Last updated: September 9, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Crevoca ("Processor" or "we") and you ("Controller" or "Customer") and reflects the parties' agreement with respect to the processing of personal data under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR").
The Controller determines the purposes and means of processing personal data. The Processor processes personal data on behalf of the Controller in accordance with the Controller's instructions through the provision of the Service. This DPA applies to personal data that the Controller submits to or makes available through the Service.
The Processor shall:
The Controller grants general authorization for the Processor to engage sub-processors to support the provision of the Service. The Processor shall remain liable for the performance of its sub-processors to the same extent it is liable under this DPA. Current sub-processors include:
The Processor shall give the Controller prior notice of intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes.
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligations to respond to requests from data subjects exercising their rights under the GDPR, including:
Where personal data is transferred outside the European Economic Area ("EEA"), the Processor shall ensure appropriate safeguards are in place, which may include Standard Contractual Clauses ("SCCs") approved by the European Commission, the EU-US Data Privacy Framework, or other lawful transfer mechanisms.
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under this DPA and shall contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.
Upon termination of the Service, the Processor shall, at the choice of the Controller, delete or return all personal data to the Controller, and delete existing copies, unless applicable law requires storage of the personal data. Data retained for legal compliance shall be stored securely and not processed for any other purpose.
For any questions regarding this DPA or to exercise data subject rights, please contact us.