Data Processing Agreement
Last updated:
The agreement under article 28 GDPR that governs how Sales Surge processes personal data on behalf of customers of Surge Revenue Desk.
Draft for legal review
This Data Processing Agreement ("DPA") is entered into between the company that uses Surge Revenue Desk ("Customer") and Sales-Surge B.V., registered with the Dutch Chamber of Commerce (KVK) under number 99261758, with its registered address at Professor W.H. Keesomlaan 12, 1183 DJ Amstelveen, the Netherlands ("Sales Surge"). It forms part of the Terms of Service and applies as soon as the Customer accepts them. Open point: [Decide whether customers can also request a countersigned copy of this DPA.]
1.Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). In addition:
- Customer Personal Data
- Personal data in Customer Data (as defined in the Terms) that Sales Surge processes on behalf of the Customer.
- Sub-processor
- A third party engaged by Sales Surge that processes Customer Personal Data.
- SCCs
- The standard contractual clauses for transfers to third countries adopted by Commission Implementing Decision (EU) 2021/914.
2.Roles of the parties
- The Customer is the controller of Customer Personal Data and Sales Surge is its processor.
- If the Customer processes personal data on behalf of its own clients, the Customer is a processor and Sales Surge a sub-processor. The Customer then ensures that its instructions to Sales Surge are authorised by the relevant controller.
- Each party complies with the GDPR and the Dutch GDPR Implementation Act (Uitvoeringswet AVG) as they apply to it. The Customer is responsible for the lawfulness of the processing, including a lawful basis and informing data subjects.
3.Subject matter, duration, nature and purpose
Sales Surge processes Customer Personal Data to provide the service described in the Terms: turning emails, form submissions and portal messages into tickets, synchronising contacts, organisations, deals and products from the Customer's Pipedrive account, calculating SLAs, customer health and revenue scores, sending emails on the Customer's behalf and writing records back to Pipedrive. Processing lasts for the duration of the Terms and the deletion period that follows. Annex 1 describes the processing in detail.
4.Instructions
- Sales Surge processes Customer Personal Data only on documented instructions of the Customer. The Terms, this DPA and the way the Customer configures and uses the service are the Customer's complete instructions. Further instructions must be agreed in writing.
- If EU or Dutch law requires Sales Surge to process Customer Personal Data in another way, Sales Surge informs the Customer first, unless that law prohibits it.
- Sales Surge informs the Customer without delay if it believes an instruction infringes the GDPR or other data protection law. It may suspend that instruction until the Customer confirms or changes it.
- Sales Surge does not process Customer Personal Data for its own purposes. The Customer authorises Sales Surge to create aggregated, anonymised statistics about the use of the service, as described in the Terms.
5.Confidentiality
Sales Surge ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, and gives access only to people who need it for their work.
6.Security of processing
Sales Surge implements the technical and organisational measures in Annex 2 to ensure a level of security appropriate to the risk, as required by article 32 GDPR. Sales Surge may update these measures, provided the overall level of protection does not decrease. The Customer is responsible for the security of its own configuration, such as the roles it assigns, which users get access, and which data it chooses to send through the service.
7.Sub-processors
- The Customer gives Sales Surge general written authorisation to engage sub-processors. The current sub-processors are listed on the Sub-processors page, which forms Annex 3 of this DPA.
- Sales Surge informs the Customer at least 30 days before it adds or replaces a sub-processor, by email to the Customer's admins and by updating that page.
- The Customer may object on reasonable grounds relating to data protection within those 30 days. The parties then discuss the objection in good faith. If they cannot resolve it, the Customer may terminate the affected service with effect from the date of the change, and Sales Surge refunds fees paid for the period after that date.
- Sales Surge imposes data protection obligations on each sub-processor in a written contract that offer at least the protection of this DPA. Sales Surge remains fully liable to the Customer for the performance of its sub-processors, as article 28(4) GDPR requires.
