Data processing addendum
Last updated: 23 August 2026
This addendum forms part of the terms of service whenever your workspace contains personal data. You are the controller; we are your processor. It is written to satisfy Article 28 UK GDPR and EU GDPR without a signature ceremony; using the service accepts it. A longer version, with annexes for the processing details, the security measures and the sub-processors, is published as the settled terms, version 1.
What changed on 23 August 2026. Clause 4 said customer data is stored in the European Union. It is stored in London, in the United Kingdom, and now says so. The security page names the region and how to check it. The longer terms are at data processing agreement, with annexes.
1. The processing
| Detail | Description |
|---|---|
| Subject matter | Provision of the crmSpace CRM service |
| Duration | The life of your workspace, plus the deletion window below |
| Nature and purpose | Storage, organisation, retrieval, display, automation and AI-assisted summarisation of your CRM records, on your instructions |
| Categories of data | Business contact details, communication content you capture, deal and billing data, and any personal data your team chooses to record |
| Data subjects | Your contacts, leads, customers, suppliers and your own workspace members |
2. Our commitments
- We process customer data only on your documented instructions, given through the product and these terms.
- Everyone with access is under a duty of confidentiality.
- We apply the technical and organisational measures in the security overview, and keep them current.
- We help you respond to data subject requests. The product includes subject access export, erasure with suppression, retention policies and an Article 30 register you can download.
- We tell workspace administrators without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data.
- We make available the information needed to demonstrate compliance, and support audits as below.
3. Subprocessors
You authorise the providers in the subprocessor list. We flow down equivalent obligations in writing, remain responsible for their performance, and give at least 30 days’ notice of additions. If you object on reasonable grounds and we cannot offer a workaround, you may terminate the affected service and we refund any prepaid fees for the unused period.
4. International transfers
Customer data is stored in London, in the United Kingdom. The security page names the region and how to check it. Where a subprocessor processes data outside the UK or EEA, the transfer relies on adequacy regulations or the applicable standard contractual clauses with the UK addendum.
5. Return and deletion
You can export your data at any time through the product. When a workspace ends, we delete customer data within 30 days, and residual copies leave encrypted backups on the backup provider’s rolling schedule, at most a further 30 days. Records we must keep by law, such as invoices we issued to you, are kept only as long as that law requires.
6. Audit
Once in any 12-month period, and with reasonable notice, you may audit our compliance with this addendum, first through our documentation and written answers, and where that is genuinely insufficient, through a remote review with us. Each side bears its own costs.
7. Liability and order
Liability under this addendum is subject to the caps in the terms of service. If this addendum conflicts with the terms, this addendum wins for data protection matters. Questions to connect@crmspace.ai.