Data Processing Addendum
Last updated: August 16, 2026
This Data Processing Addendum (DPA) applies when Dureach processes personal data on behalf of a customer under the Customer SaaS Terms, an order form, or another agreement that incorporates this DPA.
1. Roles
For customer personal data submitted to Dureach for SaaS, AI workflow, API, enrichment, support, or workspace processing, the customer is the controller or business, and Dureach is the processor, service provider, or contractor as those terms are used under applicable privacy laws.
For Dureach website operations, account administration, billing, security, product analytics, and business-contact data products, Dureach may act as an independent controller as described in the Privacy Policy.
2. Processing Instructions
Dureach will process customer personal data only to provide, secure, support, maintain, and improve the services; comply with documented customer instructions; enforce agreements; prevent abuse; and comply with law.
The agreement, product settings, customer submissions, support requests, and authorized user actions are the customer’s documented instructions.
3. Processing Details
| Item | Description |
|---|---|
| Subject matter | Provision of Dureach SaaS, AI workflow, API, enrichment, data, support, and related services. |
| Duration | The term of the customer agreement plus any retention period required for deletion, backup, dispute, audit, security, or legal purposes. |
| Nature and purpose | Hosting, storage, analysis, generation, enrichment, workflow execution, support, security, troubleshooting, billing, and service administration. |
| Data subjects | Customer users, administrators, prospects, business contacts, website visitors, CRM contacts, vendors, partners, and other individuals whose data a customer submits or authorizes for processing. |
| Data categories | Business contact details, account details, workspace activity, communications, customer content, CRM records, campaign inputs, approval records, API logs, and support metadata. |
| Sensitive data | Not permitted unless a signed agreement expressly authorizes it. |
4. Customer Responsibilities
The customer is responsible for:
- Providing lawful instructions and having a valid legal basis for processing.
- Giving required notices and obtaining required consents.
- Configuring access controls, roles, integrations, exports, and retention settings.
- Responding to privacy requests where the customer controls the data.
- Avoiding submission of prohibited or sensitive data unless a signed agreement allows it.
5. Confidentiality
Dureach will ensure personnel authorized to process customer personal data are bound by confidentiality obligations or professional duties of confidentiality.
6. Security Measures
Dureach will maintain administrative, technical, and organizational measures designed to protect customer personal data against unauthorized access, loss, misuse, alteration, and disclosure.
Measures may include access controls, encryption in transit, encryption at rest where supported, logging, vulnerability management, backup controls, incident response procedures, personnel confidentiality, vendor review, and least-privilege access.
7. Subprocessors
The customer authorizes Dureach to use subprocessors to provide the services. Dureach remains responsible for subprocessors’ processing of customer personal data under this DPA and will require subprocessors to protect customer personal data using terms materially consistent with this DPA.
Dureach will provide information about subprocessors upon request or through a public subprocessor page if available. Customers may object to a new subprocessor on reasonable data-protection grounds by contacting [email protected].
8. Privacy Request Assistance
Taking into account the nature of processing and information available to Dureach, Dureach will provide reasonable assistance for customer obligations related to access, deletion, correction, restriction, portability, objection, opt-out, and similar data-subject requests.
If Dureach receives a request relating to customer personal data, Dureach may redirect the requester to the customer unless applicable law requires a different response.
9. Security Incidents
Dureach will notify the customer without undue delay after confirming a security incident that affects customer personal data. Notice may include available details about the incident, affected data, mitigation steps, and contact channels.
Dureach’s notice is not an admission of fault or liability.
10. International Transfers
Dureach may process customer personal data in the United States and other countries where Dureach, its affiliates, subprocessors, or service providers operate.
Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, the parties will use appropriate transfer safeguards such as the applicable standard contractual clauses, UK addendum, Swiss requirements, or another lawful transfer mechanism.
11. Audits and Information
Dureach will make reasonable information available to demonstrate compliance with this DPA. Where required by law and not satisfied by available information, the customer may request an audit using a mutually agreed scope, timing, confidentiality restrictions, and method that avoids disruption and security risk.
12. Deletion or Return
Upon termination or written request, Dureach will delete or return customer personal data according to the agreement, product capabilities, retention settings, backup cycles, and legal requirements. Dureach may retain limited copies where required for legal, security, fraud-prevention, accounting, dispute, or compliance purposes.
13. U.S. State Privacy Terms
Where U.S. state privacy laws apply, Dureach will process customer personal data as a service provider, processor, or contractor as applicable. Dureach will not sell customer personal data or share it for cross-context behavioral advertising when processing it under customer instructions.
Dureach will not retain, use, or disclose customer personal data outside the business purposes described in the agreement, except as permitted by applicable law.
14. Contact
For DPA questions, contact [email protected].