Data Processing Addendum
Effective 14 August 2026
If you are a business in the UK, EU, or anywhere with comparable data protection law, this document is the one your regulator expects to exist. It applies automatically when you accept the Terms of Service - you do not need to sign anything or ask us for a copy. If your own compliance process needs a countersigned version, email legal@crmniche.com.
1. Roles
You are the controller of the personal data in your workspace. You decide whose details you collect and why. CRM Niche is the processor. We act only on your documented instructions, which are: run the service described in the Terms.
For your own account details - your name, email, and billing information - we are the controller, and the Privacy Policy governs that.
2. What we process for you
| Detail | |
|---|---|
| Subject matter | Providing a CRM service |
| Duration | For as long as your workspace exists, plus the deletion window in section 8 |
| Nature and purpose | Storing, organising, displaying, exporting and transmitting records at your instruction |
| Types of personal data | Names, email addresses, phone numbers, postal addresses, notes, appointment details, and any custom fields you create |
| Categories of data subject | Your customers, leads, contacts, and the members of your own team |
| Special category data | Not expected. The Terms ask you not to store it without a lawful basis of your own |
3. What we commit to
- Process personal data only on your documented instructions, including on international transfers, unless a law we are subject to requires otherwise. If that happens we will tell you first, unless the law forbids it.
- Ensure everyone we authorise to access personal data is under a duty of confidentiality.
- Apply appropriate technical and organisational measures, described in section 6.
- Help you respond to requests from individuals exercising their rights, using the tools in the product where possible.
- Help you with data protection impact assessments and with breach notification, taking account of what we know.
- Delete or return personal data at the end of the service, as set out in section 8.
- Make available the information needed to show we meet these obligations, and allow audits as described in section 7.
4. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with what each one receives, is published at /legal/subprocessors.
We will give at least 30 days notice by email before adding or replacing one. If you have a reasonable objection on data protection grounds, tell us within those 30 days; if we cannot resolve it, you may terminate the affected service and receive a pro-rata refund of anything prepaid.
We impose the same obligations on each sub-processor that apply to us, and we remain responsible to you for their performance.
5. International transfers
Our infrastructure is in the United States. Where you are in the UK, EU, or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this addendum by reference and take precedence over anything inconsistent in it.
- Clause 7 (docking) applies; Clause 9 uses Option 2 with the 30 days notice in section 4; Clause 11 does not use the optional independent-dispute wording; Clause 17 selects Irish law; and Clause 18(b) selects the courts of Ireland.
- Annex I is section 2 above; Annex II is section 6; Annex III is the sub-processors page.
- For UK transfers, the ICO's International Data Transfer Addendum (version B1.0) applies to those Clauses, with Tables 1 to 3 completed by the equivalent information above and neither party able to end the Addendum under Section 19.
- For Swiss transfers, references to the GDPR are read as the Swiss FADP and the supervisory authority is the FDPIC.
6. Security measures
- Encryption of data in transit and at rest.
- Row-level isolation in the database so a query authenticated for one workspace cannot return another workspace's rows. This is enforced by the database itself, not only by application code.
- Role-based access inside a workspace, separating owners, admins, and members.
- Session cookies marked httpOnly and Secure so page scripts cannot read them.
- Secrets such as integration credentials and calendar tokens held in an encrypted vault, never returned to the browser.
- Password hashing, with checks against known breached passwords.
- Bounded input sizes on every write path, including public forms.
- An immutable audit log of significant workspace actions.
- Automated encrypted backups with point-in-time recovery.
7. Audits
On written request, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably needed to show compliance with this addendum, including relevant reports from our infrastructure providers. Where that is not enough for your regulator, we will agree an on-site or remote audit at a reasonable time, with reasonable notice, subject to confidentiality and at your cost.
8. Breach notification, deletion, and return
We will notify you without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting your data. The notice will describe what happened, the likely consequences, and what we are doing about it.
You may export your data at any time from Settings. When a workspace is deleted, records are removed from the live database immediately and encrypted backups roll off within 30 days, after which deletion is complete and irreversible.
9. Liability
Liability under this addendum is subject to the limits in the Terms of Service, except where the Standard Contractual Clauses or applicable law do not permit that.