Legal
Data Processing Addendum
Terms governing SparrowHawk CRM LLC's processing of personal data on behalf of Customer.
Effective: July 13, 2026
Last updated: July 13, 2026
- v2.0 · July 13, 2026Enterprise DPA covering scope, roles, subprocessors, security, sub-processing controls, international transfers, audits, and termination.
- v1.0 · June 1, 2026Initial DPA.
This Data Processing Addendum (“DPA”) is entered into between SparrowHawk CRM LLC (“SparrowHawk CRM,” the “Processor”) and the Customer (the “Controller”) and supplements the Terms of Service (the “Agreement”). It applies to Personal Data that SparrowHawk CRM Processes on behalf of Customer when Customer uses the SparrowHawk CRM platform.
1. Scope and Order of Precedence
This DPA applies whenever SparrowHawk CRM Processes Personal Data on Customer's behalf under the Agreement. In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Personal Data. In the event of a conflict between this DPA and a signed enterprise order form or a separately signed enterprise DPA, that enterprise document controls solely with respect to the Customer that signed it.
2. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. In addition:
- "Personal Data" means information that identifies or can reasonably be linked to an identified or identifiable natural person, that Customer submits to the platform.
- "Data Protection Laws" means all laws applicable to the Processing of Personal Data under this DPA, including as applicable the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and comparable US state privacy laws.
- "Data Subject," "Processing," "Controller," "Processor," and "Personal Data Breach" have the meanings given to them under applicable Data Protection Laws.
- "Subprocessor" means a third party engaged by SparrowHawk CRM to Process Personal Data on its behalf in connection with the platform.
3. Roles and Instructions
For Personal Data Customer submits to the platform, Customer is the Controller (or, where applicable, a Processor acting on behalf of a third-party Controller) and SparrowHawk CRM is the Processor. SparrowHawk CRM will Process Personal Data only (a) as necessary to provide, maintain, secure, and improve the platform, (b) in accordance with Customer's documented lawful instructions, which include the Agreement, this DPA, Customer's use of the platform's configurable features, and support requests submitted by authorized Customer personnel, and (c) as required by applicable law, in which case SparrowHawk CRM will notify Customer unless the law prohibits notice.
SparrowHawk CRM personnel authorized to Process Personal Data are bound by confidentiality obligations.
4. Duration and Termination
This DPA remains in effect for as long as SparrowHawk CRM Processes Personal Data on Customer's behalf under the Agreement and thereafter as necessary to comply with legal obligations described in the Data Retention & Deletion Policy.
5. Nature and Purpose of Processing
The nature and purpose of Processing is the provision of the SparrowHawk CRM platform as described in the Agreement. Categories of Data Subjects and Personal Data depend on how Customer uses the platform and typically include Customer's employees and contractors, Customer's end customers, aircraft owners and operators, portal users, and marketplace buyers, together with identifying, contact, business, transaction, and content data submitted through the platform.
6. Subprocessors
Customer authorizes SparrowHawk CRM to engage the Subprocessors listed on the Subprocessor List page. SparrowHawk CRM will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, remains responsible for its Subprocessors' performance, and will provide reasonable prior notice of any new Subprocessor.
Customer may object to a new Subprocessor on reasonable data-protection grounds within thirty (30) days of notice. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Agreement without penalty, effective at the end of the then-current billing period, as its sole and exclusive remedy.
7. Security Measures
SparrowHawk CRM will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure. Those measures are described on the Security & Trust Center page and include, at a minimum:
- encryption of Personal Data in transit (TLS) and at rest
- row-level tenant isolation enforced at the database layer
- role-based access control with a defined role hierarchy
- append-only audit logging of sensitive administrative actions
- least-privilege access to production systems for authorized personnel only
- vendor risk management for subprocessors
- vulnerability monitoring and dependency patching
- documented incident-response procedures
8. Personal Data Breach Notification
SparrowHawk CRM will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Personal Data Processed under this DPA. Notice will include the information reasonably available at the time and will be updated as additional information is confirmed. SparrowHawk CRM will cooperate with Customer's reasonable requests for information necessary for Customer to meet its own regulatory notification obligations, as described in the Incident Response Policy.
9. International Data Transfers
SparrowHawk CRM operates primarily from the United States. Where Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland is transferred to the United States or to another third country, SparrowHawk CRM will implement appropriate transfer mechanisms under Data Protection Laws, including European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable. Customer agrees that those transfer mechanisms are hereby incorporated by reference into this DPA and that SparrowHawk CRM may execute them on Customer's behalf where required.
10. Assistance to Controller
Taking into account the nature of the Processing and the information available to SparrowHawk CRM, SparrowHawk CRM will provide reasonable assistance to Customer in fulfilling its obligations to (a) respond to Data Subject requests to exercise their rights under applicable Data Protection Laws, (b) ensure the security of Processing, (c) notify Personal Data Breaches to supervisory authorities and Data Subjects where required, and (d) carry out data protection impact assessments and prior consultations with supervisory authorities where required. Customer will use platform features and the routes described in the Data Retention & Deletion Policy to respond directly to Data Subject requests wherever possible.
11. Audits and Records
SparrowHawk CRM maintains records of its Processing activities as required by Data Protection Laws and will make information reasonably necessary to demonstrate compliance with this DPA available to Customer on request, subject to appropriate confidentiality obligations. Where a Customer is an enterprise Customer subject to a signed order form that includes audit rights, those audit rights control. For all other Customers, SparrowHawk CRM will respond to reasonable written questionnaires no more than once per calendar year.
12. Return and Deletion
On termination of the Agreement, SparrowHawk CRM will, at Customer's choice and subject to Customer's export within the applicable window, delete or return Personal Data Processed under this DPA in accordance with the Data Retention & Deletion Policy. SparrowHawk CRM may retain Personal Data as required by applicable law and in backups on the schedule described in that policy.
13. Liability
Each party's liability under this DPA is subject to the limitations of liability set forth in the Agreement. This DPA does not increase either party's aggregate liability under the Agreement.
14. Governing Law and Venue
This DPA is governed by the law and venue provisions of the Agreement, except that where Data Protection Laws require a different governing law for a specific transfer mechanism, that requirement applies solely to the transfer mechanism.
15. Note for Legal Counsel
Customers subject to sector-specific rules (for example, HIPAA business-associate requirements or PCI DSS scope beyond payment processing handled by Stripe) or to jurisdiction-specific data-transfer requirements should contact legal@sparrowhawkcrm.com to discuss an enterprise addendum before relying on this standard DPA.
