Data Processing Agreement (DPA) — CharterFlow CRM

Between the Customer (workspace owner — the Controller) and SUDO Technology LTD (the Processor). Effective on acceptance of the Terms of Service, of which this DPA forms part.

1. Subject matter and roles

The Processor operates CharterFlow CRM and processes personal data that the Controller enters into its workspace, solely to provide the Service. Duration: the subscription term plus the export window. This DPA implements GDPR art. 28.

2. Nature and purpose of processing

Hosting, storage, display, transmission (e.g. quotation and confirmation emails to the Controller's clients), backup, and — only where the Controller enables it — AI-assisted extraction/drafting over text the Controller submits.

3. Categories of data and data subjects

4. Controller instructions

The Processor processes only on documented instructions — the Service's functionality as configured by the Controller constitutes those instructions — unless law requires otherwise (in which case the Processor informs the Controller unless prohibited).

5. Confidentiality and personnel

Persons authorized to process the data are bound by confidentiality. Operational access to production data is restricted and logged.

6. Security (art. 32)

Technical and organizational measures include: per-workspace isolation enforced in the database (row-level security with no direct table access; access only through authorization-checking server functions); role-based permissions; masking of sensitive guest fields with audited, per-view reveal; comprehensive audit logging; encrypted transport (TLS) and provider-managed encryption at rest; secret-free application logs; separated environments; tested backup and restore procedures.

7. Subprocessors

The Controller authorizes the subprocessors listed in subprocessors.md. The Processor will notify workspace owners at least 30 days before adding or replacing a subprocessor; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution or the Controller may terminate affected services. The Processor remains liable for its subprocessors.

8. International transfers

Transfers outside the EEA/UK rely on adequacy decisions or Standard Contractual Clauses concluded with the relevant subprocessor.

9. Assistance to the Controller

Taking into account the nature of processing, the Processor assists the Controller with data-subject requests (access, rectification, erasure, portability — the Service provides export and deletion capabilities), and with the Controller's obligations under arts. 32–36 (security, breach notification, DPIAs), at reasonable cost where assistance exceeds the Service's built-in capabilities.

10. Personal-data breach

The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, providing the information reasonably required for the Controller's own notification duties, and cooperates in remediation.

11. Deletion and return

On termination, the Controller may export its data during the export window stated in the Terms. Thereafter the Processor deletes personal data (backup copies expire on their rotation schedule) unless retention is legally required.

12. Audit

The Processor makes available information reasonably necessary to demonstrate compliance (including summaries of subprocessor certifications) and allows audits — normally satisfied by documentation; on-site audits at most annually, on 30 days' notice, at the Controller's cost, without access to other customers' data.

Annex — summary of processing

Item Description
Processing operations Hosting, storage, transmission, backup, optional AI-assisted text processing
Duration Subscription term + export window
Data subjects Clients, leads, charter guests, workspace members
Data categories Contact data; CRM records; payment amounts/status; documents; guest identity-document data
Subprocessors See subprocessors.md