Data Processing Addendum

Last updated: June 11, 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service or other written agreement (the "Agreement") between We Ship CRMs LLC, a Delaware limited liability company doing business as ShipCRM ("Company," "Processor," or "Service Provider"), and the customer identified in the Agreement ("Customer," "Controller," or "Business"). This DPA applies to the extent the Company Processes Personal Data on behalf of the Customer in connection with the Services. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls. All capitalized terms not defined here have the meanings given in the Agreement.

1. Definitions

1.1 "Applicable Data Protection Laws" means all data-protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and UK Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the India Digital Personal Data Protection Act 2023 ("DPDPA").

1.2 "Personal Data" means any information relating to an identified or identifiable natural person, or that constitutes "personal information" or "personal data" under Applicable Data Protection Laws, that is contained within Customer Data and Processed by the Company on the Customer's behalf.

1.3 "Processing" (and "Process") means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure, transmission, or deletion.

1.4 "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

1.5 "Sub-processor" means any third party engaged by the Company to Process Personal Data on the Company's behalf in connection with the Services.

1.6 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by the Company or its Sub-processors.

1.7 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Decision 2021/914, and, for UK transfers, the UK International Data Transfer Addendum issued by the UK Information Commissioner.

The terms "Controller," "Processor," "Business," and "Service Provider" have the meanings given under Applicable Data Protection Laws.

2. Roles and Scope of Processing

2.1 As between the parties, the Customer is the Controller (or Business) and the Company is the Processor (or Service Provider) with respect to Personal Data. Where the Customer is itself a processor acting on behalf of a third-party controller, the Company acts as a sub-processor and the Customer warrants it has authority to engage the Company on such terms.

2.2 The Company shall Process Personal Data only (a) to provide and support the Services under the Agreement, (b) in accordance with the Customer's documented instructions (including this DPA and the Customer's configuration and use of the Services), and (c) as required by applicable law, in which case the Company will, where legally permitted, inform the Customer of that legal requirement before Processing.

2.3 The subject matter, nature, purpose, and duration of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.

2.4 The Company will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws. The Company has no obligation to assess the legality of the Customer's instructions.

3. Company Obligations

3.1 Confidentiality. The Company shall ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and Process Personal Data only as instructed.

3.2 Security. The Company shall implement and maintain the technical and organizational measures set out in Annex 2, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of Processing.

3.3 Assistance. Taking into account the nature of the Processing, the Company shall provide reasonable assistance to the Customer, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Customer's obligations to (a) respond to Data Subject requests, (b) ensure security of Processing, (c) notify Security Incidents and conduct data-protection impact assessments, and (d) consult with supervisory authorities, in each case to the extent the Customer does not have independent access to the relevant information through the Services.

4. Sub-processors

4.1 The Customer provides a general authorization for the Company to engage Sub-processors to Process Personal Data, subject to this Section. A current list of Sub-processors is set out in Annex 3 or otherwise made available to the Customer.

4.2 The Company shall impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains liable to the Customer for the performance of each Sub-processor's obligations.

4.3 The Company shall give the Customer prior notice of the addition or replacement of any Sub-processor (which may be given by updating Annex 3 or by email or in-product notice). The Customer may object on reasonable data-protection grounds within fifteen (15) days; if the parties cannot resolve the objection, the Customer may terminate the affected Services as its sole remedy.

5. Data Subject Rights

5.1 The Services provide the Customer with controls to access, correct, delete, restrict, export, or otherwise manage Personal Data, enabling the Customer to fulfill Data Subject requests itself.

5.2 If the Company receives a request from a Data Subject relating to Personal Data Processed for the Customer, the Company shall, unless legally prohibited, promptly forward the request to the Customer and shall not respond directly except on the Customer's documented instructions or as required by law.

6. Security Incidents

6.1 The Company shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting the Customer's Personal Data.

6.2 The notification shall describe, to the extent known, the nature of the Security Incident, the categories and approximate volume of Personal Data and Data Subjects affected, the likely consequences, and the measures taken or proposed. The Company shall take reasonable steps to mitigate and remediate the Security Incident. The Company's notification is not an acknowledgment of fault or liability.

7. Audits and Information

7.1 The Company shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by providing then-current third-party audit reports or certifications (e.g., SOC 2 Type II or ISO 27001), where available.

7.2 Where such reports are insufficient to demonstrate compliance, the Customer (or an independent auditor bound by confidentiality and approved by the Company) may, no more than once per twelve (12) months and on at least thirty (30) days' prior written notice, conduct an audit during normal business hours, in a manner that does not unreasonably disrupt the Company's operations or compromise other customers' data. Each party bears its own audit costs.

8. International Data Transfers

8.1 The Customer authorizes the Company and its Sub-processors to transfer Personal Data outside the country of origin as necessary to provide the Services, subject to appropriate safeguards under Applicable Data Protection Laws.

8.2 Where Personal Data subject to the GDPR or UK GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses (and, for the UK, the UK International Data Transfer Addendum) are incorporated into this DPA by reference and apply to that transfer. For the EU SCCs: Module Two (Controller to Processor) applies where the Customer is a controller, and Module Three (Processor to Processor) applies where the Customer is a processor; the Customer is the "data exporter" and the Company is the "data importer"; the optional docking clause applies; the governing law and forum are those of Ireland (or as the SCCs require); and Annexes 1 and 2 of this DPA populate the corresponding annexes of the SCCs.

