Data Processing Agreement
How we process the personal data organizations record in AgentticCRM and what we commit to as their processor.
Version 1.0 · October 10, 2026
1. Parties and purpose
This agreement is entered into between the organization that subscribes to AgentticCRM (“the Organization”), acting as controller, and Global Agenttic (Negocios Virtuales, S.A.), based in Panama, acting as processor (“we”). It forms part of the Terms of Service and prevails over them on data protection matters.
It governs the processing of personal data included in Customer Data, which we carry out only to provide, protect, and support AgentticCRM. It is interpreted in accordance with Law 81 of 2019 of the Republic of Panama and its regulation, Executive Decree 285 of 2021, and any other data protection laws that are mandatory for the Organization.
2. What data, whose, and for how long
Nature and purpose: hosting, organizing, consulting, transmitting, and storing the information the Organization and its authorized users record in AgentticCRM to manage their relationships with clients, projects, communications, billing, and support.
Types of data: identification and contact details, job title and company, communications and messages, documents and files, commercial and billing data, form responses, and any other data the Organization chooses to record. The Organization should record sensitive data only when its law allows it.
Data subjects: the Organization’s clients, contacts, and prospects, people who submit its forms, its authorized users, and other people whose data the Organization chooses to record.
Duration: for as long as the Organization keeps its subscription and, afterwards, for the time needed to return or delete the data under section 11.
3. The Organization’s instructions
We process personal data only on the Organization’s documented instructions. These instructions are this agreement, the Terms of Service, the settings the Organization chooses in the platform, and the actions of its authorized users. We do not use the data for our own purposes, we do not sell it, and we do not disclose it to third parties, except as provided in this agreement or when a law requires it; in that case we will inform the Organization first, where the law allows.
If we believe an instruction breaches applicable law, we will inform the Organization and will not carry it out.
4. Confidentiality
People who work for us and may access personal data are bound by confidentiality, including after their relationship with us ends. They access it only when needed to provide the service, handle a support request authorized by the Organization, investigate an incident, or meet a legal obligation.
5. Security measures
We apply technical and organizational measures appropriate to the risk to protect the data against unauthorized access, alteration, loss, or disclosure. They include:
- Isolation of each organization’s data, also enforced in the database.
- Encryption of communications between the browser and the platform.
- AES-256-GCM encryption of credentials, integration tokens, and recovery points.
- Role-based permissions and additional verification for sensitive actions.
- An activity log of relevant actions.
- Backups and per-organization recovery points.
We review these measures when risks or the service change. The Privacy Policy describes the measures in force.
6. Subprocessors
The Organization specifically authorizes the subprocessors named in the “Operating providers and subprocessors” section of the Providers page, in the version in force when it accepts this agreement, for the functions described there.
We will notify the Organization’s administrators by email at least 30 days before adding a new subprocessor that processes Customer Data or changing the role of an existing one. Within that period, the Organization may object in writing on reasonable data-protection grounds. If we cannot find an alternative, the Organization may end its subscription without penalty before the change applies to its data.
We contractually impose on each subprocessor data protection obligations equivalent to those in this agreement, and we remain responsible to the Organization for their compliance.
Services the Organization chooses to connect with its own accounts or keys, such as Google, Meta, or the artificial-intelligence provider it configures, operate under the Organization’s relationship with that provider and are not our subprocessors.
7. Data subject requests
The Organization decides on requests for access, rectification, deletion, objection, portability, or withdrawal of consent made by its data subjects. AgentticCRM gives it tools to record each request with its deadline and locate the person’s data, and we will assist it in carrying out its decision.
If we receive a request directly that concerns the Organization’s data, we will forward it no later than the next business day and will not answer it on our own, unless the Organization instructs us to or the law requires it.
8. Security incidents
If we confirm a security incident affecting the Organization’s personal data, we will notify its administrators by email without undue delay and no later than 24 hours after confirming it.
The notice includes, as far as known: what happened and when, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact person. We will complete the information as the investigation progresses and cooperate so that the Organization can notify the authority and data subjects when it must; in Panama, within 72 hours.
9. International transfers
AgentticCRM’s main infrastructure and some subprocessors are located outside Panama. The Organization authorizes these transfers so that we can provide the service. We protect them through the obligations in this agreement, those we impose on each subprocessor, and the measures in section 5, so that the data keeps a level of protection equivalent to the one required by applicable law.
When the Organization’s law requires data subjects’ consent to transfer their data abroad—for example, in Costa Rica or the Dominican Republic—the Organization must disclose it and obtain it in its own privacy notice.
10. Information and audits
We will make available to the Organization the reasonable information needed to demonstrate compliance with this agreement. The Organization may request an audit at most once a year, except after an incident or at an authority’s request, with at least 30 days’ notice, at its own cost, during business hours, without compromising other organizations’ security, and under a duty of confidentiality regarding what it learns.
11. Return and deletion at the end
During the subscription, the Organization can export its data from the platform. When it ends, we will delete Customer Data within the following 30 days, except data that a law requires us to keep, which we will keep blocked only for that legal period.
Copies held in recovery points are deleted when their retention period expires, which the Organization configures: 30 days by default and never more than 365.
12. Governing law and liability
This agreement is governed by the laws of the Republic of Panama, without prejudice to the data protection rules of another country that are mandatory for the Organization. Each party’s liability is governed by the Terms of Service, unless applicable law provides otherwise.
13. Acceptance and record
An administrator of the Organization accepts this agreement on its behalf from Settings › Data Processing Agreement. The platform records the accepted version, the date, and the person who accepted it, and lets you download the record. If we publish a new version, we will notify administrators reasonably in advance; the accepted version remains in force until the new one is accepted or the subscription ends.