← NDA CRM

Data Processing Agreement

Last updated: 17 August 2026 · Applies to every merchant using NDA CRM

This agreement forms part of the terms between NDA CRM ("the processor") and the merchant using the app ("the controller"). It applies automatically when the app is installed; no signature is required, though we will sign a copy on request.

1. Roles

The merchant determines why and how their customers' personal data is processed and is the controller. NDA CRM processes that data solely to provide the service and only on the merchant's documented instructions, which include the configuration chosen inside the app.

2. Subject matter and duration

Processing lasts as long as the app is installed, plus the retention periods set out below. On uninstall, store access tokens are deleted immediately.

3. Categories of data and data subjects

Data subjects: the merchant's customers and the people who place orders with them. Categories: name, phone number, email address, delivery and billing address, order contents and totals, parcel and tracking status, call notes and message history.

4. Our obligations

  1. We process personal data only on the merchant's instructions, and tell the merchant if an instruction appears to breach applicable law.
  2. We keep the data confidential and bind everyone with access to confidentiality.
  3. We apply the technical and organisational measures described in section 6.
  4. We assist the merchant in answering data subject requests, and in meeting their obligations on security, breach notification and impact assessments.
  5. We delete or return personal data at the end of the service, at the merchant's choice, unless we are required to keep it by law.
  6. We make available the information needed to demonstrate compliance and allow audits, as described in section 8.

5. Sub-processors

The merchant gives general authorisation for the sub-processors listed in our Privacy Policy. We impose the same data protection obligations on each of them. If we add or replace a sub-processor, we notify merchants by email at least 30 days in advance, and a merchant who objects on reasonable data protection grounds may terminate without penalty.

6. Security measures

MeasureHow
Encryption in transitTLS on every connection, to the app and to every supplier API
Encryption at restPlatform-level encryption, plus AES-GCM encryption applied by us to all supplier credentials, with the master key held separately from the database
BackupsManaged and encrypted by the infrastructure provider
Tenant isolationEvery stored record is namespaced per workspace and the boundary is enforced server-side on each request
Test separationWorkspaces marked as test write under a separate namespace and never share storage with production data
Access controlRoles and departments enforced on the server; a request outside a user's departments is refused, not merely hidden
AuthenticationPasswords hashed with PBKDF2; minimum ten characters, mixed character classes, common and breached passwords rejected
Access loggingReads of personal data are recorded with user, route, time and IP; the log records the access, not the content
RetentionAutomatic deletion once the periods in section 7 pass, with the result written to the audit log
Loss preventionCredentials never leave the server in readable form; the app returns no supplier secret to the browser; exports are limited to the merchant's own workspace and are logged

7. Retention

CategoryKept for
Parcels and orders24 months
Call records and conversations12 months
Access log12 months
Audit log24 months
Privacy requests received from Shopify90 days

Deletion runs automatically each day. A merchant may request earlier deletion at any time.

8. Audits

On reasonable notice and no more than once a year, we will answer a written security questionnaire and provide the documentation we hold. We have not yet completed an external certification such as SOC 2 or ISO 27001; when that changes, this section will say so with the date.

9. Breach notification

If we become aware of a personal data breach, we notify the affected merchants without undue delay and in any case within 72 hours, with the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken.

10. International transfers

Data is processed on infrastructure located in the European Union. Where a merchant connects a supplier outside the EU — a messaging or courier provider of their choosing — that transfer is made on the merchant's instruction and under that provider's own terms.

Contact

[email protected]