9. CCPA / CPRA Service-Provider Terms

9.1 To the extent the Company Processes Personal Data that is "personal information" under the CCPA/CPRA, the Company acts as a Service Provider and shall: (a) not sell or share such personal information; (b) not retain, use, or disclose it except for the limited and specified business purpose of providing the Services or as otherwise permitted by the CCPA/CPRA; (c) not retain, use, or disclose it outside the direct business relationship between the parties; and (d) not combine it with personal information obtained from other sources, except as permitted by the CCPA/CPRA.

9.2 The Company certifies that it understands and will comply with the restrictions in Section 9.1. The Company shall notify the Customer if it determines it can no longer meet its obligations as a Service Provider.

10. Return and Deletion of Personal Data

10.1 Upon termination or expiration of the Agreement, the Company shall, at the Customer's option, return and/or delete Personal Data in accordance with the post-termination data-retrieval and purge provisions of the Agreement (a minimum thirty (30)-day export grace period, after which Personal Data may be deleted from active production systems).

10.2 The Company may retain Personal Data to the extent required by applicable law or held in routine backups, in which case this DPA continues to apply to such retained Personal Data until deletion.

11. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a party's liability means the aggregate liability of that party under the Agreement and this DPA combined.

12. Term, Conflict, and Governing Law

12.1 This DPA takes effect on the effective date of the Agreement and continues until the Company ceases to Process Personal Data on the Customer's behalf.

12.2 Except as expressly modified here, the Agreement remains in full force. With respect to the Processing of Personal Data, this DPA controls over any conflicting term of the Agreement; the SCCs control over this DPA to the extent of any conflict regarding transfers governed by the GDPR or UK GDPR.

12.3 This DPA is governed by the law and jurisdiction stated in the Agreement, except where Applicable Data Protection Laws (or the SCCs) require otherwise.

13. Miscellaneous

If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in effect. This DPA may be executed in counterparts and by electronic signature.

Annex 1 — Details of Processing

Data Exporter / Controller: The Customer identified in the Agreement. Contact details as provided in the Customer's account.

Data Importer / Processor: We Ship CRMs LLC (dba ShipCRM), 8 The Green, Suite B, Dover, DE 19901. Contact: support@shipcrm.ai.

Subject matter: Provision of the cloud-based CRM and AI sales-intelligence Services under the Agreement.

Duration: For the term of the Agreement plus the post-termination retention period described in Section 10.

Nature and purpose: Hosting, storage, organization, analysis, and processing of Customer Data to provide, maintain, secure, and support the Services, including AI-assisted features.

Categories of Data Subjects: The Customer's contacts, leads, prospects, customers, and the Customer's authorized users (Customer to specify/confirm).

Categories of Personal Data: Names, business contact details (email, phone, address), job titles, company affiliations, communication records, and other data the Customer chooses to upload (Customer to specify/confirm). The Services are not intended for special-category or sensitive Personal Data; the Customer should not upload such data.

Special categories of data: None intended. If processed, only as expressly agreed in writing.

Frequency of transfer: Continuous, for the duration of the Services.

Competent supervisory authority (SCCs): The supervisory authority of the EU member state of the data exporter, or as determined under Clause 13 of the SCCs.

Annex 2 — Technical and Organizational Security Measures

The Company maintains the following measures, which it may update provided the level of security is not materially diminished:

  • Access control: Role-based access controls, unique user credentials, least-privilege access, and revocation upon role change or departure.
  • Authentication: Enforced password policies and support for multi-factor authentication for administrative access.
  • Encryption: Encryption of Personal Data in transit (TLS) and at rest using industry-standard algorithms.
  • Network and infrastructure security: Firewalls, network segmentation, and use of reputable cloud hosting providers with physical-security controls.
  • Logging and monitoring: Audit logging of access and administrative actions, and monitoring for anomalous activity.
  • Resilience and backups: Regular backups, and procedures designed to restore availability and access to Personal Data in a timely manner after an incident.
  • Vulnerability management: Patching, periodic vulnerability scanning, and remediation processes.
  • Personnel: Confidentiality obligations and security-awareness practices for personnel with access to Personal Data.
  • Vendor management: Diligence and contractual data-protection obligations for Sub-processors.
  • Incident response: A documented Security Incident response process, including notification under Section 6.

Annex 3 — Approved Sub-processors

As of the effective date, the Company engages the following Sub-processors. The Company will update this list and provide notice of changes under Section 4.3.

  • Cloud hosting and database: Fly.io, Inc. (United States; primary region Dallas, Texas) — cloud hosting, application infrastructure, and the PostgreSQL database in which Customer Data is stored.
  • AI model provider: Anthropic, PBC (United States) — large-language-model provider (Claude) powering the AI features; processes prompts and inputs to generate AI Outputs. Anthropic does not train its models on data submitted through its commercial API, consistent with Section 12.2 of the Terms.
  • Email delivery: Mailjet (a Sinch company; European Union) — delivery of transactional and system emails.
  • Payments and billing: Polar Software, Inc. (United States; polar.sh) — subscription billing and payment processing as merchant of record (which in turn uses Stripe as its underlying payment processor); processes limited account and billing Personal Data.
  • Translation: Microsoft Corporation — Azure AI Translator (United States/European Union) — machine translation of text within the Services, where the feature is used.
  • Authentication and Google Workspace integration: Google LLC (United States) — sign-in/OAuth and, where a Customer connects its Google account, Gmail and Google Calendar integration to send and read email and sync calendar events on the Customer's behalf.

Signatures

Agreed and accepted by the parties as of the effective date of the Agreement.

Customer (Controller / Business):

By: ______________________________   Name: ____________________   Title: ____________   Date: __________

We Ship CRMs LLC (dba ShipCRM) (Processor / Service Provider):

By: ______________________________   Name: ____________________   Title: ____________   Date: __________