1. Purpose
This Data Processing Agreement (“DPA”) describes how OctaVertex Media (“Processor”) processes personal data on behalf of the customer organization (“Controller”) that uses Vertex CRM (the “Service”). It supplements the Terms and Privacy Policy. For enterprise contracts, a signed order form or paper DPA may prevail if it conflicts with this page.
2. Roles
- Controller: the customer organization that decides why CRM personal data (contacts, leads, etc.) is processed.
- Processor: OctaVertex Media, providing Vertex CRM hosting/software and processing data only on documented instructions (use of the Service, configuration, and support requests).
- End users: customer employees/contractors who access the workspace under the Controller’s authority.
3. Subject matter and duration
Processing covers personal data uploaded to or generated in the customer’s Vertex CRM organization for the term of the subscription and any wind-down/export period, plus limited retention required by law or security (see Data Retention).
4. Nature and purpose of processing
Hosting, storage, transmission, display, backup, security monitoring, support troubleshooting, and optional integrations the Controller enables (email, Meta Ads/Lead Ads/WhatsApp, AI features). Processor does not sell Controller personal data or use it for Processor’s unrelated advertising.
5. Types of personal data
May include names, business emails, phone numbers, job titles, company names, deal notes, message contents, IP/technical logs, and Meta-sourced lead or messaging fields when integrations are enabled. Special-category data should not be submitted unless the Controller has a lawful basis and the Service is configured appropriately.
6. Data subjects
Controller’s personnel, customers, prospects, and other individuals whose data the Controller chooses to store in the CRM.
7. Processor obligations
- Process only on Controller instructions (including configuration of the Service)
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational measures (see Security)
- Assist with data subject requests when Controller cannot fulfill them alone (see Account deletion and admin DSAR tools)
- Notify Controller without undue delay after becoming aware of a personal data breach affecting the Service
- Delete or return personal data after end of services, subject to legal retention and backup windows (Data deletion)
8. Subprocessors
Controller authorizes Processor to use infrastructure and operations subprocessors (e.g., hosting, DNS, email delivery, error monitoring) under written terms imposing data protection obligations no less protective than this DPA. A current list can be requested via Contact.
9. International transfers
Data may be processed in India and/or other regions depending on deployment. Where required, transfers use appropriate safeguards (contractual clauses or other lawful mechanisms).
10. Meta and other third-party APIs
When Controller connects Meta or other providers, Controller instructs Processor to exchange data with those providers as needed for the integration. Those providers process data under their own terms; Processor does not control Meta’s systems.
11. Controller obligations
Controller warrants it has a lawful basis to submit personal data, configures access appropriately, and does not misuse the Service. Controller remains responsible for end-user notices where required.
12. Contact
DPA and privacy requests: vertexcrm.in/contact (subject: “DPA / privacy”).
Last updated: August 2026. Not legal advice; counsel should review for your jurisdiction.