Data Processing Agreement
Standard processing terms for customer personal data handled through IPcom CRM.
Last updated: 3 October 2026
These standard processing terms apply with the customer's accepted order, service description and other applicable IPcom CRM terms.
1. Parties and application
This Data Processing Agreement forms part of the agreement between the customer identified in an accepted order (the Controller) and IPcom Limited (the Processor) where IPcom Limited processes personal data on the customer's behalf through IPcom CRM. It does not change either party's role where that party independently determines the purposes and means of processing.
2. Processing details
- Subject matter and duration
- Provision, support, security, backup and controlled termination of the subscribed CRM service for the service term and the documented exit period.
- Nature and purpose
- Hosting, storing, organising, retrieving, transmitting, backing up, securing, supporting, exporting and deleting customer-controlled CRM information.
- Data subjects
- The customer's contacts, customers, prospects, sellers, staff, members, suppliers and other people whose data the customer chooses to process.
- Personal-data categories
- Identity and contact details, organisation and account information, communications, marketing preferences, commerce and order information, service records, and technical or audit data. Special-category data is not intended unless expressly agreed in writing.
3. Documented instructions
IPcom Limited will process customer personal data only on documented instructions in the agreement, the customer's authorised use of the service and written support requests, unless Union or Member State law requires otherwise. IPcom Limited will inform the customer if an instruction appears to infringe applicable data-protection law.
4. Confidentiality and security
People authorised to process customer personal data must be bound by confidentiality. IPcom Limited will maintain measures appropriate to the risk, including access control, role restrictions, authentication, logging, backups, patching, monitoring and recovery controls. Security measures may evolve provided the overall level of protection is not materially reduced.
5. Subprocessors
The customer gives general written authorisation for the subprocessors listed in the Subprocessor Register. IPcom Limited will impose appropriate data-protection obligations on each subprocessor and remains responsible for its obligations under this DPA. Material additions or replacements will be recorded before the provider processes customer personal data. A customer may raise a reasonable data-protection objection by contacting admin@ipcom.ie.
6. Assistance
Taking account of the nature of processing and information available, IPcom Limited will reasonably assist the customer with data-subject requests, security obligations, breach assessment, impact assessments and prior consultation. Assistance outside normal service scope may be charged where the agreement permits and the customer is told in advance.
7. Personal-data incidents
IPcom Limited will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer's assessment and reporting. The Security & Incident Procedure explains the reporting channel and response process.
8. Return and deletion
At the end of the service, the customer may request an export under the Customer Exit & Data Export procedure. IPcom Limited will then delete or return customer personal data in accordance with the customer's documented choice, except where applicable law requires retention. Residual backup copies remain protected and are removed through the normal backup rotation.
9. Information and audits
IPcom Limited will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow proportionate audits by the customer or an agreed independent auditor. Audits must protect other customers, security controls and confidential information, and normally require reasonable written notice unless a regulator or urgent incident requires otherwise.
10. Transfers and precedence
Customer personal data will not be transferred outside the EEA unless an applicable lawful transfer mechanism and supplementary measures are in place where required. If this DPA conflicts with another service term on processing customer personal data, this DPA takes precedence for that conflict. Irish law governs this DPA, subject to mandatory applicable law.