Skip to content
Spin CRM

Data processing terms

These terms apply when your company keeps its customers’, contacts’, suppliers’ or employees’ personal data in Spin CRM. In that case you are the data controller and UAB „Empera LT“ is the data processor, acting on your instructions.

This document meets the requirements of Article 28 of the General Data Protection Regulation (GDPR) and forms an integral part of the service agreement. It can be attached to that agreement on its own.

For the data of which we are the controller — your account, billing, your visits to the website — see the Privacy policy.

1. The parties

Data controller Your company — the customer named in the service agreement
Data processor UAB „Empera LT“, company code 304066716, Dūkštelių g. 106, Gudelių k., LT-14247 Vilnius district, Lithuania
Contact for data matters [email protected], +370 663 52000

2. Subject matter and duration

Subject matter. Provision of the Spin CRM business management system: storing, processing and presenting data to you through the system’s interface, its API and the integrations you have switched on.

Duration. Processing continues for as long as the service agreement is in force and ends once the return or deletion described in section 10 has been carried out.

Nature and purpose. Data is collected, stored, altered, sorted, displayed, transmitted to the integrations you designate, and deleted — solely so that the service you ordered works.

3. Categories of data and data subjects

Exactly what data to keep in the system is for you to decide, including in fields you create yourself. Typically it is:

Data subjects Categories of data
Your customers and prospects Name, job title, company, email, phone, address, correspondence, records of calls having taken place, deals, invoices, payments, documents
Your customers’ contact persons Name, job title, contact details, communication history
Your suppliers and partners Registration details, contact persons, purchase documents
Your employees Contact details, job title, department, work schedules, per diems, document expiry dates, activity records
Visitors to your website Data submitted in forms and the chat widget, the sequence of pages viewed in the context of a conversation

Special categories of data. The system is not intended for health, biometric, religious, political or other data listed in Article 9 GDPR. If you nevertheless intend to keep such data, you must tell us in advance so that we can assess whether additional measures are needed.

4. Your instructions

We process data only on your documented instructions. Instructions means:

  • the service agreement and these terms;
  • the settings you have made in the system — modules, integrations, automations, permissions and retention periods you have switched on;
  • separate written requests from you that we have accepted.

If, in our view, an instruction would infringe the GDPR or other data protection law, we will inform you without delay and may suspend carrying it out until the matter is resolved.

If the law required us to process data otherwise than you instructed, we will inform you beforehand — unless that same law prohibits such notification on important grounds of public interest.

5. What we do not do

These undertakings are the heart of this document, so we set them out plainly:

  • We do not use your data for our own purposes — not for marketing, not for sales, not for product analysis, not for market research.
  • We do not sell your data and do not supply it to advertising networks.
  • We do not train public artificial intelligence models on your data.
  • We do not combine your data with other customers’ data — every customer has a separate database.
  • We do not access your data needlessly: only where maintaining the service requires it or where you ask us for help.

6. Confidentiality

Only those of our staff who need it for their work have access to your data. All of them have undertaken in writing to keep it confidential, and that undertaking survives the end of their employment. Staff are trained on data protection requirements.

7. Security measures

We implement the technical and organisational measures required by Article 32 GDPR:

Measure How it works
Data separation Every customer has a separate database — there is no shared table holding every company’s data
Encryption in transit TLS between the browser, the mobile app, the API and the system
Access control Roles and their hierarchy, sharing rules, permissions by component, by action and down to a single record and field
Authentication Two-factor authentication (Google Authenticator or SMS) in “allowed / recommended / mandatory” modes; an allowed IP address list; protection against password guessing
Traceability User activity log, login history, device management, integration operation log
Recovery Backups are taken once a day at night and kept for 14 days
Personnel Reassignment of records when an employee leaves; withdrawal of access when employment ends

We review the measures and update them where needed. If a measure were to be replaced with a less protective one, we would inform you in advance.

8. Sub-processors

You give us general written authorisation to engage sub-processors. We enter into a contract with each of them imposing data protection obligations no lower than those in these terms. We remain liable for a sub-processor’s acts as for our own.

