LiveCRM Data Processing Addendum
This Data Processing Addendum (the "DPA") forms part of the LiveCRM Master Subscription Agreement (the "Agreement") between LiveCRM, Inc. ("LiveCRM") and the customer that accepted it ("Customer"). It applies where LiveCRM processes Personal Data on Customer's behalf. If a term is defined in the Agreement and not here, the Agreement's definition applies. Where this DPA conflicts with the Agreement, this DPA controls for the subject it covers.
1. Definitions #
"Data Protection Laws" means all privacy and data protection laws that apply to LiveCRM's processing of Personal Data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the GDPR as incorporated into United Kingdom law ("UK GDPR"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), and comparable United States state privacy laws.
"Personal Data" means information within Customer Data that relates to an identified or identifiable individual and is protected as personal data, personal information, or an equivalent term under Data Protection Laws.
"Processing", "Controller", "Processor", "Data Subject", "Business", "Service Provider", "Sell", and "Share" have the meanings given in the applicable Data Protection Laws.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by LiveCRM.
"Standard Contractual Clauses" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"UK Addendum" means the International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
"Subprocessor" means a third party engaged by LiveCRM to process Personal Data in connection with the Service.
2. Roles and scope #
2.1 Roles. For Personal Data that Customer or its Users submit to the Service, or that the Service retrieves from a Connected System on Customer's instruction, Customer is the Controller and Business, and LiveCRM is the Processor and Service Provider. Where Customer is itself a Processor acting for another Controller, Customer warrants that it has the authority the other Controller must give for LiveCRM to act as a Subprocessor, and references in this DPA to Customer's instructions include that Controller's instructions passed through Customer.
2.2 LiveCRM as Controller. LiveCRM is an independent Controller for the limited data it processes to run its business rather than to provide the Service to Customer, including account registration details, billing records, and the usage information described in Section 9.8 of the Agreement. This DPA does not govern that processing, which is described in LiveCRM's privacy policy.
2.3 Details of processing. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex I.
3. Instructions #
3.1 Documented instructions. LiveCRM will process Personal Data only on Customer's documented instructions, which consist of the Agreement, this DPA, the configuration Customer and its Users set in the Service, and any further written instruction the parties agree. LiveCRM will not process Personal Data for any other purpose.
3.2 Unlawful instructions. LiveCRM will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, unless prohibited by law from doing so. LiveCRM may suspend the affected processing until the instruction is amended or confirmed.
3.3 Legal requirement to process. If a law to which LiveCRM is subject requires processing beyond Customer's instructions, LiveCRM will inform Customer of that requirement before processing, unless the law prohibits the notice on important grounds of public interest.
3.4 No training. LiveCRM will not use Personal Data to train or fine-tune any artificial intelligence model, and will not permit any Subprocessor to do so.
4. Confidentiality #
LiveCRM will ensure that every person authorized to process Personal Data is bound by an appropriate obligation of confidentiality, and will limit access to those who need it to provide, secure, or support the Service.
5. Security #
5.1 Measures. LiveCRM will implement and maintain the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to Data Subjects.
5.2 No material reduction. LiveCRM will not materially reduce the overall protection of those measures during Customer's Subscription Term.
5.3 Customer's own responsibility. Customer is responsible for its use of the Service, including the permissions it grants to its Users and to the integration user it uses to connect a Connected System, the scope of the runs it starts, and the changes it approves.
6. Subprocessors #
6.1 General authorization. Customer gives LiveCRM general authorization to engage Subprocessors. The current Subprocessors are listed at livecrm.ai/subprocessors.
6.2 Notice and objection. LiveCRM will update that page, and notify Customer by email if Customer has subscribed to notifications there, at least 30 days before a new Subprocessor begins processing Personal Data. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected part of the subscription and receive a refund of prepaid fees for the remaining term.
6.3 Flow-down and liability. LiveCRM will impose on each Subprocessor data protection obligations that are no less protective than those in this DPA, and remains liable to Customer for each Subprocessor's performance of those obligations.
6.4 Customer's own third-party services. A Connected System, data provider, or artificial intelligence provider that Customer connects with its own credentials is not a Subprocessor. Customer's use of it is governed by Customer's own agreement with that provider.
7. Data Subject rights #
7.1 Assistance. Taking into account the nature of the processing, LiveCRM will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from Data Subjects to exercise their rights. The Service's own functions, including search, export, reversal, and deletion, are the primary means of that assistance.
7.2 Requests received by LiveCRM. If LiveCRM receives a request from a Data Subject concerning Personal Data it processes for Customer, it will not respond to the substance of the request other than to direct the Data Subject to Customer, and will inform Customer without undue delay.
8. Assistance and impact assessments #
LiveCRM will provide Customer with reasonable assistance, at Customer's expense for anything beyond the information LiveCRM makes generally available, in carrying out data protection impact assessments and prior consultations with supervisory authorities, in each case in relation to the Service and taking into account the information available to LiveCRM.
