Effective date: 31.12.2025
This Data Processing Agreement ("DPA") is entered into between:
This DPA forms part of the Terms of Service and applies where the Customer processes personal data using the HelloClient platform.
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the HelloClient CRM platform.
3.1. The Processor processes personal data solely for the purpose of providing the services, on documented instructions from the Controller. Processing includes: collection, recording, storage, organisation, retrieval, use, and deletion.
3.2. The duration of processing corresponds to the duration of the Customer's account and is specified in Section 9.
4.1. Categories of data subjects: customers and employees of the Controller (natural persons).
4.2. Categories of personal data: names, phone numbers, email addresses, addresses, order history, payment amounts, and other data entered by the Customer into the platform.
4.3. The platform is not intended for processing special categories of personal data. The Customer shall not upload such data.
The Processor shall:
5.1. process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by law (in which case the Processor shall inform the Controller before processing, unless the law prohibits such information);
5.2. ensure that persons authorised to process personal data are bound by confidentiality obligations;
5.3. implement the technical and organisational measures set out in Section 8;
5.4. assist the Controller, where reasonably possible, in fulfilling its obligations to respond to requests of data subjects, to notify personal data breaches, and to carry out data protection impact assessments;
5.5. notify the Controller without undue delay (and no later than 24 hours) after becoming aware of a personal data breach;
5.6. at the choice of the Controller, delete or return all personal data after the end of the provision of services, and delete existing copies, unless storage is required by applicable law;
5.7. make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
The Controller shall:
6.1. ensure a lawful basis for processing personal data;
6.2. inform data subjects about the processing;
6.3. ensure that data uploaded to the platform does not violate applicable law;
6.4. use the platform's settings to implement its own data protection requirements.
7.1. The Controller gives a general written authorisation for the Processor to engage the sub-processors listed on the sub-processors page: helloclient.app/en/documents/partners.
7.2. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes. The notification is made by updating the sub-processors page and by notice to the Controller.
7.3. Where the Processor engages a sub-processor, the same data protection obligations as set out in this DPA shall be imposed on that sub-processor by way of a contract, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
8.1. The Processor implements the following organisational measures:
8.2. The Processor implements the following technical measures:
8.3. Hosting: Personal data are hosted on the servers of Amazon Web Services (AWS), Regions: EU and/or US.
Upon termination of the Customer's account:
Deletion is not performed where retention is required by applicable law.
Where personal data are transferred outside the EU/EEA, such transfers are based on the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914, Module 2 — transfer controller to processor), which form an integral part of this DPA. Onward transfers by sub-processors require the same safeguards.
Each party is liable for damage caused by its violation of this DPA. The Processor is liable to the Controller for damage caused by processing only where it has not complied with obligations specifically directed to processors under applicable law or where it has acted outside or contrary to lawful instructions of the Controller. Limitations of liability in the Terms of Service apply to this DPA to the extent permitted by law.
This DPA is effective for the term of the Customer's use of the platform and continues until deletion of personal data in accordance with Section 9. The DPA terminates automatically upon termination of the Terms of Service.
Still have questions? We're here to help:
Contact us on What's App
If everything is clear — join us! Register now and start managing your business for free
Product
Features
For Your Business
Get in Touch