Addit CRM

Data Processing Agreement

Last updated: [DATE]

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and [Company Legal Name] (“Processor”) for the Addit CRM service.

1. Subject matter & roles

The Processor processes personal data on behalf of the Controller solely to provide the Service and per the Controller’s documented instructions.

2. Nature of processing

Hosting, storage, and processing of CRM records (e.g. contacts, companies, activities) submitted by the Controller and its users.

3. Data subjects & categories

The Controller’s customers, prospects, and staff; contact details and any personal data the Controller chooses to store.

4. Sub-processors

The Processor may engage sub-processors (e.g. cloud hosting at [Cloud Provider / Region]) under written terms providing equivalent protection, and will inform the Controller of changes.

5. Security

The Processor maintains appropriate technical and organizational measures, including encryption in transit, access control, and per-tenant data isolation.

6. International transfers

Where transfers occur outside the Controller’s region, appropriate safeguards (e.g. Standard Contractual Clauses) apply.

7. Assistance & breach notification

The Processor assists the Controller with data-subject requests and notifies the Controller without undue delay after becoming aware of a personal-data breach.

8. Deletion & return

On termination, the Processor deletes or returns personal data as instructed, subject to legal retention requirements.

9. Audits

The Processor makes available information necessary to demonstrate compliance and allows for reasonable audits.

10. Contact

[Company Legal Name][dpo@yourdomain]