Customermates logoCustomermates logo Home
PricingFeaturesDocumentation
ContactLogin
Customermates logoCustomermates logo Home

Data Processing Agreement (DPA)

Version 2026-08-07, last updated 7 August 2026; effective for each Customer when concluded under Section 2

This Data Processing Agreement ("DPA") supplements and forms an integral part of the Terms and Conditions (the "Main Agreement") between Benjamin Wagner, operating as Customermates, An den Kasernen 25, 68167 Mannheim, Germany (the "Provider" or "Processor"), and the customer (the "Customer" or "Controller"). It governs the processing of personal data carried out by the Provider on behalf of the Customer within the framework of the software-as-a-service offering, including the optional connected-account feature (email, messaging and social-network operations, and calendar), in accordance with Art. 28 GDPR.

This version takes effect for a Customer only when concluded under Section 2. Publication, display, or access to this document does not by itself conclude or amend a DPA for an existing customer.

1. Subject Matter, Roles, and Duration

The subject matter of this DPA is the processing of personal data that the Provider performs on behalf of and on the documented instructions of the Customer in performing the Main Agreement.

With respect to the personal data covered by this DPA, in particular the Customer's connected mailboxes, messages, contacts, calendars, social content and engagement data, profiles, relationship requests, and Sales Navigator search and list data, the Customer acts as the controller and the Provider acts as the processor within the meaning of Art. 4 GDPR. The underlying communication platforms that the Customer connects (for example Google, Microsoft, LinkedIn, Meta/WhatsApp, Meta/Instagram, and Telegram) act as independent controllers for their own services.

This allocation does not affect the Provider's role as an independent controller for its own website, account, billing, security, and support data, which is described in the Provider's privacy policy and is not the subject of this DPA.

This DPA takes effect together with the Main Agreement and remains in force for as long as the Provider processes personal data on behalf of the Customer, irrespective of the termination of the Main Agreement, until all such data has been deleted or returned in accordance with Section 11.

2. Conclusion and Parties

The parties to this DPA are the Provider named above and the Customer, who is identified by the account and company data held in the Customer's account.

This DPA is concluded in electronic form within the meaning of Art. 28(9) GDPR when an authorised system administrator accepts the Main Agreement and this identified DPA version during onboarding on behalf of the business Customer. A later identified version amends this DPA only when an authorised system administrator accepts it electronically through the managed-service legal-update flow after the notice described in Section 10 of the Main Agreement. Updating the list maintained at Subprocessors under Section 9 does not constitute an amendment to this DPA and remains subject to the separate notice and objection procedure in that section. On request, the Provider provides the Customer with a copy of this DPA in text form.

Where the Customer does not itself determine the purposes and means of the processing, but makes the Service available to its own customers under its own agreement, for example as a reseller or partner, the Customer acts as a processor toward those customers and the Provider acts as a subprocessor. In that case, every reference in this DPA to the Customer as controller is to be read as a reference to the Customer acting on the documented instructions of its own customer. The Customer warrants that it is authorised to conclude this DPA and to issue the instructions given under it, and that the relevant controller has authorised the engagement of the Provider as a subprocessor. The Customer remains responsible toward the Provider for all obligations under this DPA.

This DPA covers only the managed Service operated by the Provider. Running the software on infrastructure independently controlled by a self-host operator does not by itself appoint the Provider as processor, and personal data covered by this DPA is not transmitted to the Provider merely because the software is installed or updated. The independent operator determines its own infrastructure, providers, purposes, and means of processing and is responsible for its own processor agreements and transfer safeguards. Any support, managed operation, Enterprise service, or other activity through which the Provider actually receives personal data requires the separately applicable agreement.

3. Nature and Purpose of the Processing

The Provider processes personal data solely for the purpose of providing the contractual services under the Main Agreement. The processing comprises:

  • the core CRM service: creating, storing, displaying, searching, linking, exporting, and deleting the Customer's CRM records, in particular contacts, organisations, deals, services, tasks, notes, and custom fields; the administration of users and permissions; activity and audit logging; product notifications; and the delivery of webhooks to endpoints configured by the Customer; and
  • where activated, the connected-account feature: connecting the Customer's own email, messaging, social-network, and calendar accounts; retrieving, sending, synchronizing, and displaying messages, contacts, and calendar events; retrieving and displaying social posts, comments, reactions, and person or company profiles; listing, sending, accepting, withdrawing, or declining relationship requests; running Sales Navigator lead and company searches; viewing existing lead or account lists and adding entries to them; and storing a copy of synchronized content where described in the Privacy Policy.