8.International transfers
- Sales Surge transfers Customer Personal Data outside the European Economic Area only where the transfer complies with chapter V GDPR: on the basis of an adequacy decision, the SCCs or another appropriate safeguard under article 46 GDPR.
- Where a sub-processor processes Customer Personal Data outside the European Economic Area, Sales Surge concludes the SCCs (module 3, processor to processor) with that sub-processor or relies on its certification under the EU-US Data Privacy Framework, and assesses whether supplementary measures are needed.
- The Customer authorises the transfers described on the Sub-processors page.
9.Requests from data subjects
- If Sales Surge receives a request from a data subject about Customer Personal Data, it forwards the request to the Customer without undue delay and does not respond itself, unless the Customer instructs it to.
- The service lets the Customer find, export, correct and delete personal data itself. Where the Customer needs more help to respond to a request, Sales Surge assists as far as reasonably possible. Sales Surge may charge reasonable costs for assistance that goes beyond the tools in the service.
10.Data protection impact assessments
Sales Surge gives the Customer the information it reasonably needs for a data protection impact assessment or a prior consultation with a supervisory authority under articles 35 and 36 GDPR, as far as it relates to the service.
11.Personal data breaches
- Sales Surge notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and no later than Open point: [48 hours; confirm the notification window] after becoming aware of it.
- The notification describes, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and limit its effects. Where not all information is available at once, Sales Surge provides it in phases.
- Sales Surge takes reasonable measures to contain the breach and limit its consequences, documents the breach, and keeps the Customer informed.
- The Customer decides whether to notify the supervisory authority and data subjects. Sales Surge does not notify them on the Customer's behalf unless the Customer asks it to or the law requires it.
- A notification is not an acknowledgement of fault or liability.
12.Information and audits
- Sales Surge makes available to the Customer all information necessary to demonstrate compliance with article 28 GDPR, for example by answering a reasonable security questionnaire.
- The Customer may have an audit carried out once every 12 months, and additionally after a personal data breach or at the request of a supervisory authority. The audit is carried out by an independent auditor bound by confidentiality, announced at least 30 days in advance, held during business hours, and designed to avoid disruption and access to data of other customers.
- Sales Surge may first offer a recent report from an independent auditor. If that report answers the Customer's reasonable questions, it replaces the audit.
- The Customer bears the costs of the audit, unless the audit shows a material breach of this DPA by Sales Surge. Sales Surge remedies shortcomings found in the audit within a reasonable period.
13.Deletion and return
- During the subscription, and for 30 days after it ends or after the Customer uninstalls the app, the Customer can export Customer Personal Data from the service in CSV and JSON format.
- When the Customer uninstalls the app, Sales Surge immediately deletes the Pipedrive access tokens it holds for the Customer and removes the webhooks it registered.
- 30 days after the uninstall or the end of the subscription, whichever comes first, Sales Surge permanently deletes Customer Personal Data from its production systems. Backup copies are deleted as the backups expire, within Open point: [backup retention period, to confirm with the hosting set-up]. Sub-processors are instructed to do the same.
- Sales Surge keeps Customer Personal Data longer only where EU or Dutch law requires it.
- On request, Sales Surge confirms the deletion in writing.
- Records the service created in the Customer's Pipedrive account remain there under the Customer's control.
14.Liability
Article 82 GDPR governs liability towards data subjects. Between the parties, the limitations of liability in the Terms of Service apply to this DPA, to the extent the law allows. An administrative fine imposed on a party is borne by that party.
15.Term, precedence and governing law
- This DPA applies for as long as Sales Surge processes Customer Personal Data.
- If there is a conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms.
- This DPA is governed by the laws of the Netherlands. Disputes are submitted to the court designated in the Terms.
- Questions about this DPA go to info@sales-surge.nl.
16.Annex 1: Description of the processing
- Categories of data subjects
- The Customer's customers, prospects and their contact persons who contact the Customer through email, web forms or the customer portal, or who are stored in the Customer's Pipedrive account, including people who answer CSAT and NPS surveys. The Customer's users of the service (admins, agents and viewers).
