Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between Crutan ("Processor") and the business customer ("Controller") using the Crutan Service. It applies when Crutan processes personal data on behalf of the Controller in connection with the Service, including prospect records, page visitors, form submissions, and CRM-synced contact data.
In the event of conflict between this DPA and the Terms of Service, this DPA controls with respect to processing of personal data.
1. Roles and scope
- Controller determines the purposes and means of processing personal data uploaded or connected to the Service.
- Processor processes personal data only on documented instructions from the Controller, including through account configuration, integrations, and API use.
Crutan's Privacy Policy describes processing where Crutan acts as an independent controller (for example, account billing and product analytics relating to account users).
2. Processing details
Subject matter: Provision of personalized landing page operations, CRM sync, analytics, and related features.
Duration: For the term of the subscription plus any retention period described in the Privacy Policy or account settings.
Categories of data subjects: Prospects, leads, page visitors, and contacts whose data the Controller imports or syncs.
Categories of personal data: Contact details, professional information, engagement events, form responses, meeting details, and custom fields supplied by the Controller.
Processing operations: Storage, hosting, personalization, analytics, delivery to integrations, and deletion upon Controller instruction.
3. Controller obligations
The Controller will:
- Provide lawful instructions and a valid legal basis for processing
- Provide required notices to data subjects and honor data subject rights
- Ensure accuracy and quality of personal data submitted to the Service
- Configure integrations, domains, and page tracking in compliance with applicable law
4. Processor obligations
Crutan will:
- Process personal data only on documented instructions from the Controller
- Ensure personnel authorized to process personal data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Controller with data subject requests where technically feasible
- Notify the Controller without undue delay after becoming aware of a personal data breach
- Delete or return personal data upon termination, subject to legal retention requirements
5. Subprocessors
The Controller authorizes Crutan to engage subprocessors to provide the Service. Current subprocessors include infrastructure, hosting, email, payment, AI, and observability providers listed in our Privacy Policy. Crutan remains responsible for subprocessors and will impose data protection obligations substantially similar to this DPA.
We will provide notice of material subprocessor changes by updating our documentation or notifying account owners. The Controller may object on reasonable grounds relating to data protection by contacting privacy@crutan.com.
6. Security
Crutan maintains measures designed to protect personal data, including encryption of sensitive credentials at rest, workspace-level tenant isolation, access controls, audit logging for important account actions, and monitoring for abuse. Details of our security program are available upon reasonable request.
7. International transfers
Personal data may be processed in the United States and other countries where Crutan or its subprocessors operate. Where required, Crutan will implement appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by subprocessors.
8. Audits
Upon reasonable written request, Crutan will provide information necessary to demonstrate compliance with this DPA and allow for audits no more than once per year, subject to confidentiality and minimal disruption to operations. The Controller may use third-party audit reports where available in lieu of on-site audits.
9. Data subject requests
If Crutan receives a request from a data subject relating to Controller personal data, we will promptly notify the Controller and will not respond directly except as instructed or required by law. Export and deletion tools are available in account settings; additional assistance is available at privacy@crutan.com.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where prohibited by applicable data protection law.
11. Contact
Crutan — Data ProtectionEmail: privacy@crutan.com
Support: support@crutan.com