Data Processing Addendum
This addendum applies where IT Pro Services LLC processes personal data on your behalf as part of ITPS CRM. It forms part of the Terms of Service and takes effect when you accept them.
In it, you are the controller and we are the processor. Terms such as personal data, processing, controller, processor and data subject carry the meaning given in applicable data protection law, including the UK and EU GDPR.
What we process, and for whom
- Subject matter. Providing the CRM described in the Terms of Service.
- Duration. For as long as your subscription is active, plus the 30-day period described below.
- Nature and purpose. Storing, organising, transmitting, backing up and displaying your data so that you can run your business with it.
- Types of data. Contact details, company records, deals and notes; email, text messages and call records including recordings and voicemail where enabled; website chat transcripts and form submissions; files you upload; and any custom fields you create.
- Categories of data subject. Your customers and prospects, the people who work for them, your own staff, and visitors to your website.
We do not determine the purposes of this processing. You do.
Our obligations
We will:
- Process personal data only on your documented instructions. Using the product is an instruction; so is a written request from an account owner. If we believe an instruction breaks the law, we will tell you.
- Keep the people who process it bound by confidentiality.
- Apply appropriate technical and organisational security measures, described in the Security section below.
- Engage sub-processors only under the terms below.
- Help you respond to a data subject's request, so far as the product's own tools do not already let you do it yourself.
- Help you with security, breach notification and impact assessments, taking into account what we know and what you can see.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know and what we are doing.
- Delete or return the data at the end of the contract, as set out below.
- Make available the information you reasonably need to show we meet these obligations.
Security
Measures currently in place:
- data in transit protected with HTTPS
- passwords stored as hashes, never recoverable
- credentials you give us — mail, telephony and payment keys — encrypted at rest
- role-based access inside a workspace, with an audit log of significant actions
- two-factor authentication available on every account, and session and device revocation
- rate limiting and lockout on sign-in
- regular backups, restorable by the platform operator
- production access limited to staff who need it
We may change these measures as long as security is not reduced.
Sub-processors
You give general authorisation for the sub-processors below. We remain responsible for what they do with your data.
- Our hosting provider — running the application and database.
- Stripe — subscription billing and payments.
- Twilio — phone numbers, calls, recordings and text messages, for workspaces that use them.
- Google and Microsoft — sign-in, and mail from a mailbox you connect.
- OpenAI or Anthropic — only where you have switched on the AI agent, and only for the conversation text being answered.
We will give notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, you may cancel the affected part of the service.
International transfers
Where a sub-processor processes data outside your country, we rely on the transfer safeguards that provider offers, including standard contractual clauses where they apply.
Data subject requests
The CRM lets you find, correct, export and delete records yourself, which is usually the fastest route. If a data subject contacts us directly about data we hold for you, we will not respond substantively — we will pass it to you.
Deletion and return
- Deleting a record inside the CRM sends it to your recycle bin; emptying that is permanent.
- Call recordings are deleted automatically at the end of the retention window you set, from our records and from the telephony provider.
- On termination, you can export your data for 30 days. After that we delete it, other than what we must keep by law and what remains in backups until those expire on their normal cycle.
Audit
On reasonable written notice, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information you need to verify compliance with this addendum.
Contact
Data protection enquiries: legal@it-ps.net
IT Pro Services LLC
245 Riverside Avenue Suite 100 PMB1016, Jacksonville, FL 32202
