Contract addendum for Providers / business customers | Effective: 22 September 2026 | Operator: Adstim LLC (Wyoming)
Publication note: replace every bracketed placeholder before launch. This draft must be aligned with the actual product configuration and reviewed by qualified counsel in the jurisdictions where Crewelo launches.
This DPA forms part of the agreement between Adstim LLC ("Crewelo") and the business customer or Provider ("Customer") where Crewelo processes Personal Data on behalf of Customer in connection with hosted business websites, forms, CRM, lead management, communications, or related business tools.
1. Definitions and roles
“Personal Data,” “processing,” “controller,” and “processor” have the meanings given by applicable data-protection law. For Customer-controlled lead/customer data processed solely to provide Customer’s business tools, Customer is controller/business and Crewelo is processor/service provider/contractor as applicable. Crewelo remains an independent controller/business for data it uses for its own account administration, security, fraud prevention, billing, marketplace/network functions, legal compliance, and service improvement where law permits.
2. Customer instructions
Crewelo will process Customer Personal Data only on documented instructions from Customer, including the instructions in the agreement and Customer’s use of the services, unless law requires otherwise. Crewelo will notify Customer before legally required processing unless prohibited by law.
3. Confidentiality and personnel
Crewelo will ensure persons authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and receive access only as needed for their duties.
4. Security measures
Crewelo will maintain technical and organizational measures appropriate to the risk, which should include: encryption in transit; appropriate encryption at rest; identity and access management; least-privilege authorization; secrets management; vulnerability and dependency management; logging and monitoring; secure development and deployment controls; logical tenant separation; backup and recovery controls; incident-response procedures; employee/vendor access controls; and periodic review of security measures. The final contractual security exhibit must match the production architecture and must not promise controls that are not actually deployed.
5. Subprocessors
Customer authorizes Crewelo to use subprocessors for infrastructure, hosting, storage, communications, analytics, security, support, AI, and related service functions. Crewelo will maintain a current subprocessor list at [SUBPROCESSOR URL] and, where required by contract or law, provide notice of material new subprocessors and a reasonable mechanism to object on legitimate data-protection grounds. Crewelo will impose data-protection obligations on subprocessors appropriate to their processing.
6. Assistance
Taking into account the nature of processing, Crewelo will reasonably assist Customer with data-subject requests, security obligations, breach response, data-protection impact assessments, and regulator consultations where applicable and where the relevant information is available to Crewelo. Customer remains responsible for determining its own legal obligations and for responding to requests as controller.
7. Personal data breaches
Crewelo will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data where notification is required under applicable law or the agreement. Notification will include information reasonably available to Crewelo about the nature, likely consequences, and mitigation. Notification is not an admission of fault or liability.
8. Return and deletion
Upon termination and Customer’s request, Crewelo will return or delete Customer Personal Data as required by applicable law and the agreement, except information Crewelo must or is permitted to retain for legal, security, fraud-prevention, backup, dispute, or independent-controller purposes. Data in backups may remain until normal rotation, protected from ordinary production use.
9. International transfers
If Customer Personal Data protected by EEA GDPR is transferred to a country lacking an adequacy decision, the parties incorporate by reference the applicable European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914, ordinarily Module Two (controller-to-processor), with Adstim LLC as data importer unless the parties’ roles require another module. For UK restricted transfers, the parties incorporate the applicable UK International Data Transfer Addendum to the EU SCCs or other lawful transfer mechanism. Swiss modifications apply where required by Swiss law.
10. U.S. state privacy terms
Where Crewelo processes personal information as a service provider/processor/contractor under applicable U.S. state privacy law, Crewelo will process it only for the specified business purposes, will not sell it or share it for cross-context behavioral advertising, will not retain/use/disclose it outside the permitted relationship except as allowed by law, and will provide the level of privacy protection required of such processors/service providers. Customer and Crewelo may take reasonable steps to verify compliance as required by law.
11. Audit information
Crewelo will make available information reasonably necessary to demonstrate compliance with this DPA, such as relevant policies, certifications, assessments, or summaries. Where legally required and such information is insufficient, the parties will agree on a reasonable audit process that protects security, confidentiality, other customers, and operational integrity. Customer bears audit costs unless material noncompliance is found or law requires otherwise.
12. Processing details — Schedule A
Subject matter: operation of Customer’s hosted website, forms, CRM, communications, lead management, quotes/bookings, and related business tools. Duration: term of the services plus the retention/deletion period. Nature: collection, storage, organization, retrieval, use, transmission, display, support, backup, deletion, and other processing needed to provide the services. Data subjects: Customer personnel, leads, customers, prospective customers, reviewers, and other persons interacting with Customer through the services. Data types: identifiers/contact data, service request/job details, messages, quotes, bookings, uploaded files/photos, preferences, transaction metadata, consent records, and other Customer-submitted data. Special categories/sensitive data: not intended unless a feature expressly supports it and the parties have documented an appropriate lawful basis and safeguards.