This Data Processing Addendum (the "DPA") forms part of the Growtheon Terms of Service and applies only where Growtheon processes Customer Personal Data that is subject to Applicable Data Protection Law. This DPA is a standard addendum and is not legal advice. Customer remains responsible for determining whether its own use of Growtheon complies with the laws that apply to Customer.
1. Parties and Applicability
This DPA is entered into between Growtheon LLC ("Growtheon") and the customer that has accepted the Growtheon Terms of Service ("Customer").
- Where Growtheon processes Customer Personal Data on Customer's behalf in providing the Growtheon platform, Growtheon acts as a processor (or, where applicable, a service provider or subprocessor).
- Customer acts as controller of Customer Personal Data, or as a processor where Customer processes that data on behalf of its own customers. Where Customer acts as a processor, Customer confirms it has the necessary authority from the relevant controller to instruct Growtheon as described in this DPA.
- This DPA is incorporated into and forms part of the Terms where and to the extent Applicable Data Protection Law requires a written data processing agreement.
- This DPA applies only to processing of Customer Personal Data subject to Applicable Data Protection Law. It does not apply to data that is not personal data or to data Growtheon processes as an independent controller as described in Section 3.
2. Definitions
- "GDPR" means Regulation (EU) 2016/679, and where applicable the UK General Data Protection Regulation as incorporated into UK law.
- "Applicable Data Protection Law" means data protection and privacy laws applicable to the processing of Customer Personal Data under this DPA, including the GDPR where it applies.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law.
- "Customer Personal Data" means Personal Data contained in Customer's content that Growtheon processes on Customer's behalf in providing the Growtheon platform.
- "Processing" means any operation performed on Personal Data, including collection, storage, organization, retrieval, use, transmission, erasure, or destruction.
- "Controller" means the party that determines the purposes and means of Processing Personal Data.
- "Processor" means a party that Processes Personal Data on behalf of a Controller.
- "Subprocessor" means a third party engaged by Growtheon to Process Customer Personal Data in connection with providing the platform.
- "Data Subject" means the individual to whom Personal Data relates.
3. Roles of the Parties
- Customer determines the purposes and means of Processing Customer Personal Data, including what data is submitted to the platform and how the platform is configured and used.
- When acting as processor, Growtheon Processes Customer Personal Data only on Customer's documented instructions as described in Section 4.
- Customer is responsible for determining that its use of Growtheon, and the data it submits, complies with the laws applicable to Customer. This DPA does not represent that Customer's use of Growtheon is compliant with the GDPR or any other law.
- Growtheon may act as an independent controller for limited purposes where applicable, including account administration and authentication, billing and payment processing, customer support, fraud prevention, platform security and abuse prevention, service improvement, and compliance with Growtheon's own legal obligations. Such processing is described in the Privacy Policy.
4. Processing Instructions
- Growtheon will Process Customer Personal Data only on Customer's documented instructions, except where Processing is required by law that applies to Growtheon.
- The Terms, this DPA, Customer's configuration and use of the platform (including features, integrations, automations, and communications Customer enables), and any additional written instructions agreed by the parties constitute Customer's documented instructions.
- Where Growtheon is legally required to do so, Growtheon will inform Customer if, in Growtheon's reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited by law from doing so. Growtheon may suspend performance of an instruction until it is confirmed, amended, or withdrawn.
5. Confidentiality
Growtheon will ensure that personnel authorized to Process Customer Personal Data are subject to obligations of confidentiality, whether by contract or by statutory duty, and that access is limited to those who need it to provide the platform, support, or to meet Growtheon's legal obligations.
6. Security
- Growtheon will implement and maintain technical and organizational measures designed to protect Customer Personal Data at a level appropriate to the risk, as required by Applicable Data Protection Law.
- Growtheon may update these measures over time provided the level of protection is not materially reduced. A description of Growtheon's security and privacy practices is available in the Privacy Policy and on the Compliance page.
- Customer is responsible for the security decisions within its control, including user and permission management, credential hygiene, third-party integrations it enables, and the configuration choices it makes in the platform.
7. Subprocessors
- Customer provides general written authorization for Growtheon to engage Subprocessors to Process Customer Personal Data where reasonably necessary to provide and support the platform.
- Growtheon will inform Customer of intended additions or replacements of Subprocessors before the change becomes effective, thereby providing Customer a reasonable opportunity to object on legitimate data-protection grounds.
- Notices under this Section may be provided through the email address associated with Customer's account, by in-product notice, or by another reasonable electronic communication method.
- A current register of Subprocessors is published at growtheon.co/subprocessors. That page is the public register of current Subprocessors; it is not the sole mechanism by which notice of an intended change is given.
- Growtheon will impose on each Subprocessor data protection obligations that are substantially equivalent to those in this DPA, to the extent required by Applicable Data Protection Law.
- Customer may object on legitimate data-protection grounds by contacting privacy@growtheon.co. The parties will discuss the objection in good faith; if no reasonable resolution is available, Customer may stop using the affected functionality or terminate the affected subscription in accordance with the Terms.
- Growtheon remains responsible for a Subprocessor's performance of its data protection obligations to the extent required by Applicable Data Protection Law.
8. Assistance
Taking into account the nature of the Processing and the information available to Growtheon, Growtheon will assist Customer as required by Applicable Data Protection Law in relation to:
- Requests from Data Subjects exercising rights under Applicable Data Protection Law. Customer is responsible for responding to its own Data Subjects, and may in many cases action a request directly using the platform's available features.
- Customer's obligations relating to the security of Processing in respect of Customer Personal Data.
