Last updated: [DATE]
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and [Company Legal Name] (“Processor”) for the Addit CRM service.
The Processor processes personal data on behalf of the Controller solely to provide the Service and per the Controller’s documented instructions.
Hosting, storage, and processing of CRM records (e.g. contacts, companies, activities) submitted by the Controller and its users.
The Controller’s customers, prospects, and staff; contact details and any personal data the Controller chooses to store.
The Processor may engage sub-processors (e.g. cloud hosting at [Cloud Provider / Region]) under written terms providing equivalent protection, and will inform the Controller of changes.
The Processor maintains appropriate technical and organizational measures, including encryption in transit, access control, and per-tenant data isolation.
Where transfers occur outside the Controller’s region, appropriate safeguards (e.g. Standard Contractual Clauses) apply.
The Processor assists the Controller with data-subject requests and notifies the Controller without undue delay after becoming aware of a personal-data breach.
On termination, the Processor deletes or returns personal data as instructed, subject to legal retention requirements.
The Processor makes available information necessary to demonstrate compliance and allows for reasonable audits.
[Company Legal Name] — [dpo@yourdomain]