Self-service execution. This DPA is pre-signed by Chantro. If you need a countersigned copy for your records, email legal@chantro.com from the domain associated with your Workspace Owner account and we will return a countersigned PDF within two business days. Customers with executed Orders can rely on this online version as incorporated into the Terms of Service.
1. Incorporation & order of precedence
This Data Processing Addendum (“DPA”) forms part of the agreement between SmartTech ProServe LLC (“Chantro” or “Processor”) and Customer (“Controller”) for Chantro's processing of Personal Data in the course of providing the Service (the “Agreement”). In the event of conflict, this DPA controls over the main Agreement solely with respect to the processing of Personal Data. Terms not defined here have the meaning given in the Agreement.
2. Definitions
- “Data Protection Laws” means laws applicable to the parties relating to the processing of personal data, including the EU General Data Protection Regulation 2016/679 (“GDPR”); the UK Data Protection Act 2018 and UK GDPR (“UK GDPR”); the Swiss Federal Act on Data Protection (“FADP”); and U.S. state privacy laws where they apply.
- “Personal Data” means any information relating to an identified or identifiable natural person that is processed by Chantro on Customer's behalf under the Agreement.
- Terms such as “controller,” “processor,” “data subject,” “personal data breach,” “processing,” and “supervisory authority” have the meanings given in the applicable Data Protection Laws.
- “Standard Contractual Clauses” or “SCCs” means the module 2 (controller-to-processor) clauses approved by the European Commission on 4 June 2021 (Commission Implementing Decision (EU) 2021/914), as amended.
3. Processing details
Annex A sets out the subject matter, duration, nature, purpose, categories of data, and categories of data subjects for the processing performed under this DPA.
4. Roles of the parties
With respect to Personal Data processed under the Agreement, Customer is the Controller and Chantro is the Processor. If Customer acts on behalf of another controller (for example, its own customer), Customer represents that it has the right to enter into this DPA on that controller's behalf and that the instructions Customer gives Chantro are lawful.
5. Customer instructions
Chantro will process Personal Data only on documented instructions from Customer. Such instructions consist of the Agreement (including this DPA and the configurations and options Customer selects in the Service), plus any additional written instructions given to Chantro by Customer (or its authorized administrators). Chantro will promptly notify Customer if, in its opinion, an instruction violates Data Protection Laws.
6. Confidentiality of personnel
Chantro ensures that personnel authorized to process Personal Data are bound by written confidentiality obligations or are under a statutory obligation of confidentiality, and are trained appropriately.
7. Security measures
Chantro implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures are summarized in Annex B and in our Security Overview. Chantro may update measures provided that the overall level of security is not diminished.
8. Subprocessors
8.1 General authorization
Customer provides a general authorization for Chantro to engage subprocessors, subject to this Section 8. Chantro remains liable to Customer for each subprocessor's performance of its DPA obligations.
8.2 Current list
Chantro's current subprocessors are listed at chantro.com/legal/subprocessors.
8.3 Notice of changes
Chantro will notify Customer (for example, by updating the subprocessor page and by email to subscribers on eligible plans) of any intended addition or replacement of a subprocessor at least thirty (30) days before the change takes effect.
8.4 Objection right
Customer may object to a new subprocessor on reasonable grounds related to data protection by writing to privacy@chantro.com during the notice period. The parties will discuss in good faith. If Chantro cannot reasonably accommodate the objection, Customer may terminate the affected portion of the Service by giving written notice before the subprocessor is engaged. Notwithstanding Section 7.6 of the Agreement, Chantro will refund a pro-rata share of prepaid, unused fees for the affected portion of the Service in that case.
8.5 Contracts with subprocessors
Chantro enters into written contracts with each subprocessor that impose obligations on them substantially similar to those imposed on Chantro under this DPA.
9. Data-subject rights
Taking into account the nature of the processing, Chantro will provide Customer with appropriate tools and reasonable assistance to respond to requests from data subjects to exercise their rights under Data Protection Laws. If a data subject contacts Chantro directly, Chantro will, unless legally prohibited, refer the request to Customer.
10. Assistance to controller
Chantro will provide reasonable assistance to Customer with (a) data protection impact assessments, (b) prior consultations with supervisory authorities, and (c) compliance with security and breach-notification obligations — taking into account the nature of processing and information available to Chantro.
