Data Processing Addendum
Data processing addendum for customers.
Last updated: July 2, 2026 · SellioCRM, LLC
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
This Data Processing Addendum, including its Annexes, applies where SellioCRM, LLC processes Personal Data on behalf of Customer in connection with the Services. This DPA is incorporated into and forms part of the SellioCRM Terms of Service and any applicable Order Form.
For purposes of this document, "SellioCRM," "Company," "we," "us," and "our" mean SellioCRM, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services. If you access or use the Services on behalf of an organization, you represent and warrant that you have authority to bind that organization, and that organization is the Customer.
1. Definitions
"Applicable Data Protection Laws" means privacy, data protection, data security, breach notification, and similar laws applicable to the processing of Personal Data under the Agreement, which may include the GDPR, UK GDPR, Swiss data protection law, LGPD, CCPA/CPRA, Australia Privacy Act, and other applicable laws.
"Agreement" means the SellioCRM Terms of Service, applicable Order Form, and incorporated policies.
"Controller," "Processor," "Data Subject," "Personal Data," "Process," "Processing," "Subprocessor," and similar terms have the meanings given under Applicable Data Protection Laws.
"Customer Personal Data" means Personal Data processed by SellioCRM on behalf of Customer under the Agreement.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by SellioCRM.
2. Roles of the Parties
For Customer Personal Data, Customer is the Controller or Processor, and SellioCRM is the Processor or Subprocessor, as applicable. Customer determines the purposes and means of processing Customer Personal Data. SellioCRM processes Customer Personal Data only on behalf of Customer and in accordance with Customer's documented instructions.
3. Customer Instructions
Customer instructs SellioCRM to process Customer Personal Data to provide, secure, maintain, support, bill, meter, and improve the Services; to comply with the Agreement; to respond to Customer requests; to prevent fraud, abuse, spam, and security incidents; and as otherwise documented in the Agreement.
SellioCRM will notify Customer if it believes an instruction violates Applicable Data Protection Laws, unless prohibited by law.
4. Customer Obligations
- complying with Applicable Data Protection Laws
- providing required notices and obtaining required consents
- establishing lawful bases for processing CRM data, leads, contacts, prospects, customers, communications, and imports
- ensuring Customer Personal Data is accurate, relevant, and lawful
- configuring the Services appropriately
- responding to Data Subject requests where Customer is responsible
- honoring opt-outs, unsubscribes, suppression lists, and communication preferences
- ensuring that Customer's instructions are lawful
5. SellioCRM Processor Obligations
- process Customer Personal Data only in accordance with documented instructions;
- ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations
- implement appropriate technical and organizational measures
- assist Customer with Data Subject requests where required and reasonably possible
- assist Customer with data protection impact assessments and regulator consultations where required and reasonably possible
- notify Customer of Security Incidents as required by this DPA
- delete or return Customer Personal Data as required by this DPA and the Agreement
- make available information reasonably necessary to demonstrate compliance with this DPA
6. Subprocessors
Customer provides general authorization for SellioCRM to engage Subprocessors to provide the Services, including providers for hosting, compute, database, storage, content delivery, email delivery, communications, AI, monitoring, logging, security, analytics, support, billing, and payment processing.
SellioCRM will maintain a list of Subprocessors or make such information available upon request. SellioCRM will impose written data protection obligations on Subprocessors that are substantially protective as those in this DPA, to the extent applicable to the services provided by the Subprocessor.
Customer may object to a new Subprocessor on reasonable data protection grounds by notifying SellioCRM within the period specified in the Subprocessor notice or, if no period is specified, within 15 days after notice.
7. Security Measures
SellioCRM will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, including measures described in Annex II. Customer acknowledges that security measures may evolve and that SellioCRM may update them, provided that overall protection is not materially reduced.
8. Security Incident Notification
SellioCRM will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to SellioCRM, which may include the nature of the incident, affected data, mitigation measures, and recommended Customer actions.
