Data Processing Addendum
The terms that govern how Sales Day processes Customer Personal Data as a processor.
Effective date: 1 July 2026
Last updated: 1 July 2026
This Data Processing Addendum forms part of the Sales Day Terms of Service or any other agreement governing the Customer's use of Sales Day.
1. Parties
This Data Processing Addendum is entered into between:
- the Customer identified in the applicable Sales Day Account, Order or agreement; and
- Sales Day Software Ltd, company number NI740756, whose registered office is at 15 Kerrsland Drive, Belfast, BT5 6ER, United Kingdom.
The Customer and Sales Day are each a Party and together the Parties.
2. Purpose and scope
This Addendum applies where Sales Day processes Personal Data on behalf of the Customer in connection with the Service.
It governs Customer Personal Data entered into, stored within, generated through or otherwise processed using Sales Day, including personal data contained in:
- Accounts;
- Contacts;
- Leads;
- Deals;
- Tasks;
- Meetings;
- notes;
- comments;
- activities;
- notifications;
- imports;
- exports;
- calendar integrations;
- Team Workspaces; and
- related CRM records.
This Addendum does not govern personal data for which Sales Day acts as an independent controller, including personal data processed for:
- Account administration;
- authentication;
- Subscription and billing management;
- customer support;
- security;
- fraud and misuse prevention;
- legal compliance;
- service communications; and
- Sales Day's own business administration.
Sales Day's controller processing is described in the Sales Day Privacy Notice.
3. Relationship with the Terms
This Addendum forms part of the Sales Day Terms of Service.
Capitalised terms not defined in this Addendum have the meanings given in the Terms.
If there is a conflict between this Addendum and the Terms concerning the processing of Customer Personal Data, this Addendum takes priority.
If the Parties have entered into a separately signed agreement containing data-processing terms, that agreement will take priority to the extent of any direct conflict.
4. Definitions
In this Addendum:
Applicable Data Protection Law means any data-protection or privacy law applying to the relevant processing, including, where applicable:
- the UK GDPR;
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations 2003;
- the EU GDPR; and
- any legislation amending, replacing or supplementing them.
Controller, Data Subject, Personal Data, Personal Data Breach, Processing, Processor and Supervisory Authority have the meanings given in Applicable Data Protection Law.
Customer Personal Data means Personal Data contained within Customer Data that Sales Day processes on behalf of the Customer.
Customer Data has the meaning given in the Terms.
Data Subject Request means a request by a Data Subject to exercise a right under Applicable Data Protection Law.
Instructions means the Customer's documented instructions for Processing Customer Personal Data, including:
- this Addendum;
- the Terms;
- an Order;
- the Customer's use and configuration of the Service;
- actions taken through authorised Accounts;
- instructions submitted through support; and
- any further written instruction agreed by the Parties.
Restricted Transfer means a transfer of Personal Data that requires an approved safeguard under Applicable Data Protection Law.
Subprocessor means a third party engaged by Sales Day to Process Customer Personal Data on behalf of the Customer.
UK GDPR means the retained and amended form of Regulation (EU) 2016/679 that applies in the United Kingdom.
5. Roles of the Parties
5.1 Customer as controller
Where the Customer determines the purposes and means of Processing Customer Personal Data:
- the Customer is the Controller; and
- Sales Day is the Processor.
5.2 Customer as processor
Where the Customer processes Personal Data on behalf of another Controller:
- the Customer is a Processor;
- Sales Day is the Customer's Subprocessor; and
- the Customer confirms that the relevant Controller has authorised the Customer to appoint Sales Day.
References in this Addendum to the Customer's obligations as Controller apply to the Customer as necessary to ensure compliance with its own controller–processor agreement.
5.3 Sales Day as independent controller
Sales Day may separately act as Controller for Account, billing, support, security, legal and operational data.
That independent Controller processing is outside the scope of this Addendum.
