Skip to content
DailyCRM
Legal Sign in Start free

Legal documents

  • Terms of Service
  • Acceptable Use Policy
  • Stock Images & Customer Content Policy
  • Privacy Policy
  • Data Processing Addendum
  • Cookie Policy

On this page

  1. 1. Definitions
  2. 2. Roles and instructions
  3. 3. Customer obligations
  4. 4. DailyCRM obligations
  5. 5. Subprocessors
  6. 6. Security incidents
  7. 7. Individuals’ requests
  8. 8. International transfers
  9. 9. Information and audits
  10. 10. Return and deletion
  11. 11. Liability and duration
  12. Annex A — Details of processing
  13. Annex B — Security measures

Legal / Data Processing Addendum

Data Processing Addendum

Last updated
October 3, 2026
Version
2026-10-03
Contents
  1. 1. Definitions
  2. 2. Roles and instructions
  3. 3. Customer obligations
  4. 4. DailyCRM obligations
  5. 5. Subprocessors
  6. 6. Security incidents
  7. 7. Individuals’ requests
  8. 8. International transfers
  9. 9. Information and audits
  10. 10. Return and deletion
  11. 11. Liability and duration
  12. Annex A — Details of processing
  13. Annex B — Security measures

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between [OPERATOR LEGAL NAME] (“DailyCRM”) and the Customer. It applies whenever DailyCRM processes Customer Personal Data on the Customer’s behalf. Capitalized terms not defined here have the meaning given in the Terms. If this DPA conflicts with the Terms regarding Customer Personal Data, this DPA prevails.

1. Definitions

  • Customer Personal Data — personal information about End Clients, leads, Customer Site visitors, Authorized Users and the Customer’s employees that the Customer submits to the Services or that the Services collect for the Customer.
  • Data Protection Laws — privacy and data-protection laws that apply to the processing, including PIPEDA, Alberta and British Columbia PIPA, Quebec’s Act respecting the protection of personal information in the private sector, the CCPA and other US state privacy laws, and, where applicable, the GDPR and UK GDPR.
  • Subprocessor — a third party engaged by DailyCRM that processes Customer Personal Data.
  • Security Incident — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data in DailyCRM’s control.

2. Roles and instructions

  • The Customer is the controller (the organization responsible for the personal information). DailyCRM is a processor / service provider that processes Customer Personal Data only on the Customer’s documented instructions.
  • The Terms, this DPA and the Customer’s configuration and use of the Services (for example, sending an email, publishing a Customer Site, enabling an integration) are the Customer’s complete instructions. DailyCRM will inform the Customer if it believes an instruction violates Data Protection Laws and may decline to follow it.
  • DailyCRM may also process Customer Personal Data as required by law (with notice to the Customer where legally permitted) and to secure the Services and prevent abuse.

3. Customer obligations

  • The Customer is responsible for the lawfulness of the processing: providing privacy notices, obtaining and recording consents (including for marketing messages, cookies and conversion tracking on Customer Sites and for recording employee location), and for the accuracy and quality of Customer Personal Data.
  • The Customer will not submit sensitive information (such as health data, government identification numbers or full payment card numbers) unless it is necessary and lawful, and will not instruct processing that violates Data Protection Laws.
  • The Customer is responsible for responding to requests from individuals and for notifying regulators and individuals of incidents where the law places that duty on the controller.

4. DailyCRM obligations

  • Process Customer Personal Data only to provide the Services and as instructed, and not for any other purpose.
  • Not sell or share Customer Personal Data (as those terms are defined in the CCPA), not retain, use or disclose it outside the direct business relationship with the Customer, and not combine it with personal information from other sources except as permitted by Data Protection Laws. DailyCRM certifies that it understands and will comply with these restrictions.
  • Ensure that personnel authorized to process Customer Personal Data are bound by confidentiality, and that staff access to Customer accounts is limited, justified and logged.
  • Implement the security measures described in Annex B.
  • Provide reasonable assistance, taking into account the nature of the processing, with the Customer’s obligations regarding individuals’ requests, security, incident notification and privacy impact assessments.

