Data Processing Agreement

Last updated: June 15, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer entity subscribing to RepDesk ("Customer," "Controller," or "you") and RepDesk LLC ("RepDesk," "Processor," or "we") for the RepDesk cloud CRM platform (the "Service"). This DPA supplements the Terms of Service and Privacy Policy.

By using the Service, Customer instructs RepDesk to process Customer Data as described herein and in the Terms. Where Customer is subject to GDPR, CCPA/CPRA, or similar laws, this DPA reflects standard B2B SaaS processor commitments.

1. Parties and Roles

  • Customer is the data controller for Customer Data submitted through the Service.
  • RepDesk is the data processor, processing Customer Data only on documented instructions from Customer as set out in the Terms, this DPA, and Customer's use of the Service.

2. Subject Matter and Duration

Subject matter: Processing of Customer Data to provide, maintain, secure, and improve the Service, including hosting, storage, backup, display, integration sync, commission calculation, notifications, and related CRM functionality.

Duration: For the term of Customer's subscription and until deletion or return of Customer Data as described in the Privacy Policy (including the 30-day post-termination retention window where applicable).

3. Nature and Purpose of Processing

RepDesk processes Customer Data to:

  • Operate the multi-tenant CRM Service in a logically isolated organization environment;
  • Authenticate Authorized Users and enforce role-based access;
  • Sync data with Third-Party Integrations enabled by Customer;
  • Generate reports, commissions, maps, notifications, and exports requested by Customer;
  • Maintain audit logs, backups, and disaster recovery;
  • Provide support and comply with applicable law.

4. Categories of Data and Data Subjects

Categories of personal data mirror those described in Privacy Policy Section 1, including:

  • Authorized User account data (name, email, role, activity);
  • Business CRM records (accounts, contacts, leads, deals, tasks, calendar events);
  • Sales and order data (quotes, orders, commissions, inventory references);
  • Communication records (email threads, SMS consent logs where enabled);
  • Integration metadata and synced records from connected systems;
  • Technical logs (IP address, device, usage events).

Data subjects may include Customer's employees, contractors, customers, prospects, and consignees (where SMS or tracking features are used).

5. Customer Obligations

Customer shall:

  • Establish and document a lawful basis for processing personal data it submits;
  • Provide accurate instructions through Authorized Users and Service configuration;
  • Ensure Authorized Users comply with the Terms and applicable privacy laws;
  • Not submit sensitive categories of data unless necessary and permitted by law;
  • Respond to data subject requests for data Customer controls, using in-app tools where available.

6. Processor Obligations

RepDesk shall:

  • Process Customer Data only on documented instructions (Terms, this DPA, and Customer's use of the Service), unless required by law;
  • Ensure personnel authorized to process Customer Data are bound by confidentiality obligations;
  • Implement appropriate technical and organizational measures, including TLS in transit, encryption at rest for integration credentials, row-level security tenant isolation, and access controls as described in Privacy Policy Section 6;
  • Engage subprocessors listed in Section 7 and provide notice of material changes via this page;
  • Assist Customer with data subject requests by providing in-app export and deletion tools and cooperating on reasonable requests via privacy@repdesk.io;
  • Delete or return Customer Data upon termination per Privacy Policy Section 7 (30-day window unless law requires longer retention);
  • Not sell Customer Data and not use Customer Data to train machine learning or AI models without Customer's explicit opt-in consent (Terms Section 9);
  • Notify Customer without undue delay upon becoming aware of a personal data breach affecting Customer Data, to the extent permitted by law.

7. Subprocessors

Customer authorizes RepDesk to engage the following subprocessors to support the Service. RepDesk remains responsible for subprocessors' performance of data protection obligations.

SubprocessorPurposeLocation
Supabase, Inc.Database, authentication, file storageUnited States (us-west-2)
Vercel, Inc.Application hosting and edge deliveryUnited States
Stripe, Inc.Subscription billing and paymentsUnited States
ResendTransactional email deliveryUnited States
Twilio, Inc.SMS shipment notifications (when tenant enables)United States
Google LLCCalendar/Gmail integrations (optional per tenant)United States / global
Intuit Inc.QuickBooks Online integration (optional per tenant)United States

Additional subprocessors may process data when Customer enables specific integrations (e.g., ShipStation, Fishbowl connectors). Customer's use of those integrations is subject to the third party's terms and privacy policies.

8. International Transfers

Customer Data may be processed in the United States and other countries where RepDesk or its subprocessors operate. Where required by applicable law, RepDesk implements appropriate safeguards for cross-border transfers, which may include Standard Contractual Clauses or reliance on adequacy decisions, and Customer consents to such transfers by using the Service where permitted by law.

9. Audit

Upon reasonable written request, RepDesk will provide information necessary to demonstrate compliance with this DPA. Customer may not conduct unlimited onsite audits. RepDesk may satisfy audit requests through third-party certifications, summaries of security measures, or targeted questionnaires, subject to confidentiality and frequency limits customary for SaaS providers.

10. Liability

Liability arising from processing under this DPA is subject to the limitation of liability and disclaimers in the Terms of Service.

11. Governing Law

This DPA is governed by the laws of the State of Idaho, United States, consistent with Terms Section 17.

12. Order of Precedence

If there is a conflict between documents governing the Service, the following order of precedence applies: (1) a signed order form or enterprise agreement between the parties; (2) this DPA; (3) the Terms of Service; (4) the Privacy Policy.

13. Contact

Privacy and data processing inquiries: privacy@repdesk.io