Data Processing Addendum
Last updated: September 4, 2026
This Data Processing Addendum (the “Addendum”) forms part of the Terms of Service between IT Partners Plus LLC, a Delaware limited liability company (“ITPartners+,” “we,” “us”) and the customer entity that has agreed to those Terms (“Customer,” “you”), and governs our processing of personal data on your behalf in providing Current (the “Service”).
1. Roles of the parties
For personal data contained in Customer Data, you are the controller (or, where you process on behalf of your own clients, the processor) and we are the processor (or sub-processor). We process that personal data only on your documented instructions, which consist of these Terms, this Addendum, the configuration choices you make in the Service, and any further written instruction you give us.
For account, billing, security-log, and marketing data about your administrators and contacts, we act as an independent controller, as described in the Privacy Policy. This Addendum does not apply to that processing.
We will tell you if, in our opinion, an instruction infringes applicable data-protection law, and we may suspend the affected processing until the instruction is withdrawn or amended.
2. Your obligations
You warrant that you have a lawful basis for the personal data you place in, or connect to, your workspace, that you have given the notices and obtained the consents applicable law requires, and that your instructions to us comply with that law. This applies in particular to:
- employee, contact, and client personal data you synchronize from a connected PSA, CRM, RMM, or mailbox;
- prospecting and enrichment data obtained through an integration you connect using your own account — you are the controller for that data, and Articles 13 and 14 notice obligations toward those individuals are yours, not ours;
- outbound campaign and sequence email sent through the Service — you are the sender and controller, and you are responsible for compliance with direct-marketing rules, including the UK Privacy and Electronic Communications Regulations and equivalent ePrivacy rules, which treat sole traders and partnerships differently from incorporated businesses; and
- any personal data you expose to external users through the partner portal, public lead forms, or booking pages.
3. Details of processing
Subject matter and duration
Provision of the Service, for the duration of your subscription plus the retention periods in Section 9.
Nature and purpose
Hosting, storage, synchronization with the systems you connect, scheduling and project delivery, CRM and sales operations, time capture for billing in your PSA, reporting and dashboards, notification delivery, and AI-assisted drafting and analysis — all as directed by your use of the Service’s features.
Types of personal data
Names, business contact details, job titles, employment and assignment records, calendar and availability data, time entries, message and comment content, email content where you enable mailbox capture, file references, commercial records that identify individuals (deals, quotes, contracts, tickets), authentication identifiers, and usage and audit logs.
Categories of data subjects
Your personnel; your clients’ personnel and contacts; your prospects; and external users you invite to the partner portal.
Special category data
The Service is not designed for, and must not be used to process, special categories of personal data under Article 9, criminal-offence data under Article 10, payment card numbers, or government identification numbers. If you place such data in a workspace, you do so on your own instruction and at your own risk.
4. Confidentiality and personnel
We limit access to Customer Data to the personnel who need it to deliver, support, and secure the Service. Those personnel are bound by written confidentiality obligations that survive their engagement, and access is provisioned on the principle of least privilege.
5. Security measures
We implement and maintain appropriate technical and organizational measures under Article 32. Our controls are covered by a SOC 2 Type II attestation; the report is available under NDA on request. Measures include:
- Tenant isolation enforced in the database. Every tenant-scoped table carries a tenant identifier and a Postgres row-level security policy, so isolation is enforced by the database itself rather than by application code. Externally facing roles carry additional restrictive policies on top.
- Automated isolation testing. We run a cross-tenant isolation test suite on a recurring basis and again whenever the database schema changes. A cross-tenant finding blocks release.
- Encryption. Data is encrypted in transit with TLS and at rest at the storage layer. Integration credentials and OAuth tokens are held in a separate store that application roles cannot read.
- Access control. Role-based permissions inside each workspace, multi-factor authentication available on all accounts and enforceable by administrators, and single sign-on support.
- Independent testing. External penetration testing of the platform.
- Logging. An append-only audit log of privileged and data-affecting actions within each workspace, plus platform-level security and error telemetry.
- Resilience. Managed, encrypted backups of the production database, and a documented restoration path.
- Change management. Reviewed changes, migration replay testing, and automated guard tests that fail a release if a security control regresses.
We may update these measures over time, provided the level of protection is not materially reduced.
6. Subprocessors
You give a general written authorization for us to engage subprocessors. The current, named list — what each does, what it processes, and where — is published at current.day/subprocessors, which forms part of this Addendum.
We impose data-protection obligations on each subprocessor that are no less protective than those in this Addendum, and we remain liable to you for their performance. Before adding or replacing a subprocessor that can process Customer Data we give at least 30 days’ notice, and you may object on reasonable data-protection grounds within that period; the objection process and remedy are set out on that page.
A third-party service you connect using your own account and credentials — your PSA, HubSpot, a prospecting or enrichment tool, an email verifier, a direct-mail service, or a reporting feed — is not our subprocessor. We exchange data with it under your instruction; your relationship with that vendor is governed by your contract with them.
