This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and Cornerstone Business Consultants LLC ("SwitchBoard121", "we", "us") when you use SwitchBoard121 to process personal data of your referral partners and you are subject to the GDPR, UK GDPR, or similar data-protection laws (or act as a "business" under the CCPA/CPRA).
Last updated 4 October 2026
Customer is the controller of partner personal data. SwitchBoard121 is the processor and processes that data only on Customer's documented instructions and as necessary to provide the service.
We process partner personal data (name, email address, job title, company, keywords, and introduction paragraphs) solely to provide the SwitchBoard121 service: storing the partner list, drafting and sending introduction emails from Customer's mailbox, and maintaining introduction records. Processing continues for as long as Customer's account exists or until Customer deletes the data or the account.
Data subjects: Customer's referral partners and other individuals whose details Customer chooses to store.
Personal data: name, email address, job title, company, keywords describing what they do and who they would like to meet, and introduction paragraphs.
We use the following sub-processors:
We will provide reasonable notice of any intended changes to sub-processors. Current details and locations are available on request or via our Trust Center / Security page.
Where required for transfers of personal data from the EEA, UK, or Switzerland, the Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) that form part of our agreements with Vercel apply and are flowed down as appropriate.
We implement appropriate technical and organizational measures to protect personal data. Details are set out in our Privacy Policy and on our Trust Center / Security page. These include encryption in transit and at rest, access controls on a need-to-know basis, and additional application-layer encryption for mailbox credentials.
We will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer's partner data, and will provide information reasonably required for Customer to meet its own notification obligations.
We will assist Customer, insofar as reasonably possible, with data-subject requests, security, breach notifications, and data-protection impact assessments.
On termination of the account or on Customer's written request we will delete or return partner personal data (except for residual copies that may remain in backups for a limited period, after which they are deleted).
Customer may request information reasonably necessary to demonstrate compliance with this DPA. Formal audits are available on reasonable notice and subject to appropriate confidentiality obligations.
This DPA is governed by the same law and dispute-resolution provisions as the Terms of Service. In the event of conflict between this DPA and the Terms or Privacy Policy on data-protection matters, this DPA prevails.
Questions about this page? Email support@switchboard121.com.