6. Customer instructions
6.1 Documented instructions
Sales Day will Process Customer Personal Data only:
- on the Customer's documented Instructions;
- as necessary to provide, secure, maintain and support the Service;
- as described in this Addendum and the Terms; or
- where required by applicable law.
The Customer's use and configuration of the Service constitutes Instructions to Sales Day.
6.2 Required processing by law
Where Sales Day is legally required to Process Customer Personal Data other than on the Customer's Instructions, Sales Day will inform the Customer before Processing unless the law prohibits such notification.
6.3 Unlawful instructions
Sales Day will notify the Customer if, in Sales Day's reasonable opinion, an Instruction infringes Applicable Data Protection Law.
Sales Day may suspend the affected Processing until the Parties have resolved the issue.
Sales Day is not required to obtain independent legal advice concerning Customer Instructions.
6.4 Additional instructions
Instructions materially outside the scope of the Service may require:
- technical assessment;
- additional fees;
- a separate written agreement; or
- a reasonable implementation period.
Sales Day is not required to follow an instruction that would:
- breach law;
- compromise security;
- adversely affect another Customer;
- require material development outside the Service;
- conflict with the Terms; or
- impose disproportionate cost or operational burden.
7. Customer responsibilities
The Customer is responsible for:
- complying with Applicable Data Protection Law;
- ensuring it has a lawful basis for Processing Customer Personal Data;
- providing required privacy information to Data Subjects;
- obtaining any required consents or authorisations;
- ensuring Customer Personal Data is accurate, relevant and lawful;
- ensuring it has authority to disclose Customer Personal Data to Sales Day;
- issuing lawful and proportionate Instructions;
- configuring Workspace permissions appropriately;
- controlling which Users can access Customer Personal Data;
- removing Users who no longer require access;
- reviewing connected integrations;
- responding to Data Subject Requests;
- complying with direct-marketing and electronic-communications laws;
- exporting Customer Personal Data where needed for continuity or retention;
- avoiding use of the Service for prohibited or unsupported sensitive information; and
- ensuring that its use of Sales Day does not infringe another person's rights.
The Customer acknowledges that Sales Day does not generally review Customer Data to determine whether the Customer's Processing is lawful.
8. Details of Processing
The subject matter, duration, nature and purpose of Processing, categories of Personal Data and categories of Data Subjects are described in Annex 1.
The Parties agree that Annex 1 satisfies the requirement to describe the Processing covered by this Addendum.
9. Confidentiality and personnel
Sales Day will ensure that personnel authorised to Process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive access only where reasonably necessary;
- are informed of relevant data-protection and security responsibilities; and
- Process Customer Personal Data only in accordance with Sales Day's obligations and the Customer's Instructions.
Sales Day will take reasonable steps to ensure the reliability of personnel who may access Customer Personal Data.
10. Security
10.1 Appropriate measures
Taking into account:
- the state of the art;
- implementation costs;
- the nature, scope, context and purposes of Processing; and
- the risks to Data Subjects,
Sales Day will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data.
The current measures are described in Annex 2.
10.2 Platform-dependent controls
Some security, hosting, authentication, encryption, resilience and backup controls are provided by Sales Day's platform and infrastructure providers.
Sales Day will select and use such providers subject to appropriate contractual and data-protection arrangements.
Sales Day does not guarantee that any security measure will prevent every incident.
10.3 Customer security responsibilities
The Customer is responsible for:
- securing User credentials;
- controlling Workspace membership;
- applying appropriate roles and permissions;
- maintaining secure devices and networks;
- reviewing integrations;
- protecting exported files;
- maintaining any additional backup or business-continuity measures it requires; and
- notifying Sales Day promptly of suspected compromise.
10.4 Security information
Sales Day may provide additional security information through:
- the Security and Data Protection Overview;
- support responses;
- contractual documentation;
- provider documentation; or
- other reasonable means.
Security information may be subject to confidentiality restrictions.
11. Personal Data Breaches
11.1 Notification
Sales Day will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Notification will be sent to:
- the Customer's Account owner;
- billing owner;
- nominated administrator; or
- another contact reasonably identified by the Customer.
