Legal
Data Processing Addendum
Last updated · October 2026
01About this addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service, or any other written agreement, between AutomateNexus CRM ("AutomateNexus CRM," "we," "us") and the customer that uses the Service ("Customer," "you") (the "Agreement"). It applies wherever we process personal data on your behalf and a data protection law applies to that processing.
It takes effect when you accept the Agreement and stays in force for as long as we process personal data for you. You do not need to sign anything for it to apply. If you need a signed copy, write to support@automatenexuscrm.com and we will send this DPA for signature.
02Definitions
"Data Protection Law" means the laws that apply to the processing of personal data under the Agreement, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws such as the California Consumer Privacy Act.
"Customer Personal Data" means personal data that you, or anyone using the Service under your account, submit to the Service and that we process on your behalf. "Controller," "processor," "data subject," "personal data," "processing," "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
"Sub-processor" means another processor we engage to process Customer Personal Data. "Standard Contractual Clauses" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0).
03Roles
For Customer Personal Data you are the controller and we are your processor. If you use the Service for your own clients, for example as an agency running client organizations, you act as a processor for those clients and we act as your sub-processor. In that case you confirm that your instructions to us are authorized by the controllers you act for.
We are a controller of the data we need to run our own business with you: your account and billing details, your communications with us, and usage records. Our Privacy Policy covers that processing, and this DPA does not.
04How we process your data
We process Customer Personal Data only on your documented instructions. Your instructions are the Agreement, this DPA, the way you set up and use the Service (including the integrations you connect and the AI features you turn on), and any further written instructions that are consistent with the Agreement. If we believe an instruction breaks Data Protection Law, we will tell you.
We do not sell Customer Personal Data, share it for advertising, use it for our own purposes, or use it to train third-party AI models. The details of the processing are set out in Annex 1.
You are responsible for having a lawful basis for the personal data you put into the Service, for giving the notices and obtaining the consents the law requires, including consent to contact the people in your records, and for the accuracy of that data. The Service is not designed for special categories of personal data, health information regulated by HIPAA, or payment card numbers, and you agree not to submit them, other than through a payment provider you connect.
05Confidentiality
Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality. Access is limited to the people who need it to provide and support the Service, and our team opens a customer's records only to give support that customer asked for, for a limited time, with the access logged.
06Security
We maintain the technical and organizational measures described in Annex 2 to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorized access. We may update those measures as the Service develops, provided the overall level of protection does not decrease.
You are responsible for using the Service securely: choosing who has access and what role they hold, protecting sign-in credentials and API keys, and turning on the controls you need, such as two-factor authentication and single sign-on.
07Sub-processors
You give us general authorization to engage sub-processors to help provide the Service, such as hosting, storage and email delivery providers. We send the current list to any customer who asks at support@automatenexuscrm.com. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible to you for their work.
We will give notice at least 30 days before a new sub-processor starts processing Customer Personal Data, by email to your account owner or by a notice in the Service. You may object on reasonable data protection grounds within that period. We will work with you in good faith to resolve the objection; if we cannot, you may end the Agreement by written notice, and fees are handled as the Agreement and our Refund Policy provide.
Services that you choose to connect under your own account, such as your telephony, payment, email-sending or AI provider, or your Google or Microsoft workspace, process data under your agreement with them. They are not our sub-processors.
08Requests from individuals
The Service gives you the means to find, correct, export and delete the personal data in your account, so that you can answer requests from the people it is about. If someone sends such a request to us about data we hold for you, we will pass it to you without undue delay and will not answer it ourselves beyond telling them we have done so, unless the law requires otherwise.
Where you cannot answer a request using the Service, we will give you reasonable help on request, taking into account the nature of the processing.
09Assessments and regulators
Taking into account the nature of the processing and the information available to us, we will give you reasonable help with data protection impact assessments and with consultations with a supervisory authority where the law requires you to carry them out for your use of the Service.
10Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and, where feasible, within 72 hours. Our notice will describe what we know about the nature of the breach, the kinds of data and people affected, the likely consequences, and what we have done and propose to do about it. We will keep you updated as we learn more and will take reasonable steps to contain and remedy the breach.
We send breach notices to the account owner's email address, so keep it current. Our notice is not an admission of fault or liability.
11Return and deletion
You can export Customer Personal Data from the Service at any time while your account is active. After the Agreement ends we keep your data in a recoverable state for 30 days, as our Cancellation Policy describes, and then delete it from our active systems. Copies in backups expire on our normal backup rotation. If you ask us in writing to delete your data sooner, we will.
We may keep personal data for longer only where the law requires it, and in that case we will keep it confidential and process it only for that purpose.
12Information and audits
On request we will give you the information reasonably needed to show that we meet our obligations under this DPA, including our security documentation, under a confidentiality agreement.
