1. Incorporation, Scope, and Roles
This Data Protection Attachment (the "DPA") is incorporated into and made part of the BROSH Terms and Conditions at /page/Terms-and-Conditions and any agreement, order form, subscription, or written addendum that references those terms (the "Agreement").
This DPA governs the Processing of Personal Data by ZAAPIT AS LTD doing business as BROSH ("BROSH", "ZaapIT", "Company", "we", "us", or "our") as a Processor on behalf of Customer or Customer Affiliates, as applicable, in connection with BROSH CRM and related services. Unless this DPA defines a capitalized term differently, capitalized terms have the meanings given to them in the Agreement.
Customer acts as Controller, or as Processor for its own customers, for Personal Data submitted to or Processed through the service. BROSH acts as Processor for that Personal Data only to the extent BROSH Processes it on Customer instructions and for purposes of providing, securing, supporting, maintaining, and administering the service under the Agreement.
If Customer uses the service on behalf of Customer Affiliates or permits Customer Affiliates to submit Personal Data, Customer represents that it is authorized to give instructions, receive notices, make decisions, and exercise rights under this DPA on behalf of those Customer Affiliates. Customer remains responsible for coordinating all DPA communications with BROSH.
2. Definitions
The terms "Personal Data", "Personal Data Breach", "Process", "Processing", "Controller", "Processor", "Subprocessor", and "Data Subject" have the meanings ascribed to them under Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), provided that "Personal Data" as used in this DPA applies only to Personal Data for which BROSH is a Processor.
| Term | Meaning |
|---|---|
| EEA | The European Economic Area. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, concerning protection of natural persons with regard to the processing of personal data and the free movement of such data. |
| Processor Privacy Code / Processor Code | ZaapIT's processor privacy code or other processor data-protection rules, policies, or transfer terms made available by ZaapIT on its website, including through /page/Terms-and-Conditions or another posted legal or security page. |
| Services / service | BROSH CRM and related websites, applications, APIs, add-ons, support, hosting, security, maintenance, and other services provided under the Agreement. |
| Customer Affiliate | An entity that controls, is controlled by, or is under common control with Customer and whose Personal Data is Processed through the service under Customer's account or instructions. |
References to the Agreement include the Terms and Conditions, this DPA, any applicable order form, security policy, support policy, privacy-related attachment, product documentation, and written amendment accepted by BROSH.
3. Data Processing and Protection of Personal Data
3.1 Scope of Processing. The duration of BROSH Processing of Personal Data is the duration of the Agreement, except as otherwise agreed by the parties in writing or required by applicable law, backup retention, security, dispute, or legal-hold obligations. The subject matter of Processing is Customer use of the service. The nature and purpose of Processing are the provision, operation, maintenance, security, support, improvement, and administration of the service for Customer, as described in the Agreement and this DPA.
| Processing detail | Description |
|---|---|
| Subject matter | Personal Data submitted to, generated in, stored in, transmitted through, or otherwise Processed by BROSH CRM for Customer. |
| Nature | Hosting, storage, retrieval, transmission, display, organization, CRM record management, support, security monitoring, maintenance, backup, deletion, and related technical operations. |
| Purpose | To provide the service to Customer in accordance with the Agreement and Customer's documented instructions. |
| Duration | The term of the Agreement plus any period needed for legal compliance, backup cycles, security, dispute handling, or return/deletion obligations. |
3.2 Processing Limitations. With respect to Personal Data Processed by BROSH or a BROSH Affiliate as Processor on behalf of Customer or Customer Affiliate, or as Subprocessor where Customer Processes such Personal Data on behalf of its own customers, BROSH will Process Personal Data only as necessary to provide the service in accordance with the Agreement, this DPA, and Customer documented instructions, including instructions provided electronically through the service.
- BROSH will not disclose Personal Data to third parties except to employees, affiliates, contractors, service providers, Subprocessors, or professional advisers who need to know the Personal Data for purposes consistent with the Agreement and are subject to confidentiality obligations at least as protective as those described in this DPA.
- BROSH may disclose Personal Data where required to comply with valid legal process, applicable law, court order, governmental request, or regulatory obligation, subject to the notice and confidentiality protections available under the Agreement and applicable law.