The connected-account feature is powered by the transport provider UNIPILE SAS, which is engaged as a subprocessor subject to Section 9. Authentication takes place in a Unipile-hosted flow in which the Customer's user enters the relevant provider credentials or completes the provider's OAuth flow. Those credentials or the OAuth authorization are processed within that flow; the Provider receives neither provider passwords nor OAuth tokens and retains only an opaque account identifier and non-secret account metadata.

4. Categories of Data Subjects and Personal Data

Categories of data subjects. The processing concerns the Customer's own users; any natural persons whose personal data the Customer stores in the CRM, for example contacts, leads, prospects, customers, suppliers, partners, and their employees; correspondents with whom the Customer communicates; and other people returned or affected by connected-account operations, including post and comment authors, reactors, profile subjects, parties to relationship requests, Sales Navigator leads, and company representatives.

Categories of personal data. Depending on how the Customer configures and uses the service, the processing may cover:

  • CRM record data, including names, contact details, company and role, deal and task data, free-text notes, and customer-defined custom fields;
  • audit and activity logs recording actions taken in the Customer's account;
  • content from the Customer's account that the Customer attaches to or reproduces in a support or feedback request;
  • connected-account metadata (for example the connected account's identifier, type, and status);
  • email content, including subject, body, sender and recipient addresses, and attachments;
  • chat and direct-message content across the connected social and messaging channels;
  • contact and participant profile data, including name, avatar, LinkedIn headline or occupation, profile URL, and the email address, phone number, or handle used as an identifier;
  • social posts and engagement data, including post or comment text, authors, reactors, timestamps, reaction types, and counters;
  • person and company profile and relationship data, including provider identifiers, names, profile URLs and images, descriptions, employment, location, industry, network distance, connection status, and request messages;
  • Sales Navigator search inputs, results, and list data, including search URLs and filters, lead and company profiles, list names and membership, and saved status;
  • calendar events, including attendee email addresses and RSVP status;
  • message and account metadata; and
  • the raw inbound payloads received from the underlying providers.

Attachment binaries are streamed or proxied on demand and are not stored by the Provider; only attachment metadata is stored. Because message, contact, calendar, social, relationship, and search content is determined by the Customer, its correspondents, and the underlying platforms, it may contain further categories of personal data, including special categories of personal data under Art. 9 GDPR where the Customer determines such content. The Customer, as controller, is responsible for the lawfulness of the content and operations it initiates through the service.

5. Instructions of the Controller

The Provider processes the personal data covered by this DPA only on the documented instructions of the Customer, including with regard to the transfer of personal data to a third country or an international organisation, unless required to do otherwise by Union or Member State law to which the Provider is subject; in that case the Provider informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Customer's documented instructions are constituted by this DPA, the Main Agreement, and the Customer's use and configuration of the service (including the accounts it connects and the actions it initiates through the product). Additional or amended instructions must be given in text form.

The Provider informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.

6. Obligations and Rights of the Controller

The Customer is responsible for the lawfulness of the processing and of the instructions it issues. In particular, the Customer is responsible for having a legal basis for the personal data it uploads, imports, or ingests into the service, for fulfilling its information duties toward data subjects, and for the accuracy of the personal data it processes through the service.

The Customer is entitled to issue instructions to the Provider on the processing of personal data on its behalf, to obtain information about that processing, and to exercise the audit rights set out in this DPA.

7. Confidentiality

The Provider ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the personal data only on the instructions of the Customer.

8. Security of Processing (Art. 32 GDPR)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, the Provider implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. These measures comprise in particular: encryption of personal data in transit by TLS, and encryption at rest for the production database and its backups; role-based access control, individual named accounts, and authentication for all administrative access; segregation of Customer data by company account at the data layer; logging and monitoring of access and of security-relevant events; measures to restore the availability of and access to personal data in a timely manner after a physical or technical incident; and a process for regularly testing and evaluating the effectiveness of these measures.

9. Subprocessors

The Customer grants the Provider a general written authorization to engage subprocessors. The Provider maintains a current page of its processors, subprocessors, and other recipients at Subprocessors. Only the entries expressly identified there as processing personal data covered by this DPA on the Customer's behalf are incorporated into this DPA as subprocessors, including their identity, purpose, and location.

Before a subprocessor processes personal data on the Customer's behalf, the Provider enters into a written contract that imposes the same data-protection obligations required by this DPA in accordance with Art. 28(2) and (4) GDPR. Disclosing a contractual gap does not replace that written contract or authorize processing. Where a subprocessor fails to fulfil its data-protection obligations, the Provider remains fully liable to the Customer for the performance of those obligations.

