Data Processing Agreement
Last updated: June 15, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer entity subscribing to RepDesk ("Customer," "Controller," or "you") and RepDesk LLC ("RepDesk," "Processor," or "we") for the RepDesk cloud CRM platform (the "Service"). This DPA supplements the Terms of Service and Privacy Policy.
By using the Service, Customer instructs RepDesk to process Customer Data as described herein and in the Terms. Where Customer is subject to GDPR, CCPA/CPRA, or similar laws, this DPA reflects standard B2B SaaS processor commitments.
1. Parties and Roles
- Customer is the data controller for Customer Data submitted through the Service.
- RepDesk is the data processor, processing Customer Data only on documented instructions from Customer as set out in the Terms, this DPA, and Customer's use of the Service.
2. Subject Matter and Duration
Subject matter: Processing of Customer Data to provide, maintain, secure, and improve the Service, including hosting, storage, backup, display, integration sync, commission calculation, notifications, and related CRM functionality.
Duration: For the term of Customer's subscription and until deletion or return of Customer Data as described in the Privacy Policy (including the 30-day post-termination retention window where applicable).
3. Nature and Purpose of Processing
RepDesk processes Customer Data to:
- Operate the multi-tenant CRM Service in a logically isolated organization environment;
- Authenticate Authorized Users and enforce role-based access;
- Sync data with Third-Party Integrations enabled by Customer;
- Generate reports, commissions, maps, notifications, and exports requested by Customer;
- Maintain audit logs, backups, and disaster recovery;
- Provide support and comply with applicable law.
4. Categories of Data and Data Subjects
Categories of personal data mirror those described in Privacy Policy Section 1, including:
- Authorized User account data (name, email, role, activity);
- Business CRM records (accounts, contacts, leads, deals, tasks, calendar events);
- Sales and order data (quotes, orders, commissions, inventory references);
- Communication records (email threads, SMS consent logs where enabled);
- Integration metadata and synced records from connected systems;
- Technical logs (IP address, device, usage events).
Data subjects may include Customer's employees, contractors, customers, prospects, and consignees (where SMS or tracking features are used).
5. Customer Obligations
Customer shall:
- Establish and document a lawful basis for processing personal data it submits;
- Provide accurate instructions through Authorized Users and Service configuration;
- Ensure Authorized Users comply with the Terms and applicable privacy laws;
- Not submit sensitive categories of data unless necessary and permitted by law;
- Respond to data subject requests for data Customer controls, using in-app tools where available.
6. Processor Obligations
RepDesk shall:
- Process Customer Data only on documented instructions (Terms, this DPA, and Customer's use of the Service), unless required by law;
- Ensure personnel authorized to process Customer Data are bound by confidentiality obligations;
- Implement appropriate technical and organizational measures, including TLS in transit, encryption at rest for integration credentials, row-level security tenant isolation, and access controls as described in Privacy Policy Section 6;
- Engage subprocessors listed in Section 7 and provide notice of material changes via this page;
- Assist Customer with data subject requests by providing in-app export and deletion tools and cooperating on reasonable requests via privacy@repdesk.io;
- Delete or return Customer Data upon termination per Privacy Policy Section 7 (30-day window unless law requires longer retention);
- Not sell Customer Data and not use Customer Data to train machine learning or AI models without Customer's explicit opt-in consent (Terms Section 9);
- Notify Customer without undue delay upon becoming aware of a personal data breach affecting Customer Data, to the extent permitted by law.
7. Subprocessors
Customer authorizes RepDesk to engage the following subprocessors to support the Service. RepDesk remains responsible for subprocessors' performance of data protection obligations.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | United States (us-west-2) |
| Vercel, Inc. | Application hosting and edge delivery | United States |
| Stripe, Inc. | Subscription billing and payments | United States |
| Resend | Transactional email delivery | United States |
| Twilio, Inc. | SMS shipment notifications (when tenant enables) | United States |
| Google LLC | Calendar/Gmail integrations (optional per tenant) | United States / global |
| Intuit Inc. | QuickBooks Online integration (optional per tenant) | United States |
Additional subprocessors may process data when Customer enables specific integrations (e.g., ShipStation, Fishbowl connectors). Customer's use of those integrations is subject to the third party's terms and privacy policies.
8. International Transfers
Customer Data may be processed in the United States and other countries where RepDesk or its subprocessors operate. Where required by applicable law, RepDesk implements appropriate safeguards for cross-border transfers, which may include Standard Contractual Clauses or reliance on adequacy decisions, and Customer consents to such transfers by using the Service where permitted by law.
9. Audit
Upon reasonable written request, RepDesk will provide information necessary to demonstrate compliance with this DPA. Customer may not conduct unlimited onsite audits. RepDesk may satisfy audit requests through third-party certifications, summaries of security measures, or targeted questionnaires, subject to confidentiality and frequency limits customary for SaaS providers.
10. Liability
Liability arising from processing under this DPA is subject to the limitation of liability and disclaimers in the Terms of Service.
11. Governing Law
This DPA is governed by the laws of the State of Idaho, United States, consistent with Terms Section 17.
12. Order of Precedence
If there is a conflict between documents governing the Service, the following order of precedence applies: (1) a signed order form or enterprise agreement between the parties; (2) this DPA; (3) the Terms of Service; (4) the Privacy Policy.
13. Contact
Privacy and data processing inquiries: privacy@repdesk.io