- If BROSH has reason to believe that Customer instructions infringe the GDPR or other EEA data-protection provisions, BROSH will notify Customer without undue delay, unless legally prohibited from doing so.
3.3 Assistance to Customer and Regulatory Investigations. Upon written request, and taking into account the nature of Processing and the information available to BROSH, BROSH will provide reasonable assistance and information to Customer in fulfilling Customer legal obligations under the GDPR regarding data protection impact assessments, data and systems inventories, consultations with data-protection authorities, and investigations by governmental authorities, if and to the extent the request relates to Personal Data Processed by BROSH in accordance with the Agreement.
Such assistance will be provided at Customer sole expense, except where the investigation, assessment, or required assistance results from BROSH failure to act in accordance with the Agreement or this DPA. BROSH may charge Customer at then-current professional-service rates for assistance that exceeds standard product functionality or support.
4. Transfers of Personal Data from the EEA
In providing the service, BROSH may transfer, access, store, or Process Personal Data in countries where BROSH, BROSH Affiliates, hosting providers, support personnel, or Subprocessors operate, or as otherwise required by applicable law. This may include transfers to or from countries outside the EEA.
Where Personal Data is subject to restrictions under the GDPR or other applicable EEA data-protection laws regarding outbound transfers of Personal Data and is Processed by BROSH in a country outside the EEA, BROSH will use a lawful transfer mechanism to the extent required by applicable law. Such mechanism may include an adequacy decision, the Processor Code, Standard Contractual Clauses, supplementary measures, or another transfer mechanism recognized under applicable data-protection law.
The most current version of the Processor Code or applicable transfer terms may be made available on the BROSH website, currently through /page/Terms-and-Conditions, /page/Security-Policy, or another page designated by BROSH. The applicable terms are incorporated by reference into this DPA to the extent they apply to the relevant Processing.
BROSH will make commercially reasonable efforts to maintain the applicable Processor Code, transfer terms, or replacement transfer mechanism for the duration of the Agreement and will notify Customer of material changes that materially affect the lawful transfer of Personal Data under this DPA.
5. Customer Responsibilities
Customer is responsible for properly implementing access controls, user permissions, authentication settings, integrations, exports, deletion settings, backup practices, and other configuration choices for the service. Customer must configure and use the service in a manner Customer deems adequate to maintain appropriate security, protection, deletion, retention, and backup of Personal Data.
Customer is responsible for providing all notices, obtaining all consents, maintaining all lawful bases, honoring all opt-out and data-subject requests, and complying with all laws that apply to Customer collection, submission, use, disclosure, and Processing of Personal Data through the service.
BROSH is entitled to rely on instructions relating to Personal Data from Customer, Customer Affiliates, Customer account administrators, and other persons using Customer credentials or administrative authority, unless BROSH knows that an instruction is unauthorized. Customer must keep account, administrator, billing, and legal-contact information accurate and current.
Customer is responsible for coordinating all communications with BROSH under this DPA, including communications made on behalf of Customer Affiliates and Customer own customers where Customer acts as Processor.
6. Information Security and Audit
BROSH will safeguard Personal Data using appropriate technical, physical, and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure, as described in the Processor Code, Security Policy, Agreement, or other applicable BROSH security documentation.
Security measures may include access controls, authentication controls, personnel confidentiality obligations, hosting safeguards, logging, monitoring, encryption or equivalent protections where appropriate, backup practices, vulnerability management, and incident-response procedures, taking into account the nature, scope, context, and purpose of Processing.
The parties agree that the audit, security-review, documentation, and inspection rights provided under the Processor Code, Agreement, Security Policy, and applicable law will be used to satisfy any audit or inspection requests by or on behalf of Customer and to demonstrate BROSH compliance with applicable obligations under this DPA. Customer must exercise audit rights in a manner that avoids unreasonable disruption, protects BROSH and third-party confidential information, and does not compromise service security.
7. Personal Data Breach and Data Privacy Contact
BROSH will notify Customer without undue delay after BROSH becomes aware of a Personal Data Breach affecting Personal Data Processed by BROSH under this DPA. Notice may be provided by email, account notice, support notice, or another reasonable communication method.
Taking into account the nature of Processing and the information available to BROSH, BROSH will provide reasonable information and assistance at Customer request and Customer expense to help Customer comply with Customer notification obligations regarding Personal Data Breaches under the GDPR, except to the extent the Personal Data Breach resulted from BROSH failure to comply with this DPA.