For the connected-account feature, the Provider uses UNIPILE SAS (RCS Roanne 885265595, 168 rue de la Rotonde, 42153 Riorges, France) as a subprocessor for connected email, messaging, social-network, and calendar data and operations. This includes retrieving social posts and engagement, looking up person and company profiles, managing relationship requests, and performing Sales Navigator searches and list operations initiated by the Customer. The executed supplier DPA identifies the Provider as controller and Unipile as processor; in the downstream processing governed by this DPA, the Customer is controller, the Provider is processor, and Unipile performs the supplier role described here. The supplier DPA's annex lists personal master data, contact data, professional data, information disclosed or contained in public directories, and IP addresses, while the operational scope also includes the categories listed in Section 4. Further details are set out at Subprocessors.

For the storage of the personal data processed on the Customer's behalf, the Provider engages Databricks, Inc. (Neon) (https://neon.com) as the contracted subprocessor operating the managed PostgreSQL database through Neon, LLC. The Provider has configured its primary production database in the AWS Frankfurt region (eu-central-1). This is a selected product setting and not a contractually guaranteed data-residency commitment; the Provider informs the Customer of a change of region using the notification procedure set out in this Section. The Neon Platform Services Product Specific Schedule dated 5 August 2026 adds Grafana Labs in the United States to the full current Databricks subprocessor list. That list identifies some cloud and AI providers as customer-selected; the Provider has not selected an AI-backed Databricks service for its Neon database. Databricks is established in a third country, and the transfer mechanism for restricted transfers to Databricks is indicated at Subprocessors.

Forward Email, LLC hosts and stores the Provider's final operator mailbox and is not used for the connected-account feature or ordinary CRM processing. Where the Customer attaches or reproduces personal data covered by this DPA in a support or feedback request delivered to that mailbox, Forward Email stores and otherwise processes that fragment as a subprocessor. For ordinary account and business correspondence, it supports processing for which the Provider is an independent controller and which is outside this DPA. Forward Email's standard data processing agreement is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers; details are stated at Subprocessors.

Where the Provider itself decides to add or replace a subprocessor, it informs the Customer before that subprocessor begins processing personal data on the Customer's behalf and allows the Customer a reasonable opportunity to object before processing begins. Where an existing supplier gives notice of an intended addition or replacement in its own supply chain, the Provider informs the Customer without undue delay after receiving that notice. If the supplier notice provides an objection period, the Provider states the remaining period in its notice to the Customer. The Customer may object in text form without undue delay on reasonable data-protection grounds. Where the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected service in accordance with the Main Agreement. For supplier-originated changes, the Provider does not promise a fixed advance-notice period that its supplier contracts do not guarantee.

10. Assistance to the Controller

Taking into account the nature of the processing, the Provider assists the Customer, by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under Arts. 12 to 23 GDPR. Where a data subject addresses such a request directly to the Provider, the Provider forwards it to the Customer without undue delay and does not respond to it itself unless instructed by the Customer.

The Provider further assists the Customer in ensuring compliance with the obligations under Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Provider. In particular, the Provider notifies the Customer without undue delay after becoming aware of a personal data breach affecting the personal data processed on the Customer's behalf, and provides the information reasonably necessary for the Customer to meet its own notification and communication obligations under Arts. 33 and 34 GDPR.

11. Deletion or Return of Data

When the Customer disconnects a connected account, the Provider deletes that account's stored threads, messages, participants, and calendar data from its own systems and requests that Unipile remove the corresponding account. The Provider has no contractual per-account deletion right against Unipile and can only make that request. Where a connected account is instead removed automatically, in particular on a failed payment, on expiry of a trial period or after prolonged inactivity, the stored data is at present only deactivated and marked as deleted in the Provider's systems; the Customer may require its deletion at any time. Raw inbound records that could not be associated with a connected account cannot currently be attributed to a Customer for per-account export or deletion and are retained for error analysis without a fixed period.

For 30 days after the end of the services relating to processing, the Provider retains the personal data available in its own systems and attributable to the Customer so that the Customer can choose deletion or return in text form. If the Customer chooses deletion, or does not communicate a choice within that period, the Provider deletes the data from its own systems without undue delay after the choice or expiry of the period. If the Customer chooses return within that period, the Provider returns the data in accordance with the Main Agreement and then deletes the remaining copies in its own systems. Union or Member State law requiring continued storage remains unaffected. Limitations affecting data held by subprocessors and unassigned raw inbound records are stated in this Section and at Subprocessors.

Deletion required by this Section is completed in the Provider's active systems without undue delay and in its backups at the latest within 90 days as those backups expire. The Provider instructs its subprocessors to delete the corresponding data; deletion at subprocessor level follows the terms of the respective agreement with that subprocessor.

