D3CRM LEGAL · VERSION 2026-10-08

Data Processing Agreement

This agreement is part of accepted d3CRM terms for personal data we process on a customer’s behalf. It sets out the customer’s instructions and our duties as its processor.

1. Parties and processing schedule

The customer is the business identified by its workspace and accepting representative; the processor is the operator below. Where an agency is a processor for its client, it confirms the client’s authorization for d3CRM to act as a further processor. This agreement does not transfer a customer’s legal duties to d3CRM.

  • Subject and duration: managing website enquiries and related workspace records for the service term, followed by return/deletion and any lawful restricted retention.
  • Operations and purposes: receiving, storing, organizing, retrieving, displaying, updating, reporting, exporting, transmitting configured notifications/webhooks, and deleting data to provide the requested CRM.
  • People: website enquirers/prospects and customer/client personnel whose details occur in workspace content.
  • Data: customer-chosen form answers (typically names, email, telephone, and messages), enquiry browser/source/campaign metadata, contact identifiers, assignments, notes, follow-up details, templates, saved views/searches, and activity metadata.
  • Excluded uses: selling data, advertising, AI training, and unauthorized secondary purposes. Children’s, special-category, criminal-offence, and similarly sensitive data require a prior written arrangement and safeguards.

2. Instructions and customer responsibilities

Accepted service terms, workspace configuration, authorized user actions, and written support requests are documented instructions. We process customer data only on these instructions, including transfers, unless law requires otherwise; we inform the customer of a legal requirement when permitted and flag instructions we believe infringe applicable data-protection law.

The customer determines collection purposes, field minimization, lawful grounds, notices/consents, retention, access, and integration destinations. It must respond to individuals and regulators, keep instructions lawful, and ensure authority from any client controller. Our independent account, billing, and security administration is described separately in the Privacy Policy.

3. Confidentiality and security

We restrict access to authorized people with confidentiality duties and maintain technical and organizational measures appropriate to the processing risks. Application measures include password hashing, current membership checks, input validation, rate limiting, hashed configured IP identifiers, encryption of queued email bodies and webhook secrets, and signed webhooks to validated HTTPS destinations. Customer records are separated by workspace access controls.

We also maintain appropriate infrastructure access controls, transport protection, backup/recovery, vulnerability handling, and incident procedures for the actual service deployment. We provide relevant details on request. This agreement does not assert a security certification or that all fields are encrypted at rest. Customers must protect credentials and choose safe webhook/export destinations.

4. Further processors and transfers

The customer authorizes the hosting/database/backup providers disclosed here: provider details are pending; new registration remains closed. Processing/support locations: to be published before registration opens. Resend is used when email is enabled. Stripe performs payment/subscription processing when enabled, including its own independent legal functions. The actual service order/provider disclosure identifies processing locations and applicable roles; customer-chosen webhook and email destinations are the customer’s instructions.

We engage further processors under written duties providing equivalent applicable protection and remain responsible for their processing obligations. We give at least 30 days’ advance notice before adding or replacing a further processor that handles customer personal data. Customers may object on reasonable data-protection grounds during that period; we discuss an alternative or permit termination of the affected service with a refund of unused prepaid affected fees if the objection cannot be resolved.

We do not make a restricted international transfer until its required safeguards and assessments are in place. If EU/EEA or UK transfer rules apply, the parties must first complete the relevant clauses/instrument, annexes, and assessment in a separate agreement. This page does not itself incorporate unsigned Standard Contractual Clauses or assert that a provider has an adequacy status. Indian transfer restrictions and other applicable local requirements remain binding.

5. Rights, incidents, and assistance

Taking account of the nature of processing and available information, we assist with individual rights requests, security obligations, breach notifications, impact assessments, and regulator consultation as applicable. Requests concerning customer data are referred to the customer, unless law requires us to respond directly. We do not disclose one customer’s data to another.

We notify the customer without undue delay after becoming aware of a breach of customer personal data. We share known facts about affected records/people, likely consequences, containment, and the incident contact, and supplement incomplete information as it becomes available. The customer leads its required controller notifications; this does not remove our own reporting duties. The customer must keep an accurate monitored contact address.

6. Return, erasure, and audit

At the customer’s choice, we return available customer data or delete it at the end of the service and delete existing copies unless applicable law requires retention. Customers can export enquiry CSVs; contact us for remaining records and workspace deletion. We confirm scope and timing, address activity/delivery metadata and further-processor copies, and apply deletion to backups through the documented backup lifecycle. Legally retained data is isolated and used only for the permitted reason. A deletion request must not be treated as complete just because an enquiry was removed from the inbox.

We make information needed to demonstrate applicable processing compliance available, and allow and contribute to proportionate audits and inspections by the customer or a confidential independent auditor. Reasonable scheduling and protection for unrelated records do not restrict legally required audits, regulator access, or urgent incident investigation. We promptly inform the customer if an instruction is unlawful. Any service liability terms apply only to the extent legally permitted and do not diminish mandatory processor duties or individuals’ rights.

California service-provider processing

Where California service-provider rules apply, we do not sell or share customer personal information, retain/use/disclose it outside the specified business purposes or direct business relationship, or combine it with other sources except as the law permits. We provide the legally required level of protection, notify the customer if we can no longer meet these duties, and permit reasonable steps to verify compliance and stop or remedy unauthorized processing.

Operator and privacy contact

The operator’s public contact details are pending. New registrations remain closed until these details are available.

If your enquiry was submitted on another business’s website, contact that business first: it decides how to use your enquiry. You can also contact the d3CRM operator for help identifying the responsible workspace. We verify identity and authority proportionately before disclosing, changing, or deleting records.

Data Processing Agreement · d3CRM