Data Processing Addendum
Effective September 1, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Servicebetween AlbrightForge LLC (“Processor”) and the customer (“Controller”) and applies where we process personal data on the Controller’s behalf.
1. Roles
The Controller determines the purposes and means of processing Customer Data. The Processor processes it only on the Controller’s documented instructions, which include providing the Service under the Terms.
2. Scope of processing
- Subject matter: provision of the AlbrightForge CRM platform.
- Duration: the term of the customer’s subscription.
- Data subjects: the Controller’s contacts, clients, and staff.
- Data types: contact details, business records, invoices, files, and any fields the Controller chooses to store.
3. Confidentiality & security
We keep Customer Data confidential, restrict access to personnel who need it, and apply technical and organizational measures including encryption in transit and at rest for sensitive fields.
4. Subprocessors
The Controller authorizes the use of the subprocessors listed on our Subprocessors page. We remain responsible for their performance and will give notice before adding a new one that processes Customer Data.
5. Data-subject requests
We provide self-service export and deletion tools in the app, and will assist the Controller in responding to data-subject requests to the extent it cannot do so itself.
6. Breach notification
We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data.
7. Deletion & return
On termination, or on the Controller’s request, we delete Customer Data from production systems within 30 days, subject to legal retention requirements and rolling backup expiry.
8. International transfers
Where data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) with our subprocessors as applicable.
9. Contact
To countersign this DPA or ask questions: legal@albrightforge.com.