Data Processing Addendum
Last updated July 3, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”, acting as data controller) and Crane (acting as data processor) and governs Crane’s processing of personal data on the Customer’s behalf in connection with the Service.
1. Definitions
“Personal Data”, “Data Controller”, “Data Processor”, “Data Subject”, and “Processing” have the meanings given in applicable data-protection law, including the GDPR and the UK GDPR. “Customer Personal Data” means personal data that Crane processes on the Customer’s behalf under the Service.
2. Roles and scope
The Customer is the controller and Crane is the processor of Customer Personal Data. Crane processes Customer Personal Data only on the Customer’s documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law.
3. Nature and purpose of processing
- Subject matter: provision of the B2B outreach Service.
- Duration: the term of the Terms, plus any legally required retention.
- Nature and purpose: sourcing, enrichment, storage, sequencing, sending, and reply management of business-contact data.
- Data subjects: the Customer’s prospects and business contacts, and the Customer’s users.
- Data categories: business-contact details (name, title, employer, business email), campaign content, and reply content.
4. Confidentiality
Crane ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
5. Security measures
Crane implements and maintains appropriate technical and organizational measures to protect Customer Personal Data, including encryption in transit, access controls, tenant isolation, and logging, taking into account the state of the art and the risks of processing.
6. Sub-processors
The Customer authorizes Crane to engage sub-processors (such as cloud hosting, email delivery, and data-enrichment providers) to process Customer Personal Data. Crane imposes data-protection obligations on its sub-processors that are no less protective than those in this DPA and remains responsible for their performance. Crane will provide notice of material changes to its sub-processors.
7. Data-subject requests
Crane will, taking into account the nature of the processing, assist the Customer by appropriate measures in responding to requests from data subjects to exercise their rights. Where Crane receives such a request directly, it will refer the data subject to the Customer, except for opt-out requests, which Crane processes automatically via suppression as described in our unsubscribe information.
8. Personal-data breaches
Crane will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably necessary for the Customer to meet its own notification obligations.
9. International transfers
Where Crane transfers Customer Personal Data outside the EEA, UK, or other regulated regions, it does so using an appropriate transfer mechanism, such as the applicable standard contractual clauses.
10. Deletion and return
Upon termination of the Service, and at the Customer’s choice, Crane will delete or return Customer Personal Data, except where retention is required by law (for example, suppression records maintained to honor opt-outs).
11. Audits
Crane will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality and security controls.
12. Contact
To request a signed copy of this DPA or ask questions, contact privacy@crane.app.