11.2 Information provided
To the extent reasonably available, the notification will include:
- the nature of the Personal Data Breach;
- affected categories of Personal Data;
- affected categories or approximate number of Data Subjects;
- likely consequences;
- measures taken or proposed;
- mitigation actions;
- relevant contact information; and
- additional information reasonably required for the Customer's assessment.
Information may be provided in stages where it is not available at the same time.
11.3 Cooperation
Sales Day will provide reasonable assistance to help the Customer comply with applicable breach-notification obligations, taking into account:
- the nature of Processing;
- information available to Sales Day; and
- the Customer's ability to access relevant information itself.
11.4 No admission
Notification of a Personal Data Breach does not constitute an admission of fault or liability.
11.5 Customer incidents
The Customer must notify Sales Day promptly if the Customer becomes aware of:
- compromised credentials;
- unauthorised Workspace access;
- misuse of an integration;
- accidental disclosure through Customer actions; or
- another incident that may affect the security of the Service or Customer Personal Data.
12. Data Subject Requests
12.1 Customer responsibility
The Customer is responsible for responding to Data Subject Requests concerning Customer Personal Data.
12.2 Requests received by Sales Day
If Sales Day receives a Data Subject Request concerning Customer Personal Data, Sales Day will, where reasonably identifiable:
- notify the Customer;
- direct the Data Subject to the Customer; or
- otherwise assist the Customer as appropriate.
Sales Day will not respond substantively on the Customer's behalf unless:
- instructed by the Customer;
- legally required; or
- necessary to confirm that Sales Day is not the relevant Controller.
12.3 Self-service tools
Sales Day may satisfy part of its assistance obligation by providing tools that allow the Customer to:
- search records;
- correct records;
- export data;
- archive data;
- delete data;
- remove Team access;
- disconnect integrations; and
- manage Workspace permissions.
12.4 Additional assistance
Where assistance requires material work beyond normal Service functionality, Sales Day may charge reasonable fees after providing advance notice.
13. Assistance with compliance
Taking into account the nature of Processing and information available to Sales Day, Sales Day will provide reasonable assistance with:
- security obligations;
- Personal Data Breach assessment;
- Data Subject Requests;
- data-protection impact assessments;
- prior consultation with a Supervisory Authority; and
- information reasonably needed to demonstrate compliance.
The Customer remains responsible for deciding whether:
- a data-protection impact assessment is required;
- prior consultation is necessary;
- Processing is lawful; and
- its technical and organisational measures are appropriate.
14. Subprocessors
14.1 General authorisation
The Customer gives Sales Day general written authorisation to appoint Subprocessors to provide the Service.
14.2 Current Subprocessors
Sales Day's current Subprocessors are listed in the Sales Day Subprocessor List.
The Subprocessor List forms part of this Addendum.
14.3 Subprocessor obligations
Before allowing a Subprocessor to Process Customer Personal Data, Sales Day will impose data-protection obligations that provide a level of protection materially consistent with this Addendum, including obligations concerning:
- confidentiality;
- security;
- use restrictions;
- breach notification;
- deletion or return;
- assistance;
- international transfers; and
- further Subprocessors.
14.4 Sales Day responsibility
Sales Day remains responsible to the Customer for its Subprocessors' performance of the data-protection obligations Sales Day has delegated to them, subject to the liability provisions of the Terms.
14.5 Changes to Subprocessors
Sales Day may add or replace Subprocessors.
Sales Day will provide reasonable prior notice of a material new Subprocessor through one or more of:
- email;
- an in-app notice;
- the Subprocessor List;
- a legal-update page; or
- another reasonable electronic method.
14.6 Customer objections
The Customer may object to a new Subprocessor on reasonable, documented grounds relating specifically to data protection.
An objection must:
- be sent to privacy@sales.day;
- identify the Subprocessor;
- explain the data-protection concern; and
- be received within 14 calendar days of notice.
