Data Processing Addendum
Version 1 · Updated 2026-08-04
Big Simple CRM Data Processing Addendum (DPA)
Last updated: August 2025
This DPA forms part of the Agreement between the Customer (Controller) and
Big Simple CRM (Processor) and governs the processing of Personal Data.
1. Scope & Roles
BSC processes Personal Data only to provide the service and on the Customer's
documented instructions. The Customer is the Controller; BSC is the Processor.
2. Subject Matter & Duration
Processing continues for the duration of the subscription and any wind-down period.
3. Nature & Purpose
Hosting, storing and processing lead/client CRM data; generating analytics;
delivering configured communications.
4. Categories of Data & Data Subjects
Contact details, communications and pipeline data of the Customer's leads and
clients; account data of the Customer's staff.
5. Sub-Processors
BSC may engage sub-processors under written terms no less protective than this DPA
and remains responsible for their performance. A list is available on request.
6. Security Measures
Encryption in transit, role-based access control, secret masking, audit logging,
signed webhooks and least-privilege architecture.
7. Data Subject Requests
BSC will assist the Controller in responding to data-subject requests using
appropriate technical and organisational measures.
8. Personal Data Breach
BSC will notify the Controller without undue delay after becoming aware of a
Personal Data breach and provide reasonable cooperation.
9. Deletion & Return
On termination, BSC will delete or return Personal Data per the Customer's
instruction, subject to legal retention requirements.
10. Audits
BSC will make available information reasonably necessary to demonstrate compliance.
Contact: privacy@bigsimplecrm.com.