Last updated: 6 August 2026
1. Parties and incorporation
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer and the AdyOps contracting entity when AdyOps processes personal data on the customer's behalf. Capitalised terms not defined here have the meaning in the main agreement.
2. Processing roles
The customer acts as the data fiduciary, controller or equivalent party that determines the purpose and essential means of processing. AdyOps acts as the data processor or service provider for customer workspace data. Each party remains independently responsible for processing it controls for its own business purposes.
3. Subject matter and duration
Processing covers hosting and operating the configured CRM, forms, attribution, team, chat, confirmation, logistics, reporting, support, backup and integration functions. Processing continues for the subscription and any limited post-termination retention or backup period.
4. Nature and purpose
Operations may include collection, recording, organisation, storage, retrieval, consultation, transmission to authorised integrations, reporting, correction, backup, export and deletion. Processing is performed to provide, secure, support and improve the purchased service.
5. Data subjects and categories
Data subjects may include the customer's prospects, customers, employees, agents, managers, suppliers and authorised users. Data may include contact details, form responses, communication notes, assignment, attribution, order and operational status, technical identifiers and account activity. The customer should not submit special-category or highly sensitive data unless expressly approved.
6. Documented instructions
AdyOps will process customer data only on documented instructions contained in the agreement, plan configuration, authorised application actions and support requests, unless law requires other processing. AdyOps will inform the customer where an instruction appears unlawful, unless prohibited from doing so.
7. Confidentiality and personnel
Personnel authorised to process customer data are subject to confidentiality obligations and receive access only for assigned responsibilities. AdyOps maintains reasonable awareness and access-removal processes.
8. Security measures
AdyOps applies measures described in the Security and Data Protection Policies, considering the nature of processing, deployment and risk. Customers are responsible for their user access, devices, source data, integrations and lawful instructions.
9. Subprocessors
The customer authorises AdyOps to use hosting, backup, email, payment, monitoring, support and integration subprocessors reasonably required for the service. AdyOps will require relevant confidentiality and data-protection commitments and remains responsible for its own contractual obligations. A subprocessor list should be supplied or maintained for production customers where contractually required.
10. Data-subject requests
Taking into account the nature of processing, AdyOps will reasonably assist the customer with authenticated requests for access, correction, completion, erasure, withdrawal or grievance handling. AdyOps may refer a direct request to the customer unless law requires a different response.
11. Personal-data incidents
AdyOps will notify the customer's designated contact without undue delay after confirming a personal-data breach affecting customer data, provide reasonably available details and cooperate with containment and required notifications. Notification is not an admission of fault.
12. Return, export and deletion
During the active term, the customer may use available export functions. Following termination, AdyOps will return or delete customer data according to the agreement, subject to backup cycles, legal holds and data required to establish or defend claims.
13. Cross-border processing
Where data is processed across borders, the parties will use applicable transfer mechanisms and respect notified restrictions. The customer is responsible for assessing sector-specific or data-localisation obligations applicable to its activity.
14. Audit information
AdyOps will provide reasonable information needed to demonstrate compliance with this DPA. Any audit must protect other customers, security information and confidentiality, avoid unreasonable disruption and be subject to agreed frequency and cost arrangements.
15. Conflict and liability
If this DPA conflicts with the main agreement on processing customer personal data, this DPA controls for that subject. Liability remains subject to the limitations and exclusions in the main agreement unless applicable law requires otherwise.
16. Contact
Data-processing questions can be sent to Support@adyops.com.