The Parties will work in good faith to seek a commercially reasonable solution.
Possible solutions may include:
- configuration changes;
- disabling an affected integration or feature;
- limiting the relevant Processing;
- using an available alternative; or
- terminating the affected part of the Service.
If no reasonable solution is available, either Party may terminate the affected Service.
Any refund will be determined in accordance with the Terms and the circumstances of the termination.
15. Integrations selected by the Customer
The Customer may choose to connect third-party services, including Google Calendar.
Where an integration is selected and authorised by the Customer:
- the Customer instructs Sales Day to exchange relevant data with that provider;
- the provider may act as the Customer's independent Controller, Processor or separate service provider;
- the provider's own terms and privacy documentation may apply;
- the Customer is responsible for reviewing the provider;
- Sales Day is not responsible for the provider's independent processing; and
- the integration may stop if permissions are withdrawn or the provider changes its service.
A provider chosen and contracted directly by the Customer is not necessarily a Sales Day Subprocessor merely because Sales Day enables the connection.
16. International transfers
16.1 Lawful transfers
Sales Day will ensure that Restricted Transfers of Customer Personal Data made by Sales Day or its Subprocessors are supported by a legally recognised transfer mechanism where required.
This may include:
- adequacy regulations or decisions;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- the European Commission Standard Contractual Clauses;
- an approved certification or framework;
- binding corporate rules; or
- another lawful safeguard.
16.2 Transfer information
Relevant information about:
- Subprocessor identity;
- processing purpose;
- processing location; and
- available transfer safeguard
will be included in the Subprocessor List where reasonably available.
16.3 UK transfers
Where a Restricted Transfer subject to the UK GDPR requires contractual safeguards, the Parties agree that the applicable UK transfer mechanism may be incorporated by reference into this Addendum.
Where the UK Addendum is used:
- the Customer will be the exporter where it transfers Customer Personal Data to Sales Day;
- Sales Day will be the importer where applicable;
- the processing details are those in Annex 1;
- the security measures are those in Annex 2;
- the relevant Subprocessors are those in the Subprocessor List; and
- the governing law and courts will be determined in accordance with the applicable approved transfer instrument.
16.4 EU transfers
Where the EU Standard Contractual Clauses are required:
- Module Two will apply to Controller-to-Processor transfers;
- Module Three will apply to Processor-to-Processor transfers;
- the processing details are those in Annex 1;
- the security measures are those in Annex 2; and
- the Subprocessor information is contained in the Subprocessor List.
The optional docking clause may apply where appropriate.
The Parties will complete or supplement any information required by the applicable clauses.
16.5 Transfer assessments
Where required by Applicable Data Protection Law, Sales Day will undertake or assist with reasonable transfer-risk assessments relating to its Processing and Subprocessors.
The Customer remains responsible for assessing transfers arising from its own use, configuration or selected integrations.
17. Records and compliance information
Sales Day will maintain records of Processing activities where required by Applicable Data Protection Law.
On reasonable request, Sales Day will provide information necessary to demonstrate compliance with this Addendum.
Sales Day may satisfy this obligation by providing:
- this Addendum;
- the Subprocessor List;
- security documentation;
- relevant provider documentation;
- policies;
- questionnaire responses;
- audit summaries;
- certifications held by relevant providers; or
- other appropriate evidence.
18. Audits
18.1 Information rights
The Customer may request reasonable information needed to verify Sales Day's compliance with this Addendum.
Sales Day may first provide existing documentation and written responses.
18.2 Customer audit
If existing information is not sufficient to meet a legal requirement, the Customer may request an audit.
Unless required otherwise by Applicable Data Protection Law, an audit must:
- be requested in writing;
- be limited to Processing covered by this Addendum;
- occur no more than once in any 12-month period;
- be conducted during normal business hours;
- give at least 30 days' notice;
- avoid unreasonable disruption;
- comply with Sales Day's security procedures;
- protect other Customers' information;
- be carried out by an independent auditor;
- be subject to confidentiality; and
- not require access to systems or information that would compromise security.
