Data Processing Addendum

Legal review required. This document is a draft prepared for review by qualified legal counsel and does not constitute legal advice. Remove this notice only after counsel approves the document.

Effective date: July 19, 2026   Last updated: July 19, 2026

In short

This DPA describes how SimpleGrowHQ processes Customer-controlled rep and sales data, the safeguards it uses, its approved subprocessors, and how it assists Customers with privacy obligations.

Product
SimpleGrowHQ
Founder / operator
Ashkan Alasvand
Privacy and legal contact
privacy@simplegrowhq.com

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the Customer Agreement. Customer is the controller or business for Customer-supplied rep, sales, commission, and operational personal data. SimpleGrowHQ is the processor or service provider and will process that data only on Customer’s documented instructions, including instructions in the Agreement and use of the Services.

2. Processing details

Subject matter: providing SimpleGrowHQ dashboards, imports, reports, AI features, goals, RGU pacing, commission tools, security, and support. Duration: the subscription term plus the agreed export and deletion period. People: Customer employees, reps, managers, administrators, and business contacts. Data: account identifiers, work contact data, roles, sales, RGUs, goals, locations, commission rates and amounts, logs, device information, and AI-feature inputs.

3. Processor obligations

SimpleGrowHQ will process personal data only on documented instructions unless law requires otherwise; ensure authorized personnel are bound by confidentiality; use reasonable security measures; notify Customer if an instruction appears unlawful; and provide reasonable assistance with data-subject requests, impact assessments, regulator consultations, and compliance information, considering the nature of processing.

4. Security measures

Measures include company-scoped row-level security, authentication, MFA for privileged actions, encryption in transit, provider-managed encryption at rest, secret storage for privileged keys, least-privilege operator access, and API/AI rate limiting. These are practices, not claims of SOC 2, ISO 27001, HIPAA, or PCI-DSS certification.

5. Subprocessors

Customer authorizes Supabase, Cloudflare, Hostinger, Stripe, Anthropic (Claude API), Titan Email, Resend, and Google Analytics/Google Site Kit for the purposes described in the Privacy Policy. SimpleGrowHQ remains responsible for applicable processor obligations and will provide reasonable advance notice of a material new subprocessor by email, in-product notice, or an updated list, allowing Customer to raise a reasonable data-protection objection.

6. Security incidents

After confirming a personal-data breach affecting Customer Data, SimpleGrowHQ will notify Customer without undue delay and within the timing required by applicable law and the applicable agreement where feasible. Notice will include available information about the event, likely effects, affected data, mitigation, and a contact point. Notice is not an admission of fault.

7. Return and deletion

On termination, Customer may export Customer Data for the period available under the applicable plan or agreement. SimpleGrowHQ will delete or return remaining Customer Data within the period stated in the applicable retention policy, unless applicable law requires limited retention.

8. Audits

On reasonable written request and subject to confidentiality, SimpleGrowHQ will provide information reasonably necessary to demonstrate compliance. Audits must avoid unnecessary disruption, protect other customers, and normally occur no more than annually unless a regulator or confirmed incident reasonably requires more.

9. International transfers

International-transfer terms apply only when legally required. When legally required, the parties will use applicable Standard Contractual Clauses, the UK Addendum, an adequacy mechanism, or another valid transfer method. The applicable module and party details must be completed with counsel before relying on this DPA for regulated international transfers.

10. Conflict and contact

If this DPA conflicts with the Customer Agreement on personal-data processing, this DPA controls. Governing law and dispute terms follow the Customer Agreement unless applicable privacy law requires otherwise. Privacy contact: privacy@simplegrowhq.com.