Data Protection & Processing Terms
These terms describe PipelineIQ’s safeguards and form the data-processing addendum when a business customer uses the service to process personal data on its behalf.
1. Roles and scope
The customer is the controller and PipelineIQ is the processor for personal data placed in a customer workspace. Processing lasts for the customer’s use of the service and any limited deletion or backup period. Its purpose is to host, organize, analyze, import, export and display CRM and inbound information and to provide customer-requested integrations and follow-ups.
2. Data and people covered
Data may include business identity and contact details, employment information, account relationships, deal and activity information, communications, notes, tasks, uploaded files and technical identifiers. Data subjects may include the customer’s staff, users, leads, prospects, buyers, clients, suppliers and business contacts. Customers must avoid uploading special-category or highly sensitive personal data unless PipelineIQ has agreed in writing that the service is suitable for it.
3. Customer instructions
PipelineIQ processes customer personal data only on documented instructions expressed through the service, these terms, support requests and connected integrations, unless EU or Danish law requires otherwise. PipelineIQ will inform the customer if an instruction appears to violate data-protection law, unless prohibited by law.
4. Confidentiality and security
People authorized to process customer data are bound by confidentiality. Safeguards include authenticated account access, workspace and role checks, encrypted transport, encrypted saved integration credentials, server-side secret handling, input limits and validation, tenant separation, controlled imports, audit-style activity records, backups or recovery mechanisms where available, and monitoring of operational errors. Security is reviewed in light of the risk, available technology and the nature of this early-access service.
5. Subprocessors
The customer gives general authorization for subprocessors needed to run the service. Current categories and providers are: hosting, storage and inbound email routing through Cloudflare; sign-in through Supabase; payments through Stripe; AI processing through OpenAI; outgoing email through Resend; and company mailboxes through Google Workspace. PipelineIQ remains responsible for its processor obligations and will require appropriate data-protection commitments. The current provider list is published on the Subprocessors page. PipelineIQ will give at least 30 days’ notice of a material addition where reasonably possible. A customer may object on reasonable data-protection grounds by contacting PipelineIQ.
6. International transfers
Where customer personal data is transferred outside the EEA, PipelineIQ will use a valid transfer mechanism required by applicable law, such as an adequacy decision or Standard Contractual Clauses, and apply supplementary safeguards where appropriate.
7. Assistance
Taking account of the nature of processing, PipelineIQ will reasonably assist the customer with data-subject requests, security obligations, breach assessment, data-protection impact assessments and regulator consultations. The customer remains responsible for its notices, legal basis, data accuracy, retention rules and responses as controller.
8. Incidents
PipelineIQ will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer’s assessment and notifications. Customers should report suspected incidents immediately using the contact details below.
9. Return and deletion
On termination or written request, PipelineIQ will delete or return customer personal data, at the customer’s choice where technically available, unless applicable law requires retention. Deletion may take additional time to propagate through protected backups. Customers should export needed records before closing an account.
10. Information and audits
PipelineIQ will make information reasonably necessary to demonstrate compliance with processor obligations available to the customer. Audits must protect other customers, confidential information and system security; documentary review or independent reports should be used first, with any further inspection coordinated in advance and limited to what is legally necessary.
11. Order of terms
If these Data Protection terms conflict with the Terms of Service on processing customer personal data, these Data Protection terms control. Any mandatory requirements of applicable data-protection law continue to apply.
Contact
Questions or requests can be sent to hello@pipelineiq.eu or +45 25 56 07 08.