18.3 Audit costs
The Customer bears its own audit costs.
Sales Day may charge reasonable fees for audit assistance that requires substantial personnel time, unless the audit identifies a material breach by Sales Day.
18.4 Regulatory audits
The limitations above do not prevent cooperation required by a competent Supervisory Authority.
19. Return, export and deletion
19.1 During the Service
The Service may allow the Customer to:
- export supported CRM data;
- correct records;
- archive records;
- delete records;
- remove Team members; and
- delete eligible Workspaces.
19.2 On termination
On termination or expiry of the affected Service, Sales Day will, at the Customer's choice and subject to the Terms:
- allow the Customer a reasonable opportunity to export supported Customer Personal Data;
- return Customer Personal Data in an available standard format; or
- delete Customer Personal Data.
The Customer must submit any special return or deletion instruction before Account or Workspace access ends.
19.3 Default deletion
If the Customer provides no additional instruction, Sales Day may delete Customer Personal Data according to:
- the Service's deletion functionality;
- Sales Day's retention schedule;
- provider backup cycles;
- legal requirements; and
- legitimate security, billing or dispute needs.
19.4 Backup copies
Customer Personal Data may remain temporarily in backups, logs or disaster-recovery systems.
Where retained in backups:
- it will remain protected under this Addendum;
- it will not be restored or used except for recovery, security or legal purposes; and
- it will be deleted or overwritten through the applicable provider retention cycle.
19.5 Legal retention
Sales Day may retain Customer Personal Data where required by law.
Sales Day may also retain limited information needed for:
- fraud prevention;
- security;
- billing and tax;
- dispute resolution;
- legal claims;
- enforcement; or
- proof of compliance.
Any retained Customer Personal Data remains protected under this Addendum and will not be used for unrelated purposes.
20. Special-category and high-risk data
The Parties do not ordinarily anticipate that the Service will be used to Process substantial volumes of:
- special-category Personal Data;
- criminal-offence data;
- medical records;
- biometric data;
- genetic data;
- children's data;
- payment-card data;
- government authentication identifiers; or
- similarly high-risk regulated information.
The Customer must not use the Service for such information unless:
- the Processing is permitted under the Terms;
- the Customer has an appropriate lawful basis;
- additional safeguards are applied;
- any required impact assessment has been completed; and
- Sales Day has agreed in writing where reasonably required.
21. Government and legal requests
If Sales Day receives a legally binding request for Customer Personal Data, Sales Day will, where legally permitted:
- review the validity and scope of the request;
- seek to limit excessive requests;
- notify the Customer before disclosure;
- disclose only the information legally required; and
- document the request as appropriate.
Sales Day may be unable to notify the Customer where notification is prohibited by law.
22. Liability
Each Party's liability arising from this Addendum is subject to the exclusions and limitations in the Terms.
Nothing in this Addendum limits liability to the extent such limitation is prohibited by Applicable Data Protection Law.
This section does not alter the allocation of regulatory responsibility imposed directly by law.
23. Term and termination
This Addendum begins when the Customer accepts the Terms or otherwise enters into an agreement for the Service.
It remains in force while Sales Day Processes Customer Personal Data on the Customer's behalf.
Provisions concerning confidentiality, security, deletion, international transfers, liability and retained data survive termination for as long as relevant Customer Personal Data remains in Sales Day's possession or control.
24. Changes to this Addendum
Sales Day may update this Addendum where reasonably necessary to:
- reflect legal or regulatory changes;
- update approved transfer mechanisms;
- reflect changes to the Service;
- update Processing activities;
- address regulator guidance;
- improve clarity; or
- update Subprocessor arrangements.
Sales Day will provide reasonable notice of a material change.
A change will not materially reduce the level of protection for Customer Personal Data during a current paid Subscription without a valid legal or operational reason.
25. Governing law
This Addendum is governed by the governing-law provision in the Terms, except where an applicable international-transfer instrument requires another governing law or forum.