11. Personal data breach notification
Chantro will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's Personal Data, and will use reasonable efforts to provide that notice within seventy-two (72) hours. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences, and the measures taken or proposed to address the breach.
12. Audits
12.1 Information
On Customer's reasonable written request, and no more than once per twelve-month period (or more frequently when required by a supervisory authority or by a material change in risk), Chantro will make available information necessary to demonstrate compliance with this DPA, including its most recent security documentation, questionnaires, and attestations.
12.2 On-site audits
Where information sharing is insufficient and Customer reasonably demonstrates that an on-site audit is necessary, Chantro will cooperate with an on-site audit conducted by Customer (or an independent auditor mutually agreed to) at Customer's expense, subject to (a) at least thirty (30) days' advance notice; (b) execution of confidentiality undertakings reasonably acceptable to Chantro; (c) conducting the audit during business hours without unreasonable interference with Chantro's operations; and (d) scope limited to controls relevant to Customer's Personal Data.
13. International transfers & SCCs
13.1 EEA transfers
Where Chantro's processing of Personal Data subject to the GDPR involves a transfer to a country outside the European Economic Area that has not received an adequacy decision, the parties agree that the Standard Contractual Clauses (module 2, controller to processor) are incorporated into this DPA by reference, with the elections set out in Annex C.
13.2 UK transfers
Where transfers are subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs (issued by the Information Commissioner) by reference, using the tables completed in Annex C.
13.3 Swiss transfers
For transfers subject to the FADP, the SCCs apply with the amendments required by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
14. Return & deletion of personal data
On termination or expiration of the Agreement, Customer may export Personal Data through the Service's self-service export tools for thirty (30) days. After that window, Chantro will delete or anonymize Personal Data from active production systems. Routine backups are purged in the ordinary course of our backup-retention cycle (typically within a further thirty (30) days). Chantro may retain Personal Data to the extent required by law.
15. Liability
Each party's liability under or in connection with this DPA is subject to the aggregate liability cap and exclusions in the Agreement, except where Data Protection Laws prohibit such limitations.
16. Duration & termination
This DPA is effective from the date the Agreement is entered into and remains in force until Chantro ceases all processing of Personal Data on Customer's behalf.
Annex A — Processing details
| Subject matter | Provision of the Chantro Service under the Agreement. |
|---|---|
| Duration | The term of the Agreement, plus any post-termination retention permitted under Section 14. |
| Nature & purpose | Hosting, storing, transmitting, displaying, backing up, and processing Customer Data to provide the Service, including AI features, support, analytics, and security operations. |
| Categories of data subjects | Customer's Users (employees, contractors, and other authorized personnel); Customer's own customers, leads, vendors, and contacts; individuals identified in project documents, photos, or communications uploaded to the workspace. |
| Categories of Personal Data | Identifiers (name, email, phone, job title, IP), professional information, workspace content and messages, project/financial information, documents and photos, AI prompts and outputs, voice transcripts when voice mode is used, device and usage telemetry. |
| Special categories | None intentionally processed. See the Acceptable Use Policy, Section 5. |
| Frequency of transfer | Continuous during the term. |
| Retention period | Personal Data is retained for the term of the Agreement, plus the post-termination window described in Section 14 of this DPA. Backups follow the retention cycle described there. |
| Subprocessor transfers | Onward transfers to subprocessors are limited to the providers listed at chantro.com/legal/subprocessors, each of which is bound by written data-protection terms substantially equivalent to this DPA. |
Annex B — Security measures
- TLS 1.2+ in transit; AES-256 encryption at rest.
- Multi-tenant isolation enforced in application middleware and at the database layer via PostgreSQL row-level security.
- Role-based access controls and least-privilege access to production systems.
- Production access restricted to approved personnel using single sign-on and a managed endpoint; administrative actions are logged.
- Append-only audit logging of security-relevant Workspace events (sign-ins, permission changes, exports, deletions, integration connects).
- Secrets managed in AWS Secrets Manager; high-sensitivity secrets envelope-encrypted with AWS KMS.
- Production network and data segmented from corporate and test environments; test data is synthetic or pseudonymized.
