Skip to content
FiggyCRM

Legal

Data Processing Agreement

Last updated: August 21, 2026

This Data Processing Agreement (“DPA”) forms part of the FiggyCRM Terms of Service (the “Terms”) between FIGGYCRM, LLC, a Connecticut limited liability company (“FiggyCRM,” “we,” “us”), and the customer that accepts the Terms (“Customer,” “you”). It governs our processing of Customer Personal Data. Capitalized terms not defined here have the meaning given in the Terms.

If you accept the Terms, this DPA applies automatically. You do not need to sign a separate copy. If your organization requires a countersigned version, email hello@figgycrm.com.

1. Definitions

Applicable Data Protection Law means all privacy and data protection laws that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), and the Connecticut Data Privacy Act (CTDPA).

Customer Personal Data means personal data contained in the contacts, deals, projects, tasks, notes, files, and other content you or your users store in your FiggyCRM workspace.

Account Data means personal data about you and your users that we collect to create and administer your account, bill you, provide support, and secure the Service.

Controller, Processor, Data Subject, Personal Data Breach, and Processing have the meanings given in the GDPR. Where the CCPA applies, Business and Service Provider carry the meanings given there.

Subprocessor means a third party engaged by us to process Customer Personal Data.

2. Roles of the parties

2.1 Customer Personal Data. You are the Controller. We are the Processor. You determine why and how Customer Personal Data is processed; we process it only to provide the Service and only on your instructions.

2.2 Account Data. We are the Controller of Account Data, and we process it as described in our Privacy Policy.

2.3 Your responsibilities. You are responsible for the accuracy and lawfulness of Customer Personal Data, for having a valid legal basis for the processing you instruct, for providing any notices and obtaining any consents your own data subjects require, and for the security of your users' credentials and access settings.

2.4 Prohibited data. The Terms prohibit storing special categories of personal data in the Service, including health and medical information, biometric and genetic data, and data revealing racial or ethnic origin, religious beliefs, or sexual orientation. FiggyCRM is not designed for regulated data, we do not sign HIPAA business associate agreements, and we are not a consumer reporting agency under the Fair Credit Reporting Act. If you store prohibited data in the Service, you do so contrary to the Terms and at your own risk, and we have no obligation under this DPA in respect of it.

3. Scope and instructions

3.1 Documented instructions. We process Customer Personal Data only on your documented instructions, which consist of the Terms, this DPA, your configuration of the Service, and any further written instructions you give that we agree to.

3.2 Legal requirement. We may process Customer Personal Data where required by law. Where legally permitted, we will tell you before doing so.

3.3 Unlawful instructions. If we believe an instruction from you violates Applicable Data Protection Law, we will tell you without undue delay and may suspend that processing until it is resolved.

3.4 No sale, no secondary use. We do not sell or share Customer Personal Data, and we do not use it for our own purposes, including advertising, profiling, or training machine learning models. We do not combine Customer Personal Data with data from other sources except as necessary to provide the Service to you.

3.5 Aggregated data. We may generate aggregated and de-identified statistics about use of the Service. Such data contains no personal data, is not attributable to you or any data subject, and we will not attempt to re-identify it.

4. Confidentiality

We ensure that anyone authorized to process Customer Personal Data is bound by a duty of confidentiality, whether by contract or by statute, and receives access only to the extent necessary to perform their role.

5. Security

5.1 Measures. We implement and maintain the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature and risk of the processing.

5.2 Changes. We may update our security measures over time, provided the overall level of protection is not reduced.

5.3 Access controls. You are responsible for configuring roles and permissions in your workspace and for removing access when a user should no longer have it.

6. Subprocessors

6.1 General authorization. You give us general authorization to engage Subprocessors. Our current Subprocessors are listed in Annex III.

6.2 Terms. We enter a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.

6.3 Changes. Before adding or replacing a Subprocessor, we will give you at least 30 days' notice by email or through the Service. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service and receive a pro rata refund of prepaid fees. Termination is your exclusive remedy.

7. Data subject rights

7.1 Self-service. The Service lets you access, correct, export, and delete Customer Personal Data directly. In most cases this is how you will respond to data subject requests, without needing us.

7.2 Our assistance. Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in responding to data subject requests.

7.3 Requests received by us. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to direct them to you, and we will forward the request to you without undue delay.

8. Personal Data Breach

8.1 Notification. We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 Content. Our notice will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where we cannot provide all of this at once, we will provide it in phases as it becomes available.

8.3 Assistance. We will provide reasonable assistance with your obligations to notify supervisory authorities and data subjects. You remain responsible for determining whether notification is required and for making it.

8.4 No admission. Notifying you is not an acknowledgment of fault or liability.

9. Deletion and return

9.1 During the term. You can export Customer Personal Data at any time through the Service.

9.2 On termination. After your account is cancelled, your data remains available for export unless you delete it or ask us to. On your written request, we will delete the workspace.

