Data Processing Agreement

Last updated: April 2026. Questions? Email support@unavoidablem.com

๐Ÿ”’ Your data and security are our number one priority

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Unavoidable Marketing Ltd ("Processor") and you, the Customer ("Controller"). It governs how we handle personal data on your behalf in accordance with UK GDPR Article 28.

1. Definitions

2. Subject Matter and Nature of Processing

We process the following categories of personal data on your behalf:

Processing is carried out for the purpose of providing the CRM service as described in your subscription plan.

3. Your Obligations as Controller

As the Data Controller, you are responsible for:

4. Our Obligations as Processor

We commit to:

5. Technical and Organisational Security Measures

๐Ÿ”
Encryption at rest
Database encryption, encrypted API key storage, bcrypt password hashing.
๐Ÿ”’
Encryption in transit
TLS 1.2+ enforced for all connections. HSTS with 1-year duration.
๐Ÿข
Data isolation
Strict company-level data separation. No account can access another's data.
๐Ÿšช
Access controls
Role-based access (owner/admin/user), 2FA, session timeouts, brute force protection.
๐Ÿ’พ
Backups
Daily encrypted backups retained for 90 days. Disaster recovery plan in place.
๐Ÿ”
Audit logging
All significant data operations are logged with timestamps and user identifiers.

6. Sub-processors

We use the following authorised sub-processors. By using the Service, you consent to their use:

We will notify you of any intended changes to sub-processors with at least 30 days notice, giving you the opportunity to object.

7. Data Transfers

Your data is primarily processed and stored in the UK and EEA. Where data is transferred to processors outside the UK (e.g. US-based services), we ensure adequate safeguards are in place via Standard Contractual Clauses (SCCs) or UK adequacy decisions.

8. Data Retention and Deletion

We retain your data for the duration of your subscription plus 30 days. On request, we will permanently delete your data within 72 hours. Backup copies are purged within 90 days.

You can export all your data at any time via Settings โ†’ Data & GDPR within the CRM.

9. Data Breach Notification

In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware, providing:

10. Contact

Data Protection Queries

For DPA queries, data subject requests or breach notifications:

dpo@unavoidablem.com

Unavoidable Marketing Ltd ยท 152 Osmondthorpe Lane ยท Leeds ยท LS9 9EG ยท Company No. 08013355