Legal
Data Processing Addendum (DPA)
Scope and Authority
- Regulatory Framework: This DPA incorporates the UK GDPR and Data Protection Act 2018.
- Party Roles: The Customer acts as the Data Controller; VouchrPulse acts as the Data Processor.
- Instruction Boundary: VouchrPulse will process personal data only on documented instructions from the Customer.
Categories of Data
- Data Subjects: Customer's employees, B2B clients, prospects, leads, and business contacts.
- Data Types: Names, business emails, phone numbers, job titles, billing histories, and communication metadata.
- Exclusions: The Customer agrees not to upload any special category data (e.g., health or biometric data).
Technical and Organisational Measures
- Hosting Security: Core CRM data is hosted within the UK/EEA using DigitalOcean's infrastructure.
- Encryption: Customer Data is encrypted at rest using AES-256 and in transit via TLS 1.3.
- Access Control: Employee access to customer databases is restricted using the principle of least privilege.
Sub-processors
- Authorized Infrastructure: The Customer authorizes the appointment of the following key sub-processors:
- DigitalOcean LLC: Cloud infrastructure and database hosting.
- Stripe Payments Europe, Ltd: Subscription billing processing and financial transactions.
- Twilio Inc: Telecommunications routing (SMS, WhatsApp, and VoIP voice traffic).
- Notification of Change: VouchrPulse will give 30 days notice before adding or replacing any sub-processors.
- Objection Rights: The Customer may object to changes on reasonable data protection grounds within 14 days.
Incident Management & Audits
- Breach Notification: VouchrPulse will notify the Customer within 72 hours of confirming a personal data breach.
- Audit Rights: VouchrPulse will provide standard security certificates to satisfy Customer compliance audits once per year.