Data Processing Addendum (DPA)
Last updated June 11, 2026
Introduction
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Cintram Terms of Service ("Terms"). It reflects the agreement between Cintram Inc. ("Processor") and any Customer or Controller of the Cintram platform ("Controller") regarding the processing of personal data under applicable data protection laws.
This DPA applies specifically to Customer Data processed by Cintram on behalf of the Controller in connection with the Services. It does not apply to Cintram's processing of its own account, billing, or operational data, which is governed by the Cintram Privacy Policy.
This DPA is designed to meet the requirements of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), UK GDPR, and similar applicable data privacy laws.
If there is a conflict between this DPA and the Terms regarding the processing of Customer Data, this DPA will control.
1. Roles and Instructions
The Controller determines the purposes and means of processing personal data submitted to the Services.
Cintram acts as a Processor, processing personal data only on behalf of the Controller, in accordance with the Controller's documented instructions, and as described in the Terms and this DPA.
The Controller's documented instructions include the Terms, this DPA, the Controller's configuration of the Services, account settings, use of features, integrations, and written instructions submitted to Cintram.
If Cintram is required by applicable law to process personal data in a manner that conflicts with the Controller's instructions, Cintram will inform the Controller before such processing takes place, unless prohibited from doing so by law.
Cintram ensures that personnel authorized to process Customer Data are subject to appropriate confidentiality obligations.
2. Types of Data Processed
Cintram may process the following types of personal data on behalf of the Controller:
- Contact details such as names, email addresses, and phone numbers
- Client records including notes, tasks, communication logs, and workflow data
- Uploaded files, documents, and related business data
- Client portal data, form submissions, and integration data
- Other personal data submitted through the Services by the Controller or their Authorized Users
Cintram does not access, use, or share this data except as required to provide the Services, comply with applicable law, or as otherwise permitted under the Terms and this DPA.
3. Details of Processing
Subject Matter: Cintram processes Customer Data on behalf of the Controller to provide the Services.
Duration: Cintram processes Customer Data for the duration of the Customer's use of the Services and as otherwise described in this DPA, the Terms, and the Privacy Policy.
Nature and Purpose: The processing includes hosting, storing, organizing, transmitting, displaying, securing, supporting, troubleshooting, analyzing, and otherwise processing Customer Data as necessary to provide the Services, support customer workflows, operate client portals, deliver communications, support automations, and provide AI-assisted features where enabled.
Categories of Data Subjects: Customers, Authorized Users, End Clients, contacts, leads, prospects, vendors, contractors, and other individuals whose information is submitted to the Services by or on behalf of the Controller.
Categories of Personal Data: Contact details, account identifiers, communication data, client records, notes, tasks, files, form submissions, workflow data, portal activity, usage data, integration data, and other personal data submitted to or processed through the Services.
Special Categories of Data: Cintram does not require Customers to submit special category data. If the Controller submits special category or sensitive personal data to the Services, the Controller is responsible for ensuring it has a valid legal basis, notices, consents, and safeguards for that processing.
4. Controller Obligations
The Controller is responsible for:
- Complying with applicable data protection laws in connection with its use of the Services
- Providing required privacy notices and obtaining required consents from data subjects
- Ensuring it has a lawful basis for processing Customer Data and for instructing Cintram to process that data
- Ensuring its instructions to Cintram are lawful
- Determining whether the Services are appropriate for the categories of personal data it chooses to process, including any sensitive, regulated, or special category data
- Ensuring its use of Cintram with End Clients is consistent with its own privacy policies, client agreements, and legal obligations
5. Subprocessors
Cintram engages third-party subprocessors to help deliver the Services. The Controller provides general authorization for Cintram to engage subprocessors to process Customer Data as necessary to provide the Services, subject to the notice and objection process described in this section.
Cintram will impose data protection obligations on subprocessors that are substantially similar to those in this DPA, to the extent applicable to the services provided by the subprocessor.
Current subprocessors that may process Customer Data include:
- Amazon Web Services (AWS): Cloud hosting infrastructure
- AWS SES: Platform email notifications
- Cloudflare: Security and content delivery
- Stripe: Billing-related data processing, including account and payment contact details
- SendGrid: Email delivery for Cintram communications or customer-enabled messaging, where applicable
- Twilio: SMS communications, where Customer Data appears in messages
- Intercom: In-app customer support and live chat, where Customer Data is shared in support conversations
- Additional vendors as reasonably necessary to support platform functionality
A current list of subprocessors is available upon request. Cintram will provide at least 30 days advance written notice before adding or replacing any subprocessor that processes Customer Data, giving the Controller a reasonable opportunity to object. If the Controller objects and the parties cannot resolve the objection, either party may terminate the affected Services with written notice.
