Data Processing Addendum
Terms that apply when Demand Trail processes Customer Personal Data as a processor or service provider.
Effective September 1, 2026Last updated September 1, 2026
1. Scope and Incorporation
This Data Processing Addendum ("DPA") forms part of the Agreement between Customer and Demand Trail LLC for the Demand Trail Services where Demand Trail processes Customer Personal Data on behalf of Customer.
This DPA applies only to processing of Customer Personal Data subject to applicable Data Protection Laws. Capitalized terms not defined here have the meanings in the Agreement.
2. Roles of the Parties
Customer is the controller, business, or other party that determines the purposes and means of processing Customer Personal Data, and Demand Trail is the processor or service provider processing Customer Personal Data on Customer's behalf, except where applicable law assigns different terminology.
Each party will comply with obligations applicable to it under Data Protection Laws.
3. Processing Instructions
Demand Trail will process Customer Personal Data only on documented instructions from Customer, including instructions contained in the Agreement, Customer configuration of the Services, Authorized User actions, support requests, and other written instructions consistent with the Agreement.
Demand Trail may process Customer Personal Data where required by law. Where legally permitted, Demand Trail will inform Customer before such processing.
If Demand Trail reasonably believes an instruction violates Data Protection Laws, Demand Trail may suspend the affected processing and notify Customer so the parties can address the issue.
4. Confidentiality and Personnel
Demand Trail will limit access to Customer Personal Data to personnel and contractors who need access to perform the Services and who are subject to appropriate confidentiality obligations.
Demand Trail will provide appropriate privacy and security awareness to personnel with access to Customer Personal Data in accordance with its internal practices.
5. Security Measures
Demand Trail will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Annex 2 describes the control categories for the Services.
6. Subprocessors
Customer generally authorizes Demand Trail to engage subprocessors to process Customer Personal Data for the purposes of providing the Services.
Demand Trail will maintain a current public list of subprocessors at /legal/subprocessors and will impose data protection obligations on subprocessors appropriate to the services they provide.
Demand Trail will provide a reasonable mechanism for Customers to receive notice of material new subprocessors. Customer may object on reasonable data protection grounds within the notice period stated on the Subprocessor page. The parties will work in good faith to address the objection. If no reasonable alternative is available, either party may terminate the affected Service as the applicable Agreement permits.
7. Data Subject Requests
Taking into account the nature of processing, Demand Trail will provide reasonable assistance to Customer with requests by individuals to exercise rights under Data Protection Laws where Customer cannot fulfill the request using available product functionality.
If Demand Trail receives a request relating to Customer Personal Data, Demand Trail may direct the requester to Customer and will not independently respond on Customer's behalf unless authorized or legally required.
8. Personal Data Breach
Demand Trail will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer Personal Data where notification to Customer is required by applicable Data Protection Laws.
The notice will include information reasonably available to Demand Trail that Customer needs to meet applicable breach notification obligations. Demand Trail may provide information in phases as an investigation continues.
Notification of an incident is not an admission of fault or liability.
9. Compliance Assistance
Taking into account the nature of processing and information available to Demand Trail, Demand Trail will provide reasonable assistance with data protection impact assessments, regulator consultations, and Customer compliance obligations where required by Data Protection Laws and not otherwise available through Documentation.
10. Audit Information
Demand Trail will make reasonably available information necessary to demonstrate compliance with this DPA, which may include security documentation, summaries, certifications, or independent audit reports when available.
If information made available is insufficient for a legally required audit, Customer may request an audit subject to reasonable confidentiality, scope, timing, security, and cost controls designed to minimize disruption and protect other customers.
11. International Transfers
Where processing involves a restricted international transfer, the parties will use an applicable lawful transfer mechanism. For transfers subject to the EEA GDPR, the then-current European Commission Standard Contractual Clauses may be incorporated as applicable to the parties' roles. For UK transfers, the applicable UK transfer addendum or equivalent mechanism may apply.
The parties will complete required annex information using the processing details in this DPA, applicable Order, Subprocessor page, and security documentation.
12. Return and Deletion
During the subscription term, Customer may export Customer Data using available product functionality subject to plan limits and Documentation.
After termination, Demand Trail will return or delete Customer Personal Data in accordance with the Agreement, Customer instructions, backup retention practices, and applicable law. Demand Trail may retain information where legally required, provided retained information remains protected and is not processed for unrelated purposes.
13. Government Requests
Demand Trail will evaluate government requests for Customer Personal Data and, where legally permitted, notify Customer before disclosure. Demand Trail will seek to limit disclosure to information legally required and may challenge requests that it reasonably believes are invalid or overbroad.
14. Order of Precedence and Liability
If this DPA conflicts with the Agreement on processing of Customer Personal Data, this DPA controls to the extent of the conflict. The liability provisions of the Agreement apply to this DPA unless applicable law requires otherwise.
Annex 1. Details of Processing
Subject matter: Provision of the Demand Trail cloud CRM, workflow, automation, integration, reporting, list, communication, and related services purchased or activated by Customer.
Duration: The subscription term plus the limited period required for export, deletion, backup rotation, legal retention, and dispute resolution.
Nature and purpose: Hosting, organizing, retrieving, displaying, securing, backing up, transmitting, transforming, synchronizing, automating, reporting on, and otherwise processing Customer Personal Data according to Customer instructions and product configuration.
Categories of data subjects: Customer Authorized Users, Customer employees and contractors, prospects, leads, contacts, customers, suppliers, partners, representatives, and other individuals whose information Customer chooses to process through the Services.
Types of Personal Data: Names, business contact details, job information, organization information, identifiers, CRM records, communication metadata and content, activities, notes, tasks, relationship history, custom fields, technical identifiers, and other data Customer submits or connects.
Sensitive data: Demand Trail is not intended for regulated or sensitive categories beyond those expressly supported in the Documentation or agreed in writing. Customer must not upload sensitive data categories that Demand Trail has not agreed to process.
Annex 2. Technical and Organizational Measures
Taking into account the nature of the Services, Demand Trail will maintain technical and organizational measures designed to protect Customer Personal Data in the following control categories:
- Logical tenant separation and authorization checks designed to prevent cross-tenant access
- Role-based access control and authenticated user context for protected operations
- Encryption of supported network traffic in transit
- Protection of production databases, object storage, backups, and secrets
- Restricted production access and secrets management
- Logging and monitoring for material authentication, authorization, administrative, and security events
- Backup, restoration, and disaster recovery procedures appropriate to the production environment
- Secure software development practices, including code review, dependency management, and vulnerability remediation
- Incident response procedures and escalation paths
- Vendor and subprocessor review appropriate to risk
- Account security controls such as multi-factor authentication where supported or required