Data Processing Agreement

Last updated: 2026-09-01

1. Summary

  • The customer is the controller and [Szolgáltató cégneve / Provider's legal name] the processor; the agreement is part of the terms, with no separate signature.
  • We process data only on the customer's instructions: anything done through the interface, the API or MCP counts as one.
  • We report a personal data breach within 48 hours at the latest.
  • One person's complete record can be exported and erased; an issued invoice stays, the personal data does not.
  • The customer can set retention rules: expired data is removed by the same path as an erasure request.
  • Subprocessors: [Tárhelyszolgáltató / Hosting provider]; [E-mail küldő szolgáltató / SMTP provider]; Anthropic PBC (548 Market Street, San Francisco, CA, USA); Számlázz.hu (KBOSS.hu Kft., 1031 Budapest, Záhony utca 7.); Billingo (Billingo Technologies Zrt., 1133 Budapest, Árbóc utca 6.); SMS-átjáró / SMS gateway; WooCommerce, Shopify, ShopRenter, UNAS; Webhook-címzettek és bővítmények / Webhook recipients and add-ons; Böngészők push-szolgáltatásai / Browser push services (Google, Mozilla, Apple, Microsoft). Changes are announced 30 days ahead.

2. Parties and subject

This Data Processing Agreement (the "DPA") is entered into between the organisation using the MiniCRM service as controller (the "Controller") and [Szolgáltató cégneve / Provider's legal name] ([Székhely / Registered address]) as processor (the "Processor"), and forms an integral part of the Terms of Service. By accepting the Terms the Controller accepts this DPA; no separate signature is needed.

The DPA sets out the terms required by Article 28(3) GDPR for the personal data the Controller records in, uploads to or collects through the Service.

3. Nature, purpose and duration of processing

The purpose of processing is providing the Service: storing, organising, displaying, searching and exporting the Controller's customer and partner data, and — on the Controller's instruction — sending email, SMS and documents and receiving data through public forms and websites.

Categories of data subjects: the Controller's customers, prospects and partners and their contact persons, visitors to the Controller's websites and forms, and the Controller's staff (for data recorded in the People module).

Categories of personal data: identification and contact details (name, email, phone, address, job title), business relationship data (deals, quotes, invoices, notes, correspondence, calls), behavioural data (email opens, clicks, unsubscribes), the content of custom fields the Controller defines, and for staff, employment data (start date, leave, working time). The Service is not intended for special categories of data; recording any is the Controller's responsibility.

Processing lasts for the term of the agreement under the Terms, including the grace period after an organisation's deletion is requested.

4. Obligations of the Processor

The Processor processes personal data only on the Controller's documented instructions; every operation performed through the Service's interface, API or MCP endpoint, and every setting made in it, counts as an instruction. If the Processor considers an instruction infringes the law, it informs the Controller without delay.

The Processor ensures that persons with access to personal data are bound by confidentiality and access data only to the extent their tasks require.

The Processor maintains technical and organisational measures meeting Article 32 GDPR, described on the Security page. In particular: strict separation between organisations (every query filters on the organisation id, enforced by automated checks), passwords and tokens stored only as hashes, external credentials encrypted, role- and record-level access control, daily backups with tested restores, and audit logging.

Taking into account the nature of processing, the Processor assists the Controller with requests from data subjects through tools built into the Service: a data subject's complete record can be exported (right of access), and a data subject can be erased while accounting records that must be kept by law are retained with the personal data removed from them (right to erasure).

The Processor assists the Controller with its obligations under Articles 32–36 GDPR and notifies the Controller of a personal data breach without undue delay, and at the latest within 48 hours of becoming aware of it, with the information then available.

The Processor makes available the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it, once a year on reasonable notice and at the Controller's cost.

5. Subprocessors

The Controller gives general authorisation for the Processor to engage subprocessors. The current list is on the Subprocessors page. The Processor gives at least 30 days' notice by email of any intended addition or replacement; the Controller may object on reasonable grounds, and failing agreement may terminate before the change takes effect.

The Processor imposes on each subprocessor data protection obligations at least equivalent to those in this DPA and remains fully liable to the Controller for the subprocessor's performance.

Számlázz.hu and Billingo are subprocessors only where the Controller has configured the invoicing integration with its own account; in that case the buyer details needed to issue the invoice are transferred.

6. Transfers to third countries

The Processor stores personal data within the European Union. Transfers to third countries occur only on the Controller's instruction (for example to the recipient of a webhook or integration the Controller configures) or under the safeguards of Chapter V GDPR.

7. End of processing

On termination the Controller may take its personal data out through the Service's export function. Export remains available throughout the 14-day grace period after deletion is requested; when it ends the Processor deletes all personal data, and it leaves the backups through their normal rotation of at most 14 days. Data that Union or member state law requires to be kept (accounting records) is retained separately until the statutory period ends.

8. Liability and miscellaneous

Article 82 GDPR and the liability provisions of the Terms apply. Hungarian law governs this DPA. It is to be interpreted in accordance with the GDPR, and in case of conflict with the Terms this DPA prevails.