Data Processing Agreement
Last updated:
This Data Processing Agreement ("DPA") forms part of the Crownvo Terms of Service and applies to the extent that Crownvo processes personal data on behalf of a customer in connection with the Service. This DPA reflects the parties' agreement with respect to the processing of personal data in accordance with the requirements of Regulation (EU) 2016/679 ("GDPR") and other applicable data-protection laws.
1. Definitions
Capitalized terms not defined here have the meanings given in the GDPR. For purposes of this DPA:
- "Customer Personal Data" means personal data that Customer provides to Crownvo for processing in connection with the Service.
- "Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates.
- "Processing" has the meaning given in the GDPR, and "process" and "processed" shall be construed accordingly.
- "Subprocessor" means any third party engaged by Crownvo to process Customer Personal Data.
- "Supervisory Authority" means an independent public authority established under Article 51 of the GDPR.
2. Subject matter and duration
Crownvo processes Customer Personal Data on behalf of Customer for the purpose of providing the Service in accordance with the Terms. Processing continues for the duration of the customer's subscription to the Service and any post-termination transition period agreed between the parties.
3. Nature and purpose of processing
Crownvo processes Customer Personal Data only for the purposes of:
- Providing, maintaining, and securing the Service
- Storing and retrieving Customer Content at Customer's direction
- Sending transactional notifications and Service-related communications
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations to which Crownvo is subject
4. Types of personal data and categories of data subjects
The types of Customer Personal Data processed include account and contact data, billing data, subscriber and engagement data uploaded by Customer, and technical log data. Data subjects typically include Customer's end users, employees, and other individuals whose data Customer uploads to or processes through the Service.
5. Processor obligations
Crownvo will:
- Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers
- Ensure that persons authorized to process Customer Personal Data are committed to confidentiality
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
- Engage Subprocessors only in accordance with the requirements set out in this DPA
- Assist Customer, by appropriate technical and organizational measures, in fulfilling Customer's obligations to respond to requests from Data Subjects
- Notify Customer without undue delay of any confirmed personal-data breach affecting Customer Personal Data
- Assist Customer in ensuring compliance with Articles 32 to 36 of the GDPR
- Make available to Customer all information necessary to demonstrate compliance with this DPA
6. Subprocessors
Customer acknowledges and agrees that Crownvo may engage Subprocessors to process Customer Personal Data. A current list of Subprocessors is maintained at our Subprocessors page and is incorporated into this DPA by reference.
Crownvo will: (a) enter into a written agreement with each Subprocessor imposing data-protection terms no less protective than those in this DPA; (b) remain fully liable to Customer for the performance of each Subprocessor's obligations; and (c) provide Customer with at least 30 days' prior notice of any new or replacement Subprocessor, giving Customer the opportunity to object on reasonable data-protection grounds.
7. Technical and organizational measures
Crownvo implements technical and organizational measures appropriate to the risk of processing, including: encryption of personal data in transit and at rest; access controls based on least privilege; regular security testing; logging and monitoring of access to Customer Personal Data; incident-response procedures; and employee training on data protection.
A summary of our security practices is available on our Security page; customers may request additional detail under NDA.
8. Data subject rights assistance
Crownvo will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under the GDPR.
9. International data transfers
Customer Personal Data may be transferred to and processed in countries other than the customer's own. When personal data is transferred from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of protection, Crownvo relies on appropriate safeguards — including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — and takes supplementary measures where necessary.
10. Personal-data breach notification
Crownvo will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. The notification will include the information required by Article 33(3) of the GDPR to the extent Crownvo has it, and will be updated as additional information becomes available.
11. Audit rights
Crownvo will make available to Customer all information necessary to demonstrate compliance with this DPA, including by providing audit reports and responses to reasonable information requests. Where a Supervisory Authority or Customer requires an on-site audit, the parties will agree on the scope, timing, and confidentiality terms in advance.
12. Return or deletion of personal data
On termination of the Service, Crownvo will, at Customer's election, return or delete Customer Personal Data within 30 days, except where retention is required by law. For information about data export prior to termination, see our documentation on data portability.
13. Liability and termination
The parties' liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms. Customer may terminate the Service if Crownvo materially breaches this DPA and fails to cure within 30 days of notice.
14. How to execute this DPA
Customers on Pro and Enterprise plans can execute our standard DPA via the in-app DPA signature flow once available. For custom DPAs, or to execute by countersignature, contact legal@crownvo.com.
By accepting the Terms, the parties acknowledge and agree to the terms of this DPA as of the effective date of the customer's subscription.
15. Contact us
Questions about this DPA can be sent to dpo@crownvo.com.