Data Processing Agreement (DPA) | CRM-iSystem
Data Processing Agreement

How we handle your
customers’ data

This agreement governs how Inexpro Cloudsec AB, as data processor, processes personal data on your behalf when you use CRM-iSystem.

This Data Processing Agreement (“DPA”) forms an annex to, and an integral part of, the Terms of Service for CRM-iSystem, and governs the processing of personal data that takes place when you (“Data Controller”, “Customer”) use the CRM-iSystem service provided by Inexpro Cloudsec AB (Reg. No. 559433-5340), 252 76 Helsingborg, Sweden (“Data Processor”, “we”, “us”).

1. Background and purpose

The Customer is the data controller for the personal data about its own contacts, customers, and leads that is entered into CRM-iSystem. The Data Processor processes this data solely on the Customer’s behalf and in accordance with the Customer’s documented instructions, in compliance with the EU General Data Protection Regulation (GDPR).

2. Subject matter and nature of the processing

Subject matterStorage, processing, and display of customer data within the CRM-iSystem service
Nature of processingCollection, storage, organization, alteration, retrieval, and erasure
PurposeTo provide CRM functionality (contact management, pipeline, activity log, email sending, dashboard) to the Customer
Categories of data subjectsThe Customer’s contacts, leads, and customers (name, email, phone, company details, notes, and any other data the Customer enters)
Duration of processingFor as long as the Customer’s CRM-iSystem agreement is in effect, plus the period required for deletion under section 6 below

3. Data Processor obligations

  • We process personal data only in accordance with the Customer’s documented instructions, unless required otherwise by EU or Member State law.
  • We ensure that persons authorized to process the personal data have committed themselves to confidentiality.
  • We implement appropriate technical and organizational security measures under Article 32 GDPR (see section 5).
  • We assist the Customer, insofar as possible, with appropriate technical and organizational measures to fulfil the Customer’s obligation to respond to requests for exercising data subjects’ rights.
  • We assist the Customer in ensuring compliance with the obligations under Articles 32–36 GDPR (including security and personal data breaches).
  • We delete or return all personal data to the Customer after the provision of services has ended, in accordance with section 6.
  • We make available to the Customer all information necessary to demonstrate compliance with the obligations set out in this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

4. Sub-processors

The Customer hereby gives general authorization for the Data Processor to engage sub-processors to fulfil the service. The Data Processor shall inform the Customer of any changes to sub-processors, and the Customer has the right to object to such changes. The Data Processor is responsible for ensuring that sub-processors are bound by the same data protection obligations set out in this agreement.

Current sub-processor for hosting and data storage: Render (cloud hosting and PostgreSQL database), server region Frankfurt, Germany (EU). No customer data is stored or processed outside the EU/EEA.

5. Security measures

The Data Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit (HTTPS/TLS).
  • Access-controlled permissions and secure authentication (including two-factor authentication where offered).
  • Regular backups of the database.
  • Logging to detect and investigate unauthorized access.

6. Deletion and return of data

Upon termination of the Customer’s agreement, or at the Customer’s request, the Data Processor shall delete or return all personal data processed on the Customer’s behalf, unless retention is required under applicable law.

7. Personal data breaches

If the Data Processor becomes aware of a personal data breach affecting the Customer’s data, the Customer shall be notified without undue delay after the Data Processor becomes aware of the breach, so that the Customer can fulfil any notification obligations towards supervisory authorities and data subjects.

8. Liability

The parties’ liability for damage arising from processing that violates the GDPR or this DPA is governed by applicable law and, where applicable, by the Terms of Service for CRM-iSystem.

9. Term

This agreement applies for as long as the Data Processor processes personal data on the Customer’s behalf within CRM-iSystem, and ceases to apply once such processing has ended entirely, including after deletion or return under section 6.

10. Contact

Questions about this Data Processing Agreement can be directed to:

Inexpro Cloudsec AB
Reg. No.: 559433-5340
Address: 252 76 Helsingborg, Sweden
Email: info@crm-isystem.com

Last updated: September 6, 2026