Skip to main content
Spodus
  • Enterprise
  • Pricing
Log inContact salesStart free

Legal

Data Processing Agreement

What we commit to as the custodian of the data you put into Spodus. Published so you can read it before you sign, not after.

Effective July 28, 2026

On this page

  1. 1. Roles
  2. 2. Our instructions
  3. 3. Confidentiality of personnel
  4. 4. Security measures
  5. 5. Sub-processors
  6. 6. Requests from individuals
  7. 7. Breach notification
  8. 8. Return and deletion
  9. 9. Audits and information
  10. 10. US state privacy laws: service provider terms
  11. 11. Data location, and personal data from outside the US
  12. 12. Liability and precedence
  13. 13. Annex A: details of processing
  14. 14. Annex B: technical and organisational measures

This agreement (the “DPA”) forms part of the terms of service between Olum LLC (“Spodus”, “we”) and the customer (“you”). It applies automatically when you use Spodus Cloud. You do not need to request, sign or negotiate it for it to bind us.

If your procurement process needs a countersigned copy on your own paper, email [email protected] and we’ll sort it out. We don’t charge for that and we don’t gate it behind a plan tier.

1. Roles

For the records you load into Spodus, you are the controller (or “business”) and we are the processor (or “service provider”). You decide what personal information to collect, from whom, and why. We process it only to provide the service to you.

For your own account, billing and support data, we act as controller in our own right. That is covered by our privacy notice, not by this DPA.

2. Our instructions

We will process personal information only on your documented instructions. Your instructions consist of this DPA, the terms of service, your configuration of the product, and any further written instruction you give us.

We will tell you if, in our opinion, an instruction you give us would break the law, and we may decline to act on it until it’s resolved. If we are legally compelled to process data beyond your instructions, we’ll notify you first unless the law forbids it.

3. Confidentiality of personnel

Access to your data is limited to personnel who need it to operate or support the service. Everyone with such access is bound by a written confidentiality obligation that survives their engagement with us, and receives training appropriate to what they can reach. Access is authenticated, least-privilege, and logged.

4. Security measures

We maintain the technical and organisational measures set out in Annex B, clause 14 below. We may update them as technology and threats change, but we will not materially reduce the overall level of protection during your subscription.

5. Sub-processors

You give us general authorisation to engage sub-processors. Every one currently engaged is listed by name, with its purpose and location, on our sub-processors page, which is the authoritative list.

We will give at least 30 days’ notice before a new sub-processor begins processing your data, by updating that page and emailing anyone on the notification list. You may object on reasonable, documented grounds; if we cannot resolve your objection, you may terminate the affected subscription and receive a pro-rated refund for the unused remainder of the term.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

6. Requests from individuals

Spodus gives you the tools to access, correct, export and delete records yourself, so in most cases you can answer a request from an individual without involving us at all.

Where you can’t, we’ll provide reasonable assistance, at no charge for ordinary volumes. If an individual contacts us directly about data you control, we will not respond substantively; we will tell them to contact you, and let you know it happened.

7. Breach notification

We will notify you without undue delay, and in any case within 72 hours of becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your data.

That notice will include, as far as we know it at the time:

  • what happened and when, and when we found out;
  • the categories and approximate volume of data and individuals affected;
  • the likely consequences;
  • what we have done to contain and remediate it; and
  • a contact who can answer follow-up questions.

We will send a first notice within that window even if the picture is incomplete, and update you as we learn more. Waiting for a tidy account is how notification deadlines get missed.

This said 48 hours. We changed it to 72 because 48 was a number we could not stand behind: Spodus is run by a very small team with no 24/7 on-call rotation, and a commitment that depends on someone happening to be awake is not a commitment. 72 hours is what we can meet on a weekend. In practice you will hear from us far sooner — the clock is a floor, not a plan.

Deciding whether to notify regulators or individuals about data you control is your call as controller. We will give you the information you reasonably need to make it and to meet your own deadlines.

8. Return and deletion

You can export your data at any time during your subscription, without asking us. On termination you have 30 days to export.

After that we delete your data from live systems. It ages out of backup rotation within a further 30 days. We’ll confirm deletion in writing on request.

One honest limitation: we cannot surgically remove an individual record from a backup image that has already been written. Deletion from backups happens when that image expires, on the rotation described above. Any vendor telling you otherwise is describing a system that does not work the way backups work.

9. Audits and information

On reasonable written request, and no more than once a year unless a breach or a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate our compliance with this DPA. That includes completed security questionnaires and our documented security measures.

We do not hold a SOC 2 or ISO 27001 report of our own and we will not pretend to. Rather than send you an audit report we don’t have, we’ll answer your questionnaire directly and tell you where we fall short. Our security page sets out our current position without varnish.

10. US state privacy laws: service provider terms

Where you are subject to a US state privacy law such as the California Consumer Privacy Act, we act as your service provider or processor as those laws define the term, and we certify that we:

  • will not sell or share personal information, as those terms are defined by applicable state law;
  • will not retain, use or disclose personal information for any purpose other than performing the service for you, or as otherwise permitted by law;
  • will not retain, use or disclose it outside the direct business relationship between us;
  • will not combine it with personal information received from another source, except as the law permits a service provider to do;
  • will not use it for cross-context behavioural advertising, or to build or train any general-purpose model; and
  • will notify you if we determine we can no longer meet these obligations, and will stop processing or take reasonable steps to remediate.

