MiridarMiridar
Sales CRMAIIntegrationsPricingHR AppContact
Login →Get a demo
HomeLegal documentsData Processing Agreement
DPA — Data Processing Agreement

Data Processing Agreement

This DPA governs how Miridar (as processor) handles personal data that the customer (controller) uploads into Miridar CRM. Companion document to the Terms and Privacy Policy. Compliant with Art. 28 GDPR.

Last updated: May 27, 2026 Miridar — Strada Mihai Viteazu 4, Chișinău, Moldova
Table of contents
  1. Parties and roles
  2. Subject matter and duration
  3. Processor obligations
  4. Subprocessors
  5. International transfers
  6. Data-subject rights
  7. Security breach notification
  8. Return / deletion at contract end
  9. How we accept this DPA

Questions about this document?

[email protected]

1. Parties and roles

Controller (data controller): the Miridar CRM customer who decides the purpose and means of processing the data entered into the app.

Processor (data processor): Miridar (MiriDar HR + IT Agency SRL), who processes data exclusively on behalf of the customer, per documented instructions.

2. Subject matter and duration

Miridar processes customer data for the duration of the subscription plus 90 days post-cancellation (for final export). Data types include:

  • Contact data (name, email, phone of the customer's contacts)
  • Deal/contract data (amounts, status, history)
  • HR data (if HR App is active): employment contracts, time tracking, leave, CVs, documents
  • App usage data (audit log)

3. Processor obligations

Miridar undertakes to:

  • Process data only per the customer's documented instructions.
  • Ensure confidentiality — data access is restricted to authorized personnel under non-disclosure clauses.
  • Implement appropriate technical and organizational measures: TLS encryption in transit, AES-256 at rest, 2FA for personnel, audit log, daily backup, EU hosting.
  • Assist the customer with data-subject requests (access, rectification, erasure, portability).
  • Notify the customer without undue delay if a security breach occurs.
  • Allow audits on reasonable request, with 30 days' notice.

4. Subprocessors

To deliver the service, Miridar uses the following authorized subprocessors:

  • Amazon Web Services (AWS) Frankfurt — hosting, databases, backup (European Union)
  • Cloudflare — DNS and DDoS protection
  • Google (gtag/GA4) — aggregated analytics on the marketing site (NOT on the CRM application)

For BYO integrations (AI: OpenAI / Anthropic; Email: Mailjet), the customer contracts directly with that provider — Miridar only facilitates the connection, transmits no data of its own.

30 days' notice before adding a new subprocessor. The customer may object with reason; if no replacement is found, the contract may be terminated without penalty.

5. International transfers

Data stays in the EU on AWS Frankfurt infrastructure. We do not transfer data outside the EEA without a GDPR legal basis (standard contractual clauses or European Commission adequacy decision).

6. Data-subject rights

The customer, as controller, is responsible for responding to data-subject requests (employees, contacts). Miridar assists technically — we provide:

  • Complete data export (Excel, CSV, JSON) for portability / access requests
  • Data deletion feature for 'right to be forgotten' requests
  • Audit log for all changes on a specific contact

7. Security breach notification

In case of a breach, Miridar notifies the customer within 72 hours of becoming aware, with:

  • Nature of the breach
  • Categories and approximate number of data subjects
  • Likely consequences
  • Measures taken or proposed for remediation

8. Return / deletion at contract end

At the end of the contract, the customer has 90 days to export all data. After that, Miridar irreversibly deletes the customer's data from production within 30 days, including from backup (in the normal 30-day post-active retention cycle).

9. How we accept this DPA

This DPA is an integral part of the Terms accepted by the customer when signing the Cloud or Self-hosted subscription. For a physically/electronically signed DPA, email office@miridar.com — we send it within 2 business days.

Let's see for ourselves

Want to see what Miridar CRM looks like
for your business?

Request a personalized demo. We'll show you exactly how it maps onto your processes — sales, integrations, new client journey. Direct answers, no pitch.

Get a personalized demo or talk to us directly

20 minutes, no commitment. We'll tell you honestly if Miridar fits your company.

EU hosting·EU hosting·We reply within 24 business hours
MiridarMiridar

The CRM that shows you exactly where every new client stands.

Built for service providers and SMBs. All features, from the first user.

Get a personalized demo
Platform
  • Sales CRM Core
  • AI + Automation
  • Integrations & Communications
  • New Client Journey
  • Pricing
  • About Miridar
  • Contact
Modules & Integrations
  • AI Workspace
  • Mailjet
  • Telegram
  • External API
  • History & Audit
  • Miridar HR App →
Resources & Contact
  • Privacy Policy
  • Terms & Conditions
  • DPA
  • [email protected]
  • +373 683 09049
  • Strada Mihai Viteazu 4,
    Chișinău, Moldova
© 2026 Miridar SRL. All rights reserved.Made with ♥ in Chișinău.
|Login →