SellioCRM's notification is not an admission of fault or liability. Customer is responsible for determining whether notification to Data Subjects, regulators, customers, or other parties is required.
9. Data Subject Requests
If SellioCRM receives a request from a Data Subject relating to Customer Personal Data, SellioCRM may refer the requester to Customer, unless prohibited by law. SellioCRM will provide reasonable assistance to Customer in responding to requests, taking into account the nature of processing and information available to SellioCRM.
10. Return and Deletion
Upon termination or expiration of the Services, SellioCRM will delete or return Customer Personal Data in accordance with the Agreement, account settings, backup cycles, legal obligations, and operational requirements. Customer should export Customer Personal Data before termination or account closure.
SellioCRM may retain Customer Personal Data where required by law, necessary for security, fraud prevention, dispute resolution, billing, tax, accounting, backup integrity, or legal defense, or where data has been anonymized or aggregated.
11. Audits
SellioCRM will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, non-disruptive, subject to confidentiality, and limited to matters relevant to Customer Personal Data. Customer may not access data of other customers, proprietary information, or systems that would create security risk.
12. International Transfers
SellioCRM is based in the United States and may process Customer Personal Data in the United States and other countries. Where a transfer mechanism is required, the parties will use appropriate safeguards, such as Standard Contractual Clauses, UK transfer addendum, Swiss safeguards, ANPD-recognized mechanisms, adequacy decisions, or other lawful transfer mechanisms.
13. CCPA/CPRA Service Provider Terms
Where California privacy laws apply and SellioCRM processes Customer Personal Data as a service provider or contractor, SellioCRM will process Customer Personal Data only for business purposes described in the Agreement, will not sell or share Customer Personal Data, will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by law, and will not combine Customer Personal Data with personal information from other sources except as permitted by the CCPA/CPRA.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by Applicable Data Protection Laws.
15. Order of Precedence
If there is a conflict between this DPA and the Agreement, this DPA controls with respect to processing of Customer Personal Data. If there is a conflict between this DPA and Standard Contractual Clauses or another mandatory transfer mechanism, the mandatory transfer mechanism controls for the applicable transfer.
16. Annex I - Details of Processing
|
Item |
Description |
|
Subject matter |
Provision of the SellioCRM CRM platform, related support, infrastructure billing, security, and associated services. |
|
Duration |
For the term of the Agreement and as otherwise described in the Agreement, retention policies, and applicable law. |
|
Nature and purpose |
Hosting, storing, organizing, displaying, analyzing, transmitting, importing, exporting, securing, supporting, backing up, billing, metering, and processing Customer Personal Data in CRM workflows. |
|
Categories of Data Subjects |
Authorized Users, administrators, employees, contractors, leads, contacts, prospects, customers, vendors, partners, representatives, and other individuals whose data is submitted by Customer. |
|
Categories of Personal Data |
Names, business contact details, company details, job titles, phone numbers, email addresses, notes, activities, tasks, communications, attachments, files, CRM records, deal information, opportunity records, imports, exports, prompts, AI outputs, usage logs, and related business information. |
|
Sensitive Data |
Customer should avoid submitting sensitive data unless necessary, lawful, and permitted by the Agreement. Sensitive data may include special categories of personal data where submitted by Customer. |
|
Frequency of transfer |
Continuous or as initiated by Customer, Authorized Users, integrations, automations, APIs, and providers. |
17. Annex II - Technical and Organizational Measures
- access control and authentication controls;
- least privilege access for personnel where feasible
- encryption in transit for supported connections
- encryption at rest or equivalent safeguards depending on provider capabilities and architecture
- logging, monitoring, and abuse detection
- backup and recovery processes appropriate to the Services
- segregation or logical separation of customer data where appropriate
- vulnerability management and secure development practices
- confidentiality obligations for personnel
- vendor and subprocessor review based on risk
- incident response processes
- data minimization, retention, and deletion controls where supported
18. Annex III - Contact
Data protection inquiries may be sent to legal@selliocrm.com.