Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Pipemetry ("Pipemetry", "we", "us") and the customer that accepts the Agreement ("Customer", "you"). It applies whenever Pipemetry processes personal data on your behalf in providing the Service — most notably the CRM data you connect. This DPA is incorporated into the Agreement automatically; no signature is required. If your procurement process needs a countersigned copy, email [email protected] and we will execute one.

1. Roles and scope

For CRM data and other content you submit to the Service ("Customer Personal Data"), you are the controller (or a processor acting on behalf of your own controllers) and Pipemetry is your processor. "Personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in the GDPR (and, where applicable, the UK GDPR). This DPA does not apply to personal data Pipemetry processes as a controller (such as your account registration and billing details), which is described in our Privacy Policy.

2. Details of processing

3. Instructions

We process Customer Personal Data only on your documented instructions: the Agreement, this DPA, your configuration of the Service (including integrations, exports, webhooks, and share links you direct), and written instructions you send us. We will inform you if we believe an instruction violates applicable data-protection law.

4. Confidentiality and personnel

Persons we authorize to process Customer Personal Data are bound by confidentiality obligations. Access is limited to what is needed to operate, secure, and support the Service, and sensitive access is recorded in a write-once audit log.

5. Security

We implement appropriate technical and organizational measures, including: per-tenant row-level isolation enforced in the database; least-privilege service roles; encryption of data in transit over public networks; encryption of stored integration credentials and backups; scoped, revocable, hashed API keys; signed, expiring export links; and an append-only (WORM) access audit. Our current measures are described on the Security page, which we keep up to date as controls evolve.

6. Subprocessors

You generally authorize the subprocessors listed on our Subprocessors page. We will update that page before adding or replacing a subprocessor (subscribe to changes as described there); if you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected service and receive a pro-rata refund of prepaid fees. We remain responsible for our subprocessors' performance under this DPA.

7. Assistance with data subject requests

Taking into account the nature of the processing, we assist you in fulfilling data subject requests: the Service provides workspace administrators a complete machine-readable export (access and portability) in-product; we execute workspace deletion (erasure) on request through our audited erasure process; and we will provide reasonable further assistance. If a data subject contacts us directly about Customer Personal Data, we will refer them to you.

8. Personal data breach

We will notify you without undue delay — and in any case within 72 hours — after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably required for your own notification obligations as it becomes available, followed by remediation details.

9. Deletion and return

During the term you can export Customer Personal Data at any time. On termination, the Agreement provides an export window, after which we delete or de-identify Customer Personal Data (we target completing deletion within 30 days after that window closes), except for write-once audit and billing records retained to satisfy legal and security obligations (GDPR Art. 17(3)(b)/(e)) and residual copies in encrypted backups, which are purged on a rolling schedule.

10. Audits and information

We will make available information reasonably necessary to demonstrate compliance with this DPA: our security documentation, completed security questionnaires, and — as our compliance program matures — third-party audit reports under NDA. Where these are insufficient to meet a requirement under Art. 28(3)(h) GDPR, we will cooperate with an audit conducted with reasonable notice, at most once annually, during business hours, without disrupting the Service, and at your expense.

11. International transfers

The Service is hosted in the United States. Where Customer Personal Data protected by EEA, UK, or Swiss data-protection law is transferred to us or our subprocessors outside those jurisdictions, the parties incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) — or Module Three where you act as processor — completed with the processing details in this DPA, with Pipemetry as data importer and you as data exporter; for UK transfers, the ICO's International Data Transfer Addendum applies the Clauses accordingly. If a required transfer mechanism is invalidated, the parties will cooperate in good faith on a replacement.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations of liability in the Agreement. If this DPA conflicts with the Agreement on data-protection matters, this DPA prevails; the Standard Contractual Clauses prevail over both where they apply.

Contact

Questions about this DPA: [email protected]. For a countersigned copy: [email protected].