Data Processing Agreement (DPA)
Scope of Agreement:
This Data Processing Agreement ("DPA") supplements the Johnson Softwares Master Subscription Agreement ("Agreement") entered into by and between Johnson Softwares ("Data Processor") and the Customer ("Data Controller"). It governs the processing of personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and equivalent international privacy frameworks.
1. Roles and Processing Instructions
The Customer acts as Data Controller for all customer, prospect, and patient information entered into their CRM instance. Johnson Softwares processes personal data solely on documented instructions from the Controller, specifically to provide automated speed-to-lead routing, Meta WhatsApp messaging, and pipeline intelligence.
2. Single-Tenant Data Isolation & Security
Each client deployment is provisioned in a dedicated, isolated database container. Johnson Softwares maintains strict organizational and technical measures (TOMs), including AES-256 encryption at rest, TLS 1.3 encryption in transit, role-based access control (RBAC), and automated hourly WAL integrity checkpoints.
3. Sub-Processors
The Controller authorizes Johnson Softwares to engage vetted sub-processors essential for service delivery:
- Hostinger / DigitalOcean: Cloud infrastructure and virtual server hosting (Frankfurt / Bangalore data centers).
- Meta Platforms, Inc. (WhatsApp Cloud API): End-to-end messaging delivery.
- Twilio / Exotel: Telephony and outbound SMS delivery gateways.
- Razorpay / Stripe: Payment verification and billing tokenization.
4. Data Subject Rights & Incident Notification
Johnson Softwares provides the Controller with technical capabilities to export, rectify, or permanently delete personal data upon request (Right of Erasure). In the event of a confirmed security incident affecting personal data, Johnson Softwares will notify the Controller without undue delay within seventy-two (72) hours of becoming aware of the breach.
5. International Transfers & Standard Contractual Clauses
Where personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside these territories, the parties agree to abide by the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor).