signals matching Customer's configured criteria and make the source context and generated assessment available for Customer's human review.
3. Data Subjects and Categories of Personal Data
- Data subjects: people who post, reply, or are identified or referenced in content from a connected source.
- Personal data: content and metadata made available from the connected source, which may include a display name or username, message content, timestamps, source and message identifiers, reply context, and other personal data contained in the content. Generated summaries, assessments, rankings, reasons, and review status may also relate to an identifiable person.
The Service is not designed to target children or special-category personal data. Customer must not configure it for those purposes and must stop processing where it cannot establish an appropriate legal basis.
4. Controller Obligations
Customer will:
- ensure its instructions, selected sources, criteria, review, and outreach comply with applicable law and Telegram's rules;
- have the rights and lawful basis required to disclose Personal Data to Processor and instruct the processing;
- provide required notices, respond to data-subject requests, and document its own decisions as Controller;
- limit account access to authorized personnel and protect connection and account credentials; and
- not instruct Processor to process Personal Data in a way that violates applicable law.
5. Processor Obligations
Processor will:
- process Personal Data only on Customer's documented instructions, unless law requires otherwise, in which case Processor will inform Customer before processing unless prohibited by law;
- ensure people authorized to handle Personal Data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures under Section 7;
- engage sub-processors in accordance with Section 6;
- taking into account the nature of the processing and information available to Processor, provide reasonable assistance with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and consultations required by applicable law;
- after the end of processing, handle deletion and any agreed return under Section 9 unless law requires continued storage; and
- make information reasonably necessary to demonstrate compliance available to Customer and allow a reasonable audit by Customer or its independent auditor, subject to confidentiality, security, advance notice, reasonable frequency, and reimbursement of reasonable costs.
6. Sub-processors
Customer gives general authorization for Processor to use service providers needed to deliver the Service, including providers of infrastructure, AI inference, communications, analytics, support, security, and payment services. Processor remains responsible for imposing applicable data-protection obligations on a sub-processor that handles Connected-Source Personal Data.
Customer may request current sub-processor information by emailing [email protected]. Where applicable law or a written customer agreement requires notice of an intended change, Processor will provide notice before the new sub-processor begins the relevant processing and give Customer an opportunity to raise reasonable data-protection objections.
7. Security Measures
Processor will maintain measures appropriate to the risk and nature of the Service. These measures include protection for data in transit, role-appropriate access controls, credential and secret handling, and operational logging needed to secure and troubleshoot the Service. Additional current security information may be requested through support and may be subject to reasonable confidentiality controls.
8. Assistance with Requests and Breaches
If Processor receives a data-subject request relating to Connected-Source Personal Data, Processor will direct the request to Customer where practicable and provide reasonable assistance, unless law requires Processor to respond directly. Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting data processed under this DPA and will provide information reasonably available to help Customer meet applicable notification duties.
9. Data Deletion and Return
Customer can manage Connected-Source Personal Data through the product controls currently made available and may contact support for a deletion request those controls do not cover. The business-data cleanup workflow starts an asynchronous deletion process; it does not guarantee that every copy is erased at the instant the request is submitted.
The current product does not present a general self-service data-export function. If Customer requires return of Personal Data, it must contact support before initiating deletion or ending the Service so the parties can identify an available, secure method and format where return is required or agreed.
At the end of the relevant processing, Processor will delete Connected-Source Personal Data after completing any agreed return, unless applicable law requires continued storage. Limited data may remain for the time needed to complete ordinary backup rotation, protect account and Service security, document deletion, keep transaction records, resolve disputes, or meet a legal obligation. While retained for those purposes, it remains protected under this DPA and will not be used for another purpose.
A deletion or return request does not itself create a refund right; refunds are governed by the Refund Policy.
10. International Transfers
Because Processor is established in Singapore and may use service providers in other countries, processing can involve an international transfer. Before relying on Standard Contractual Clauses, a UK Addendum, or another transfer instrument for a transfer that requires one, the parties will complete or otherwise validly incorporate the applicable document and required annexes. This DPA does not treat the Top Prospect application homepage as a completed transfer instrument.
Customer may request information about the transfer mechanism applicable to its processing by contacting [email protected].
11. Liability
Each party's liability arising out of this DPA is subject to the limitations and exclusions in the Terms of Service to the extent permitted by applicable law.
12. Term and Order of Precedence
This DPA remains in effect while Processor handles Connected-Source Personal Data for Customer and for any period during which retained data remains protected under Section 9. If this DPA conflicts with the Terms regarding the processing of Connected-Source Personal Data, this DPA controls. The Terms control in other respects.
13. Contact
Data-protection questions relating to this DPA may be sent to [email protected].