8.1. Sub-processors always involved

Sub-processor Service Location
Hosting and data centre provider Servers, data storage, backups European Union
Cloudflare Protection against attacks, traffic management EU / USA — standard contractual clauses
OpenAI Artificial intelligence features, where switched on USA — standard contractual clauses (see s. 13)
Google (Firebase Cloud Messaging) Push notifications, where switched on EU / USA — standard contractual clauses

8.2. Connectors you switch on yourself

More than twenty Spin CRM integrations (accounting, banks, email, telephony, messaging channels, marketing platforms) do not run by themselves — you switch each one on, in your own settings and with your own credentials.

By switching a connector on you, as the data controller, decide to transfer certain data to that service. From the moment of transfer, that provider’s terms govern the processing of that data and the relationship with them is yours to manage — we are only the technical channel. Before switching one on, satisfy yourself that you have a legal basis for doing so.

The full and current list of connectors is on the integrations page.

8.3. Changes

We give at least 30 days’ notice of any intention to engage a new sub-processor under section 8.1 or to replace an existing one. You may reasonably object within that period. If an objection cannot be resolved, you have the right to terminate the service agreement without penalty, and we refund the amount paid for the unused period.

9. Assistance to you

Data subject requests. When one of your customers or employees approaches you, the tools in the system — search, views, export, editing, deletion — let you answer them yourself. If that is not enough, we help. If a data subject approaches us directly, we will not act on the request: we will forward it to you without delay, because you are the controller.

Impact assessments and consultations. Taking into account the information available to us, we assist you in meeting your obligations under Articles 32–36 GDPR, including data protection impact assessments and prior consultation with the supervisory authority.

10. Return and deletion of data

At any time while using the system you can export your data yourself to Excel or retrieve it through the open REST API. The data is yours.

When the service agreement ends we will, at your choice, return the data in a machine-readable format or delete it. You must tell us your choice within 30 days of the end of the agreement; if you do not, we delete the data.

Once data is deleted from the live system, we also remove it from backups in the course of the normal rotation cycle — within 14 days. Until the backups have rotated, the data remains isolated within them and is not used for any purpose.

We may keep data longer only to the extent required by European Union or Lithuanian law.

11. Personal data breaches

Having become aware of a personal data breach affecting your data, we will inform you without undue delay and in any event within 24 hours of becoming aware of it.

The notification will state what is known at the time: the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures we have taken or intend to take. If we do not have all the information at once, we provide it in stages, without preventing you from notifying the supervisory authority in time.

Notification to the supervisory authority and to data subjects is made by you as the controller; we provide the information and assistance needed for it.

12. Audits and evidence

At your request we provide the information needed to demonstrate our compliance with the obligations in Article 28 GDPR.

You have the right to carry out an audit, or to mandate an independent auditor to whom we do not object. Audits are arranged in advance — on at least 30 days’ notice, during working hours, no more than once a year (unless prompted by a personal data breach or a requirement of the supervisory authority), and in a manner that does not disrupt the service or expose other customers’ data. The auditor signs a confidentiality undertaking.

13. Transfers outside the EU

Your system data is held in the European Union.

Where data reaches the US providers named in section 8.1, the transfer relies on the European Commission’s standard contractual clauses and, where applicable, the EU–US Data Privacy Framework, together with supplementary safeguards.

Artificial intelligence features. If you switch them on, AI requests are processed by OpenAI in the United States. OpenAI does not use the transferred data to train models and keeps it for no longer than 30 days for abuse monitoring, after which it is deleted.

Where data is transferred outside the EU because of a connector you switched on yourself, that transfer follows from your decision and it is for you to ensure it has a legal basis.

14. Artificial intelligence

If you switch AI features on, the following additional terms apply:

  • We send the AI model only what a specific action requires — for example, the contents of the document being scanned or the text of an email. We do not transfer your database as a whole.
  • Public models are not trained on your data.
  • The AI connector (MCP) is read-only — it cannot change or delete a single record — and sees exactly as much as that same person would see at that moment. It does not bypass the permission system.
  • The result of a scanned document is confirmed by a person before it is saved. There is no automatic entry without review.
  • AI makes no decisions producing legal effects for you or for data subjects.
  • AI features can be switched off entirely — the system works the same without them.

15. Liability and validity

The parties’ liability is set out in the service agreement. If these terms conflict with the service agreement on matters of personal data processing, these terms prevail.

These terms are governed by the law of the Republic of Lithuania. We give at least 30 days’ notice of material changes to them.

This version applies from 31 August 2026.