Data Processing Addendum
Version 1.1LeadCat is a product of Staminal Technologies Private Limited.
This Data Processing Addendum ("DPA") forms part of the LeadCat CRM Terms of Service, an order form, or another written agreement governing the Customer's use of LeadCat CRM (the "Main Agreement").
This DPA is between the business identified in the applicable CRM workspace, order form, or Main Agreement ("Customer") and STAMINAL TECHNOLOGIES PRIVATE LIMITED (CIN: U62013TN2023PTC165254), a company incorporated in India with its registered office in Tamil Nadu ("Staminal"). Customer and Staminal are each a "Party" and together the "Parties".
This DPA covers Customer Personal Data processed on the Customer's behalf. Staminal's processing of account administration, billing, fraud-prevention, legal-compliance, and service-security data for its own purposes is described in the Privacy Policy and is outside the processor obligations in this DPA.
1. Definitions
In this DPA:
- "Applicable Data Protection Law" means privacy, data protection, and security law applicable to the processing covered by this DPA, including the Digital Personal Data Protection Act, 2023 and rules brought into force under it.
- "Customer Personal Data" means Personal Data submitted to, received by, stored in, or otherwise processed through the Service by or for the Customer, excluding data Staminal processes for its own independent purposes.
- "Data Fiduciary", "Data Principal", "Data Processor", "Personal Data", and "Processing" have the meanings given by Applicable Data Protection Law. "Controller", "Data Subject", and "Processor" have the corresponding meanings under other applicable privacy laws.
- "Personal Data Breach" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Staminal.
- "Service" means LeadCat CRM and related support, integration, hosting, and processing services supplied under the Main Agreement.
- "Subprocessor" means a third party engaged by Staminal to process Customer Personal Data on the Customer's behalf in providing the Service.
2. Scope, Roles, and Customer Instructions
- Customer appoints Staminal to process Customer Personal Data only to provide, secure, support, maintain, back up, and improve the reliability of the Service; operate Customer-enabled integrations; comply with the Customer's documented instructions; and meet legal obligations applicable to Staminal.
- The Main Agreement, the Customer's configuration and use of the Service, support requests made by authorized Customer users, and Schedule 1 are the Customer's documented instructions. Additional instructions must be lawful, technically feasible, and agreed in writing. Staminal may charge reasonable costs for material work outside the Service.
- Staminal will notify the Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law. Staminal may suspend the affected processing while the Parties resolve the concern.
- If law requires Staminal to process Customer Personal Data outside the Customer's instructions, Staminal will inform the Customer before processing unless the law prohibits that notice.
3. Customer Responsibilities
Customer will:
- Collect and use Customer Personal Data lawfully and provide all notices, consents, and choices required for lead capture, follow-up, marketing, and connected-channel use.
- Ensure its instructions, communication practices, retention choices, imports, and use of the Service comply with Applicable Data Protection Law and relevant platform terms.
- Limit Customer Personal Data to what is relevant and necessary, maintain reasonable accuracy, and avoid uploading prohibited or unlawfully obtained data.
- Not intentionally submit payment-card credentials, authentication secrets, government identity documents, biometric data, health data, children's data, or similarly high-risk data unless the Parties first agree in writing on the use case and additional safeguards.
- Control user access, remove former staff promptly, protect account credentials, and ensure each connected social media, messaging, or business account is authorized.
- Act as the primary contact for Data Principals and determine whether a rights request is valid, subject to Staminal's assistance under Section 7.
4. Staminal Processing Obligations
Staminal will:
- Process Customer Personal Data only as described in this DPA and the Main Agreement.
- Ensure personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where needed for their duties.
- Maintain the technical and organizational safeguards described in Schedule 2, taking into account the nature, scope, context, purposes, and risk of the processing.
- Not sell Customer Personal Data or use it for Staminal's unrelated advertising.
- Not combine Customer Personal Data across unrelated Customer workspaces to expose one Customer's lead data to another Customer.
5. Confidentiality and Access
Staminal will restrict access to Customer Personal Data to personnel and subprocessors that need access to provide or secure the Service. Access will be subject to confidentiality, authentication, authorization, and logging controls appropriate to the role. Support access must be limited to an identified operational or security need.
6. Security and Personal Data Breaches
- Staminal will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, loss, or destruction. The current baseline measures are in Schedule 2.
