Data Processing Agreement (DPA)
Definitions
“Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given in applicable Data Protection Laws. “Sub-processor” means any third party engaged by us to process Personal Data under this DPA.
Roles and Scope
You are the Controller and we are the Processor of Personal Data processed on your behalf through the Services. You determine the purposes and means of processing and are responsible for the lawfulness of the Personal Data you provide and the instructions you give. We process Personal Data only as needed to provide the Services and as described in Annex A.
For most Crestora software products that run on your own device or server, Personal Data (such as your organization’s or store’s records) typically stays within your environment and is not transmitted to us; in those cases we act as Processor only to the limited extent we access such data — for example, when you send us data or grant us access for support or custom-development work.
We act as a “service provider” (and, where applicable, “processor”) under U.S. state privacy laws (including the CCPA/CPRA) and will not sell or share Personal Data, nor retain, use, or disclose it for any purpose other than providing the Services under this DPA.
Processing Instructions
We process Personal Data only on your documented instructions, including those in this DPA and the Services agreements, unless required by law (in which case we will inform you unless legally prohibited). You instruct us to process Personal Data to provide, secure, maintain, and support the Services, and to comply with your reasonable written instructions consistent with the Services. We will inform you if, in our opinion, an instruction infringes Data Protection Laws.
Confidentiality
We ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
Security
We implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing, and the risks to data subjects. A summary of measures is in Annex B. You are responsible for the security and configuration of your own environment, backups, and access controls.
Sub-processors
You generally authorize us to engage Sub-processors to support the Services (for example, hosting, email/support tooling, and payment processing). We impose data-protection obligations on each Sub-processor no less protective than those in this DPA and remain responsible for their performance. A current list of Sub-processors is published at crestoralabs.com/subprocessors or available on request by contacting [email protected]. Before engaging a new or replacement Sub-processor, we will notify you by email to your registered account administrator and by updating that page, giving you at least 30 days to object on reasonable data-protection grounds.
Data-Subject Requests
Taking into account the nature of the processing, we will provide reasonable assistance, by appropriate technical and organizational measures, to help you respond to requests from data subjects to exercise their rights. If we receive such a request directly relating to your data, we will, where permitted, refer the data subject to you.
Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data breach affecting Personal Data we process on your behalf, and provide information reasonably available to us to help you meet your notification obligations. You are responsible for notifying supervisory authorities and data subjects where required.
Assistance and DPIAs
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with your obligations regarding security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities.
International Transfers
Where we process or transfer Personal Data internationally on your behalf, we will rely on a valid transfer mechanism where required, including the European Commission’s Standard Contractual Clauses and the UK Addendum, which are incorporated by reference where applicable.
Return and Deletion
On termination of the Services, and at your choice, we will delete or return the Personal Data we process on your behalf and delete existing copies, unless retention is required by law. Where data resides on your own device or server, deletion is within your control.
Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, frequency limits, and our security policies. The Customer shall first rely on the information, certifications, and audit reports we make available, and a physical on-site inspection shall only be permitted where such information is demonstrably insufficient to demonstrate compliance. We may satisfy audit requests by providing relevant third-party certifications or reports where available.
Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms and Conditions and applicable Services agreement.
Governing Law
This DPA is governed by the law that governs the underlying agreement (State of Florida, United States), except that, where required by Data Protection Laws (such as the GDPR), the data-protection provisions and any incorporated Standard Contractual Clauses are governed by the law specified in those clauses or the relevant Data Protection Law.
Annex A — Details of Processing
- Subject matter: provision of Crestora software products and related support and services.
- Duration: for the term of the applicable agreement and any retention required by law.
- Nature and purpose: installation, configuration, support, debugging, and custom development of Crestora products; only to the extent Personal Data is shared with or accessed by us.
- Categories of data subjects: your customers, employees, and contacts whose data appears in materials you share or systems you grant us access to.
- Types of Personal Data: e.g., names, contact details, order data, and any data contained in logs, databases, or files you provide for support or development. You agree not to share special-category data unless separately agreed.
Annex B — Security Measures (summary)
Access controls and least-privilege access to any data you share; encryption in transit for data transfers; confidentiality obligations on personnel; use of reputable hosting and tooling providers; prompt revocation of access credentials after an engagement; and procedures to identify and respond to security incidents.
Contact us
Questions about this DPA or our data-processing practices? Reach us any time.
Email [email protected] · Phone 321-586-0010
Address
Crestora Labs
6300 N Wickham Rd
# 130 - 422
Melbourne, FL 32940
United States