BROSH notice of or response to a Personal Data Breach is not an admission of fault, liability, or violation. Customer remains responsible for determining whether notification to Data Subjects, regulators, customers, or other parties is required.
BROSH data privacy contact may be reached at support@brosh.io.
8. Data Subject Rights: Access, Correction, Restriction, and Deletion
Taking into account the nature of Processing, the service provides functionality designed to assist Customer, by appropriate technical and organizational measures insofar as possible, to access, correct, amend, restrict, export, or delete Personal Data contained in BROSH applications in response to requests by Data Subjects under the GDPR.
If Customer is not familiar with BROSH functionality that may be used for these purposes, BROSH may provide documentation or customer-support assistance to educate Customer on how to take such actions in a manner consistent with service functionality and the Agreement. Assistance beyond standard product functionality or support may be charged at BROSH then-current rates.
If BROSH receives a request from a Data Subject to access, correct, restrict, delete, or otherwise exercise rights with respect to Personal Data for which Customer is Controller, BROSH will, where legally permitted and reasonably identifiable as Customer data, advise the Data Subject to submit the request to Customer. Customer is responsible for responding to such requests using the functionality provided with the service.
BROSH is not responsible for determining the validity, legal basis, scope, timing, or proper response to a Data Subject request directed to Customer. BROSH may decline to act on direct Data Subject instructions where Customer is responsible for the Personal Data.
9. Subprocessors
BROSH may engage Subprocessors to provide parts of the service, subject to the restrictions of the Agreement and this DPA. BROSH will ensure that Subprocessors Process Personal Data only in accordance with this DPA and are bound by written agreements requiring them to provide at least the level of data protection required by this DPA.
Before appointing any new Subprocessor, BROSH will inform Customer of the appointment, including the name and location of the Subprocessor and the activities it will perform, either by electronic mail or by publication to a BROSH website, currently including /page/Security-Policy, prior to the appointment.
Customer may object to BROSH appointment of a new Subprocessor by giving written notice to BROSH within thirty (30) days after being informed of the appointment. Customer objection must explain the reasonable data-protection grounds for the objection.
If, within thirty (30) days after BROSH receipt of Customer objection, BROSH fails to provide a commercially reasonable alternative to avoid Processing of Personal Data by the appointed Subprocessor, Customer may, as its sole and exclusive remedy, terminate the affected BROSH services to which this DPA applies. Customer remains responsible for all fees incurred before the effective date of termination, unless the Agreement expressly states otherwise.
10. Return or Disposal of Personal Data
Before termination or expiration of the Agreement for any reason, Customer may retrieve Personal Data Processed by BROSH in accordance with the Agreement and available service functionality. Customer is responsible for exporting Personal Data before access ends.
At Customer written request provided to BROSH before termination or expiration, and subject to applicable law, technical feasibility, backup cycles, security obligations, and the Agreement, BROSH will promptly return or delete Personal Data from BROSH systems unless applicable law requires storage of the Personal Data.
BROSH may retain copies of Personal Data in backups, logs, archives, legal-hold systems, security records, and business-continuity systems until such copies are overwritten or deleted in accordance with BROSH ordinary retention practices, provided that retained copies remain protected under this DPA.
11. Governing Law, Jurisdiction, and Dispute Terms
The Agreement and this DPA are governed by the laws of Israel, without regard to conflict-of-law rules, and will not be governed by the United Nations Convention on Contracts for the International Sale of Goods. Exclusive venue for all disputes arising out of or relating to the Agreement or this DPA will be in Tel Aviv, Israel, unless mandatory law requires otherwise.
Each party agrees not to bring an action in any other venue, waives objections to venue, and agrees not to dispute personal jurisdiction or venue in those courts, except where such waiver is prohibited by mandatory law. Customer agrees that it will not bring or participate in any class action lawsuit against ZaapIT, BROSH, or any of their employees, officers, directors, affiliates, licensors, or service providers.
Each party agrees that it will not bring a claim under the Agreement or this DPA more than two (2) years after the time the claim accrued, except where a longer period is required by mandatory law. The provisions of this DPA concerning confidentiality, security, return or deletion, liability, governing law, venue, and any provisions that by their nature should survive will survive expiration or termination.
