BSC
Big Simple CRM

Data Processing Addendum

Version 1 · Updated 2026-08-04
Big Simple CRM Data Processing Addendum (DPA) Last updated: August 2025 This DPA forms part of the Agreement between the Customer (Controller) and Big Simple CRM (Processor) and governs the processing of Personal Data. 1. Scope & Roles BSC processes Personal Data only to provide the service and on the Customer's documented instructions. The Customer is the Controller; BSC is the Processor. 2. Subject Matter & Duration Processing continues for the duration of the subscription and any wind-down period. 3. Nature & Purpose Hosting, storing and processing lead/client CRM data; generating analytics; delivering configured communications. 4. Categories of Data & Data Subjects Contact details, communications and pipeline data of the Customer's leads and clients; account data of the Customer's staff. 5. Sub-Processors BSC may engage sub-processors under written terms no less protective than this DPA and remains responsible for their performance. A list is available on request. 6. Security Measures Encryption in transit, role-based access control, secret masking, audit logging, signed webhooks and least-privilege architecture. 7. Data Subject Requests BSC will assist the Controller in responding to data-subject requests using appropriate technical and organisational measures. 8. Personal Data Breach BSC will notify the Controller without undue delay after becoming aware of a Personal Data breach and provide reasonable cooperation. 9. Deletion & Return On termination, BSC will delete or return Personal Data per the Customer's instruction, subject to legal retention requirements. 10. Audits BSC will make available information reasonably necessary to demonstrate compliance. Contact: privacy@bigsimplecrm.com.

← Back to Trust Center·Home