Data Processing Agreement (DPA) — CharterFlow CRM
Between the Customer (workspace owner — the Controller) and SUDO Technology LTD (the Processor). Effective on acceptance of the Terms of Service, of which this DPA forms part.
1. Subject matter and roles
The Processor operates CharterFlow CRM and processes personal data that the Controller enters into its workspace, solely to provide the Service. Duration: the subscription term plus the export window. This DPA implements GDPR art. 28.
2. Nature and purpose of processing
Hosting, storage, display, transmission (e.g. quotation and confirmation emails to the Controller's clients), backup, and — only where the Controller enables it — AI-assisted extraction/drafting over text the Controller submits.
3. Categories of data and data subjects
- Data subjects: the Controller's clients, prospective clients (leads), charter guests, and workspace members.
- Data: contact details; lead/inquiry content; quotation and booking records; payment amounts and status (no card data); uploaded documents; guest manifest data, which may include identity-document details (passport number, date of birth, nationality) — special care category handled with masking-by-default and audited reveal in the Service.
4. Controller instructions
The Processor processes only on documented instructions — the Service's functionality as configured by the Controller constitutes those instructions — unless law requires otherwise (in which case the Processor informs the Controller unless prohibited).
5. Confidentiality and personnel
Persons authorized to process the data are bound by confidentiality. Operational access to production data is restricted and logged.
6. Security (art. 32)
Technical and organizational measures include: per-workspace isolation enforced in the database (row-level security with no direct table access; access only through authorization-checking server functions); role-based permissions; masking of sensitive guest fields with audited, per-view reveal; comprehensive audit logging; encrypted transport (TLS) and provider-managed encryption at rest; secret-free application logs; separated environments; tested backup and restore procedures.
7. Subprocessors
The Controller authorizes the subprocessors listed in subprocessors.md.
The Processor will notify workspace owners at least 30 days before adding
or replacing a subprocessor; the Controller may object on reasonable
data-protection grounds, in which case the parties will seek a solution or
the Controller may terminate affected services. The Processor remains liable
for its subprocessors.
8. International transfers
Transfers outside the EEA/UK rely on adequacy decisions or Standard Contractual Clauses concluded with the relevant subprocessor.
9. Assistance to the Controller
Taking into account the nature of processing, the Processor assists the Controller with data-subject requests (access, rectification, erasure, portability — the Service provides export and deletion capabilities), and with the Controller's obligations under arts. 32–36 (security, breach notification, DPIAs), at reasonable cost where assistance exceeds the Service's built-in capabilities.
10. Personal-data breach
The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, providing the information reasonably required for the Controller's own notification duties, and cooperates in remediation.
11. Deletion and return
On termination, the Controller may export its data during the export window stated in the Terms. Thereafter the Processor deletes personal data (backup copies expire on their rotation schedule) unless retention is legally required.
12. Audit
The Processor makes available information reasonably necessary to demonstrate compliance (including summaries of subprocessor certifications) and allows audits — normally satisfied by documentation; on-site audits at most annually, on 30 days' notice, at the Controller's cost, without access to other customers' data.
Annex — summary of processing
| Item | Description |
|---|---|
| Processing operations | Hosting, storage, transmission, backup, optional AI-assisted text processing |
| Duration | Subscription term + export window |
| Data subjects | Clients, leads, charter guests, workspace members |
| Data categories | Contact data; CRM records; payment amounts/status; documents; guest identity-document data |
| Subprocessors | See subprocessors.md |