SoarSCRM Legal Center

Data Processing Addendum

This addendum applies when SoarSCRM processes customer personal data subject to data-protection law for a business customer.

Version: 1.0Effective: August 31, 2026

1. Scope and roles

The customer is the controller or processor of personal data submitted through conversations, contacts, materials, translation, automation, and backups; SoarSCRM acts as processor or subprocessor on the customer's instructions. SoarSCRM generally acts as an independent controller for account, billing, support, and security data.

2. Instructions and customer duties

We process customer personal data only under the agreement, orders, product settings, and documented instructions, as needed to provide, protect, and support the services. The customer must ensure a lawful basis for collection, import, disclosure, and instructions and configure appropriate access, retention, and export rules.

3. Confidentiality, security, and incidents

Authorized personnel are bound by confidentiality. We maintain risk-appropriate access controls, transmission protection, logs, backup recovery, vulnerability management, and personnel measures. After confirming a security incident affecting customer personal data, we will notify the customer without undue delay and provide available information and reasonable assistance.

4. Subprocessors and international transfers

The customer generally authorizes subprocessors for cloud hosting, content delivery, payments, support, monitoring, communications, translation, or AI. We contractually restrict their processing and require appropriate protection, and will reasonably publish or notify material new subprocessors. International processing must use recognized transfer mechanisms and supplementary safeguards where required.

5. Data subject and government requests

Considering the nature of processing and available features, we will reasonably assist with access, correction, deletion, restriction, objection, portability, impact assessments, and regulator consultation. Government requests are reviewed for validity, and disclosure is limited to what law requires.

6. Return, deletion, and audits

Customers may export or delete data where supported and should complete exports before closure. After termination, we delete or de-identify remaining data under agreed retention and backup rotation, except where law requires retention. On reasonable notice, we may first provide security descriptions, certifications, or audit summaries; if necessary, the parties may agree on an audit that protects confidentiality and service continuity.

7. Processing details and precedence

Data subjects may include customer users, prospects, end customers, and platform users. Data may include identity and contact details, conversations and files, labels, device data, and logs. Processing generally continues for the service term and agreed retention period. This addendum controls a conflict about customer personal data. Request an executed copy, SCCs, or further details at [email protected].