Data Processing Agreement
Data Processing Agreement for AmpleoCRM
Between: [Customer name, company registration number, and address] (the "Controller")
and
Ampleo ApS, company registration number 39640708, Hestetorvet 7, 1.th, Roskilde, Denmark (the "Processor")
1. Background and purpose
This Data Processing Agreement (the "DPA") governs the Processor's processing of personal data on behalf of the Controller in connection with the provision of the AmpleoCRM platform and related services (the "Service") pursuant to the main agreement entered into between the Parties (the "Main Agreement").
The DPA sets out the rights and obligations of the Parties in relation to the processing of personal data and is entered into to ensure that processing is carried out in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Danish Data Protection Act, and other applicable legislation.
In the event of conflict between this DPA and the Main Agreement regarding the processing of personal data, this DPA shall prevail.
2. Obligations of the Controller
The Controller is responsible for ensuring that a valid legal basis exists for the personal data processed under this DPA.
The Controller warrants that the personal data transferred to the Processor has been lawfully collected and that the data subjects have been informed as required by Articles 13 and 14 of the GDPR.
The Controller instructs the Processor regarding processing as further described in Annex A.
3. Obligations of the Processor
3.1 Instructions
The Processor shall process personal data only on documented instructions from the Controller. This DPA constitutes such instructions.
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection legislation.
3.2 Confidentiality
The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 Security
The Processor implements appropriate technical and organisational measures in accordance with Article 32 of the GDPR to ensure that processing meets the requirements of the regulation and protects the rights of data subjects. The measures are further described in Annex C.
3.4 Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller with:
- Responding to requests from data subjects exercising their rights under Chapter III of the GDPR.
- Security of processing, including the handling of personal data breaches.
- Data protection impact assessments and prior consultations with supervisory authorities, where relevant.
The Processor is entitled to reasonable compensation for assistance that exceeds its ordinary obligations under this DPA, unless such assistance is necessitated by circumstances attributable to the Processor.
3.5 Notification of personal data breaches
The Processor shall notify the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach. The notification shall as a minimum contain the information set out in Article 33(3) of the GDPR.
4. Sub-processors
The Controller hereby grants the Processor general authorisation to engage sub-processors. The sub-processors approved as of the date of this DPA are listed in Annex B.
The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors with at least 30 days' notice. Notice may be given by publication on the AmpleoCRM website, in the customer portal, or by e-mail.
The Controller may object to changes before the expiry of the notice period. If the Controller objects, the Processor is entitled, but not obliged, to continue using the existing sub-processor. If the Parties cannot reach a solution, the Controller is entitled to terminate the Main Agreement for the affected part of the Service.
The Processor imposes the same data protection obligations on sub-processors as those set out in this DPA by means of a written agreement.
5. Transfers to third countries
Processing of personal data under this DPA takes place within the EU/EEA as a general rule.
If a transfer to a third country exceptionally takes place, it shall only be carried out on the basis of a valid transfer mechanism under Chapter V of the GDPR, including the European Commission's standard contractual clauses and any necessary supplementary measures.
The Processor primarily uses infrastructure provided by Hetzner Online GmbH in Germany and other European suppliers to minimise the need for transfers outside the EU/EEA.
6. Rights of data subjects
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
Requests from data subjects received directly by the Processor shall be forwarded to the Controller without undue delay, and the Controller is responsible for responding.
7. Audit and inspection
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR.
The Processor allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Audits shall be carried out upon reasonable notice of at least 30 days, during normal business hours, and in a manner that does not unreasonably disrupt the Processor's operations. The Controller bears its own costs as well as the Processor's documented additional costs associated with audits, unless the audit reveals a material breach by the Processor.
The Processor may fulfil parts of its audit obligation by providing recognised third-party certifications (such as ISO 27001) or auditor reports (such as ISAE 3000), where available.
8. Deletion and return
Upon termination of the services under the Main Agreement, the Processor shall, at the Controller's choice, delete or return all personal data to the Controller and delete existing copies, unless retention is required by Union or Member State law.
For up to 30 days after termination, the Controller may export its data via the Service's standard functionality. After this period, the Processor shall delete personal data from production environments within 30 days and from backup media within 90 days.
9. Liability
The Parties' liability under this DPA is governed by the liability provisions of the Main Agreement, including any limitations of liability, to the extent compatible with mandatory law.