9. Personal Data Breach #
9.1 Notice. LiveCRM will notify Customer without undue delay, and in any event within 72 hours, after confirming a Personal Data Breach affecting Personal Data in LiveCRM's systems.
9.2 Contents. The notice will describe, to the extent known, the nature of the breach, the categories and approximate volume of Personal Data and Data Subjects affected, the likely consequences, and the measures taken or proposed. LiveCRM will provide further information as it becomes available.
9.3 Cooperation. LiveCRM will take reasonable steps to contain and remediate the breach and will cooperate with Customer so that Customer can meet its own notification obligations. LiveCRM's notice is not an acknowledgment of fault.
10. Return and deletion #
10.1 Deletion on request. At any time, including after the Agreement ends, Customer's account administrator may ask LiveCRM in writing to delete the Personal Data held in Customer's account. LiveCRM will delete it within 30 days of the request.
10.2 Export first. Customer is responsible for exporting anything it wishes to keep before requesting deletion, using the export functions the Service makes available.
10.3 Backups and legal retention. Copies of Personal Data in backups expire on LiveCRM's normal backup cycle, and LiveCRM may retain Personal Data where a law requires it, in each case subject to the confidentiality and security obligations in this DPA and the Agreement.
10.4 Changes already made. Changes the Service made in a Connected System remain in that system and are not affected by deletion of Customer's account.
11. Audits and reports #
11.1 Reports and documentation. LiveCRM will make available to Customer the information necessary to demonstrate compliance with this DPA. That information consists of LiveCRM's then-current third-party audit reports and certifications where LiveCRM holds them, its security documentation, and its responses to reasonable security questionnaires.
11.2 Audits. Where the information described in Section 11.1 is not sufficient to demonstrate compliance, Customer, if it holds a paid subscription, may audit LiveCRM's processing, once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting LiveCRM's operations, subject to confidentiality obligations, and at Customer's expense. A supervisory authority may audit on the terms it requires.
12. International transfers #
12.1 Transfer mechanism. Where Customer's use of the Service involves a transfer of Personal Data subject to the GDPR, UK GDPR, or Swiss law to LiveCRM in the United States, the Standard Contractual Clauses apply and are incorporated into this DPA by reference.
12.2 Modules and options. Module Two applies where Customer is a Controller and Module Three applies where Customer is a Processor. Clause 7, the docking clause, does not apply. In Clause 9, Option 2, general written authorization, applies with the notice period in Section 6.2. In Clause 11, the optional independent dispute resolution language does not apply. In Clause 13 and Annex I.C, the competent supervisory authority is the one identified in Annex I. In Clause 17, the governing law is the law of Ireland. In Clause 18(b), disputes are resolved before the courts of Ireland. Annex I and Annex II of this DPA serve as Annexes I and II to the Standard Contractual Clauses, and Section 6.1 serves as the list required by Annex III.
12.3 United Kingdom. For transfers subject to the UK GDPR, the UK Addendum applies to the Standard Contractual Clauses. In Table 4 of the UK Addendum, neither party may end the addendum as set out in Section 19 of it.
12.4 Switzerland. For transfers subject to Swiss law, references in the Standard Contractual Clauses to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Federal Data Protection and Information Commissioner, and the clauses also protect the data of legal entities until Swiss law no longer requires it.
12.5 Alternative mechanism. If LiveCRM adopts another lawful transfer mechanism, including self-certification under an adequacy framework, LiveCRM may rely on it in place of the Standard Contractual Clauses to the extent it covers the transfer, on notice to Customer. LiveCRM is not currently certified under the EU-US Data Privacy Framework, so the Standard Contractual Clauses are the operative mechanism.
13. United States state privacy laws #
13.1 Service Provider status. LiveCRM is a Service Provider, or the equivalent under other state laws, for Personal Data it processes on Customer's behalf. The business purposes for which Customer discloses Personal Data to LiveCRM are described in Annex I.
13.2 Restrictions. LiveCRM will not Sell or Share Personal Data, will not retain, use, or disclose Personal Data for any purpose other than performing the Service and the business purposes described in Annex I or as otherwise permitted by the CCPA, will not retain, use, or disclose Personal Data outside the direct business relationship between the parties, and will not combine Personal Data with personal information it receives from another source, except as the CCPA permits a Service Provider to do.
13.3 Certification. LiveCRM understands the restrictions in Section 13.2 and will comply with them.
13.4 Notice of inability. LiveCRM will notify Customer if it determines it can no longer meet its obligations under the CCPA, and Customer may take reasonable steps to stop and remediate unauthorized processing.
13.5 Deidentified data. If either party discloses deidentified data, it will not attempt to reidentify it and will bind any recipient to the same restriction.
14. Liability, term, and general #
14.1 Liability. Each party's liability under this DPA, including under the Standard Contractual Clauses, is subject to the limitations and exclusions in the Agreement, to the extent Data Protection Laws permit.
14.2 Term. This DPA takes effect when Customer accepts the Agreement, or on the date the parties sign it if signed separately, and continues until LiveCRM has deleted the Personal Data in accordance with Section 10.