If that information is not enough for you to meet your own legal obligations, you or an independent auditor you appoint may audit our processing of Customer Personal Data once in any twelve-month period, and additionally after a personal data breach or where a supervisory authority requires it. An audit needs at least 30 days' written notice, takes place during business hours, is at your cost, is subject to confidentiality, and must not expose other customers' data or unreasonably disrupt our operations.
13International transfers
Customer Personal Data is hosted in the United States. Where your use of the Service involves a transfer of personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been recognized as providing adequate protection, the Standard Contractual Clauses are incorporated into this DPA and apply to that transfer: Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor.
For the Standard Contractual Clauses: the optional docking clause in Clause 7 and the optional redress language in Clause 11 do not apply; Option 2 of Clause 9 (general written authorization) applies with the notice period in section 7 of this DPA; the governing law under Clause 17 is the law of Ireland and the courts under Clause 18 are the courts of Ireland; Annex I is completed by Annex 1 of this DPA with you as data exporter and us as data importer; Annex II is completed by Annex 2; and Annex III is the sub-processor list referred to in section 7.
For transfers from the United Kingdom, the UK Addendum applies, completed with the information in this DPA, and either party may end it as its Table 4 provides. For transfers from Switzerland, references in the Standard Contractual Clauses to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
If we receive a legally binding request from a public authority for Customer Personal Data, we will tell you unless the law forbids it, will challenge a request we believe is unlawful, and will disclose no more than the request requires.
14United States privacy laws
Where a United States state privacy law applies, we act as your "service provider" or "processor" under that law. We do not sell or share Customer Personal Data; we do not keep, use or disclose it outside our direct business relationship with you or for any purpose other than providing the Service; and we do not combine it with personal data we receive from other sources, except as that law permits a service provider to do.
We will comply with the obligations those laws place on us and will tell you if we can no longer meet them. You may then take reasonable and appropriate steps to stop and remedy any unauthorized use of Customer Personal Data.
15Liability, precedence and changes
Each party's liability under this DPA is subject to the limits and exclusions in the Agreement, to the extent the law allows. Nothing in this DPA limits the rights that individuals have under the Standard Contractual Clauses or under Data Protection Law.
If this DPA conflicts with the Agreement on a data protection matter, this DPA prevails. If the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail. This DPA is governed by the law that governs the Agreement, except where the Standard Contractual Clauses provide otherwise.
We may update this DPA when the law or the Service changes. We will not reduce the protection it gives to Customer Personal Data, we will announce material changes, and we will revise the "last updated" date below.
16Annex 1: details of the processing
Subject matter and purpose: providing the AutomateNexus CRM Service to you under the Agreement. Nature of the processing: hosting, storing, organizing, retrieving, transmitting and deleting the data you put into the Service; sending the emails, text messages and calls you start, through the providers you connect or the sending service you buy from us; and analyzing and drafting with AI features at your direction.
Duration: the term of the Agreement, plus the 30-day recovery period and backup rotation described in section 11. Frequency of transfer: continuous.
People the data is about: your staff and other users of your account; your contacts, leads, customers and their employees; your clients' users, where you run client organizations or a client portal; and people who fill in your forms, book with you, or receive messages and calls from you.
Kinds of data: names and contact details such as email addresses, phone numbers and postal addresses; company and job information; the records you keep, such as deals, notes, tasks, activities, quotes and invoices; the content of communications you send or log, including emails, messages, and call recordings and transcripts where you turn those features on; form and booking submissions; files you upload; and sign-in, device and usage information such as IP addresses. Special categories of personal data are not intended to be processed.
17Annex 2: security measures
Encryption: data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. The credentials and API keys you store for integrations are encrypted separately, and backups are encrypted.
Separation: each organization's records are isolated from every other organization's at the database level, and workspaces inside an organization are isolated from each other in the same way.
Access control: role-based permissions that can be set down to the field; two-factor authentication that an organization can require for everyone; sign-in with Google, Microsoft or LinkedIn; and SAML single sign-on with directory provisioning.
Accountability: a history of changes to records, a log of exports, and a log of every action taken by an AI agent, with approval steps before sensitive actions are carried out.
Our own access: production systems are open only to authorized personnel. Our team opens a customer's records only to give support that customer asked for, for a limited time, and that access is logged.
Resilience: regular encrypted backups and continuous monitoring, on infrastructure operated by hosting providers that are independently audited against recognized security standards.
Operations: security updates are applied to the Service and the software it depends on, security findings are reviewed and fixed according to their severity, and we follow an incident response process that includes the notification in section 10.
Last updated · October 2026
Need a signed copy, or our current list of sub-processors? Write to support@automatenexuscrm.com, or contact us.