← Back to sign in

Data Processing Addendum

Effective date: June 9, 2026

Last updated: June 9, 2026

1. Scope and Roles

This Data Processing Addendum (DPA) forms part of the agreement between Facify (the Processor) and the customer organization (the Controller) governing use of the Facify service. The customer determines the purposes and means of processing personal data; Facify processes personal data only on the customer's behalf and documented instructions.

2. Categories of Data and Data Subjects

Processing covers personal data contained in the customer's connected Salesforce organization and the Facify platform, including names, email addresses, mailing addresses, phone numbers, employer and role information, and communication activity. Data subjects include the customer's employees, business contacts, prospects, and clients.

3. Nature and Purpose of Processing

Facify processes personal data to synchronize records between the customer's Salesforce organization and the Facify platform, to execute outreach workflows the customer configures (including email and physical card sending), and to provide reporting and activity history within the service.

4. Confidentiality

Facify ensures that personnel authorized to process personal data are bound by confidentiality obligations and access customer data only as necessary to operate, support, and secure the service.

5. Security Measures

Facify implements technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest, tenant-level data isolation, role-based access control, encrypted storage of integration credentials, structured audit logging, and regular review of access to production systems.

6. Subprocessors

The customer authorizes Facify to engage subprocessors for cloud hosting, database services, file storage, transactional email delivery, and print-and-mail fulfillment. Facify maintains a current list of subprocessors, available on request, imposes data protection obligations on each subprocessor no less protective than those in this DPA, and will notify customers of subprocessor changes with an opportunity to object.

7. Data Subject Requests

Facify will, taking into account the nature of the processing, assist the customer in responding to requests from data subjects to exercise their rights (access, correction, deletion, portability, restriction). Requests received directly by Facify will be forwarded to the customer without undue delay.

8. Breach Notification

Facify will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data, and will provide information reasonably required for the customer to meet its own notification obligations.

9. Data Return and Deletion

Upon termination of the agreement, Facify will, at the customer's choice, return or delete all personal data processed on the customer's behalf within 90 days, except where retention is required by applicable law.

10. Audits

Facify will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and security documentation, and will allow for audits conducted by the customer or an agreed independent auditor, subject to reasonable notice and confidentiality obligations.

11. International Transfers

Customer data is stored and processed in the United States. Where personal data originating from other jurisdictions is processed, the parties will rely on appropriate transfer mechanisms required by applicable data protection law.

12. Governing Law

This DPA is governed by the laws of the State of New Jersey, United States, consistent with the Terms of Service.

13. Contact

For questions about this DPA or to request the current subprocessor list, contact ed.corvelli@facify.io.