HelloClient - CRM system for service centers

Data Processing Agreement

Effective date: 31.12.2025

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

  • Customer — the user of the HelloClient platform who processes personal data of data subjects in the platform (the "Controller"); and
  • Individual Entrepreneur DENIS NEUSTROYEV, Identification Number 302360558, registered in Georgia, legal address: Georgia, Tbilisi, Chugureti district, Mikheil Tsinamdzghvrishvili street, N52, attic (the "Processor").

This DPA forms part of the Terms of Service and applies where the Customer processes personal data using the HelloClient platform.

2. Purpose

This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the HelloClient CRM platform.

3. Scope and Nature of Processing

3.1. The Processor processes personal data solely for the purpose of providing the services, on documented instructions from the Controller. Processing includes: collection, recording, storage, organisation, retrieval, use, and deletion.

3.2. The duration of processing corresponds to the duration of the Customer's account and is specified in Section 9.

4. Categories of Data and Data Subjects

4.1. Categories of data subjects: customers and employees of the Controller (natural persons).

4.2. Categories of personal data: names, phone numbers, email addresses, addresses, order history, payment amounts, and other data entered by the Customer into the platform.

4.3. The platform is not intended for processing special categories of personal data. The Customer shall not upload such data.

5. Processor Obligations

The Processor shall:

5.1. process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by law (in which case the Processor shall inform the Controller before processing, unless the law prohibits such information);

5.2. ensure that persons authorised to process personal data are bound by confidentiality obligations;

5.3. implement the technical and organisational measures set out in Section 8;

5.4. assist the Controller, where reasonably possible, in fulfilling its obligations to respond to requests of data subjects, to notify personal data breaches, and to carry out data protection impact assessments;

5.5. notify the Controller without undue delay (and no later than 24 hours) after becoming aware of a personal data breach;

5.6. at the choice of the Controller, delete or return all personal data after the end of the provision of services, and delete existing copies, unless storage is required by applicable law;

5.7. make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

6. Controller Obligations

The Controller shall:

6.1. ensure a lawful basis for processing personal data;

6.2. inform data subjects about the processing;

6.3. ensure that data uploaded to the platform does not violate applicable law;

6.4. use the platform's settings to implement its own data protection requirements.

7. Sub-processing

7.1. The Controller gives a general written authorisation for the Processor to engage the sub-processors listed on the sub-processors page: helloclient.app/en/documents/partners.

7.2. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes. The notification is made by updating the sub-processors page and by notice to the Controller.

7.3. Where the Processor engages a sub-processor, the same data protection obligations as set out in this DPA shall be imposed on that sub-processor by way of a contract, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.

8. Data Security and Hosting

8.1. The Processor implements the following organisational measures:

  • least-privilege access;
  • logging of actions with personal data;
  • integrity assurance;
  • regular security analysis;
  • physical access control;
  • internal data protection policies;
  • designated responsible persons;
  • internal control of measures.

8.2. The Processor implements the following technical measures:

  • TLS 1.3 encryption of all connections;
  • two-step authentication;
  • automatic and semi-automatic incident response;
  • WAF;
  • regular security audits (internal and independent);
  • firewall;
  • continuous monitoring;
  • timely software updates;
  • password rotation every 90 days;
  • antivirus software.

8.3. Hosting: Personal data are hosted on the servers of Amazon Web Services (AWS), Regions: EU and/or US.

9. Deletion of Data

Upon termination of the Customer's account:

  • account data are deleted within 3 years;
  • CRM data are deleted within 3 years;
  • backups are deleted within 3 years;
  • logs are retained for not more than 3 years.

Deletion is not performed where retention is required by applicable law.

10. International Transfers

Where personal data are transferred outside the EU/EEA, such transfers are based on the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914, Module 2 — transfer controller to processor), which form an integral part of this DPA. Onward transfers by sub-processors require the same safeguards.

11. Liability

Each party is liable for damage caused by its violation of this DPA. The Processor is liable to the Controller for damage caused by processing only where it has not complied with obligations specifically directed to processors under applicable law or where it has acted outside or contrary to lawful instructions of the Controller. Limitations of liability in the Terms of Service apply to this DPA to the extent permitted by law.

12. Term and Termination

This DPA is effective for the term of the Customer's use of the platform and continues until deletion of personal data in accordance with Section 9. The DPA terminates automatically upon termination of the Terms of Service.

Still have questions? We're here to help:
Contact us on What's AppWhat's App support

If everything is clear — join us! Register now and start managing your business for free