- Contact details
- Names, email addresses, phone numbers and addresses, as received by email or synchronised from Pipedrive.
- CRM identifiers
- Pipedrive IDs of persons, organisations, deals, products, activities, leads and users.
- Message content
- Subjects and bodies of emails, form submissions and portal messages, attachments, replies and internal notes, and email headers needed for threading and delivery.
- Commercial context
- Deals, products, values, pipeline stages, owners and renewal dates linked to persons and organisations.
- Service data
- Ticket status, priority, tags, assignments and SLA timestamps, CSAT and NPS scores and comments, sentiment and intent classifications, health scores, check-in notes, and the audit trail of changes.
- Special categories
- Not intended. Data subjects may include them in free text. The Customer decides how its channels are used and informs data subjects accordingly.
- Nature of the processing
- Receiving and storing messages; synchronising data from Pipedrive; organising and displaying data to users; calculating SLAs, customer health and revenue scores; when the Customer enables AI, classifying messages and drafting replies and summaries for review by a user; sending emails; writing activities, notes, leads and deals to Pipedrive; exporting and deleting data.
- Purpose
- Providing the service to the Customer under the Terms.
- Frequency and duration
- Continuous for the duration of the subscription, followed by deletion as described in Deletion and return.
- Location
- European Economic Area Open point: [confirm hosting and database regions], with the transfers listed in Annex 3.
17.Annex 2: Technical and organisational measures
Tenant isolation
- Every table that holds Customer Data carries a company identifier. Row-level security is enforced on every such table in the database, so a query only returns rows of the customer it runs for.
- The customer is identified only from a verified source: the signed session, a signed token issued by Pipedrive, or per-customer webhook credentials. Never from a parameter in a request.
- Background jobs that work across customers name the customer explicitly in every query.
Encryption
- Pipedrive access tokens, refresh tokens and webhook credentials are encrypted with AES-GCM before they are stored. The key is kept outside the database.
- All traffic to and from the service is encrypted with TLS.
- Data at rest is encrypted by the hosting and database providers. Open point: [confirm encryption at rest with the providers]
Access control
- The app requests only the Pipedrive permissions it needs for its features (least privilege).
- Role-based access in the app: admins change settings, agents work tickets, viewers read.
- Sessions use HMAC-signed cookies with HttpOnly, Secure and SameSite=Lax, valid for 7 days and renewed on use. Embedded Pipedrive views use a short-lived token kept only in memory.
- Access to production systems is limited to named Sales Surge staff who need it. Open point: [confirm the staff access procedure and multi-factor authentication]
Application security
- Incoming HTML is sanitised against an allowlist when it is stored. Outgoing email is generated only from our own templates.
- All input is validated at every boundary: requests, webhooks and inbound email.
- Every public route is rate limited. Webhooks are authenticated with per-customer credentials.
Logging and monitoring
- Structured logs never contain tokens, secrets, email bodies or personal data beyond identifiers.
- An audit trail records ticket changes and administrative actions.
Availability and resilience
- Incoming messages and webhooks are stored before processing and handled by a job queue with retries, so a temporary outage does not lose them. Duplicates are detected and ignored.
- Regular backups. Open point: [confirm backup frequency, retention and restore testing]
Development and testing
- Test and load traffic never uses real customer accounts. Development uses simulated services and a sandbox.
- Changes are type-checked, tested and reviewed before release.
AI features
- Off until a customer admin switches them on. Only the content needed for a request is sent. The AI provider may not train models on it under its commercial terms. A user always reviews and sends.
Organisation
- Confidentiality obligations for everyone with access, an incident response procedure and a responsible disclosure policy.
18.Annex 3: Sub-processors
The current list of sub-processors, with their purpose, the data they process, their location and the transfer mechanism, is published on the Sub-processors page. That list forms part of this DPA.