How we handle your
customers’ data
This agreement governs how Inexpro Cloudsec AB, as data processor, processes personal data on your behalf when you use CRM-iSystem.
This Data Processing Agreement (“DPA”) forms an annex to, and an integral part of, the Terms of Service for CRM-iSystem, and governs the processing of personal data that takes place when you (“Data Controller”, “Customer”) use the CRM-iSystem service provided by Inexpro Cloudsec AB (Reg. No. 559433-5340), 252 76 Helsingborg, Sweden (“Data Processor”, “we”, “us”).
1. Background and purpose
The Customer is the data controller for the personal data about its own contacts, customers, and leads that is entered into CRM-iSystem. The Data Processor processes this data solely on the Customer’s behalf and in accordance with the Customer’s documented instructions, in compliance with the EU General Data Protection Regulation (GDPR).
2. Subject matter and nature of the processing
| Subject matter | Storage, processing, and display of customer data within the CRM-iSystem service |
|---|---|
| Nature of processing | Collection, storage, organization, alteration, retrieval, and erasure |
| Purpose | To provide CRM functionality (contact management, pipeline, activity log, email sending, dashboard) to the Customer |
| Categories of data subjects | The Customer’s contacts, leads, and customers (name, email, phone, company details, notes, and any other data the Customer enters) |
| Duration of processing | For as long as the Customer’s CRM-iSystem agreement is in effect, plus the period required for deletion under section 6 below |
3. Data Processor obligations
- We process personal data only in accordance with the Customer’s documented instructions, unless required otherwise by EU or Member State law.
- We ensure that persons authorized to process the personal data have committed themselves to confidentiality.
- We implement appropriate technical and organizational security measures under Article 32 GDPR (see section 5).
- We assist the Customer, insofar as possible, with appropriate technical and organizational measures to fulfil the Customer’s obligation to respond to requests for exercising data subjects’ rights.
- We assist the Customer in ensuring compliance with the obligations under Articles 32–36 GDPR (including security and personal data breaches).
- We delete or return all personal data to the Customer after the provision of services has ended, in accordance with section 6.
- We make available to the Customer all information necessary to demonstrate compliance with the obligations set out in this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
4. Sub-processors
The Customer hereby gives general authorization for the Data Processor to engage sub-processors to fulfil the service. The Data Processor shall inform the Customer of any changes to sub-processors, and the Customer has the right to object to such changes. The Data Processor is responsible for ensuring that sub-processors are bound by the same data protection obligations set out in this agreement.
5. Security measures
The Data Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (HTTPS/TLS).
- Access-controlled permissions and secure authentication (including two-factor authentication where offered).
- Regular backups of the database.
- Logging to detect and investigate unauthorized access.
6. Deletion and return of data
Upon termination of the Customer’s agreement, or at the Customer’s request, the Data Processor shall delete or return all personal data processed on the Customer’s behalf, unless retention is required under applicable law.
7. Personal data breaches
If the Data Processor becomes aware of a personal data breach affecting the Customer’s data, the Customer shall be notified without undue delay after the Data Processor becomes aware of the breach, so that the Customer can fulfil any notification obligations towards supervisory authorities and data subjects.
8. Liability
The parties’ liability for damage arising from processing that violates the GDPR or this DPA is governed by applicable law and, where applicable, by the Terms of Service for CRM-iSystem.
9. Term
This agreement applies for as long as the Data Processor processes personal data on the Customer’s behalf within CRM-iSystem, and ceases to apply once such processing has ended entirely, including after deletion or return under section 6.
10. Contact
Questions about this Data Processing Agreement can be directed to:
Inexpro Cloudsec AB
Reg. No.: 559433-5340
Address: 252 76 Helsingborg, Sweden
Email: info@crm-isystem.com
Last updated: September 6, 2026