Effective Date: 10 August 2026
Version: 1.0
This Data Processing Agreement ("DPA") forms part of the agreement between Logical Pure Minds SRL, a company registered in Romania under registration number RO43302770, with registered office at Strada Lazăr Vicol, nr. 15, bl. E37, sc. A, ap. 47, Suceava 720245, Romania ("CRMsynQ", "Processor"), and the customer identified in the CRMsynQ account ("Customer", "Controller") for use of the CRMsynQ service (the "Services").
This DPA applies where CRMsynQ processes Personal Data on the Customer's behalf. In the event of conflict with the Terms and Conditions, this DPA prevails in respect of data protection matters.
Terms not defined here have the meaning given in the GDPR.
2.1 The Customer is the Controller of Customer Personal Data. CRMsynQ is the Processor.
2.2 CRMsynQ is an independent Controller in respect of account, billing, and usage data relating to the Customer's personnel. That processing is governed by the CRMsynQ Privacy Policy, not this DPA.
2.3 The Customer warrants that it has a valid lawful basis for processing Customer Personal Data, that any required notice has been given to data subjects, and that its instructions to CRMsynQ comply with Applicable Data Protection Law.
3.1 CRMsynQ processes Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA, and the Customer's configuration within the Services — schedule filters, sync frequency, field mappings, and the designated LinkedIn URL field — constitute the Customer's complete documented instructions.
3.2 CRMsynQ will not:
(a) sell, rent, or license Customer Personal Data;
(b) use Customer Personal Data to train machine learning or artificial intelligence models;
(c) use Customer Personal Data to build, enrich, or supplement any independent dataset or data product;
(d) combine Customer Personal Data with data from other customers or from any other source except as required to perform the Services;
(e) process Customer Personal Data for any purpose other than performing the Services.
3.3 CRMsynQ writes only to the CRM fields the Customer has expressly mapped. It does not create or delete contact records. Where a mapped value requires an associated company or organisation record that does not already exist in the Customer's CRM, CRMsynQ may create that record and associate it with the contact.
3.4 If CRMsynQ is required by EU or Member State law to process Customer Personal Data beyond the Customer's instructions, it will inform the Customer before processing unless that law prohibits such notification. If CRMsynQ considers an instruction to infringe Applicable Data Protection Law, it will inform the Customer without undue delay.
CRMsynQ ensures that all personnel authorised to process Customer Personal Data are bound by written confidentiality obligations, receive appropriate data protection training, and access Customer Personal Data only as necessary to perform their duties.
5.1 CRMsynQ implements the technical and organisational measures set out in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.
5.2 CRMsynQ may update these measures provided the level of security is not degraded.
6.1 The Customer grants CRMsynQ general authorisation to engage Sub-processors, subject to this Section.
6.2 The current Sub-processors are listed in Annex III and maintained at https://crmsynq.com/sub-processors.
6.3 CRMsynQ will give the Customer at least 30 days' notice before engaging a new Sub-processor that processes Customer Personal Data. Customers may subscribe to notifications at that page.
6.4 The Customer may object on reasonable data protection grounds within the notice period. The parties will discuss in good faith. If no resolution is reached, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.
6.5 CRMsynQ imposes on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Sub-processor's performance.
7.1 Taking into account the nature of the processing, CRMsynQ assists the Customer by appropriate technical and organisational measures in fulfilling its obligations to respond to data subject requests under Chapter III GDPR.
7.2 The Services allow the Customer to access, correct, and delete Customer Personal Data directly, including deletion of sync change history per contact or per schedule.
7.3 Where CRMsynQ receives a request directly from a data subject, it will not respond substantively but will forward the request to the Customer without undue delay, and in any event within 5 business days.
7.4 CRMsynQ operates a suppression list. Where an individual asks CRMsynQ not to process their profile information, CRMsynQ will add them to that list and exclude them from future sync runs, and will notify Customers whose records were synced for that individual in the preceding 12 months.
8.1 CRMsynQ notifies the Customer without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification will describe, to the extent known: the nature of the breach and categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where information is not available at once, it will be provided in phases without undue delay.
8.3 CRMsynQ assists the Customer in meeting its obligations under Articles 33 and 34 GDPR. CRMsynQ will not notify supervisory authorities or data subjects on the Customer's behalf unless legally required or expressly instructed.
CRMsynQ provides reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, taking into account the nature of processing and the information available to CRMsynQ.
10.1 Customer Personal Data is hosted on infrastructure located in the European Union.
10.2 Where CRMsynQ transfers Customer Personal Data outside the EEA to a country without an adequacy decision, the transfer is governed by the SCCs, which are incorporated by reference:
(a) Module Two (Controller to Processor) applies where the Customer is a Controller established in the EEA;
(b) Module Three (Processor to Processor) applies where the Customer is itself a Processor;
(c) Docking clause (Clause 7) applies; Clause 9 Option 2 (general written authorisation) applies with the 30-day period in Section 6.3; Clause 11 optional redress body does not apply; Clause 17 is governed by the law of Romania; Clause 18(b) designates the courts of Romania.
10.3 For transfers subject to UK law, the UK Addendum applies, with Tables 1–3 populated by reference to this DPA and Annexes, and Table 4 selecting "neither party".