- Personal data breaches involving Customer Personal Data, as described in Section 9.
- Data protection impact assessments and prior consultation with a supervisory authority, where applicable, by making available the information Growtheon holds about the platform that is relevant to the assessment.
This Section does not require Growtheon to provide legal advice or to perform open-ended professional or consulting services, and does not limit the assistance required by Applicable Data Protection Law.
9. Personal Data Breaches
- Growtheon will notify affected Customers without undue delay after becoming aware of a personal data breach affecting Customer Personal Data that requires notification under Applicable Data Protection Law.
- Notification will include the information reasonably available to Growtheon at the time and may be supplemented as more information becomes available. Notice may be provided by email to the contact associated with the account or through the platform.
- Growtheon's notification is not an acknowledgment of fault or liability. Customer is responsible for any notifications it must make to supervisory authorities or Data Subjects.
10. Return and Deletion of Customer Personal Data
- Customer may export or delete Customer Personal Data using the platform's available features during the term of its subscription.
- Following termination or expiration of the Services involving Processing of Customer Personal Data, Growtheon will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, except to the extent applicable law requires continued storage.
- Residual copies may remain temporarily in ordinary backup systems and will be removed in accordance with normal backup lifecycle procedures. Such copies remain protected under this DPA for as long as they are held and are not restored to ordinary production use except for disaster recovery purposes.
11. Audits and Compliance Information
- Growtheon will make available to Customer the information reasonably necessary to demonstrate compliance with its obligations under Article 28 GDPR, where applicable.
- Customer should ordinarily use the documentation and information Growtheon makes available first, including this DPA, the Privacy Policy, the Subprocessors register, and responses to reasonable written questions.
- Where additional verification is reasonably necessary, Growtheon will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, as required by Article 28 GDPR.
- Audits may be subject to reasonable prior notice, confidentiality obligations, security requirements, an agreed scope, and conduct that does not unreasonably disrupt Growtheon's operations. Audits do not extend to access to other customers' or third parties' data, source code, trade secrets, or unrestricted access to systems or infrastructure.
- These procedural requirements will not be applied so as to prevent an audit or inspection required by Applicable Data Protection Law or by a competent supervisory authority.
12. International Transfers
- Growtheon and its Subprocessors may Process Customer Personal Data in locations outside the country or region in which Customer or the relevant Data Subjects are located, including outside the European Economic Area, where permitted by Applicable Data Protection Law.
- Where Customer Personal Data is transferred outside the European Economic Area and Applicable Data Protection Law requires a transfer mechanism for that transfer, Growtheon will use an applicable lawful transfer mechanism available at the time of the transfer.
- Growtheon does not represent that any particular transfer mechanism has been put in place with any individual Subprocessor, and does not represent that Customer Personal Data will be Processed exclusively within any particular country or region. Customer is responsible for assessing whether the platform is appropriate for its own transfer requirements.
13. Customer Obligations
- Customer is responsible for the lawful collection, use, and submission of Customer Personal Data, including having a valid legal basis for the Processing it instructs.
- Customer is responsible for providing required privacy notices, obtaining and recording any required consents, honoring opt-outs and communication preferences, and responding to its own users, customers, and Data Subjects.
- Customer must not use the platform for unlawful or prohibited Processing, or in a way that violates the Acceptable Use Policy or the Terms.
- Customer is responsible for determining whether special-category, sensitive, or otherwise regulated data is appropriate and lawful for its use case. Growtheon does not require such data to provide the platform and the platform is not offered as a compliance solution for any specific regulated sector.
14. Liability and Conflicts
- The limitations and exclusions of liability set out in the Terms remain in full force and apply to claims arising under or in connection with this DPA. This DPA does not expand Growtheon's aggregate liability.
- In the event of a direct conflict between this DPA and the Terms, this DPA controls, but only with respect to the Processing obligations required by Applicable Data Protection Law. In all other respects the Terms control.
- Where Standard Contractual Clauses apply and directly conflict with this DPA, the Standard Contractual Clauses prevail to the extent of the conflict.
Annex — Details of Processing
| Subject matter | Provision of the Growtheon CRM, marketing, and communications platform and related services to Customer. |
|---|
| Duration | The term of Customer's use of Growtheon, plus any period during which Customer Personal Data remains in Growtheon's systems as described in Section 10. |
|---|
| Nature of processing | Storage, organization, retrieval, transmission, communication, automation, analysis, and other operations initiated or configured by Customer through the platform. |
|---|
| Purpose | Providing the platform and services requested by Customer, including related support. |
|---|
| Categories of data subjects | Customer's users and personnel, and leads, contacts, customers, prospects, employees, contractors, and other individuals whose Personal Data Customer submits to the platform. |
|---|
| Categories of personal data | Identity and contact information, CRM records and notes, communications content and metadata (such as email, SMS, chat, and call records), appointment and calendar information, form and survey responses, transaction and order references, usage and activity information, and other data Customer chooses to submit. |
|---|
| Special categories of data | Growtheon does not require special-category Personal Data to provide the platform, and the platform is not designed or offered for any specific regulated data category or sector. Nothing in this DPA constitutes acceptance of any particular category of special-category or regulated data. Customer is responsible for determining whether submitting such data is lawful and appropriate for its use case. |
|---|
| Frequency of transfer | Continuous, as initiated or configured by Customer. |
|---|
| Retention | For the duration of the service and thereafter in accordance with Growtheon's applicable retention practices and legal obligations, as described in Section 10 and the Privacy Policy. |
|---|