- Dependency review and update cadence; automated dependency-vulnerability scanning is part of our active engineering roadmap.
- Regular encrypted backups with access controls and maintained restore runbooks.
- Documented incident-response, business-continuity, and change-management procedures.
- Vendor security assessments before and during engagement of subprocessors.
Further detail is available in our Security Overview. The level of these measures may evolve; Chantro will not materially reduce the protections summarized here during the term.
Annex C — SCC elections
Where Section 13 of this DPA incorporates the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the parties make the elections set out below. Where Section 13 incorporates the UK International Data Transfer Addendum (issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018), the parties complete the UK Addendum tables as set out below.
C.1 EU SCCs (Module 2, Controller to Processor)
- Module — Module 2 (Controller to Processor) applies. Modules 1, 3, and 4 do not apply.
- Clause 7 (Docking clause) — the optional docking clause is not included.
- Clause 9(a) (General or specific authorisation of subprocessors) — Option 2 (general written authorization) applies, with advance notice of at least thirty (30) days for any intended addition or replacement of a subprocessor, as detailed in Section 8 of this DPA.
- Clause 11(a) (Redress — independent dispute-resolution body) — the optional language is not selected. Chantro will nonetheless publish a data-subject contact (privacy@chantro.com) and handle complaints as described in the Privacy Policy.
- Clause 17 (Governing law) — the SCCs are governed by the law of Ireland. Clause 17 requires the governing law to be that of an EU Member State that allows third-party beneficiary rights; Ireland satisfies this requirement.
- Clause 18 (Choice of forum and jurisdiction) — any dispute arising from the SCCs will be resolved by the courts of Ireland.
C.2 Annex I to the EU SCCs
- Annex I.A — Parties. Data Exporter (Controller): the Customer identified in the Agreement, at the address provided in that Agreement; Data Importer (Processor): SmartTech ProServe LLC, 1405 Gallagherville Rd #1, Downingtown, PA 19335, United States. Contact for each party: Customer's administrator of record; for Chantro, privacy@chantro.com. Activities relevant to the transfer: as described in Annex A (Processing details).
- Annex I.B — Description of transfer. Categories of data subjects, categories of personal data, special categories of data, frequency of transfer, nature of processing, purpose(s), retention period, and subprocessor transfers are set out in Annex A of this DPA.
- Annex I.C — Competent supervisory authority. The supervisory authority of the EEA Member State in which the Customer (or its EU representative) is established. In the absence of such establishment or representative, the Irish Data Protection Commission.
C.3 Annex II to the EU SCCs — Technical and organisational measures
The technical and organisational measures are those set out in Annex B of this DPA and in our Security Overview.
C.4 UK International Data Transfer Addendum
Where transfers are subject to UK data-protection law, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (version B1.0, in force from 21 March 2022) is incorporated and completed as follows:
- Part 1 Table 1 — Parties. As set out in Annex I.A above.
- Part 1 Table 2 — Selected SCCs, Modules and Selected Clauses. The Approved EU SCCs (Commission Implementing Decision (EU) 2021/914) with Module 2 selected, as elected in Section C.1 above.
- Part 1 Table 3 — Appendix Information. Annex I and Annex II of the EU SCCs are completed by reference to Annex A, Annex B, and Section C.2 of this DPA.
- Part 1 Table 4 — Ending the Addendum when the Approved Addendum Changes. Neither the Importer nor the Exporter has a unilateral right to end the UK Addendum when a revised Approved Addendum is issued; the parties will instead meet in good faith and amend.
- Part 2 — Mandatory Clauses. The Mandatory Clauses set out in Part 2 of the UK Addendum apply and are incorporated.
C.5 Swiss FADP transfers
For transfers subject to the Swiss Federal Act on Data Protection (FADP), the SCCs apply with the interpretive amendments required by the Swiss Federal Data Protection and Information Commissioner (FDPIC): references to the GDPR are treated as references to the FADP; the competent supervisory authority is the FDPIC; and references to EU Member State law are treated as references to Swiss law where appropriate.
Executed by Chantro
SmartTech ProServe LLC
1405 Gallagherville Rd #1
Downingtown, PA 19335, United States
Signed electronically and made available at chantro.com/legal/dpa.