Back to home

Updated: September 21, 2026

Data Processing Agreement (DPA)

This data processing agreement under Art. 28 GDPR applies between the customer using Coldfire CRM ("Controller") and TE Software Solutions LLC, St. Petersburg str. N 1, Tbilisi, Georgia ("Processor").

It forms part of the Terms of Service and is concluded when a workspace is registered. We provide a countersigned version with your company details on request.

§ 1 Subject Matter and Duration

The Processor processes personal data on behalf of the Controller solely to provide Coldfire CRM in accordance with the Terms of Service. Annex 1 describes the nature, purpose, categories of data and data subjects.

This agreement runs for the term of the service relationship plus the period until the data has been fully deleted under § 11.

§ 2 Instructions of the Controller

The Processor processes the data only on documented instructions from the Controller. The Terms of Service, this agreement and the Controller's configuration of the workspace constitute the relevant instructions. Further instructions are given in text form.

If the Processor considers an instruction unlawful, it informs the Controller without undue delay and may suspend execution until the instruction is confirmed.

The Controller is responsible for the lawfulness of the processing, in particular for the legal basis for contacting leads, for any consent required for call recording and for informing data subjects.

§ 3 Duties of the Processor

  • Processing solely for the agreed purposes and not for its own purposes; in particular, customer data is not used to train AI models
  • Commitment to confidentiality of all persons involved in the processing
  • Implementation and maintenance of the technical and organisational measures in Annex 2
  • Assistance to the Controller with data subject requests, data protection impact assessments and consultations with the supervisory authority, as far as the processing on its behalf is concerned
  • Keeping a record of the processing activities carried out on behalf of the Controller

§ 4 Place of Processing

The application, its databases and backups are operated in data centres in Germany. Call recordings and files are stored in an EU region. Processing outside the EU or EEA takes place only through the subprocessors named in Annex 3 and only under the conditions of § 6.

§ 5 Subprocessors

The Controller grants general authorisation to engage the subprocessors named in Annex 3. The Processor contractually binds each subprocessor to a level of data protection equivalent to this agreement and remains responsible for its performance.

The Processor announces the intended addition or replacement of a subprocessor at least 14 days in advance by email. The Controller may object within that period on reasonable data-protection grounds. If no mutually acceptable solution is found, the Controller may terminate the service relationship with effect from the change.

§ 6 Transfers to Third Countries

Personal data is transferred to a third country only where the conditions of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision (including the EU-U.S. Data Privacy Framework) or the EU Standard Contractual Clauses. Annex 4 applies to the transfer from the Controller to the Processor, which is established in Georgia.

§ 7 Technical and Organisational Measures

The Processor takes the measures described in Annex 2. It may adapt them to technical progress as long as the level of protection is not reduced.

§ 8 Personal Data Breaches

The Processor notifies the Controller of personal data breaches affecting the Controller's data without undue delay after becoming aware of them, by email to the owners and administrators of the workspace. The notification contains the information available under Art. 33(3) GDPR; missing information is provided subsequently.

§ 9 Rights of Data Subjects

If a data subject contacts the Processor directly, the Processor forwards the request to the Controller where it can be attributed. The Controller can rectify, export and delete data in the application itself; beyond that, the Processor assists on request to privacy@coldfire-crm.com.

§ 10 Evidence and Audits

On request the Processor provides the Controller with the information necessary to demonstrate compliance with this agreement. Audits are carried out primarily through information and existing evidence. On-site audits are possible with reasonable notice, during normal business hours, at most once a year and without disrupting operations, where there is a justified reason; the Controller bears the costs.

§ 11 Deletion and Return

During the term the Controller can export its data in the application. After the service relationship has ended, the workspace data is kept for 60 days for reactivation or export (with an email reminder 7 days before deletion) and then deleted; backup copies are overwritten in the regular backup cycle. Statutory retention obligations of the Processor remain unaffected.

§ 12 Liability

Liability is governed by the Terms of Service. Art. 82 GDPR remains unaffected.

§ 13 Final Provisions

In the event of conflict between this agreement and the Terms of Service, this agreement prevails on data protection matters. If a provision is invalid, the remainder of the agreement stays in effect. We announce changes with 30 days' notice.

Annex 1 – Description of the Processing

Purpose

Provision of a CRM for telephone sales: management of leads and contacts, telephony, call recording, transcription, AI call documentation, email, appointments, tasks, workflows, reporting and API access.

Data subjects

The Controller's leads, prospects, customers and their contact persons; the Controller's employees and other users; participants in phone calls; senders and recipients of emails in connected mailboxes.

Categories of data

Depending on the Controller's use:

  • Master and contact data (name, company, position, address, phone numbers, email addresses)
  • Communication data (call metadata, call recordings, transcripts, AI summaries, emails including attachments, notes)
  • Sales data (status, appointments, tasks, custom fields, lists)
  • Usage and log data of users (sign-ins, IP addresses, audit log)

Special categories

The processing of special categories of personal data is not intended. The Controller ensures that such data does not enter the Service without a separate legal basis.

Annex 2 – Technical and Organisational Measures

1. Data residency

Application, database and backups operated in German data centres; recordings and files stored in an EU region.

2. Access control

Role and permission concept with fine-grained rights per workspace, hierarchy protection when assigning roles, server-side enforcement of all permissions; administrative access by the Processor only for named persons, on a need-to-know basis and over secured connections.

3. Authentication

State-of-the-art password hashing, optional two-factor authentication by email code, sign-in with Google, session tokens with limited lifetime, rate limiting on sign-in and signup endpoints.

4. Encryption

Transport encryption (TLS) for all connections to the application and between services across public networks; server-side encryption of recordings and files stored in the cloud; encrypted storage of credentials of connected mailboxes and calendars.

5. Tenant separation

Logical separation of all data per workspace, enforced in the application's data access layer; API keys are bound to one workspace and to permission scopes.

6. Logging

Audit log of security-relevant actions in the workspace; central application and infrastructure logs with limited retention.

7. System and application security

Separate development and production environments, changes through version control and review, timely security updates, protection of outgoing webhooks against access to internal networks, signed webhooks.

8. Backup and availability

Daily database backup to a separate location, regularly tested restore, monitoring of availability and error rates.

9. Deletion concept

Deletion of customer data 60 days after the end of the service relationship; backup copies overwritten in the backup cycle; deletion functions for individual records in the application.

10. Organisation

Confidentiality commitment of all staff and contractors, documented security incident procedure, regular review of the measures.

Annex 3 – Subprocessors

The current list is published at https://coldfire-crm.com/en/subprocessors and forms part of this agreement.

Annex 4 – Standard Contractual Clauses

As the Processor is established in a third country, the parties agree on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 (controller to processor), for transfers of personal data from the EU or EEA. The information for Annexes I to III follows from Annexes 1 to 3 of this agreement. The law of the EU member state in which the Controller is established applies; the competent supervisory authority is the authority responsible for the Controller.

© 2026 Coldfire · TE Software Solutions LLC, St. Petersburg str. N 1, Tbilisi, Georgia

COLDFIRE