Data Processing Addendum

Last updated: September 4, 2026

You do not need to sign this. This Addendum is incorporated into the Terms of Service and applies automatically, from the moment you create a workspace, to every customer whose processing is subject to the EU GDPR, the UK GDPR, or the Swiss FADP. If your procurement process requires a counter-signed copy, email privacy@current.day and we will send one.

This Data Processing Addendum (the “Addendum”) forms part of the Terms of Service between IT Partners Plus LLC, a Delaware limited liability company (“ITPartners+,” “we,” “us”) and the customer entity that has agreed to those Terms (“Customer,” “you”), and governs our processing of personal data on your behalf in providing Current (the “Service”).

1. Roles of the parties

For personal data contained in Customer Data, you are the controller (or, where you process on behalf of your own clients, the processor) and we are the processor (or sub-processor). We process that personal data only on your documented instructions, which consist of these Terms, this Addendum, the configuration choices you make in the Service, and any further written instruction you give us.

For account, billing, security-log, and marketing data about your administrators and contacts, we act as an independent controller, as described in the Privacy Policy. This Addendum does not apply to that processing.

We will tell you if, in our opinion, an instruction infringes applicable data-protection law, and we may suspend the affected processing until the instruction is withdrawn or amended.

2. Your obligations

You warrant that you have a lawful basis for the personal data you place in, or connect to, your workspace, that you have given the notices and obtained the consents applicable law requires, and that your instructions to us comply with that law. This applies in particular to:

3. Details of processing

Subject matter and duration

Provision of the Service, for the duration of your subscription plus the retention periods in Section 9.

Nature and purpose

Hosting, storage, synchronization with the systems you connect, scheduling and project delivery, CRM and sales operations, time capture for billing in your PSA, reporting and dashboards, notification delivery, and AI-assisted drafting and analysis — all as directed by your use of the Service’s features.

Types of personal data

Names, business contact details, job titles, employment and assignment records, calendar and availability data, time entries, message and comment content, email content where you enable mailbox capture, file references, commercial records that identify individuals (deals, quotes, contracts, tickets), authentication identifiers, and usage and audit logs.

Categories of data subjects

Your personnel; your clients’ personnel and contacts; your prospects; and external users you invite to the partner portal.

Special category data

The Service is not designed for, and must not be used to process, special categories of personal data under Article 9, criminal-offence data under Article 10, payment card numbers, or government identification numbers. If you place such data in a workspace, you do so on your own instruction and at your own risk.

4. Confidentiality and personnel

We limit access to Customer Data to the personnel who need it to deliver, support, and secure the Service. Those personnel are bound by written confidentiality obligations that survive their engagement, and access is provisioned on the principle of least privilege.

Our commitment as an MSP. ITPartners+ operates a managed services business alongside Current. Personnel access Customer Data only to provide support, investigate a security or availability issue, or comply with a legal obligation — and only where there is a logged business need. We do not access, review, or use your client lists, pricing, contracts, margins, or pipeline for any competitive, sales, benchmarking, or business-development purpose, and we do not disclose them to our managed services business. This obligation survives termination. We will sign a mutual non-disclosure agreement on request.

5. Security measures

We implement and maintain appropriate technical and organizational measures under Article 32. Our controls are covered by a SOC 2 Type II attestation; the report is available under NDA on request. Measures include:

We may update these measures over time, provided the level of protection is not materially reduced.

6. Subprocessors

You give a general written authorization for us to engage subprocessors. The current, named list — what each does, what it processes, and where — is published at current.day/subprocessors, which forms part of this Addendum.

We impose data-protection obligations on each subprocessor that are no less protective than those in this Addendum, and we remain liable to you for their performance. Before adding or replacing a subprocessor that can process Customer Data we give at least 30 days’ notice, and you may object on reasonable data-protection grounds within that period; the objection process and remedy are set out on that page.

A third-party service you connect using your own account and credentials — your PSA, HubSpot, a prospecting or enrichment tool, an email verifier, a direct-mail service, or a reporting feed — is not our subprocessor. We exchange data with it under your instruction; your relationship with that vendor is governed by your contract with them.

