---
title: "Data Processing Agreement (DPA)"
description: "Data Processing Agreement for unLocked CRM by unLocked CRM LLC. GDPR Article 28 compliant DPA covering data processing, security measures, and sub-processors."
url: https://unlockedcrm.ai/dpa
canonical: https://unlockedcrm.ai/dpa
updated: 2026-08-31
last_updated: 2026-08-31
author: "Jacob Lock"
publisher: unLocked CRM
source_url: https://unlockedcrm.ai/dpa
summary: "Data Processing Agreement for unLocked CRM by unLocked CRM LLC. GDPR Article 28 compliant DPA covering data processing, security measures, and sub-processors."
license: Citation permitted with attribution and a link to https://unlockedcrm.ai/dpa
source: unLocked CRM — AI CRM for insurance agents
---

# Data Processing Agreement (DPA)

Data Processing Agreement for unLocked CRM by unLocked CRM LLC. GDPR Article 28 compliant DPA covering data processing, security measures, and sub-processors.

Full page: https://unlockedcrm.ai/dpa

## Data Processing Agreement

Last Updated: February 20, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between unLocked CRM LLC ("Processor," "we," "our," or "us") and the entity or individual subscribing to unLocked CRM ("Controller," "you," or "your"). This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of unLocked CRM (the "Service").

This DPA is designed to comply with the requirements of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act ("CCPA"), the California Privacy Rights Act ("CPRA"), and other applicable data protection laws.

## 1. Definitions

- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller in connection with the Service.
- "Processing" means any operation or set of operations performed on Personal Data, whether automated or not, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

## 2. Scope & Purpose of Processing

The Processor shall process Personal Data only as necessary to provide the Service and as documented in the Controller's instructions. The details of processing are as follows:

- Subject Matter: Provision of unLocked CRM, including contact management, communications, policy tracking, quoting, AI-assisted features, and related insurance business tools.
- Duration: For the duration of the Agreement, plus any retention period required by law or as specified in the Terms of Service.
- Nature & Purpose: Storage, retrieval, organization, and transmission of Personal Data to enable CRM functionality, automated communications, lead management, and analytics.
- Categories of Data Subjects: Clients' customers, leads, prospects, policyholders, and beneficiaries.
- Types of Personal Data: Names, email addresses, phone numbers, mailing addresses, dates of birth, policy details, health plan selections, licensing information, and other data uploaded by the Controller.

## 3. Controller Obligations

The Controller represents and warrants that:

- It has a lawful basis for processing Personal Data and has obtained all necessary consents or authorizations from Data Subjects.
- It has provided all required notices to Data Subjects regarding the processing of their data, including disclosure of the Processor's involvement.
- All Personal Data provided to the Processor is accurate, complete, and lawfully collected.
- It shall comply with all applicable data protection laws, including GDPR, CCPA/CPRA, HIPAA, TCPA, and CMS regulations, as applicable to its use of the Service.
- It is solely responsible for the content, accuracy, and legality of all Personal Data uploaded to or stored in the Service.

## 4. Processor Obligations

The Processor shall:

- Process Personal Data only on documented instructions from the Controller, unless required by applicable law (in which case the Processor shall inform the Controller of such requirement before processing, unless prohibited by law).
- Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement and maintain appropriate technical and organizational measures to protect Personal Data as described in Section 6.
- Assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, and objection) to the extent technically feasible.
- Assist the Controller in ensuring compliance with its obligations regarding data protection impact assessments and prior consultation with supervisory authorities, where required.
- At the Controller's choice, delete or return all Personal Data upon termination of the Agreement, unless retention is required by applicable law.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections as described in Section 9.

## 5. Sub-processors

The Controller provides general authorization for the Processor to engage Sub-processors. The Processor shall:

- Maintain an up-to-date list of Sub-processors, available upon request and listed below.
- Notify the Controller of any intended changes to Sub-processors at least 30 days in advance, providing the Controller an opportunity to object.
- Enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA.
- Remain fully liable to the Controller for the performance of each Sub-processor's obligations.

Current Sub-processors:

## 6. Security Measures

The Processor shall implement and maintain appropriate technical and organizational security measures, including but not limited to:

- Encryption: AES-256 encryption for data at rest; TLS 1.2+ encryption for data in transit.
- Access Controls: Role-based access controls (RBAC), multi-factor authentication for administrative access, and principle of least privilege.
- Data Isolation: Multi-tenant architecture with logical data separation to prevent cross-tenant access.
- Monitoring & Logging: Continuous security monitoring, intrusion detection, and audit logging of access to Personal Data.
- Backup & Recovery: Regular automated backups with encryption and documented disaster recovery procedures.
- Employee Security: Background checks, security awareness training, and confidentiality agreements for all personnel with access to Personal Data.
- Vulnerability Management: Regular vulnerability assessments, patch management, and secure software development practices.
- Physical Security: Data hosted in SOC 2 Type II certified data centers with physical access controls, surveillance, and environmental protections.

## 7. Data Breach Notification

In the event of a Data Breach, the Processor shall:

- Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of the Data Breach.
- Provide the Controller with sufficient information to enable the Controller to meet its obligations to notify supervisory authorities and Data Subjects, including: The nature of the Data Breach, including the categories and approximate number of Data Subjects and records concerned.
- The likely consequences of the Data Breach.
- The measures taken or proposed to address the Data Breach, including measures to mitigate possible adverse effects.
- Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.
- Document all Data Breaches, including the facts, effects, and remedial actions taken.

## 8. International Data Transfers

The Processor shall not transfer Personal Data to a country outside the United States or the European Economic Area (EEA) without ensuring appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms as required by applicable data protection law. Where SCCs apply, they are incorporated into this DPA by reference.

