The data processing terms for customers using PearCRM as a processor for personal data in their workspaces.
This Data Processing Agreement (“DPA”) forms part of the PearCRM Terms of Service.
1. Parties
This Agreement is entered into between:
- Customer (“Controller”), who determines the purposes and means of processing personal data.
and
- PearCRM (“Processor”), which processes personal data solely on behalf of the Customer while providing the Service.
2. Scope
PearCRM processes personal data only to provide the CRM services requested by the Customer.
The Customer remains solely responsible for determining:
- what personal data is collected;
- whether such collection is lawful;
- how long such data should be retained;
- whether a lawful basis for processing exists.
3. Categories of Personal Data
Depending on how the Customer uses PearCRM, personal data may include:
- names;
- email addresses;
- phone numbers;
- business information;
- customer notes;
- order information;
- payment-related information;
- communications;
- uploaded documents;
- calendar events;
- tasks;
- any other information uploaded by the Customer.
4. Categories of Data Subjects
Data subjects may include:
- customers;
- leads;
- employees;
- contractors;
- suppliers;
- website visitors;
- business contacts.
5. Processor Obligations
PearCRM agrees to:
- process data only according to documented instructions from the Customer;
- implement reasonable technical and organizational security measures;
- restrict access to authorized personnel;
- maintain confidentiality obligations;
- assist the Customer where reasonably possible in complying with GDPR obligations.
6. Customer Responsibilities
The Customer is solely responsible for:
- ensuring a lawful basis for processing;
- obtaining required consents where applicable;
- providing required privacy notices;
- responding to data subject requests;
- ensuring uploaded data does not violate applicable law.
PearCRM does not verify the legality of Customer Data.
7. Security Measures
PearCRM maintains commercially reasonable safeguards, which may include:
- encrypted communications (HTTPS/TLS);
- password hashing;
- access controls;
- authentication mechanisms;
- infrastructure monitoring;
- software updates;
- security logging where applicable.
No security measure can guarantee complete protection against cyber threats.
8. Security Incidents
If PearCRM becomes aware of a confirmed security incident affecting Customer Data, PearCRM will notify the Customer without undue delay after becoming aware of the incident.
Notification does not constitute an admission of liability.
9. Subprocessors
PearCRM may engage trusted third-party subprocessors, including cloud hosting providers, payment processors, email providers, analytics providers, and integration providers.
PearCRM remains responsible for selecting subprocessors with appropriate contractual obligations where required by applicable law.
10. International Transfers
Where personal data is transferred outside the European Economic Area, PearCRM will implement appropriate safeguards where required by law.
11. Data Deletion
Upon termination of the Service and subject to applicable law, Customer Data may be deleted after a reasonable retention period unless the Customer requests earlier deletion where technically feasible.
Certain backup copies may remain for a limited period for disaster recovery and legal compliance.
12. Liability
Nothing in this DPA expands PearCRM’s liability beyond the limitations contained in the Terms of Service.
PearCRM shall not be liable for:
- unlawful collection of personal data by the Customer;
- inaccurate or outdated information uploaded by the Customer;
- Customer instructions that violate applicable law;
- failures of third-party services;
- unauthorized disclosure caused by Customer actions or omissions.
13. Audit Requests
Where required by applicable law, PearCRM may provide reasonable information demonstrating compliance with this DPA.
Any audit must:
- be reasonable;
- not interfere with normal operations;
- protect confidential information;
- be conducted no more than once per calendar year unless required by law.
14. Governing Law
This DPA shall be governed by the same governing law specified in the PearCRM Terms of Service.
15. Contact
Privacy and data protection requests:
Email: pearcrmadmin@gmail.com