SoarSCRM Legal Center
Data Processing Addendum
This addendum applies when SoarSCRM processes customer personal data subject to data-protection law for a business customer.
1. Scope and roles
The customer is the controller or processor of personal data submitted through conversations, contacts, materials, translation, automation, and backups; SoarSCRM acts as processor or subprocessor on the customer's instructions. SoarSCRM generally acts as an independent controller for account, billing, support, and security data.
2. Instructions and customer duties
We process customer personal data only under the agreement, orders, product settings, and documented instructions, as needed to provide, protect, and support the services. The customer must ensure a lawful basis for collection, import, disclosure, and instructions and configure appropriate access, retention, and export rules.
3. Confidentiality, security, and incidents
Authorized personnel are bound by confidentiality. We maintain risk-appropriate access controls, transmission protection, logs, backup recovery, vulnerability management, and personnel measures. After confirming a security incident affecting customer personal data, we will notify the customer without undue delay and provide available information and reasonable assistance.
4. Subprocessors and international transfers
The customer generally authorizes subprocessors for cloud hosting, content delivery, payments, support, monitoring, communications, translation, or AI. We contractually restrict their processing and require appropriate protection, and will reasonably publish or notify material new subprocessors. International processing must use recognized transfer mechanisms and supplementary safeguards where required.
5. Data subject and government requests
Considering the nature of processing and available features, we will reasonably assist with access, correction, deletion, restriction, objection, portability, impact assessments, and regulator consultation. Government requests are reviewed for validity, and disclosure is limited to what law requires.
6. Return, deletion, and audits
Customers may export or delete data where supported and should complete exports before closure. After termination, we delete or de-identify remaining data under agreed retention and backup rotation, except where law requires retention. On reasonable notice, we may first provide security descriptions, certifications, or audit summaries; if necessary, the parties may agree on an audit that protects confidentiality and service continuity.
7. Processing details and precedence
Data subjects may include customer users, prospects, end customers, and platform users. Data may include identity and contact details, conversations and files, labels, device data, and logs. Processing generally continues for the service term and agreed retention period. This addendum controls a conflict about customer personal data. Request an executed copy, SCCs, or further details at [email protected].
