Legal

Data Processing Agreement

Standard terms · last updated 4 March 2026

01Roles

You are the data controller. CRM Anvil is the data processor, acting only on your documented instructions for the scope of the engagement.

02Purpose of processing

Assessment, deduplication, normalisation, enrichment and migration of the CRM records you provide. No other processing takes place, and your data is never used for our own purposes.

03Security measures

TLS 1.2+ in transit, AES-256 at rest, named-individual access under least privilege with MFA enforced, no shared accounts, and access logging for the duration of the engagement.

04Sub-processors

A short list of infrastructure and enrichment providers, disclosed on request and before any change. Each is bound by equivalent obligations.

05Breach notification

We notify you without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting your records, with the facts known at that point and the steps taken.

06Retention and deletion

Source exports, working copies and scoped credentials are deleted on completion of the engagement. Written confirmation of deletion is provided. Merge logs are retained only where you ask us to.

07Audit and assistance

On request we provide the information needed to demonstrate compliance, and we assist with data subject requests relating to records we processed.

08Signature

We will sign this DPA on request, or review and sign yours instead. Write to hello@crmanvil.com and we will send an executable copy.

41/100
Sample account

What's your number?

A scored report of duplicates, dead numbers, invalid emails and missing fields — ranked by what it's costing you.

Score my database — $99