## 9. Audits & Inspections

The Processor shall make available to the Controller, upon reasonable request and subject to confidentiality obligations:

- Information reasonably necessary to demonstrate compliance with the obligations set out in this DPA.
- The right to conduct audits or inspections (or appoint an independent third-party auditor) with at least 30 days' prior written notice, during normal business hours, and no more than once per calendar year (unless required by a supervisory authority or following a Data Breach).
- Relevant certifications, audit reports, or summaries of independent security assessments (e.g., SOC 2 Type II reports) as an alternative to on-site audits where reasonably sufficient.

## 10. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests, including:

- Access: Providing the Controller with the ability to access, export, and retrieve Personal Data stored in the Service.
- Rectification: Enabling the Controller to correct inaccurate Personal Data within the Service.
- Erasure: Deleting Personal Data upon the Controller's documented request, subject to legal retention obligations.
- Portability: Exporting Personal Data in a structured, commonly used, and machine-readable format.
- Restriction & Objection: Implementing technical measures to restrict processing upon request where technically feasible.

If the Processor receives a request directly from a Data Subject, it shall promptly notify the Controller and shall not respond to the request directly unless authorized to do so.

## 11. Data Retention & Deletion

Upon termination or expiration of the Agreement, the Processor shall, at the Controller's election, delete or return all Personal Data within 30 days and delete all existing copies, unless applicable law requires retention. The Processor shall provide written confirmation of deletion upon request.

## 12. CCPA/CPRA Specific Terms

To the extent the CCPA/CPRA applies, the Processor certifies that it:

- Shall not sell or share Personal Data received from the Controller.
- Shall not retain, use, or disclose Personal Data for any purpose other than performing the Service, unless otherwise permitted by applicable law.
- Shall not combine Personal Data received from the Controller with Personal Data received from other sources, except as permitted to perform the Service.
- Shall comply with all applicable CCPA/CPRA obligations and shall allow the Controller to take reasonable steps to ensure the Processor uses Personal Data in a manner consistent with the Controller's obligations.

## 13. Liability & Indemnification

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. The Controller shall indemnify and hold the Processor harmless from any claims, damages, or losses arising from the Controller's breach of its obligations under this DPA or applicable data protection laws.

## 14. HIPAA & Protected Health Information

The Processor is HIPAA-compliant and will execute a Business Associate Agreement (BAA) with Controllers that are covered entities or business associates under the Health Insurance Portability and Accountability Act (HIPAA). The Service is administered with the administrative, physical, and technical safeguards required to handle Protected Health Information (PHI).

- The Processor will sign a Business Associate Agreement (BAA) upon request and provide the PHI handling obligations described therein.
- If the Controller is a HIPAA-covered entity or business associate, a signed BAA must be in place before uploading any PHI to the Service. Absent an executed BAA, the Controller must not upload PHI.
- To request a BAA, contact info@unlockedcrm.ai prior to uploading any PHI to the Service.
- Where a BAA is executed, it governs all PHI and controls over any conflicting term in this Agreement or the Privacy Policy. The order of precedence is: (1) BAA, (2) this Data Processing Agreement, (3) the Privacy Policy.

## 15. TCPA & Communications Compliance

The Service provides communication tools including SMS, voice, and email capabilities. With respect to Personal Data processed through these features:

- The Controller is solely responsible for obtaining and maintaining all required consents from Data Subjects before initiating communications, in compliance with the Telephone Consumer Protection Act (TCPA), CAN-SPAM Act, and applicable state laws.
- The Controller shall maintain records of all consents obtained and make them available to the Processor upon request.
- The Processor provides A2P 10DLC registration and compliance tools to assist the Controller, but regulatory compliance for outbound communications remains the Controller's responsibility.
- The Controller shall maintain and honor opt-out and do-not-call requests in accordance with applicable law.

## 16. Term & Termination

This DPA shall remain in effect for the duration of the Agreement and shall automatically terminate upon termination or expiration of the Agreement, except for obligations that by their nature survive termination (including Sections 7, 9, 11, and 13). In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to data processing matters.

## 17. Amendments to This DPA

The Processor may update this DPA from time to time to reflect changes in legal requirements, processing activities, or security practices. Material changes will be communicated to the Controller at least 30 days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the updated DPA. If the Controller does not agree to the revised DPA, it may terminate the Agreement in accordance with the Terms of Service.

## 18. Governing Law & Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the State of Indiana, without regard to its conflict of law provisions, consistent with the Agreement. For Data Subjects in the European Economic Area, the mandatory provisions of the GDPR shall apply regardless of governing law.

## 19. Contact Us

For questions or requests related to this DPA, please contact us:

📧 Data Protection & general inquiries: info@unlockedcrm.ai

## About unLocked CRM

unLocked CRM is an AI-powered insurance CRM built specifically for insurance agents, agencies, IMOs, and FMOs. It combines AI quoting across 1,252 carrier integrations, commission tracking from 332 carrier feeds, AI calling and texting, policy and licensing management, and compliance automation in a single platform starting at $69 per month.

- 1,252 carrier integrations (113 life and annuity, 1,139 health)
- Commission tracking across 332 carrier connections, including downline hierarchies
- AI quoting, AI outbound calling, and the Arwyn inbound AI receptionist
- 14-day free trial, 100% US-based support
- Phone: (877) 761-4369 — Website: https://unlockedcrm.ai

---

Source: [Data Processing Agreement (DPA)](https://unlockedcrm.ai/dpa) — unLocked CRM. Citation permitted with attribution and a link to https://unlockedcrm.ai/dpa.
