Data Processing Agreement (DPA)
Last updated: 2026-09-27
This page summarises how KudosCRM processes the personal data in your CRM as your data processor. When you use KudosCRM, you are the controller of the data you upload (your contacts, companies, deals, and messages), and we process it for you under this DPA. It forms part of our Terms of Service. Customers who need a signed copy for GDPR Article 28 can request one at [email protected].
Our commitments
- We process your data only on your instructions — to provide the service you've configured — and never sell it.
- Security: we apply appropriate technical and organisational measures, including encryption in transit, encryption of sensitive credentials, tenant isolation, access controls, monitoring, and security testing. See our Security overview.
- Sub-processors: we use the providers listed at Sub-processors, under contracts that require them to protect your data, and we give advance notice before adding or changing them so you can object.
- International transfers: where data moves to another region, we put appropriate safeguards (such as Standard Contractual Clauses) in place.
- AI: when an AI feature runs, relevant content is sent to our AI provider (listed at Sub-processors) to generate results, after email addresses, phone numbers, card and bank numbers, ID numbers, secrets, IP addresses and labelled dates of birth are replaced with placeholders. How KudosCRM Uses AI explains which AI features run on their own and how long AI data is kept.
- Data-subject requests: we help you respond to requests from individuals (access, deletion, correction, portability) within the timeframes the law requires.
- Breach notification: if a personal-data breach affects your data, we notify you without undue delay so you can meet your obligations.
- Return & deletion: on termination, we provide a window to export your data and then delete it.
Sensitive data
KudosCRM is a general business CRM. Please don't store special-category data (such as health, government ID, or full payment-card numbers) unless you're authorised to and have instructed us accordingly.
Contact
Data Protection Officer: [email protected] · Legal & signed DPA requests: [email protected]