Legal
Data Processing Agreement
Last updated: 12 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Beagle Software Limited ("Processor", "we") and the customer organisation ("Controller", "you") that uses Beagle CRM. It governs our processing of personal data on your behalf under UK data protection law (the UK GDPR and the Data Protection Act 2018, "Data Protection Law").
1. Roles
For the personal data your organisation loads into Beagle CRM about its own contacts, leads, and customers, you are the Controller and we are the Processor. We process that data only to provide the service and only on your documented instructions, which include the Terms of Service, this DPA, and your use of the product's features.
2. Subject matter and details of processing
- Subject matter: provision of the Beagle CRM service.
- Duration: the term of your subscription, plus the retention period in our Privacy Policy.
- Nature and purpose: storing and processing customer-relationship data so you can manage contacts, leads, invoices, and communications.
- Types of personal data: contact details, business records, correspondence, and any personal data you choose to enter.
- Categories of data subjects: your contacts, leads, customers, and staff users.
3. Our obligations as Processor
We will:
- process personal data only on your documented instructions, including for international transfers, unless required by law (in which case we will tell you, unless the law prohibits it);
- ensure people authorised to process the data are under a duty of confidentiality;
- implement appropriate technical and organisational security measures (Article 32) — see section 5;
- respect the conditions in section 4 for engaging subprocessors;
- assist you, by appropriate measures, to respond to data-subject requests;
- assist you with security, breach notification, and data protection impact assessments (Articles 32–36);
- at your choice, delete or return the personal data at the end of the service, and delete existing copies unless the law requires retention;
- make available the information needed to demonstrate compliance and allow for and contribute to audits, as set out in section 7.
4. Subprocessors
You give general authorisation for us to engage the subprocessors below. Each is bound by data protection terms no less protective than this DPA. We will give you reasonable notice of any intended change so you can object on reasonable grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Stripe | Subscription billing and card processing | UK / EU / US |
| SendGrid (Twilio) | Transactional and campaign email delivery | EU / US |
| Cloudflare | CDN, DNS, and encrypted backup storage (R2) | UK / EU |
| Hosting provider | Application and database hosting | UK / EU |
5. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit, encryption of backups, access controls, authentication (including optional two-factor), tenant isolation, and continuous backup with point-in-time recovery. Measures may evolve, but will not materially reduce the level of protection during your subscription.
6. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification obligations.
7. Audits
On reasonable written request, and no more than once a year (unless required by a regulator or after a breach), we will provide the information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality.
8. International transfers
Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place (such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses).
9. Your responsibilities as Controller
You are responsible for having a lawful basis for the personal data you load into Beagle CRM, for the accuracy of your instructions, and for responding to your own data subjects as the Controller.
10. Contact
To request a countersigned DPA or to raise a data protection matter, email hello@beaglecrm.uk.