Data processing agreement
Last updated: July 19, 2026
This data processing agreement (the "DPA") forms part of the Terms of Service between 9DollarCRM ("we", "us", the "processor") and the business that holds the workspace (the "customer", the "controller"). It applies whenever we process personal data on your behalf as part of providing the service.
1. Roles
For the data you and your team put into your workspace, you are the controller and we are the processor. You decide what data goes in, why it is there, and how long it stays. We process it only to run the service for you and only on your documented instructions, which include this DPA, the Terms of Service, and your configuration choices in the app. If we believe an instruction breaks applicable data protection law, we will tell you before acting on it.
For your own account data (your login, billing details, and usage of our service), we act as a controller. That processing is described in our Privacy Policy.
2. Scope and purpose
The data we process for you is the personal data contained in your workspace. Typically that includes:
- Contact details of your customers and leads (names, phone numbers, emails, addresses)
- Jobs, appointments, notes, and messages linked to those contacts
- Estimates, invoices, and payment records
- Details of your own team members who use the workspace
The sole purpose of the processing is to operate the CRM for you: storing records, scheduling work, sending the messages you trigger, producing invoices, and running the features you have enabled. We do not sell workspace data and we do not use it to train AI models.
3. Our obligations as processor
- Instructions only. We process workspace data only on your documented instructions, unless a law we are subject to requires otherwise, in which case we will inform you before processing unless that law forbids it.
- Confidentiality. Everyone we authorise to access workspace data is bound by confidentiality obligations, and access is limited to what is needed to run and support the service.
- Security measures. We maintain technical and organisational measures appropriate to the risk, including:
- Row-level tenant isolation enforced at the database, so each workspace's data is segregated
- Encryption of data in transit
- Multi-factor authentication available for all user accounts
- Role-based access control with configurable permissions and field-level policies
- An append-only audit log of significant actions in the workspace
- Isolated, regularly taken backups
- Breach notification. If we become aware of a personal data breach affecting your workspace data, we will notify you without undue delay and give you the information we have so you can meet your own notification duties.
- Help with data-subject requests. If one of your customers exercises their rights (access, correction, deletion, portability), the in-app tools let you handle most requests yourself, including one-click CSV export of records. Where the tools are not enough, we will assist you on request.
- Deletion or return. When your subscription ends, you can export your data. After the retention window described in the Terms of Service, we delete workspace data from live systems, and it ages out of backups on the normal backup cycle, unless a law requires us to keep it longer.
4. Subprocessors
We use a small set of subprocessors to deliver specific capabilities. A subprocessor only receives workspace data when you connect or use the capability it powers: if you never connect WhatsApp, Meta never sees your data. The current list is:
| Subprocessor | Purpose |
|---|---|
| Stripe | Card payment processing and billing |
| Razorpay | Payment processing (India and supported regions) |
| PayPal | Payment processing |
| Resend | Transactional and campaign email delivery |
| SendGrid (Twilio) | Email delivery |
| Amazon SES | Email delivery |
| Twilio | SMS and voice calling |
| Meta (WhatsApp Business) | WhatsApp messaging |
| Calendar sync and Gemini AI features | |
| Microsoft | Outlook calendar sync |
| Zoom | Meeting scheduling and links |
| Cisco Webex | Meeting scheduling and links |
| Intuit QuickBooks | Accounting export and sync |
| OpenAI | AI features (drafting, summarisation) |
| Anthropic | AI features (drafting, summarisation) |
| OpenRouter | AI model routing for AI features |
| Cloud hosting provider | Application hosting, database, backups, and file storage |
We will notify you of planned additions or replacements to this list before they take effect, and you may object on reasonable data protection grounds. Each subprocessor is bound by a written contract imposing data protection obligations no less protective than this DPA, and we remain responsible for their performance.
5. International transfers
Some subprocessors process data outside your country. Where a transfer of personal data to a third country takes place, we rely on an appropriate safeguard such as an adequacy decision or standard contractual clauses, and we will provide details of the mechanism used on request.
6. Audit rights
On written request, no more than once per year unless a breach or a supervisory authority requires otherwise, we will provide summary reports and documentation reasonably needed to demonstrate compliance with this DPA. If that is genuinely insufficient, we will discuss a proportionate audit at your cost, scheduled so it does not disrupt the service or expose other customers' data.
7. Liability and term
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA takes effect when you start using the service, lasts as long as we process workspace data for you, and the deletion and confidentiality obligations survive until that processing has fully ended.
Questions about this DPA? Reach us via the contact page. Related: Privacy Policy · Terms of Service · Cookie Policy · Security