Last updated: 23 September 2026.
This webpage is not itself a signed DPA. A binding DPA must identify the actual contracting entities, addresses, signatures, service scope, processing instructions, security schedule, subprocessors, transfer mechanism, deletion/return terms, and governing documents.
When you need one
If your organization sends personal data to CRM Software Pro on behalf of customers, employees, prospects, or website visitors, your organization will commonly be the controller and CRM Software Pro the processor. Article 28 GDPR generally requires a written controller–processor agreement.
Before production use
- Review Data Processing & Locations and the Subprocessor List.
- Document the features and connected channels you will enable, the data subjects and categories, purpose, retention, and authorized team roles.
- Confirm whether international-transfer safeguards are acceptable. The standard service is not EU-only.
- Do not upload production personal data until your authorized representative and CRM Software Pro have completed the applicable agreement.
Request the DPA
Email the information below to [email protected]:
- Customer legal name, registered address, registration/VAT number, and signatory.
- Workspace and account email.
- Intended services and integrations.
- Data-subject countries and any EU-only or sector-specific restrictions.
- Required deletion/return period and security questionnaire, if any.
Controller obligations
The DPA does not transfer the customer's controller responsibilities. Customers remain responsible for lawful instructions, notices, data minimization, user permissions, retention choices, rights-request identity checks, and avoiding prohibited or unnecessary sensitive data.