12. Audits and Information

The Provider makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

To satisfy such requests, the Provider may in the first instance provide relevant documentation, summaries of its technical and organizational measures, and available third-party audit reports or certifications (including those of its subprocessors). On-site inspections take place with reasonable advance notice, during regular business hours, without disrupting the Provider's operations, and subject to appropriate confidentiality undertakings.

13. International Transfers

The Provider processes personal data on the Customer's behalf primarily within the European Union. Before a subprocessor processes that data in a third country, the Provider ensures that an applicable transfer mechanism under Chapter V GDPR is in place and identifies it at Subprocessors. Encryption, data minimization, and other supplementary technical measures do not replace a required Chapter V transfer mechanism.

For the connected-account feature, Unipile states that connected-account data is stored in the EU (France). Its data processing agreement nevertheless permits transfers outside the European Union where Chapter V GDPR safeguards apply, and its subprocessor list names a payment provider in the USA and five proxy providers whose location is not stated. The supplier DPA identifies no specific transfer mechanism for those providers; any affected transfer is subject to the requirement in the preceding paragraph that an applicable Chapter V mechanism be in place first.

14. Liability

Each party is liable in accordance with the statutory provisions, in particular Art. 82 GDPR governing the apportionment of liability between controller and processor. As between the parties, the liability provisions of the Main Agreement apply to this DPA. Mandatory statutory liability, in particular for intent and gross negligence, for injury to life, body, or health, and other liability that cannot be excluded or limited under applicable law, remains unaffected.

15. Order of Precedence

In the event of any conflict between this DPA and the Main Agreement with respect to the processing of personal data on behalf of the Customer, this DPA prevails. In the event of any conflict between this DPA and mandatory data protection law, that mandatory law prevails.

Where the parties have individually concluded a signed data processing agreement, that agreement prevails over this DPA for the Customer concerned.

16. Final Provisions

This DPA is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods. The place of jurisdiction is the registered office of the Provider, insofar as legally permissible. Electronic acceptance under Section 2 satisfies the text-form requirement for the identified DPA version; other amendments and supplements to this DPA must be made in text form. Should any provision of this DPA be or become invalid, the validity of the remaining provisions remains unaffected.

This DPA is provided in German and in English. The German version is authoritative; the English version is a convenience translation.

Benjamin Wagner
An den Kasernen 25
68167 Mannheim
mail@customermates.com

Last Update: 07.08.2026

Data Processing Agreement (DPA)
1. Subject Matter, Roles, and Duration
2. Conclusion and Parties
3. Nature and Purpose of the Processing
4. Categories of Data Subjects and Personal Data
5. Instructions of the Controller
6. Obligations and Rights of the Controller
7. Confidentiality
8. Security of Processing (Art. 32 GDPR)
9. Subprocessors
10. Assistance to the Controller
11. Deletion or Return of Data
12. Audits and Information
13. International Transfers
14. Liability
15. Order of Precedence
16. Final Provisions
Customermates logoCustomermates logo Home
GitHubLinkedInX (Twitter)

Product

  • Pricing
  • Features
  • Automation
  • Documentation
  • Affiliate Program (35%)

Features

  • Cloud CRM
  • Contact Management
  • Lead Management
  • CRM Reporting
  • Sales Automation
  • Sales Tracking
  • View all features

Solutions

  • Construction
  • E-Commerce
  • Healthcare
  • Manufacturing
  • Property Management
  • Recruiting
  • View all industries

Compare

  • Cobra alternative
  • Folk CRM
  • HighLevel CRM
  • HubSpot vs Salesforce
  • Notion alternative
  • Vtiger alternative
  • View all comparisons

Resources

  • Agentic AI: Definition, How It Works, and Real-World Examples
  • CRM Examples: Real-World Use Cases, Software, and Industry Applications
  • CRM Software 2026: What It Does and How to Pick the Right One
  • Customer Communication Management Software in 2026
  • Customer Interaction Management: A Practical Guide for 2026
  • Customer Retention Management: The Practitioner's Guide for 2026
  • View all articles

Legal

  • Help
  • Imprint
  • Privacy
  • Terms
  • Subprocessors
  • DPA

Featured on

Featured on UneedCustomermates Reviews on SourceForgeFeatured on Twelve ToolsFeatured on Wired BusinessCustomermates - Featured on Startup FameFeatured on Open-Launch
© 2026 Customermates. All rights reserved. · Viesearch - The Human-curated Search Engine · https://www.promotebusinessdirectory.com/ · http://www.usawebsitesdirectory.com/computers_and_internet/ · https://www.bestsitesindex.com/submit.php