This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Service between you ("Customer") and RepHubCRM, LLC ("RepHubCRM"). It applies automatically when you use the Service; no signature is required. In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Information, this DPA controls.
1. Definitions
- "Applicable Privacy Law" means U.S. state privacy laws applicable to the processing under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and comparable laws of other U.S. states.
- "Customer Data" means data Customer uploads to, generates in, or directs RepHubCRM to collect through the Service, including lead and prospect records, message content, and campaign data.
- "Personal Information" means Customer Data that identifies, relates to, or could reasonably be linked with an identified or identifiable individual, as defined under Applicable Privacy Law.
- "Business," "Service Provider," "Sell," "Share," and "Business Purpose" have the meanings given in the CCPA/CPRA.
- "Subprocessor" means a third party engaged by RepHubCRM to process Personal Information on its behalf, as listed at rephubcrm.com/subprocessors.
2. Roles of the Parties
Customer is the Business with respect to Personal Information processed through the Service. RepHubCRM is a Service Provider acting on Customer's documented instructions. Customer determines the purposes and means of processing — which prospects are targeted, what is said to them, and how responses are handled — and is responsible for having a lawful basis for that processing.
Customer's instructions consist of the Terms of Service, this DPA, and Customer's configuration and use of the Service (including territory, industry, targeting criteria, campaign approvals, and integrations Customer connects).
The B2B exemption that previously excluded business contact information from the CCPA expired on January 1, 2023. The parties therefore treat business contact information processed through the Service as Personal Information.
3. Scope of Processing
- Subject matter: provision of the AI-powered B2B sales automation Service.
- Duration: the term of Customer's subscription, plus the retention period in Section 9.
- Nature and purpose: sourcing, enriching, scoring, and storing business lead records; generating, sending, and tracking outreach email; classifying replies; scheduling meetings; and producing analytics for Customer.
- Categories of individuals: Customer's personnel and authorized users; business contacts and decision-makers at prospect organizations located in the United States.
- Categories of Personal Information: name, job title, business email address, business phone number, employer and firmographic data, publicly available professional profile information, message and reply content, engagement events, and meeting details.
- Sensitive Personal Information: the Service is not designed for and must not be used to process sensitive personal information, government identifiers, financial account numbers, health information, or information about minors.
4. Service Provider Obligations (CCPA/CPRA)
RepHubCRM agrees that it shall:
- Not Sell or Share. Not sell or share Personal Information received from Customer, as those terms are defined in the CCPA/CPRA.
- Purpose limitation. Not retain, use, or disclose Personal Information for any purpose other than the Business Purposes specified in Section 3, including not retaining, using, or disclosing it for any commercial purpose other than providing the Service, and not using it outside the direct business relationship between the parties.
- No combining. Not combine Personal Information received from Customer with personal information received from or on behalf of any other person, or collected from its own interactions with individuals, except as permitted by the CCPA/CPRA to perform a Business Purpose.
- Certification. Certify that it understands the restrictions in this Section and will comply with them.
- Notice of inability to comply. Notify Customer promptly, and in any case within five (5) business days, if it determines it can no longer meet its obligations under Applicable Privacy Law, and cease processing or remediate on Customer's instruction.
- Monitoring. Permit Customer to take reasonable and appropriate steps to confirm that RepHubCRM uses Personal Information consistent with Customer's obligations, and to stop and remediate unauthorized use, as provided in Section 8.
- Confidentiality. Ensure that personnel authorized to process Personal Information are bound by an obligation of confidentiality.
AI training. RepHubCRM does not use Customer Data to train its own general-purpose machine learning models, and engages AI Subprocessors under terms that do not permit them to train their models on Customer Data submitted through the Service.