7. Assisting you

Data subject requests

The Service gives you direct access to the personal data in your workspace, so that you can find, correct, export, and delete records yourself in order to answer a data subject. If a data subject contacts us directly about data in your workspace, we will not respond substantively; we will refer them to you and tell you promptly. Where you need more help than the Service’s own tools provide, we will give reasonable assistance, taking into account the nature of the processing.

Assessments and consultation

We will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, to the extent they relate to our processing and you cannot reasonably obtain the information elsewhere.

8. Personal data breach

If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notification will describe, so far as we know it at the time, the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses and give reasonable assistance with any notification you must make to a supervisory authority or to data subjects.

Notice will go to the workspace administrators on file. Keep an administrator email address current — it is where a breach notice will be sent.

Our notifying you is not an acknowledgement of fault or liability.

9. Export, retention, and deletion

Export during your subscription

At any time while your subscription is active, you may request an export of your Customer Data in a commonly used, machine-readable format. We will provide it within 30 days of the request, at no charge for a reasonable number of requests.

On termination

For 30 days after termination or expiry, your Customer Data remains available for export on request. After that window, we delete Customer Data from live production systems within 30 days, and in any event no later than 60 days after the end of the export window.

Backups

Deleted data persists in encrypted, rolling backups until those backups age out on their normal cycle, which will be no later than 90 days after deletion from live systems. Backups are not selectively edited; they are not restored into production except to recover from an incident, and data restored from a backup is re-deleted on the same basis.

What we keep, and why

On written request we will confirm deletion has been carried out.

Where the source of truth lives. Current is designed so that the records that matter — projects, tasks, time, tickets, contracts, and billing — remain in your PSA. Deleting a Current workspace does not delete anything from your PSA, your Microsoft 365 tenant, or any other system you connect. Those remain entirely under your control.

10. International transfers

Customer Data is hosted in the United States, and our subprocessors process it in the United States unless the list at current.day/subprocessors says otherwise. Where personal data is transferred out of the EEA, the UK, or Switzerland, the following safeguards apply and are incorporated into this Addendum:

If a safeguard we rely on is invalidated or superseded, we will adopt an alternative lawful transfer mechanism without undue delay.

Government access requests. If we receive a legally binding demand from a public authority for Customer Data, we will notify you before disclosing, unless legally prohibited; where prohibited, we will use reasonable efforts to challenge the prohibition and to disclose the minimum necessary. We have not received a national-security order requiring bulk disclosure of Customer Data.

11. Audits and information

On request, and no more than once in any twelve-month period unless a supervisory authority or a personal data breach requires otherwise, we will make available the information reasonably necessary to demonstrate compliance with this Addendum. In the first instance this means our SOC 2 Type II report under NDA, our security documentation, and our response to a reasonable security questionnaire. Where that is genuinely insufficient to satisfy an audit obligation, we will discuss a further audit, conducted on reasonable notice, during business hours, without disrupting the Service or accessing another customer’s data, and at your cost.

12. AI processing

Where you use an AI feature, the workspace records relevant to that feature are processed by our AI subprocessor to generate the output. Customer Data is not used to train our models or any third party’s foundation models, and that restriction is contractual, not a setting. AI output is a draft for you to review; you decide whether to act on it. No decision producing a legal or similarly significant effect on a data subject is made by automated means without human involvement.

13. Liability and precedence

Each party’s liability under this Addendum is subject to the exclusions and the aggregate liability cap in the Terms of Service, and any liability arising under this Addendum counts toward that cap. Where a term of this Addendum conflicts with the Terms of Service or the Privacy Policy in respect of processing subject to the EU GDPR, UK GDPR, or Swiss FADP, this Addendum prevails. Where a term of this Addendum conflicts with the Standard Contractual Clauses, the Clauses prevail.

14. Term and changes

This Addendum takes effect when you accept the Terms of Service and continues until we have ceased all processing of Customer Data. We may update it to reflect a change in law, in a safeguard, or in our security measures; for material changes we will give at least 30 days’ notice by email or in-product notice, and we will not reduce the level of protection it provides.

15. Contact

For anything under this Addendum — a countersigned copy, a security questionnaire, a data subject request, a subprocessor objection, or a breach question — contact privacy@current.day, or write to IT Partners Plus LLC, 2851 Charlevoix Dr, Suite 100, Grand Rapids, MI 49512, United States.