You may take reasonable and appropriate steps to confirm we are using personal information consistently with your obligations, and to stop and remediate unauthorised use.

11. Data location, and personal data from outside the US

Spodus Cloud is hosted in Germany — Hetzner’s Nuremberg data centre — and we process your data there. Spodus is sold to businesses in the United States, and we do not market or provide the service in the European Economic Area, the United Kingdom or Switzerland.

We recognise that a US business may nonetheless hold records about people located elsewhere. Where you are subject to the EU or UK GDPR in your own right and instruct us to process such records, the commitments in this DPA, on instructions, confidentiality, security, sub-processors, assistance with individual requests, breach notification, deletion and audit, are intended to give you the processor terms Article 28 requires you to obtain from us.

Being straight with you: the infrastructure is in Germany, but Spodus is a US company. It is not established in the EU, has not appointed an Article 27 representative, and does not target the EU market. If EU or UK data protection compliance is central to your purchase, factor that in before you buy, and talk to us first. We would rather lose the deal than have you discover this at your own audit.

12. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the terms of service. Where this DPA conflicts with those terms on the handling of personal information, this DPA governs. Where you have signed a negotiated data processing agreement with us, that document governs over this one.

13. Annex A: details of processing

Subject matter. Provision of the Spodus Cloud business management suite.

Duration. The term of your subscription, plus the retention periods in clause 8.

Nature and purpose. Hosting, storage, organisation, retrieval, transmission, backup and deletion of business records, so that you can run customer relationships, finance, HR, support and internal communication.

Categories of individual. Your customers, prospects, suppliers, employees, contractors, and any other person whose details you choose to record.

Categories of personal information. Identification and contact details; business and employment details; commercial records such as deals, invoices and payment status; correspondence and support history; scheduling and calendar entries; files you upload; and system activity logs.

Excluded categories. Protected health information, consumer health data, full payment card data, biometric identifiers, and children’s data, each as set out in clause 6 of the terms of service. These must not be submitted to Spodus, and this DPA does not contemplate processing them.

Location of processing. Germany (Hetzner, Nuremberg). See our sub-processors page for each provider.

14. Annex B: technical and organisational measures

Encryption. TLS 1.2 or higher for all data in transit. Credentials for third-party services you connect (mailbox, calendar) are encrypted with AES-256-GCM before storage. Database storage, uploaded files and backup dumps are access-controlled but are not separately encrypted at rest at this time.

Access control. Role-based permissions, least-privilege administrative access, enforced authentication, and two-factor authentication available to every user on every plan. Single sign-on and directory provisioning are not offered.

Tenant isolation. Each workspace’s data is logically separated, and application queries are scoped to the requesting workspace.

Logging. Authentication events, permission changes and administrative actions are recorded to an append-only log. The database grants the application SELECT and INSERT on it and nothing else, so entries cannot be altered or deleted from inside the product — by us or by an administrator of your workspace. They are kept for the life of the workspace rather than for a fixed window.

Resilience. Automated nightly backups of the database and of the cluster roles a restore depends on, retained 14 days, pulled the same night to a second, independent host that retains 30 days. The mirror is pull-only over a private network, so a compromise of the primary cannot delete backup history. Recovery point is the last nightly run, meaning up to 24 hours of changes may be lost in a restore. Restore procedure is documented and exercised: most recently on 2 August 2026, rebuilding an actual nightly dump into a scratch database and verifying it came back identical — same 53 tables, same row counts, table ownership intact and row-level security still enforced, with no errors. An earlier drill on 31 July is what established that the role dump is required at all, because a dump without it restores data the application then cannot serve.

Network protection. Traffic fronted by Cloudflare for TLS termination, DDoS mitigation and edge filtering. Administrative interfaces are not publicly exposed.

Secure development. Version-controlled changes with peer review, dependency vulnerability monitoring, and separated development and production environments.

Personnel. Written confidentiality obligations, least-privilege access provisioning, and prompt revocation on departure.

Vulnerability reporting. A published disclosure route at /security/disclosure and in our security.txt.


Olum LLC8206 Louisiana Blvd NESte A #8845Albuquerque NM 87113
Spodus

The all-in-one business suite — CRM, finance, HR, support, and inbox — in one seat.

Product

  • CRM
  • Finance
  • HR
  • Support
  • Inbox
  • Pricing

Solutions

  • Agencies
  • Small businesses
  • Consultants
  • Startups
  • Nonprofits
  • All solutions

Features

  • Connected data
  • Automations
  • Collaboration
  • Customer portal
  • Roles & permissions
  • Dashboards
  • All features

Compare

  • vs Salesforce
  • vs HubSpot
  • vs QuickBooks
  • vs Zendesk
  • vs monday.com
  • All comparisons

Company

  • Security
  • Contact

© 2026 Spodus Studios · Operated by Olum LLC.

PrivacyTermsDPASub-processors