6. Data Security
Cintram maintains appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Encryption of Customer Data in transit and, where appropriate, at rest
- Access controls and authentication
- Role-based permissions
- Secure backups and system monitoring
- Incident response protocols
Cintram regularly reviews its security practices to ensure continued protection. The specific measures in place may evolve as technology and threats change.
7. Data Subject Rights and Assistance
Where applicable, Cintram will assist the Controller in fulfilling its obligations related to data subject rights requests, including:
- Access
- Correction
- Deletion
- Restriction of processing
- Data portability
Cintram's assistance is limited to what is technically possible within the Services and is subject to applicable law. Cintram will not respond directly to a data subject request relating to Customer Data unless required by law or instructed by the Controller. If Cintram receives a data subject request directly from an End Client relating to Customer Data, Cintram may direct the request to the relevant Controller.
Requests relating to Customer Data should be directed by the Controller to their own account tools or to [email protected]. Cintram will respond in accordance with applicable law and within the timeframes required by it.
Cintram will provide reasonable assistance to the Controller, taking into account the nature of processing and information available to Cintram, with the Controller's obligations relating to security, personal data breaches, data protection impact assessments (DPIAs), and prior consultation with supervisory authorities, where required by applicable data protection law.
8. International Data Transfers
Cintram is based in the United States. Cintram may transfer Customer Data to countries outside the European Economic Area (EEA), Switzerland, or United Kingdom. In such cases, Cintram ensures that appropriate safeguards are in place.
Where applicable, the parties agree that the EU Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, and any applicable Swiss transfer requirements are incorporated by reference into this DPA and apply to restricted transfers of Customer Data from the EEA, Switzerland, or United Kingdom to the United States or other third countries.
Other lawful transfer mechanisms may also be used as required under applicable data protection laws.
9. Personal Data Breach Notification
In the event of a personal data breach affecting Customer Data, Cintram will notify the Controller without undue delay after becoming aware of the breach and, where feasible, within 72 hours. The notification will include details sufficient to enable the Controller to meet its own legal notification obligations and take appropriate steps.
10. Return and Deletion
Cintram retains Customer Data for as long as necessary to provide the Services and fulfill the purposes outlined in this DPA and the Privacy Policy.
Upon account cancellation or termination, Cintram may retain Customer Data for up to 90 days to allow for account recovery, comply with legal obligations, resolve disputes, prevent abuse, or maintain backups. After that period, Cintram will permanently delete or de-identify Customer Data from active systems in accordance with its data retention practices. Residual copies may remain in backups for a limited period, unless Cintram is required to retain data for legal, security, fraud prevention, or compliance purposes.
Upon termination of the Services, Cintram will delete or return Customer Data in accordance with this DPA, unless applicable law requires continued retention.
Controllers are responsible for exporting and backing up their data before account cancellation or closure. Upon written request made before account closure, Cintram will make reasonable efforts to assist the Controller in exporting Customer Data in a structured, machine-readable format where technically possible.
11. Audit and Compliance Support
Cintram may satisfy audit and inspection obligations by providing relevant documentation, security summaries, subprocessor information, certifications, or third-party audit reports where available.
Upon reasonable written request and subject to confidentiality obligations, Cintram will provide additional documentation or information reasonably necessary to demonstrate compliance with this DPA.
Audit requests are subject to the following conditions:
- The Controller must provide at least 30 days advance written notice
- Audits are conducted at the Controller's expense
- Audits may be conducted no more than once per calendar year, unless required by applicable law or following a confirmed security incident
- Audits must not disrupt Cintram's operations or compromise the security or privacy of other customers' data
12. Governing Law
This DPA is governed by the same laws and jurisdiction as the Cintram Terms of Service, namely the laws of the State of Texas, United States, unless otherwise required by applicable data protection law, including GDPR or UK GDPR.
13. Updates to This DPA
Cintram may update this DPA to reflect changes in legal requirements, subprocessors, or platform operations. When we update this DPA, we will revise the "Last Updated" date above. If material changes are made, Cintram will provide reasonable notice through our website or by contacting affected Customers directly.
14. Contact Information
If you have any questions regarding this DPA or wish to request a subprocessor list, additional documentation, or a signed copy, please contact:
Privacy and Compliance Team
Cintram Inc.
8951 Cypress Waters Blvd #160
Coppell, TX 75019
[email protected]