Effective 25 May 2026
Data Processing Agreement
GDPR Article 28 agreement between you (Controller) and Roveva Solutions (Processor).
This Data Processing Agreement ("DPA") forms part of the CRM Brain Terms of Service and is entered into between the customer entity that has accepted those terms ("Controller") and Roveva Solutions, Sandstücken 9, 25421 Pinneberg, Germany ("Processor"). Where the Processor processes personal data on behalf of the Controller in connection with the CRM Brain service, the parties agree to the following terms.
1. Parties
Data Controller: The recruiting agency or other business entity that has subscribed to the CRM Brain service and whose CRM data is processed by the Service.
Data Processor: Roveva Solutions (sole trader, Anthony Avevor), Sandstücken 9, 25421 Pinneberg, Germany. Contact: hello@crm-brain.com.
2. Subject Matter and Duration
The Processor provides the CRM Brain service, which reads and analyses pipeline data from the Controller's CRM account in order to generate lead scores, pipeline insights, alerts, and daily digests. Processing takes place for the duration of the Controller's active subscription. On expiry or termination of the subscription, the Processor will delete or return personal data as described in Section 12.
3. Nature and Purpose of Processing
Processing activities include:
- Reading contact, deal, and activity records from the Controller's CRM via OAuth.
- Storing a synchronised copy of that data in a Supabase database instance located in the EU (AWS eu-central-1, Frankfurt).
- Sending subsets of deal and contact data to the Claude API (Anthropic) to generate scores, recommendations, and pipeline health assessments.
- Surfacing the resulting insights to authorised users of the Controller's CRM Brain account.
The Processor does not use the Controller's data for any purpose beyond operating and improving the Service for that Controller.
4. Types of Personal Data Processed
- Contact data: names, email addresses, phone numbers, LinkedIn profile URLs, and job titles of candidates and client contacts.
- Deal data: deal names, monetary values, pipeline stages, and deal notes entered in the CRM.
- Activity logs: call notes, email thread summaries, and meeting records associated with CRM deals.
- User account data: names and email addresses of the Controller's authorised users (recruiters, managers).
5. Categories of Data Subjects
- Job candidates whose profiles are held in the Controller's CRM.
- Client contacts (hiring managers, HR leads) at the Controller's client organisations.
- The Controller's own employees and contractors who use CRM Brain.
6. Processor Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by EU or Member State law applicable to the Processor.
- Ensure that persons authorised to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organisational measures described in Section 10 of this DPA.
- Assist the Controller in responding to requests from data subjects exercising their rights under Articles 15 to 21 GDPR, taking into account the nature of the processing.
- Assist the Controller in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).
- Delete or return all personal data to the Controller on termination of the DPA, and delete existing copies unless Union or Member State law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality obligations.
- Notify the Controller promptly before engaging a new sub-processor or making material changes to existing sub-processor arrangements.
7. Controller Instructions
The Controller's primary instruction is to operate the CRM Brain service as described in the Terms of Service and this DPA. The Controller may issue additional documented instructions by emailing hello@crm-brain.com. If the Processor considers that an instruction would infringe GDPR or other applicable data protection law, the Processor will promptly inform the Controller.
8. Sub-Processors
The Controller grants general written authorisation for the Processor to engage the sub-processors listed below. The Processor will inform the Controller of any intended changes and give the Controller at least 14 days to object before the change takes effect. Each sub-processor is bound by a data processing agreement with the Processor providing at least equivalent protections to this DPA.
| Sub-processor | Role | Location | Transfer basis |
|---|---|---|---|
| Supabase GmbH | Database storage and authentication | EU, Frankfurt (AWS eu-central-1) | EU-based; no transfer |
| Anthropic PBC | Claude AI: deal analysis and scoring | United States | SCCs (Art. 46(2)(c) GDPR); no model training on customer data per Anthropic DPA |
| Resend Inc | Transactional email delivery | United States | SCCs |
| Vercel Inc | Application hosting and CDN | United States (EU edge residency enabled) | SCCs; primary data served from EU edge nodes |
| Stripe Inc | Subscription billing and payment processing | United States | SCCs; Stripe holds card data; Processor never receives raw card numbers |
| HubSpot Inc | CRM data source (read-only integration) | United States | SCCs; Controller already has a relationship with HubSpot as its CRM provider |
9. Data Subject Rights
The Processor will provide reasonable technical assistance to enable the Controller to respond to data subject requests under Articles 15 to 21 GDPR, including access, rectification, erasure, restriction, portability, and objection. The Controller remains responsible for communicating with and responding to data subjects within the statutory time limits. To request assistance, email hello@crm-brain.com.
10. Technical and Organisational Security Measures
The Processor implements the following measures at a minimum:
- Encryption of all personal data at rest using AES-256 within Supabase.
- Encryption of all data in transit using TLS 1.2 or higher.
- Row-level security policies enforced at the database layer so that every query is scoped to the Controller's team and cannot access another team's data.
- Multi-factor authentication required for Processor staff with access to production systems.
- API keys and service credentials stored as environment secrets and never committed to version control.
- Annual security review of infrastructure and access controls.
- Access to customer data limited to Processor personnel who require it to perform their role.
11. Personal Data Breach Notification
On becoming aware of a personal data breach affecting data processed under this DPA, the Processor will notify the Controller without undue delay and within 72 hours of becoming aware. The notification will include, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the breach. The Processor will cooperate with the Controller to support the Controller's notification obligations under Article 33 GDPR.
12. Deletion and Return of Data
On termination or expiry of the subscription, the Processor will delete all personal data processed under this DPA within 30 days unless Union or Member State law requires longer retention. The Controller may request an export of its data before deletion by emailing hello@crm-brain.com. Billing records subject to mandatory retention under German commercial and tax law (§147 AO) will be retained for the legally required period.
13. Governing Law and Jurisdiction
This DPA is governed by the laws of the Federal Republic of Germany, excluding conflict of law provisions. Any disputes arising from this DPA that cannot be resolved by negotiation shall be subject to the exclusive jurisdiction of the courts of Hamburg, Germany.
14. Order of Precedence
In the event of a conflict between this DPA and the CRM Brain Terms of Service, this DPA shall prevail to the extent the conflict concerns the processing of personal data subject to GDPR.
15. Contact
Data protection queries: hello@crm-brain.com
Roveva Solutions, Sandstücken 9, 25421 Pinneberg, Germany