9.3 Deletion mechanics. Deletion removes Customer Personal Data from the live Service immediately. Copies may persist in routine encrypted backups for up to 30 days, after which they are overwritten in the ordinary course. Until overwritten, backup copies remain subject to this DPA.

9.4 Legal retention. We may retain Customer Personal Data where required by law, in which case we will continue to protect it and process it only as required for that purpose.

10. Audits and information

10.1 Documentation. We will make available the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, including this DPA, Annex II, and responses to reasonable written security questionnaires.

10.2 Audits. Where documentation is not sufficient, you may audit our compliance no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, subject to confidentiality obligations, and at your own expense. An audit following a confirmed Personal Data Breach affecting your data is not subject to the frequency limit and is at our expense.

10.3 Subprocessor audits. For Subprocessors, we will provide their published compliance documentation. We are not obliged to procure audit rights over Subprocessor facilities beyond what our agreements with them provide.

11. International transfers

11.1 Location. Customer Personal Data is stored in the United States.

11.2 Transfer mechanism. Where you transfer Customer Personal Data subject to the GDPR to us, the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914) apply and are incorporated into this DPA, with FiggyCRM as data importer and Customer as data exporter, Module Two (controller to processor). Annexes I, II, and III to this DPA populate the corresponding annexes to those clauses.

11.3 United Kingdom. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies.

11.4 Conflict. If the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail as to the transfers they govern.

12. United States state privacy laws

12.1 Service Provider status. With respect to the CCPA, you are a Business and we are a Service Provider. We do not sell or share Customer Personal Data as those terms are defined in the CCPA, and we do not retain, use, or disclose it for any purpose other than performing the Service, or as otherwise permitted by the CCPA.

12.2 Certification. We certify that we understand these restrictions and will comply with them.

12.3 Other state laws. Where the CTDPA or a comparable state law applies, we act as a processor and comply with the corresponding obligations, including cooperating with reasonable assessments.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, including the limitation of liability section. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law, including liability to data subjects under Article 82 of the GDPR.

14. Term, conflict, and changes

14.1 Term. This DPA takes effect when you accept the Terms and continues until all Customer Personal Data has been deleted in accordance with Section 9.

14.2 Conflict. If this DPA conflicts with the Terms, this DPA prevails as to the processing of Customer Personal Data.

14.3 Changes. We may update this DPA where required by Applicable Data Protection Law, to reflect a change in Subprocessors under Section 6.3, or to improve it without reducing your protection. Material changes get at least 30 days' notice.

14.4 Governing law. Connecticut law governs this DPA, except where Applicable Data Protection Law requires otherwise or where the Standard Contractual Clauses specify a different governing law for the transfers they cover.

Annex I. Details of processing

Data exporter
The Customer accepting the Terms.
Data importer
FIGGYCRM, LLC, Wallingford, Connecticut, United States. Contact: hello@figgycrm.com.
Subject matter
Provision of the FiggyCRM customer relationship management service.
Duration
The term of the Customer's account, plus the deletion period in Section 9.
Nature and purpose
Hosting, storage, organization, retrieval, transmission, backup, and deletion of Customer Personal Data, in order to provide the Service.
Categories of data subjects
The Customer's contacts, leads, clients, prospects, and other business contacts; the Customer's own personnel and workspace users.
Categories of personal data
Names; business and personal email addresses; telephone numbers; postal addresses; employer and job title; and any other information the Customer chooses to record in contact records, deal records, notes, tasks, or attachments.
Special categories
None. Storing special category data is prohibited under Section 2.4.
Frequency
Continuous, for the duration of the account.
Retention
For the duration of the account, plus up to 30 days in backups after deletion.
Supervisory authority
Determined by the Customer's place of establishment.

Annex II. Technical and organizational measures

Infrastructure
The Service runs on Supabase, hosted in Amazon Web Services data centers in the United States.
Encryption
Personal data is encrypted in transit using TLS and at rest using AES-256.
Tenant isolation
Each workspace's data is isolated at the database level through row-level security policies, not only at the application layer.
Authentication
Passwords are stored only as salted hashes. Password strength requirements apply, and new passwords are checked against a database of credentials exposed in known breaches. Two-factor authentication using a time-based one-time password application is available to all users and is enforced for FiggyCRM administrative accounts.
Payment data
Card data is processed by Stripe and does not transit or reside on FiggyCRM systems.
Backups
Daily database backups plus separate per-workspace backups retained for 30 days.
Access management
Access to production systems and Customer Personal Data is limited to the founder, who is the only person with production access.
Vulnerability reporting
Reports may be sent to security@figgycrm.com and are reviewed by a human.
Deletion
As described in Section 9.

Annex III. Subprocessors

SubprocessorPurposeLocation
SupabaseDatabase, authentication, and file storageUnited States
VercelWebsite and application hostingUnited States
Amazon Web ServicesUnderlying infrastructure for SupabaseUnited States
StripePayment processing (Account Data only)United States
ResendTransactional email deliveryUnited States
SentryApplication error monitoringUnited States

See also our Privacy Policy, Terms of Service, and Security page.