26. Contact
Questions about this Addendum should be sent to:
Sales Day Software Ltd
15 Kerrsland Drive
Belfast
BT5 6ER
United Kingdom
Company number: NI740756
Email:
Security incidents may be reported to:
Annex 1 — Details of Processing
1. Subject matter
Provision of Sales Day, a cloud-based diary-driven sales execution and customer relationship management service.
2. Duration
Processing continues for:
- the duration of the Customer's Account, Workspace or Subscription;
- any agreed transition or export period;
- the applicable deletion process; and
- any additional period required by law, backups, security or legitimate record-keeping.
3. Nature of Processing
Processing may include:
- collection;
- receipt;
- recording;
- organisation;
- structuring;
- storage;
- retrieval;
- consultation;
- display;
- transmission;
- synchronisation;
- matching;
- import;
- export;
- updating;
- restriction;
- archiving;
- deletion;
- support access;
- security monitoring;
- troubleshooting; and
- other operations needed to provide the Service.
4. Purposes
Sales Day Processes Customer Personal Data to:
- provide CRM functionality;
- provide personal and Team Workspaces;
- organise Accounts, Contacts, Leads and Deals;
- manage Tasks and Meetings;
- provide Diary and Today views;
- enable Task rescheduling and completion;
- provide notes, comments and activities;
- provide reports;
- enable email notifications;
- provide Morning Digests;
- provide calendar synchronisation;
- provide import and export;
- administer Workspace access;
- provide support;
- secure and troubleshoot the Service;
- prevent duplicate or unauthorised actions;
- maintain operational records; and
- comply with lawful Customer Instructions.
5. Categories of Data Subjects
Data Subjects may include:
- Customer employees;
- Customer directors and officers;
- contractors;
- consultants;
- agents;
- Users;
- job applicants;
- Leads;
- prospects;
- customers;
- former customers;
- suppliers;
- supplier representatives;
- business Contacts;
- Meeting attendees;
- external notification recipients;
- partners;
- referrers;
- introducers; and
- any other individual whose information the Customer enters into the Service.
Sales Day does not determine which Data Subjects the Customer chooses to record.
6. Categories of Personal Data
Customer Personal Data may include:
- name;
- business email address;
- telephone number;
- job title;
- employer or organisation;
- business address;
- relationship details;
- lead status;
- contact status;
- Deal details;
- sales history;
- Account ownership;
- Task details;
- Meeting details;
- notes;
- comments;
- activity history;
- dates and times;
- communication content;
- assignment information;
- calendar-event data;
- imported data;
- exported data;
- email-notification data;
- identifiers;
- free-text information; and
- other information selected and entered by the Customer.
7. Sensitive data
The Service is not intended for routine Processing of special-category, criminal-offence or other highly sensitive Personal Data.
If the Customer enters such data, the Customer is responsible for ensuring the Processing is lawful and appropriate.
8. Frequency
Processing may occur continuously or whenever the Customer or its Users:
- access the Service;
- create or update records;
- run an import or export;
- connect an integration;
- send a notification;
- receive a digest;
- perform an administrative action; or
- request support.
9. Customer instructions
The Customer's initial and continuing Instructions are contained in:
- the Terms;
- this Addendum;
- the applicable Order;
- feature configuration;
- authorised User actions;
- integration permissions; and
- support instructions accepted by Sales Day.
Annex 2 — Technical and Organisational Measures
Sales Day's current measures include the following, subject to the qualifications below.
1. Access control
- authenticated Account access;
- Workspace-scoped data access;
- role-based permissions;
- personal and Team Workspace separation;
- owner, administrator, manager and member roles;
- restricted platform-administrator access;
- server-side permission checks;
- database access rules;
- removal of Team-member access;
- controlled service-role use; and
- protection of administrative functions.
2. Authentication and sessions
- platform-managed authentication;
- protected Account sessions;
- login and logout functionality;
- invitation-token controls;
- OAuth authorisation for supported integrations; and
- restrictions against client-side access to protected secrets.