5. Customer Obligations
Customer represents, warrants, and agrees that it shall:
- Have a lawful basis for the collection and processing of Personal Information it uploads to, or directs RepHubCRM to collect through, the Service
- Provide any notice at collection and obtain any consent required by Applicable Privacy Law with respect to individuals whose Personal Information is processed
- Maintain and honor its own privacy policy, opt-out mechanisms, and consumer rights processes
- Use the Service only for lawful B2B outreach in the United States and in compliance with the CAN-SPAM Act and the Acceptable Use Policy
- Not upload sensitive personal information or the categories excluded in Section 3
- Issue instructions to RepHubCRM only through the features of the Service and the mechanisms described in this DPA
6. Subprocessors
Customer provides general authorization for RepHubCRM to engage Subprocessors to process Personal Information. The current list is published at rephubcrm.com/subprocessors.
- RepHubCRM imposes on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA
- RepHubCRM remains responsible to Customer for the performance of each Subprocessor's obligations
- RepHubCRM will update the Subprocessor list before a new Subprocessor begins processing Personal Information, and will notify Customers who have subscribed to notifications
- Customer may object to a new Subprocessor on reasonable data protection grounds within 30 days, with the resolution described on the Subprocessors page
7. Security Measures
RepHubCRM maintains technical and organizational measures appropriate to the nature of the Personal Information processed, including:
- Encryption of data in transit using TLS, and encryption at rest by the database and hosting Subprocessors
- AES-256-GCM encryption of stored credentials and third-party API tokens
- Password hashing using a salted adaptive hash function; RepHubCRM never stores plaintext passwords
- Row-level access controls scoping Customer Data to the owning account
- Role-based access for personnel, granted on a least-privilege basis
- Signed and authenticated webhooks for inbound third-party events
- Audit logging of automated agent actions taken on Customer Data
- Rate limiting and abuse controls on authentication and public endpoints
RepHubCRM may update these measures over time provided the level of protection is not materially reduced.
8. Assistance, Audits, and Consumer Requests
8.1 Consumer Rights Requests
If RepHubCRM receives a request from an individual to exercise rights under Applicable Privacy Law with respect to Customer Data, RepHubCRM will not respond substantively (except to acknowledge and redirect) and will forward the request to Customer without undue delay. RepHubCRM will provide reasonable assistance, taking into account the nature of the processing, to enable Customer to respond within the time limits imposed by Applicable Privacy Law — including deletion, correction, and access with respect to Personal Information held in the Service.
8.2 Audits
On written request, no more than once in any twelve (12) month period unless required by a regulator or following a Security Incident, RepHubCRM will provide Customer with a written description of its data protection practices sufficient to allow Customer to verify compliance with this DPA, and will respond to a reasonable security questionnaire. On-site audits are not offered.
9. Retention, Return, and Deletion
- RepHubCRM retains Personal Information for as long as necessary to provide the Service to Customer
- On termination, Customer may export Customer Data for thirty (30) days, as provided in Section 17 of the Terms of Service
- After that period, RepHubCRM will delete Customer Data within a further ninety (90) days, except where retention is required by law or is contained in routine backups, which are deleted on their ordinary cycle and remain subject to this DPA until then
- RepHubCRM will delete or return specific Personal Information on Customer's written instruction, subject to the same exceptions
10. Security Incidents
RepHubCRM will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information processed under this DPA (a "Security Incident"). The notice will describe, to the extent known, the nature of the incident, the categories and approximate volume of Personal Information affected, the likely consequences, and the measures taken or proposed. RepHubCRM will provide reasonable cooperation to support Customer's own notification obligations. Notice of a Security Incident is not an acknowledgment of fault or liability.
11. Geographic Scope
The Service is offered only to U.S. businesses for outreach to U.S. business contacts, and Personal Information is processed in the United States. RepHubCRM does not offer the Service to individuals in the European Economic Area, the United Kingdom, or Switzerland, and this DPA does not incorporate the EU Standard Contractual Clauses. Customer must not use the Service to process personal data subject to the GDPR or the UK GDPR.
12. Liability and Term
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service. This DPA takes effect when Customer accepts the Terms of Service and continues until RepHubCRM has deleted all Personal Information in accordance with Section 9.