5. Subprocessors

  • The Customer gives DailyCRM general authorization to engage Subprocessors. The current list is published in the Privacy Policy.
  • DailyCRM will impose on each Subprocessor data-protection obligations that are substantially as protective as this DPA and remains responsible for its Subprocessors’ performance as required by Data Protection Laws.
  • DailyCRM will update the list at least 15 days before a new Subprocessor begins processing Customer Personal Data (except in an emergency to keep the Services running). The Customer may object on reasonable data-protection grounds by writing to [PRIVACY EMAIL]; if the parties cannot resolve the objection, the Customer may terminate the affected Services as its sole remedy.
  • Third-Party Services that the Customer chooses to connect (for example, Meta, Google Ads, Microsoft Advertising or Telegram) are not DailyCRM Subprocessors; they act under their own terms with the Customer.

6. Security incidents

DailyCRM will notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Security Incident affecting the Customer’s Personal Data. The notice will describe, as far as known, the nature of the incident, the categories of data affected, likely consequences and the measures taken or proposed, and will be updated as more information becomes available. DailyCRM will take reasonable steps to contain and remedy the incident. A notification is not an admission of fault or liability.

7. Individuals’ requests

If DailyCRM receives a request from an individual about Customer Personal Data, it will refer the individual to the Customer and will not respond directly except to confirm the referral or as required by law. The Services provide tools for the Customer to find, correct, export and delete Customer Personal Data.

8. International transfers

Customer Personal Data may be processed in Canada, the United States and other countries where DailyCRM and its Subprocessors operate. DailyCRM will protect transferred data as required by Data Protection Laws, using contractual safeguards. Where the GDPR or UK GDPR applies, the parties will rely on the applicable standard contractual clauses or another lawful transfer mechanism, which are incorporated by reference to the extent required.

9. Information and audits

On written request (no more than once a year, unless required by a regulator or after a Security Incident), DailyCRM will provide information reasonably necessary to demonstrate compliance with this DPA, such as a description of its security measures or answers to a reasonable security questionnaire. On-site audits are available only where required by Data Protection Laws, with at least 30 days’ notice, during business hours, subject to confidentiality and at the Customer’s expense.

10. Return and deletion

During the subscription the Customer can export and delete Customer Personal Data using the Services. After termination, the Customer may export data for at least 30 days; DailyCRM will then delete Customer Personal Data, normally within 90 days, except copies in backups (deleted as backups are rotated, within about 6 months) and data DailyCRM must keep by law, which remain protected by this DPA.

11. Liability and duration

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA lasts as long as DailyCRM processes Customer Personal Data.

Annex A — Details of processing

Subject matter and durationProvision of the Services under the Terms, for the term of the subscription and the deletion period above.
Nature and purposeHosting, storage, organization, display, transmission (email, notifications, conversion events the Customer enables), AI processing on request, backup and deletion, to provide CRM, scheduling, invoicing, website and related features.
Data subjectsThe Customer’s clients and leads, Customer Site visitors and form submitters, Authorized Users, employees and contractors.
Categories of dataNames and contact details, service addresses, job and order details, notes, photos and files, quotes, invoices and payment status, messages, reviews, website attribution data (pages, referrer, UTM and ad-click identifiers), technician location at job start/stop, user account and activity data.
Sensitive dataNot intended. The Customer must not submit sensitive information unless necessary and lawful.

Annex B — Security measures

  • Encryption in transit (TLS) for all connections to the Services.
  • Logical isolation of each Customer’s data with database row-level security; least-privilege database roles.
  • Passwords stored as salted hashes; two-step verification (TOTP), mandatory for roles that manage the team or billing; session management and sign-out of other devices.
  • Role-based permissions within each account; audit logs of significant actions; logged and time-limited staff access with a stated reason.
  • Encryption of stored integration secrets (AES-256-GCM); secrets kept outside the codebase.
  • Upload checks: file-type verification, malware scanning, removal of location metadata from images.
  • Protection against abuse: rate limiting, bot protection, CSRF protection and security headers.
  • Daily backups with retention limits and periodic restore tests.
  • Vulnerability reports handled through our responsible disclosure process; timely patching of dependencies and systems.

This document is written in English. Any translation is provided for convenience only; if there is a conflict, the English version governs to the extent permitted by law.

DailyCRM

CRM and website for cleaning and home-service companies.

Product

How it worksWebsite builderFeaturesPricing

Account

Sign inCreate accountFAQ

Legal

Terms of ServiceAcceptable Use PolicyStock Images & Customer Content PolicyPrivacy PolicyData Processing AddendumCookie Policy
© 2026 DailyCRM All legal documents