- Staminal will notify the Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the Customer's registered owner or security contact and, as information becomes available, will describe the known nature of the incident, affected data, likely consequences, containment or remediation, and a contact for follow-up.
- Staminal will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and will provide reasonable cooperation for the Customer's legally required assessment or notification.
- Customer remains responsible for notices to Data Principals and regulators unless Applicable Data Protection Law requires Staminal to notify them directly. A breach notice is not an admission of fault or liability.
7. Data Principal Requests and Compliance Assistance
- Taking into account the nature of the processing, Staminal will provide reasonable technical and organizational assistance so the Customer can respond to lawful requests for access, information, correction, completion, updating, erasure, or grievance redressal.
- If Staminal receives a request relating primarily to Customer Personal Data, Staminal may direct the requester to the Customer and notify the Customer where legally permitted. Staminal will not independently decide the request unless required by law.
- Staminal will provide reasonable information available to it for a Customer's legally required data-protection assessment, regulator inquiry, or consultation relating to the Service.
- Assistance beyond standard Service functionality may be subject to reasonable fees when permitted by law, particularly where a request is repetitive, unusually broad, or requires custom development.
8. Subprocessors
- Customer gives Staminal general authorization to use the Subprocessors listed in Schedule 3 for the stated purposes.
- Staminal will impose written data-protection and confidentiality obligations on each Subprocessor that are appropriate to the services it performs. Staminal remains responsible for the Subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.
- Staminal will provide notice through the Service, by email, or on this page before a new material Subprocessor begins processing Customer Personal Data. Customer may object on reasonable data-protection grounds by emailing director@staminal.in within 15 days after the notice.
- The Parties will work in good faith to address a reasonable objection. If no reasonable alternative is available, either Party may terminate the affected feature or Service under the Main Agreement. An objection does not remove payment obligations accrued before termination.
9. Customer-Directed Third-Party Integrations
The Customer may direct the Service to exchange data with third-party platforms such as Meta, Instagram, Facebook, WhatsApp, YouTube, Telegram, or other Customer-selected services. Those providers may act as independent Data Fiduciaries or Controllers under their own terms, rather than as Staminal's Subprocessors. Customer authorizes the requested exchange and is responsible for the third-party account, permissions, lawful use, and provider terms. Staminal is responsible for securely implementing its side of the integration.
10. International Processing and Transfers
- Customer authorizes Staminal and the listed Subprocessors to process Customer Personal Data in the locations shown in Schedule 3, subject to Applicable Data Protection Law.
- Staminal will not transfer Customer Personal Data to a country or territory prohibited by applicable Indian law. If another applicable law requires a recognized transfer mechanism or additional contract, the Parties will reasonably cooperate to put it in place before the restricted transfer.
- Where multiple laws apply, Staminal will follow the higher protection or restriction to the extent the obligations are compatible and applicable to its role.
11. Return, Retention, and Deletion
- During an active subscription, Customer may access and export available Customer Personal Data through the Service's ordinary functionality.
- Upon a verified deletion request or termination of the Service, Staminal will delete or return Customer Personal Data within the period agreed in the Main Agreement or, where no period is stated, ordinarily within 30 days after the request is verified and any required account-closure steps are complete.
- Deleted data may remain in access-controlled backups until normal backup rotation removes it. Backup data will not be used for ordinary Service operations and, if restored, will remain subject to the applicable deletion record.
- Staminal may retain selected records where required by law or reasonably necessary for a legal hold, fraud or security investigation, payment dispute, or establishment, exercise, or defence of legal claims. Retained data will be minimized, access-restricted, and used only for that purpose.
- Operational retention periods and the verified deletion process are further described in the Privacy Policy and Data Deletion Instructions.
12. Information and Audit Rights
- On reasonable written request, Staminal will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policy summaries, security descriptions, and available independent assessment material.
- If that information is insufficient for a requirement under Applicable Data Protection Law, Customer may request an audit no more than once in any 12-month period, except after a Personal Data Breach or where a regulator requires otherwise.
- An audit must be conducted by an independent qualified auditor under confidentiality obligations, on at least 30 days' notice, during normal business hours, without disrupting the Service or accessing another customer's data, source code, vulnerability details, or Staminal secrets. Customer bears its audit costs unless the audit identifies a material breach of this DPA by Staminal.