7. Assisting you
Data subject requests
The Service gives you direct access to the personal data in your workspace, so that you can find, correct, export, and delete records yourself in order to answer a data subject. If a data subject contacts us directly about data in your workspace, we will not respond substantively; we will refer them to you and tell you promptly. Where you need more help than the Service’s own tools provide, we will give reasonable assistance, taking into account the nature of the processing.
Assessments and consultation
We will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, to the extent they relate to our processing and you cannot reasonably obtain the information elsewhere.
8. Personal data breach
If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notification will describe, so far as we know it at the time, the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses and give reasonable assistance with any notification you must make to a supervisory authority or to data subjects.
Notice will go to the workspace administrators on file. Keep an administrator email address current — it is where a breach notice will be sent.
Our notifying you is not an acknowledgement of fault or liability.
9. Export, retention, and deletion
Export during your subscription
At any time while your subscription is active, you may request an export of your Customer Data in a commonly used, machine-readable format. We will provide it within 30 days of the request, at no charge for a reasonable number of requests.
On termination
For 30 days after termination or expiry, your Customer Data remains available for export on request. After that window, we delete Customer Data from live production systems within 30 days, and in any event no later than 60 days after the end of the export window.
Backups
Deleted data persists in encrypted, rolling backups until those backups age out on their normal cycle, which will be no later than 90 days after deletion from live systems. Backups are not selectively edited; they are not restored into production except to recover from an incident, and data restored from a backup is re-deleted on the same basis.
What we keep, and why
- Billing and tax records — retained as long as financial and tax law requires, typically seven years. These contain company and billing-contact details, not workspace records.
- Security and audit logs — retained on a rolling basis for security investigation and to meet our own audit obligations.
- Synchronized ticket and time data — retained on the schedule shown in the Service’s retention settings.
On written request we will confirm deletion has been carried out.
10. International transfers
Customer Data is hosted in the United States, and our subprocessors process it in the United States unless the list at current.day/subprocessors says otherwise. Where personal data is transferred out of the EEA, the UK, or Switzerland, the following safeguards apply and are incorporated into this Addendum:
- EEA transfers — the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two where you are a controller and Module Three where you are yourself a processor, with us as data importer. Docking clause: optional. Clause 9: Option 2, general written authorization with 30 days’ notice. Clause 11: the independent dispute-resolution option is not selected. Clause 17: the law of Ireland. Clause 18(b): the courts of Ireland. Annexes I, II, and III are populated by Sections 3, 5, and 6 of this Addendum and by the subprocessor list.
- UK transfers — the above Clauses as amended by the UK International Data Transfer Addendum (version B1.0) issued by the Information Commissioner’s Office. Tables 1 to 3 are populated by this Addendum; in Table 4, neither party may end the Addendum when the Approved Addendum changes.
- Swiss transfers — the above Clauses, read so that references to the GDPR are to the Swiss FADP, the competent authority is the Federal Data Protection and Information Commissioner, and the Clauses also protect the data of legal entities.
If a safeguard we rely on is invalidated or superseded, we will adopt an alternative lawful transfer mechanism without undue delay.
Government access requests. If we receive a legally binding demand from a public authority for Customer Data, we will notify you before disclosing, unless legally prohibited; where prohibited, we will use reasonable efforts to challenge the prohibition and to disclose the minimum necessary. We have not received a national-security order requiring bulk disclosure of Customer Data.
11. Audits and information
On request, and no more than once in any twelve-month period unless a supervisory authority or a personal data breach requires otherwise, we will make available the information reasonably necessary to demonstrate compliance with this Addendum. In the first instance this means our SOC 2 Type II report under NDA, our security documentation, and our response to a reasonable security questionnaire. Where that is genuinely insufficient to satisfy an audit obligation, we will discuss a further audit, conducted on reasonable notice, during business hours, without disrupting the Service or accessing another customer’s data, and at your cost.
12. AI processing
Where you use an AI feature, the workspace records relevant to that feature are processed by our AI subprocessor to generate the output. Customer Data is not used to train our models or any third party’s foundation models, and that restriction is contractual, not a setting. AI output is a draft for you to review; you decide whether to act on it. No decision producing a legal or similarly significant effect on a data subject is made by automated means without human involvement.
13. Liability and precedence
Each party’s liability under this Addendum is subject to the exclusions and the aggregate liability cap in the Terms of Service, and any liability arising under this Addendum counts toward that cap. Where a term of this Addendum conflicts with the Terms of Service or the Privacy Policy in respect of processing subject to the EU GDPR, UK GDPR, or Swiss FADP, this Addendum prevails. Where a term of this Addendum conflicts with the Standard Contractual Clauses, the Clauses prevail.
14. Term and changes
This Addendum takes effect when you accept the Terms of Service and continues until we have ceased all processing of Customer Data. We may update it to reflect a change in law, in a safeguard, or in our security measures; for material changes we will give at least 30 days’ notice by email or in-product notice, and we will not reduce the level of protection it provides.
15. Contact
For anything under this Addendum — a countersigned copy, a security questionnaire, a data subject request, a subprocessor objection, or a breach question — contact privacy@current.day, or write to IT Partners Plus LLC, 2851 Charlevoix Dr, Suite 100, Grand Rapids, MI 49512, United States.