Data Processing Addendum
1. Incorporation, parties, and scope
This Addendum is available for written incorporation into a services agreement or order between Vault Commerce Group LLC (Cove) and the business customer identified in that agreement (Customer). It becomes effective only when both parties agree in writing to incorporate it. Publication alone does not execute it, certify an existing compliance program, or alter an existing signed DPA.
Customer Personal Data means personal information submitted to or processed through Cove on Customer's behalf. This Addendum applies where Cove acts as a processor or service provider under applicable data-protection law. Customer generally acts as controller/business, or as a processor authorized by its controller. Cove's independent account, billing, security or website purposes are addressed separately by the Privacy Policy and applicable law.
Before incorporation, the parties must confirm the processing details, relevant providers and locations, and any additional requirements in the written agreement. This Addendum does not establish a HIPAA business associate arrangement or incorporate international transfer clauses by implication.
2. Instructions and lawful processing
Cove will process Customer Personal Data only under Customer's documented lawful instructions, including the agreement, enabled features, authorized user requests and configured integrations, or as required by applicable law. Where legally permitted, Cove will inform Customer of a legal requirement to process outside those instructions. Cove will notify Customer if it reasonably believes an instruction violates applicable data- protection law and may suspend that instruction pending resolution.
Customer is responsible for lawfulness, accuracy and minimization of its data; notices and required permissions; instructions it gives; contact/recording rights; and its users and downstream recipients. Customer will not instruct prohibited processing or submit data requiring protections not expressly agreed. Neither party is relieved of duties imposed directly on it by law.
Where service-provider/contractor restrictions apply, Cove will not sell or share Customer Personal Data as those terms are defined by the applicable law, retain/use/disclose it outside the specified business purposes or direct business relationship, or combine it with other data except as permitted by that law. Customer-directed disclosures to an advertising platform or independent recipient require a separate lawful basis and role assessment; this restriction is not a blanket classification of all website or integration activity.
3. Personnel and confidentiality
Cove will restrict access to personnel and providers who need Customer Personal Data for authorized purposes and subject authorized personnel to confidentiality obligations. These duties continue after access ends. Legally compelled disclosures remain subject to applicable safeguards.
4. Security and cooperation
Cove will maintain reasonable technical and organizational measures appropriate to the nature of the processing and risks, including applicable access controls and encryption in transit. The agreed processing schedule must identify any additional required measures. The public Security page is descriptive and is not a SOC 2, ISO, HIPAA or other certification.
Taking into account the processing and information available, Cove will reasonably assist Customer with applicable security, assessment and regulatory consultation duties. No particular certification, audit report, data residency, backup schedule, recovery objective or service level is promised unless expressly agreed in writing.
5. Subprocessors
Customer authorizes the subprocessors identified for its service in the written processing schedule. Cove will use written terms requiring appropriate data-protection obligations for delegated processing and remains responsible for performance of those obligations to the extent required by applicable law and the agreement.
Cove will inform Customer of intended additions or replacements sufficiently in advance to provide an opportunity to object on reasonable data-protection grounds, using the notice method and period established in the written agreement. The parties will work in good faith to resolve an objection; if they cannot, they will address the affected processing or service under that agreement. An independent integration is not made a subprocessor merely by appearing in the public register.
The public register identifies supported providers and role distinctions. It is not a substitute for confirming the actual providers, locations and notice arrangements for the Customer before execution.
6. Individual requests and customer assistance
Where a request relates to Customer Personal Data processed on Customer's behalf, Cove will notify or direct the request to Customer as appropriate and assist with access, correction, deletion, portability, restriction or opt-out duties to the extent required by law, considering the nature of processing. Cove will not make a substantive decision on Customer's behalf unless instructed or legally required.
Customer should provide sufficient lawful identifying information and instructions to locate relevant records. The parties will protect request information and apply appropriate verification. Reasonable assistance costs may be agreed where lawful, but costs must not prevent performance of nonwaivable legal duties.
7. Personal data incidents
Cove will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to unlawful or unauthorized destruction, loss, alteration, disclosure of, or access to Customer Personal Data under Cove's responsibility. Notice will include available information reasonably needed for Customer's obligations, such as the nature of the incident, affected categories, likely consequences, and containment or remediation measures, with further information as it becomes available.
Cove will take reasonable steps to contain, investigate and mitigate the incident and cooperate with Customer. Notice is not an admission of fault. Customer is responsible for its legally required notices to individuals and regulators unless law allocates them otherwise; the parties will coordinate where practicable. Unsuccessful attempts that do not compromise personal data are not automatically notifiable breaches under this section.
8. Return, deletion, and retained copies
At the end of the relevant services, or upon lawful instruction, Cove will return or delete Customer Personal Data as selected by Customer and required by law and the agreement. The parties will confirm the scope, available format, timing, provider copies and lawful retention exceptions. Customer should request available exports before account access ends.
Data retained because of legal requirements or justified backup limitations must remain protected, restricted to the retention purpose, and deleted when that basis ends according to applicable requirements. Cove will provide reasonable information about retained categories and reasons upon request where lawful. No immediate, universal deletion from every system is implied by an in-app delete or cancellation action.
9. Information and audits
Cove will make available information reasonably necessary to demonstrate compliance with the applicable processing obligations and allow or contribute to assessments required by applicable law. The parties may use relevant documentation and an independent assessment where adequate, and agree a reasonable process for any further audit.
Audits must protect other customers, security, confidentiality and service availability, with reasonable notice, scope, timing and qualified reviewers. Customer does not gain unrestricted access to production systems, provider systems or another customer's data. These procedural protections cannot be used to deny a legally required audit or regulatory access.
10. International processing
The parties must identify relevant processing locations and transfers before any data subject to a restricted international-transfer regime is transferred. If a lawful transfer mechanism or additional safeguards are required, they must be agreed and implemented separately before that transfer. No standard contractual clauses, adequacy basis, representative, or data-residency commitment is asserted by this Addendum alone.
11. Processing details for incorporation
- Subject matter: hosted CRM and the communications, scheduling, imports, AI, support and integrations ordered or enabled by Customer.
- Nature and purpose: receipt, organization, storage, retrieval, communication routing, authorized recording/transcription, analysis and outputs, support, security, and lawful return/deletion to provide the contracted service.
- Duration: the relevant service term and any lawful, limited retention necessary to complete instructions or meet legal obligations.
- Individuals: Customer users/personnel, leads, contacts, communications participants, appointment attendees, and other individuals Customer lawfully includes.
- Data: identity/contact, account, lead/custom fields, messages/media, call metadata/audio/transcripts, appointments, consent evidence, AI inputs/outputs and related service metadata. Sensitive data is limited to what Customer lawfully submits and the parties expressly authorize for the service.
- Customer and Cove contacts, selected features, actual subprocessors and locations, additional safeguards, notice arrangements, export/deletion details and any required transfer mechanism must be identified in the incorporating agreement or its schedule.
12. Priority and contact
For a conflict concerning covered processing, this Addendum prevails over general service terms. Applicable law and any separately executed mandatory transfer provisions take priority where required. The services agreement governs other matters, including liability, to the extent permitted by law. The parties will cooperate on changes necessary to comply with applicable processing requirements.
To discuss incorporation or request processing information, contact legal@covecrm.com. A request does not itself execute this Addendum.