13. Term and Legal Effect
- This DPA starts when the Customer accepts or enters into the Main Agreement and continues while Staminal processes Customer Personal Data on the Customer's behalf. Electronic acceptance may be evidenced by the signer, Customer workspace, exact document version and hash, acceptance wording, authority confirmation, timestamp, and limited request metadata.
- If this DPA conflicts with the Main Agreement on processing Customer Personal Data, this DPA controls to the extent of that conflict. The Main Agreement otherwise remains in effect, including its commercial terms, disclaimers, and limitations of liability.
- This DPA does not reduce any non-waivable rights or obligations under Applicable Data Protection Law.
- Unless the Main Agreement states otherwise, this DPA is governed by the laws of India and disputes are subject to the competent courts in Chennai, Tamil Nadu.
Schedule 1 — Processing Details
| Item | Details |
|---|---|
| Subject matter | Providing a tenant-isolated CRM for capturing, organizing, assigning, classifying, reporting, and following up on business enquiries and leads. |
| Duration | For the term of the Main Agreement and the limited deletion, backup-rotation, and legally required retention periods described in this DPA. |
| Nature of processing | Collection or receipt, recording, organization, storage, retrieval, consultation, classification, deduplication, assignment, display, transmission at Customer direction, backup, redaction, export, and deletion. |
| Purposes | Lead capture and management, customer follow-up, connected-channel operation, reporting, Customer-authorized AI assistance, notifications, technical support, security, reliability, and compliance with Customer instructions. |
| Data Principals / Data Subjects | Customer owners, managers, staff, authorized users, prospective customers, leads, customers, social-media users, message or comment senders, and other individuals whose enquiries the Customer lawfully manages. |
| Personal Data categories | Names, business contact details, phone numbers, email addresses, social handles and identifiers, messages and comments, page/account metadata, timestamps, source, product or service interest, location, budget range, lead status, priority, notes, follow-up details, staff assignment, attachments, integration metadata, user roles, and relevant access or audit events. |
| High-risk data | Not intentionally required by the Service. Customer must not submit the high-risk categories identified in Section 3 unless separately agreed in writing with appropriate safeguards. |
| Frequency | Continuous or event-driven while the Customer uses the Service and its enabled integrations. |
Schedule 2 — Technical and Organizational Measures
Staminal's baseline controls include:
- Logical tenant separation and tenant-scoped data-access boundaries for Customer-owned CRM records.
- Role-based access controls for owners, managers, staff, and restricted platform administration.
- HTTPS/TLS for public Service traffic and private network controls for production data services where supported by the deployment.
- Strong password hashing, server-side authentication controls, expiring security credentials, and restricted secret handling.
- Encryption of stored integration access tokens, with encryption-key material separated from the encrypted database values.
- Least-privilege service credentials, restricted production access, and separation of application, database, queue, and media-storage responsibilities.
- Structured and redacted application logging designed to avoid access tokens, passwords, and unnecessary request or job payloads.
- Audit records for relevant access, administrative, deletion, integration, and background processing events.
- Access-controlled backups, restore procedures, retention controls, and verified deletion workflows.
- Security incident triage, containment, investigation, remediation, and notification procedures.
- Dependency maintenance, production configuration checks, health monitoring, and reasonable patch and vulnerability-management practices.
Staminal may update these measures as technology and risk evolve, provided the overall protection of Customer Personal Data is not materially reduced.
Schedule 3 — Authorized Subprocessors
The following providers are authorized to process Customer Personal Data only for the described Service component. A provider marked "when enabled" receives data only when the corresponding feature is configured for the deployment or Customer.
| Provider | Purpose and data | Processing location | Status |
|---|---|---|---|
| Hetzner Online GmbH | Cloud compute, network, application hosting, database, queue, and backup infrastructure; Customer Personal Data required to operate the hosted Service. | European Union, according to the selected hosting region. | Core hosting provider |
| Resend, Inc. | Transactional email, OTP, invitation, password, and Service notification delivery; recipient name, email address, delivery metadata, and applicable message content. | United States and locations used by its delivery infrastructure. | When enabled |
| OpenAI, L.L.C. | Customer-authorized AI classification and suggested-reply assistance; selected enquiry or lead text and the minimum related context required for the enabled feature. | United States and other locations permitted under the provider terms. | When enabled |
Payment providers processing Staminal's subscription and billing records for their own regulated purposes are addressed in the Privacy Policy rather than this processor list. A separate object-storage provider will be added to this Schedule before Staminal enables that provider to store Customer lead attachments in production.