14.3 Precedence. If there is a conflict, the Standard Contractual Clauses control over the rest of this DPA for transfers they cover, this DPA controls over the Agreement for its subject, and an Order Form controls over both for the transaction it covers.
14.4 Changes. LiveCRM may update this DPA where a change in Data Protection Laws, a Subprocessor, or the Service requires it, provided the update does not materially reduce the protection given to Personal Data. Material changes follow the notice process in the Agreement.
14.5 Signature. Customer accepts this DPA by accepting the Agreement. Where Customer requires a signed copy, LiveCRM will sign one on request at jaime@livecrm.ai. No signature is required for this DPA to bind the parties.
Annex I. Description of processing #
A. Parties #
Data exporter: the Customer identified in the Agreement, acting as Controller or as Processor for its own customer. Contact: the account administrator's email address on file. Role: Controller, or Processor where Module Three applies. Activities: use of the Service as described in the Agreement.
Data importer: LiveCRM, Inc., 7201 Lighthouse Lane NE, Olympia, WA 98506, United States. Contact: jaime@livecrm.ai. Role: Processor. Activities: providing the Service.
B. Description #
Subject matter: LiveCRM's provision of a customer relationship management operations service that reconciles, corrects, and changes records in Customer's Connected Systems on Customer's instruction.
Duration: for the term of the Agreement and until deletion under Section 10.
Nature and purpose: hosting a reconciled copy of records from Customer's Connected Systems; detecting duplicates, non-canonical values, and records that disagree with external sources; proposing changes; making changes Customer or its authorized agents approve or configure; recording each change with its prior values; reversing changes on request; generating alerts and notifications; and providing support.
Categories of Data Subjects: Customer's business contacts, leads, prospects, and customer representatives whose records are held in a Connected System; Customer's own personnel who use the Service or who appear as record owners in a Connected System.
Categories of Personal Data: business contact details such as name, job title, employer, business email address, business telephone number, business postal address, and public professional profile links; CRM record metadata such as ownership, activity, lifecycle status, and record history; account credentials and identifiers for Users of the Service; information Customer chooses to place in fields the Service reads or writes.
Special categories of Personal Data: none. Customer is responsible for not submitting special categories of Personal Data, protected health information, payment card data, or government identifiers to the Service, as stated in Section 5.4 of the Agreement.
Frequency: continuous for the duration of the Agreement.
Retention: for the term of the Agreement and until deletion under Section 10, subject to backup expiry.
Subprocessor processing: each Subprocessor listed at livecrm.ai/subprocessors processes Personal Data for the purpose stated there, for the duration of its engagement.
Business purposes under United States state privacy laws: providing, securing, supporting, and improving the Service for Customer; detecting and preventing security incidents and fraud; and complying with law.
C. Competent supervisory authority #
The supervisory authority of the EU member state in which the data exporter is established, or where the data exporter is not established in the EU, the supervisory authority of the member state in which its representative under Article 27 GDPR is established. For transfers under the UK Addendum, the Information Commissioner. For transfers subject to Swiss law, the Federal Data Protection and Information Commissioner.
Annex II. Technical and organizational measures #
LiveCRM maintains the measures below. A current description is published at livecrm.ai/security.
Hosting and segregation. The Service runs on Amazon Web Services in the United States. Each customer's data is separated at the database level by row-level security enforced by the database and applied even to the table owner, using a database role that cannot bypass those policies. A build-time check fails the release if a new table could hold customer data without that separation.
Encryption. Data in transit is encrypted with TLS, including between the application and its database. Data at rest, including the database, its snapshots, and storage buckets holding customer data, is encrypted with AES-256 using keys managed by the cloud provider. Credentials for Connected Systems and customer-supplied provider keys are stored in a managed secrets service under a path unique to each tenant.
Access control. Access to the Service is by federated sign-in or a one-time email link; LiveCRM stores no passwords. Administrative capabilities inside a customer account are limited by role. Access by AI agents is granted through OAuth 2.1 with proof key for code exchange and is limited to the capabilities a user approves. Access to production infrastructure is limited to LiveCRM's administrator. The database is not reachable from the internet and accepts connections only from the application's own compute, so administrative database work is performed through the application's own task definition rather than a direct connection. Deployments run through an automated pipeline with a scoped role rather than by hand. Administrative actions in the cloud account are logged across all regions with log file validation and retained for 400 days, and continuous threat detection is enabled.
Change control and accountability. Every change the Service makes to a Connected System is recorded with its prior values before the change is made, and can be reversed. The application's database role cannot delete audit records and can amend only their status fields.
Application security. Every route requires authentication except those that must be public by design, enforced by an automated test that fails the build. Requests are schema-validated and database queries are parameterized. Dependencies are scanned for known vulnerabilities on each build.
Resilience. The database is backed up daily and backups are retained for seven days. A restore has been rehearsed.
Vulnerability reporting. Reports are received at jaime@livecrm.ai and acknowledged within five business days.
Subprocessor management. Subprocessors are listed publicly, are bound to obligations no less protective than these, and are reviewed before engagement.