1. Purpose & Core Scope
This Data Processing Agreement ("DPA") governs the processing of customer personal data by NexusLink Services India Pvt Ltd ("Accovo", "Processor") on behalf of the customer ("Customer", "Controller") when accessing or using the Accovo smart financial CRM.
This DPA is incorporated into, and forms part of, our main Terms & Conditions. It is designed to satisfy the statutory requirements of global data protection laws, including the European Union's General Data Protection Regulation (GDPR) and the Indian Digital Personal Data Protection Act (DPDP Act).
2. Processor & Controller Roles
The parties acknowledge and agree that:
- Customer (Controller): Retains ownership of all uploaded CRM database entities (customer list details, item SKU lines, payment logs) and directs how and why data is compiled.
- Accovo (Processor): Processes the data solely on behalf of, and in accordance with, the documented instructions of the Customer, including settings made in the dashboard.
3. Scope of Processing & Categories
We process data to perform standard CRM accounting operations, including invoice generations, customer contacts filing, payment records, and tax calculations.
Categories of Data Subjects: Customer's employees, partners, end-users, vendors, and clients.
Types of Personal Data: Name, corporate email, billing addresses, contact phone numbers, corporate tax identifiers (GST/VAT/EIN), bank account numbers, invoice row descriptions, and transaction records.
4. Technical & Security Directives
Accovo implements appropriate technical and organizational measures to safeguard customer data against unauthorized access, alteration, disclosure, or accidental destruction. These measures include:
- Logical Partitioning: Isolating client workspaces at the database layer to prevent cross-tenant data requests.
- Encryption Protocols: Restricting standard database interactions to TLS 1.3 encrypted endpoints in transit and utilizing AES-256 for data at rest.
- Access Governance: Limiting administrator access to cloud hosting instances to a small group of authorized technicians using MFA.
- Continuous Audits: Conducting periodic code quality reviews and host system vulnerability assessments to detect zero-day exploits.
5. Sub-Processor Registry
The Customer grants general written authorization to Accovo to engage sub-processors to assist in delivering SaaS CRM capabilities.
Approved Sub-processors:
- Amazon Web Services (AWS) — Cloud Hosting and secure database infrastructure storage.
- Stripe, Inc. — Payment gateway integrations and subscription credit card handling.
- Postmark / SendGrid — Transactional mail servers for sending customer invoices and receipt emails.
We enforce strict data protection agreements with all sub-processors, matching or exceeding the data security obligations set forth in this DPA. We will notify the Customer of any planned additions or replacements of sub-processors.
6. Breach Management & Notifications
In the event of a confirmed security incident resulting in the unauthorized access, disclosure, loss, or alteration of Customer Personal Data:
- We will notify the Customer via their registered billing email address within seventy-two (72) hours of confirming the breach.
- The notice will detail the categories of data impacted, estimated scope, containment steps taken, and recommendations for mitigation.
- We will immediately launch containment and forensic protocols to secure active connections and patch vulnerabilities.
7. Audit Rights & Reviews
Accovo shall make available to the Customer all information necessary to demonstrate compliance with our obligations under global privacy frameworks.
Once per calendar year, the Customer may request our latest security summaries, compliance logs, or SOC 2 Type II audit results (subject to signing a non-disclosure agreement). Any on-site audit requests must be scheduled 30 days in advance and are limited to business days, with expenses borne by the Customer.
8. International Data Transfers & Liability
If processing customer personal data involves cross-border transfers from the European Union to jurisdictions outside the EEA, we rely on Standard Contractual Clauses (SCCs) to ensure the adequacy of protection.
Our liability under this DPA shall be subject to the limitations of liability and caps set forth in the master Terms & Conditions.