Definition
Data controller
Under the GDPR, the organisation that decides why and how personal data is processed: for cold email, that is you rather than your tool.
The data controller is the party that determines the purposes and means of processing personal data. In cold email, that is the company that chose the prospects, decided to write to them, and picked the message: your company. The software you use to send is a data processor, acting on your instructions. The controller carries the main obligations under the GDPR: having a lawful basis, informing people about the processing, answering their requests, keeping data no longer than needed, and choosing processors that offer adequate guarantees.
The distinction matters because responsibility does not move with the data. Uploading a list to a tool does not make the tool responsible for whether you were entitled to contact those people, or for honouring their objection. It does make you responsible for the tool: where it stores the data, whether it transfers it outside the EEA, and whether a contract (a data processing agreement) sets out what it may do. A controller who cannot answer “where is my prospect data and who can access it” is not in a good position when someone asks.
For Seegnals customers, the customer is the data controller and Seegnals the processor. The application is hosted in Germany and the database in Ireland, both in the EU, with no transfer outside the EEA for core processing, and a DPA is available on request.