10.4 Annexes I, II, and III to this DPA serve as Annexes I, II, and III to the SCCs.
11.1 CRMsynQ makes available all information reasonably necessary to demonstrate compliance with Article 28 GDPR.
11.2 CRMsynQ will respond to reasonable written security questionnaires no more than once per year, unless a Personal Data Breach has occurred or a supervisory authority requires otherwise.
11.3 The Customer may conduct an on-site audit on 30 days' written notice, no more than once per year, during business hours, subject to confidentiality undertakings and without unreasonably disrupting CRMsynQ's operations. The Customer bears its own costs and CRMsynQ's reasonable costs. Any available third-party audit reports or certifications will be provided first and should satisfy the audit right where adequate.
12.1 On termination, CRMsynQ deletes or irreversibly anonymises all Customer Personal Data within 30 days, except where retention is required by EU or Member State law.
12.2 CRMsynQ will certify deletion in writing on request.
Where the CCPA applies, CRMsynQ acts as a Service Provider. CRMsynQ does not sell or share Personal Information, does not retain, use, or disclose it for any purpose other than performing the Services, and does not combine it with Personal Information from other sources except as permitted. CRMsynQ certifies that it understands and will comply with these restrictions.
14.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
14.2 This DPA takes effect on the Effective Date and continues while CRMsynQ processes Customer Personal Data. Sections 4, 12, and 14 survive termination.
14.3 CRMsynQ may update this DPA on 30 days' notice where required by changes in Applicable Data Protection Law or its Sub-processors, provided no update materially reduces the protections afforded to the Customer.
Data exporter: the Customer, as identified in its CRMsynQ account. Role: Controller (or Processor, where acting on behalf of its own customer). Contact: the account administrator's email address on file.
Data importer: Logical Pure Minds SRL, Strada Lazăr Vicol, nr. 15, bl. E37, sc. A, ap. 47, Suceava 720245, Romania. Role: Processor. Contact: privacy@crmsynq.com.
Categories of data subjects: individuals whose records exist in the Customer's CRM and for whom the Customer has stored a LinkedIn profile URL — typically business contacts, leads, prospects, candidates, and partners.
Categories of personal data: name; LinkedIn profile URL; current job title; current employer; location; industry; profile headline; profile photo URL; and any additional professional profile fields the Customer elects to map. Also CRM record identifiers and the prior values of mapped fields, retained as change history.
Sensitive data: none is intentionally processed. The Customer is contractually prohibited from configuring the Services to write into fields designated for sensitive data or to deliberately collect special category data.
Frequency: continuous, on the schedules configured by the Customer (for example every 10 days, monthly, or annually).
Nature and purpose: retrieval of professional profile information from third-party data providers and updating of the corresponding fields in the Customer's CRM, so that the Customer's existing records remain accurate.
Retention: cached CRM field values — 30 days after the run that produced them. Sync change history — 12 months, or shorter where configured by the Customer. See the Privacy Policy for the full schedule.
Sub-processor processing: as set out in Annex III, for the duration of the Agreement.
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), Romania.
Encryption. TLS for all data in transit. Encryption at rest for databases and backups.
Access control. Role-based access control with least privilege. Multi-factor authentication required for all administrative and production access. Production data access limited to personnel who require it and reviewed periodically. Access revoked promptly on role change or departure.
Authentication. Customer authentication to the CRM is by OAuth; CRMsynQ does not request, receive, or store CRM passwords. Customers may revoke authorisation at any time from their CRM, with immediate effect.
Logging and monitoring. Audit logging of access to production systems. Operational logging of sync runs. Logs retained for 12 months.
Segregation. Customer data logically segregated; no cross-customer combination of Customer Personal Data.
Resilience. Regular automated backups; restoration procedures tested periodically.
Vulnerability management. Regular patching, dependency scanning, and remediation of identified vulnerabilities according to severity.
Personnel. Written confidentiality undertakings for all personnel and contractors. Data protection training.
Data minimisation. Only fields required for the Customer's configured mapping are read and cached. Free-text profile fields are opt-in and carry an in-product warning.
Deletion. Customers can delete change history per contact or per schedule from within the Services.
Incident response. Documented breach detection, escalation, and notification procedures, with notification to affected Customers within 72 hours.
| Sub-processor | Purpose | Entity location | Data location |
|---|---|---|---|
| DigitalOcean, LLC | Application hosting, databases, storage, backups | United States | European Union |
| Stripe Payments Europe, Ltd. | Payment and subscription processing (billing data only) | Ireland | EU / US |
| Brevo (Sendinblue SAS) | Transactional and service email | France | European Union |
| Bright Data Ltd. | Retrieval of publicly available professional profile information | Israel (adequacy decision) | Israel / EU |
| Datagma | Retrieval of publicly available professional profile information | France | European Union |
| Findymail | Retrieval of publicly available professional profile information | France | European Union |
The current list is maintained at https://crmsynq.com/sub-processors.
Questions about this DPA: privacy@crmsynq.com
Related documents: Privacy Policy · Sub-processors · Cookie Policy · Terms and Conditions