On this page
COMPLIANCE AND SECURITY
Data processing agreement
A data processing agreement (DPA) is a contract between a data controller (your business) and a data processor (a vendor such as your CRM) that sets out what the processor may do with personal data, the security measures it must maintain, its sub-processors, breach notification, assistance with data subject requests and what happens to the data at the end of the contract. GDPR requires one; the DPDP Act expects equivalent contractual terms.
gdprdpdp actpii
Why it matters
Without a DPA, using a cloud CRM for customer conversations is itself a compliance gap. Buyers in regulated sectors and larger companies ask for it in procurement, and it is the document that tells you where data goes and who else touches it.
In VGraple CRM
The DPA is published at /dpa with standard contractual clauses, the sub-processor list and the security measures; it applies automatically to every customer under the terms of service and can be countersigned on request for procurement.