MFA availability and certain session-security controls depend on the underlying platform and Account capabilities.
3. Tenant isolation
- records associated with Workspace identifiers;
- Workspace-aware access policies;
- backend verification of Workspace membership;
- role validation;
- protection against client-supplied Workspace manipulation; and
- controlled switching between personal and Team Workspaces.
4. Application security
- input and field validation;
- authenticated backend functions;
- protected webhook processing;
- verification of payment-provider webhook signatures;
- CSV formula-injection protection;
- import validation;
- plan-capacity validation;
- duplicate and idempotency controls;
- controlled error messages;
- page-content error boundaries; and
- prevention of raw technical error disclosure where implemented.
5. Integration security
- OAuth-based authorisation;
- provider-specific access permissions;
- protected token handling through platform connectors;
- Workspace-scoped synchronisation;
- stored technical identifiers for event synchronisation;
- disconnect functionality; and
- payment processing through Stripe-hosted or Stripe-controlled environments.
6. Confidentiality
- access limited to authorised personnel and providers;
- contractual confidentiality obligations;
- restricted administrative access;
- support access limited to operational need; and
- Subprocessor contractual protections.
7. Logging and operational records
Depending on the feature, Sales Day maintains records concerning:
- audit activity;
- support tickets;
- email delivery;
- Morning Digest delivery;
- imports;
- payment webhooks;
- Subscription changes;
- membership changes;
- failures; and
- administrative actions.
Retention periods vary by record type and provider.
8. Availability and resilience
Availability, infrastructure resilience, backups and disaster recovery are partly provided by Sales Day's platform and infrastructure providers.
Sales Day does not currently represent that it maintains:
- a formal service-level agreement;
- a Customer-specific recovery-time objective;
- a Customer-specific recovery-point objective; or
- a guaranteed fixed backup-retention period,
unless separately agreed.
9. Encryption
Encryption in transit and at rest is platform-dependent.
Sales Day relies on its platform, hosting, database, payment, email and integration providers to maintain the encryption controls described in their own security and contractual documentation.
Sales Day will not make broader encryption claims unless verified.
10. Testing and review
Sales Day may review controls through:
- code inspection;
- permission audits;
- billing and webhook testing;
- controlled data-isolation tests;
- import and export rehearsals;
- mobile and error-handling tests;
- provider documentation;
- incident review; and
- corrective development.
This Annex describes current general measures and may be updated as the Service evolves.
Annex 3 — International Transfer Terms
1. Applicability
This Annex applies only where a Restricted Transfer requires an approved contractual safeguard.
2. EU Standard Contractual Clauses
Where the European Commission Standard Contractual Clauses apply:
- Module Two applies where the Customer is a Controller and Sales Day is a Processor;
- Module Three applies where the Customer is a Processor and Sales Day is a Subprocessor;
- the Parties' identities are those in the Terms, Order and this Addendum;
- the description of Processing is in Annex 1;
- the security measures are in Annex 2;
- the Subprocessors are identified in the Subprocessor List;
- Clause 7 may apply where legally permitted;
- Option Two under Clause 9 applies for general written authorisation of Subprocessors;
- the notice period is the period stated in section 14;
- the competent Supervisory Authority is determined under Clause 13;
- the governing law and courts are selected in accordance with Clauses 17 and 18; and
- the Parties will complete any mandatory fields not fully resolved by this Addendum.
3. UK transfers
Where the UK Addendum is required, it is incorporated into this Addendum.
The relevant information for the UK Addendum is:
- the Parties: as identified in the Terms, Order and this Addendum;
- selected SCCs: the applicable Module Two or Module Three clauses;
- Processing: Annex 1;
- security: Annex 2;
- Subprocessors: the Subprocessor List; and
- termination rights: as provided by the mandatory UK Addendum.
4. Conflicts
If this Addendum conflicts with a mandatory provision of an approved transfer instrument, the transfer instrument takes priority for the affected Restricted Transfer.
