Crewmint

Legal

Data Processing Addendum

Last updated: 2 October 2026

This Data Processing Addendum ("DPA") applies when ScaleCraft LLC processes personal data for a business customer through Crewmint. It forms part of our Terms of Service. By accepting the Terms you accept this DPA, and no separate signature is needed. It is written to meet Article 28 of the EU GDPR and the UK GDPR.

01

Parties and roles

"Customer" means the business that accepted the Terms. "We" and "us" mean ScaleCraft LLC, 312 W 2nd St Unit #A9117, Casper, WY 82601, USA. "Customer Personal Data" means personal data in the content the Customer or its users add to Crewmint, or that we fetch from accounts the Customer connects, including workspace content, files, chats, contacts, prospects and leads.

For Customer Personal Data, the Customer is the controller and we are the processor. If the Customer is itself a processor acting for its own clients, we act as its subprocessor, and the Customer confirms its controller has authorised our use.

For account, billing and usage data about the Customer's users, ScaleCraft LLC is an independent controller, and our Privacy Policy applies.

Words such as controller, processor, personal data, data subject, processing and personal data breach have the meanings given in the GDPR.

02

Subject matter and duration

Subject matter: providing Crewmint, an AI workspace that drafts content, analyses data, manages contacts and runs outreach and other tasks the Customer sets up.

Duration: for as long as the Customer uses the service, and after that until we delete Customer Personal Data as set out under Deletion and return.

03

Nature and purpose of processing

We store, organise, retrieve, analyse, transmit and delete Customer Personal Data, and send it to AI models to generate replies and content, in order to provide the service, carry out the Customer's instructions, keep the service secure, give support and prevent abuse.

We do not sell Customer Personal Data, and we do not use it to train AI models.

04

Types of data and data subjects

Data subjects: the Customer's staff and other authorised users; the Customer's contacts, prospects, leads and customers; and any other people whose details the Customer adds or connects.

Types of personal data: names, job titles, employers, business email addresses, phone numbers, social profile links, postal addresses, message content and history, notes, and any other personal data contained in content the Customer adds or connects.

Special category data: the service is not designed for health, biometric, political or other special category data, or for data about criminal convictions. The Customer should not add it unless it is necessary and lawful to do so.

05

Customer responsibilities

The Customer is responsible for the lawfulness of the personal data it adds and the instructions it gives, including having a lawful basis for every contact, giving any required privacy notices, and following the email and outreach rules in our Terms.

06

Processing on instructions

We process Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA and the Customer's use and settings of the service are the Customer's complete instructions. Other instructions must be agreed in writing.

We may process data otherwise only where the law requires it. In that case we will tell the Customer first, unless the law forbids it. If we think an instruction breaks data protection law, we will tell the Customer.

07

Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, either by contract or by law, and gets access only as needed for their role.

08

Security measures

We take appropriate technical and organisational measures to protect Customer Personal Data, as Article 32 of the GDPR requires. These include:

hosting in a PostgreSQL database on our own server in Frankfurt, Germany;

encryption in transit (TLS) for traffic to and from the service;

encryption at rest for sensitive fields such as access tokens for connected accounts, and passwords stored only as secure hashes;

access controls that limit staff access to what their role needs, and workspace permissions that separate one customer's data from another's;

regular backups, security updates and monitoring of our systems;

review and contracts with each subprocessor before we use it.

We may update these measures over time, as long as the overall level of protection does not go down.

09

Subprocessors

The Customer gives us general authorisation to use subprocessors. Our current subprocessors are listed on our Subprocessors page.

Before we add or replace a subprocessor, we update that page and email workspace owners at least 14 days in advance. The Customer may object on reasonable data protection grounds by emailing help@crewmint.ai within that period. We will then work in good faith to find a solution. If we cannot, the Customer may end the affected service and we will refund any prepaid fees for the unused period.

We put a written contract in place with each subprocessor with data protection terms that give at least the same level of protection as this DPA. We remain responsible to the Customer for our subprocessors' performance of those obligations.

10

Help with data subject requests

The service lets the Customer find, export, correct and delete personal data. Where the Customer cannot do this itself, we will help it respond to requests from data subjects, taking into account the nature of the processing.

If we receive a request directly from a data subject about Customer Personal Data, we will pass it to the Customer without undue delay and will not respond ourselves, except to tell the person to contact the Customer.

11

Help with DPIAs and compliance

We will give the Customer reasonable help, using information available to us, with its data protection impact assessments, prior consultations with supervisory authorities, and its security obligations under Articles 32 to 36 of the GDPR.

12

Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of it.

The notice will describe, as far as we know at the time, the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we have taken or propose to take. We will add further information as it becomes available, and take reasonable steps to contain the breach and reduce its effects.

13

Deletion and return

The Customer can export its data from the app at any time. When the Customer deletes its account or workspace, or the service ends, we delete Customer Personal Data within 30 days. Backups are overwritten on a rolling basis within 90 days.

We may keep data longer only where the law requires it, and we will keep it confidential and process it only for that purpose.

14

Audits and information

We will make available to the Customer the information reasonably needed to show that we meet this DPA and Article 28 of the GDPR. The Customer can ask for this by emailing help@crewmint.ai, and we will answer reasonable requests within 30 days.

These information requests are how audits take place under this DPA. If a supervisory authority requires it, or the information we provide is not enough to show compliance, we will allow an audit by the Customer or an independent auditor it appoints, bound by confidentiality, with reasonable notice, scope and timing, at the Customer's cost.

15

International transfers

We store Customer Personal Data in Frankfurt, Germany. ScaleCraft LLC is based in the United States, and some subprocessors process data in the United States.

Where Customer Personal Data subject to the EU GDPR is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 apply and are incorporated into this DPA by reference. Module 2 (controller to processor) applies where the Customer is a controller, and Module 3 (processor to processor) where it is a processor. The Customer is the data exporter and we are the data importer. The optional docking clause and the optional redress language do not apply. Under clause 9 the general authorisation and 14-day notice in this DPA apply. Clauses 17 and 18 are governed by the law and courts of Ireland. The information in this DPA completes the annexes.

Where Customer Personal Data subject to the UK GDPR is transferred, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner applies and is incorporated by reference, completed with the information in this DPA.

We make sure our subprocessors that receive this data outside the EU or UK are bound by the same or equivalent safeguards.

16

Order of precedence and liability

If this DPA conflicts with the Terms on data protection, this DPA wins. If the Standard Contractual Clauses or UK Addendum conflict with this DPA, they win.

Each party's liability under this DPA is subject to the limits in the Terms, except where the law does not allow liability to be limited.

17

Contact

Questions about this DPA, or requests for information? Email help@crewmint.ai or write to ScaleCraft LLC, 312 W 2nd St Unit #A9117, Casper, WY 82601, USA.

Crewmint is a product of ScaleCraft LLC, 312 W 2nd St Unit #A9117, Casper, WY 82601, USA. Questions? Email help@crewmint.ai.