Each Party is directly liable to data subjects and supervisory authorities in accordance with Article 82 of the GDPR.
10. Term and termination
The DPA enters into force upon the Controller's acceptance of the Service's terms or upon signature by the Parties, whichever occurs first.
The DPA remains in force as long as the Processor processes personal data on behalf of the Controller under the Main Agreement.
Provisions that by their nature are intended to survive termination, including obligations regarding confidentiality, deletion, and liability, shall remain in force after termination of the DPA.
11. Governing law and venue
The DPA is governed by Danish law.
Disputes arising out of or in connection with the DPA shall be settled at Ampleo's venue from time to time as the court of first instance, unless otherwise required by mandatory law.
12. Execution
The DPA may be concluded electronically, including by acceptance of the Service's terms during signup, or by signature on paper or via a digital signature solution.
Annex A – Processing of personal data
A.1 Purpose of processing
The processing of personal data is carried out for the purpose of delivering AmpleoCRM to the Controller, including the administration of customer and contact data, sales and pipeline management, service agreements, field service tasks, document generation, and communication.
A.2 Nature of processing
The Processor performs the following types of processing:
- Hosting and operation of the CRM platform.
- Storage of information in a PostgreSQL database within the EU.
- User administration via Keycloak.
- Dispatch of system and transactional e-mails.
- Synchronisation and integration with third-party systems selected by the Controller (e.g. Microsoft 365, Google Workspace, Uniconta, Business Central).
- Recommendation and AI functionality, where enabled by the Controller.
- Backup, security, and troubleshooting.
A.3 Duration of processing
Processing takes place for the duration of the Main Agreement, as well as for a subsequent period of up to 90 days for the purpose of export and deletion, cf. Section 8 of the DPA.
A.4 Categories of data subjects
- Employees and users of the Service at the Controller.
- The Controller's customers, leads, and contact persons.
- Suppliers and business partners of the Controller.
- Other persons that the Controller chooses to register in the Service.
A.5 Categories of personal data
Ordinary personal data:
- Name, title, and organisational affiliation.
- Contact information (e-mail, telephone, address).
- Login credentials and user profiles.
- Correspondence and communication history.
- Information regarding agreements, offers, invoicing, and services.
- Tasks, notes, and activities linked to customers and contacts.
- Technical information such as IP addresses and log data.
The Controller should generally not register special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) in the Service, unless necessary and based on a valid legal basis.
Annex B – Approved sub-processors
The Controller has approved the use of the following sub-processors:
- Hetzner Online GmbH – Germany (EU) – Hosting of servers, databases, and backup – All customer data stored in AmpleoCRM.
- Mistral AI – France (EU) – AI-based recommendations and suggestions – Customer data sent to the model for recommendations (configurable).
- Lettermint – EU – Dispatch of system and transactional e-mails – E-mail addresses, sender/recipient, subject, and content of system mails.
The updated list of sub-processors is available at all times on the AmpleoCRM website and in the customer portal.
Annex C – Technical and organisational measures
The Processor has implemented the following measures in accordance with Article 32 of the GDPR:
C.1 Access control
- User authentication via Keycloak, with multi-factor authentication for administrative users.
- Role-based access control (RBAC) at tenant and record level.
- Access rights are reviewed periodically.
C.2 Encryption
- Encryption in transit via TLS 1.2 or newer.
- Encryption of data at rest at database level.
- Secure storage of access credentials and keys.
C.3 Logical and physical separation
- Multi-tenant architecture with logical separation of customer data at the database level.
- Servers are hosted in data centres with appropriate physical security (Hetzner, ISO 27001-certified locations).
C.4 Logging and monitoring
- Security log of access to and changes in the system.
- Automated monitoring of system availability and security.
- Alerting upon suspicious activity.
C.5 Backup and continuity
- Daily backup of production data.
- Backups are stored encrypted within the EU.
- Periodic testing of restore procedures.
C.6 Organisational measures
- The Processor has designated a person responsible for data protection.
- Employees and subcontractors are subject to written confidentiality obligations.
- Employees receive ongoing training in data protection and information security.
- Written policies and procedures for handling security breaches.
C.7 Handling of security breaches
- Documented procedure for detection, reporting, and handling of breaches.
- Notification to the Controller no later than 48 hours after detection of a breach.
- Evaluation and improvement of measures following incidents.