Data Processing Addendum
Last Updated: September 1, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between SystemsPal ("SystemsPal") and the business customer using the Services ("Customer") and applies only to personal data SystemsPal processes on Customer's behalf ("Customer Personal Data").
1. Roles and Scope
"Applicable Data Protection Law" means privacy or data-protection law that applies to the Processing covered by this DPA, including the GDPR and applicable U.S. state privacy laws. Customer is the Controller/business and SystemsPal the Processor/service provider for Customer Personal Data; where Customer acts as a Processor, SystemsPal acts as its Subprocessor.
Account, billing, transaction, business-contact, usage, telemetry, support, security, fraud, abuse, and administrative data that SystemsPal processes for its own lawful purposes ("Service Data") is not Customer Personal Data merely because it relates to Customer's use of the Services and is outside Customer's instruction rights under this DPA.
2. Instructions and Customer Responsibility
Customer instructs SystemsPal to Process Customer Personal Data as reasonably necessary to provide, operate, secure, support, maintain, and administer the Services; enable Customer-selected features and integrations; comply with law; and perform the Processing described in the Annex. Customer's configuration, use, uploads, support requests, integrations, and written directions constitute documented instructions.
Customer is responsible for the lawfulness, accuracy, collection, disclosure, and use of Customer Personal Data and for all required notices, consents, permissions, and legal bases. Customer will not submit data or issue instructions that are unlawful or outside the intended use of the Services. SystemsPal may refuse, suspend, or limit unlawful or materially risky instructions or features. Where mandatory law requires SystemsPal to notify Customer that an instruction violates data-protection law, SystemsPal will do so unless prohibited by law.
3. SystemsPal Obligations
SystemsPal will Process Customer Personal Data only on documented instructions or as required by law; ensure authorized persons are subject to appropriate confidentiality obligations; and maintain technical and organizational measures required by Applicable Data Protection Law and appropriate to the risk. Security measures may evolve with technology, providers, threats, and the Services, provided the legally required overall level of protection is maintained.
4. Subprocessors
Customer gives SystemsPal general written authorization to engage Subprocessors. SystemsPal will impose legally required data-protection obligations on them and remains responsible only to the extent required by Applicable Data Protection Law. SystemsPal may use personnel and contractors inside or outside the EEA subject to applicable confidentiality, security, and transfer requirements.
SystemsPal will give notice of intended Subprocessor additions or replacements only to the extent required by Applicable Data Protection Law. Customer may object only on reasonable documented data-protection grounds within 5 business days after notice, or any longer mandatory period. If a valid objection cannot reasonably be resolved, SystemsPal may replace the provider, discontinue the affected feature, or terminate the affected Services; to the maximum extent permitted by law, that is Customer's sole remedy.
5. Required Assistance and Breaches
Taking into account the nature of Processing and information available to SystemsPal, SystemsPal will provide only the assistance expressly required by Applicable Data Protection Law regarding Data Subject requests and Customer obligations concerning security, breach notifications, impact assessments, or regulator consultations. Customer remains responsible for responses to Data Subjects, regulators, and upstream Controllers. SystemsPal may refer requests concerning Customer Personal Data to Customer.
SystemsPal will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where legally required. Information may be provided in phases. Notice is not an admission of fault or liability. To the extent permitted by law, Customer will reimburse reasonable costs of extraordinary or Customer-specific assistance not caused by SystemsPal's breach of this DPA.
6. Return, Deletion, and Audits
Customer is responsible for exporting Customer Personal Data before the Services end. Where the GDPR applies, after the Services end SystemsPal will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, unless applicable Union or Member State law requires storage. Under other Applicable Data Protection Law, SystemsPal will delete or return Customer Personal Data only to the extent required by that law. SystemsPal need not create custom exports or restore deleted data. To the extent permitted by applicable law, deletion from routine backups may occur through the ordinary backup lifecycle while retained copies remain protected and are not used for other purposes.
SystemsPal will provide information and permit audits or inspections only to the extent expressly required by Applicable Data Protection Law. Existing documentation, questionnaires, reports, or security information will be used first. Any further audit must, to the extent legally permitted, be limited to relevant Processing, reasonably noticed, conducted during normal business hours, confidential, non-disruptive, and not expose other customers' data, source code, security-sensitive information, or production systems beyond what law requires. Customer bears reasonable audit costs to the extent permitted by law.
7. International Transfers
Customer authorizes international Processing necessary to provide the Services. Where Applicable Data Protection Law requires a transfer mechanism, the parties will use an applicable adequacy decision or recognized framework, the European Commission's Standard Contractual Clauses with the module appropriate to the parties' roles, or another lawful mechanism. The SCCs apply only where legally required and prevail only to the extent of an unavoidable conflict.
8. U.S. State Service-Provider Terms
Where U.S. state privacy law treats SystemsPal as a service provider, contractor, or processor, SystemsPal will process Customer Personal Data only for the specified business purposes and instructions permitted by the agreement and applicable law and will not sell or share Customer Personal Data, or retain, use, or disclose it outside the permitted business relationship, except as allowed by applicable law. Where the CCPA requires it, SystemsPal will provide the same level of privacy protection required of service providers or contractors, notify Customer if SystemsPal determines it can no longer meet those obligations, and permit Customer, upon notice, to take only the reasonable and appropriate steps required by the CCPA to help ensure compliant use or stop and remediate unauthorized use. Any related verification, assessment, audit, or inspection is limited to the minimum required by applicable law and remains subject to Section 6 to the fullest extent permitted by law. Customer authorizes SystemsPal to use Subprocessors as described above.
9. Liability and Precedence
The disclaimers, exclusions, indemnities, dispute provisions, and liability limitations in the main agreement apply to this DPA to the maximum extent permitted by law. Customer's obligations concerning lawful data, instructions, consents, compliance, payment, reimbursement, and indemnification are not expanded or limited by this DPA except where mandatory law requires otherwise.
If this DPA conflicts with the main agreement on a mandatory data-protection matter, this DPA controls only to the extent necessary to satisfy Applicable Data Protection Law. The main agreement otherwise controls commercial matters. SystemsPal may update this DPA to reflect changes in law, providers, security, or the Services, with additional notice only where required by law.
Annex — Processing Details
- Subject matter and duration: Processing necessary to provide the Services for the term of the agreement and any legally permitted retention period.
- Nature and purposes: collection, hosting, storage, organization, access, transmission, communications, automation, CRM functions, support, security, integrations, AI-enabled functionality when selected by Customer, and deletion.
- Data Subjects: Customer's customers, prospects, leads, users, personnel, contractors, and other individuals whose data Customer submits or causes to be processed.
- Data types: contact and business information; phone, email, postal and service-address information; inquiry, appointment, CRM, review, messaging, call, form, support, and transaction-related content; and technical identifiers. Customer must not submit special-category, highly sensitive, regulated, biometric, health, full payment-card, government-ID, or children's data unless the Services expressly support it and SystemsPal has agreed where required.
Contact
Privacy questions may be sent to privacy@systemspal.com or by phone at (888) 260-9444.