turgo is GDPR Article 28 compliant and acts as your data processor. A DPA is available at turgo.ai/legal, EU data residency is available on Enterprise, and the platform supports data-subject requests — access, deletion, and export — end to end.
Roles and the DPA
You are the data controller; turgo is the processor acting on your instructions. The Data Processing Addendum at turgo.ai/legal covers processing terms, sub-processors, international transfer mechanisms (SCCs), and security measures. Enterprise customers can also sign a countersigned copy.
Data-subject requests
When a prospect exercises their rights, you can honor it in turgo: search the person in Golden DB and export their record (access/portability) or delete it (erasure). Deletion removes the record and propagates to synced systems per your workflow. Suppression lists ensure a deleted person isn't re-added by later enrichment.
Lawful basis and outreach
GDPR outreach usually relies on legitimate interest for B2B prospecting; you configure agent behavior to respect it — honoring opt-outs immediately, including required disclosures, and excluding regions or segments where you lack a basis (see Compliance: GDPR, CAN-SPAM, CASL). turgo gives you the controls; the lawful basis determination is yours.
EU data residency
Enterprise plans can store data in EU-Central (Frankfurt) so personal data stays in the EU. Combined with the DPA and SCCs, this satisfies the residency expectations of most EU customers.