Legal
Data Processing Agreement
Standard terms · last updated 4 March 2026
01Roles
You are the data controller. CRM Anvil is the data processor, acting only on your documented instructions for the scope of the engagement.
02Purpose of processing
Assessment, deduplication, normalisation, enrichment and migration of the CRM records you provide. No other processing takes place, and your data is never used for our own purposes.
03Security measures
TLS 1.2+ in transit, AES-256 at rest, named-individual access under least privilege with MFA enforced, no shared accounts, and access logging for the duration of the engagement.
04Sub-processors
A short list of infrastructure and enrichment providers, disclosed on request and before any change. Each is bound by equivalent obligations.
05Breach notification
We notify you without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting your records, with the facts known at that point and the steps taken.
06Retention and deletion
Source exports, working copies and scoped credentials are deleted on completion of the engagement. Written confirmation of deletion is provided. Merge logs are retained only where you ask us to.
07Audit and assistance
On request we provide the information needed to demonstrate compliance, and we assist with data subject requests relating to records we processed.
08Signature
We will sign this DPA on request, or review and sign yours instead. Write to hello@crmanvil.com and we will send an executable copy.