This Data Processing Addendum (“DPA”) forms part of the Terms of Service between TRL Holdings, LLC, doing business as Calibrate DMS (“Calibrate,” the processor), and the customer organization that uses the Service (the controller). It applies whenever your organization stores personal data about its own customers, contacts, and staff in Calibrate — names, phone numbers, email addresses, and related records. You decide what to collect and why; we process it on your documented instructions to provide the Service.
Need a countersigned copy? This DPA applies automatically to every customer. If your organization requires an executed copy for its records, contact us at privacy@calibratedms.com and we will provide one for signature.
Scope of processing
- Subject matter and duration — the personal data your organization submits to the Service, for the duration of your agreement with us plus the return-and-deletion period below.
- Nature and purpose — hosting, storage, display, export, and transmission of records as directed by your organization through its use of the Service, including sending the email and SMS messages your organization chooses to send.
- Categories of data — business contact details and related records of your customers, contacts, and staff (names, email addresses, phone numbers, addresses, notes, documents, and photos). The Service is not designed for health data or other specially regulated categories.
- Data subjects — your organization’s customers, prospects, contacts, and team members.
We process this data only to provide and support the Service. We do not use your customers’ personal data for our own purposes, we do not use it to train machine-learning models, and we do not sell it.
Confidentiality and security
We keep personal data confidential and apply administrative, technical, and physical safeguards appropriate to the risk, including:
- Encryption — in transit (TLS) and at rest on our database and file-storage infrastructure;
- Access control — role-based access controls within the Service, and strict tenant isolation so one organization’s data is never visible to another;
- Audit logging — an append-only audit trail of administrative and data-changing actions;
- Personnel — access limited to personnel who need it to operate the Service, bound by confidentiality obligations.
Subprocessors
You authorize us to use a limited set of third-party providers (subprocessors) to help deliver the Service. The current list — each vendor, what it does for us, and where it processes data — is published at calibratedms.com/subprocessors. Each subprocessor is bound by a written contract requiring it to protect personal data and use it only to provide services to us, and we remain responsible to you for their performance. We will update that page before adding or replacing a subprocessor, and we will notify administrators of material changes through the product; if you object on reasonable data-protection grounds, you may terminate and export your data as described below.
Breach notification
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data we process for you, we will notify your organization’s administrators without undue delay and provide the information we have about the nature of the incident, the data affected, and the steps we are taking, so you can meet your own notification obligations.
Assistance with data subject requests
If one of your customers exercises a privacy right (such as access, correction, or deletion), your organization is responsible for responding as the controller. We will provide reasonable assistance — including the tools in the Service to view, correct, export, and delete records — and will refer any request we receive directly to you.
Return and deletion
You can export your organization’s data at any time while your account exists, in a standard, portable format — this works even when a lapsed subscription has made the account read-only. On termination, we keep your data available for export for at least 30 days, and then delete it on your request or per the retention timelines in our Terms of Service, except where retention is required by law. Deleted data may persist in encrypted backups until those backups age out on our rolling backup schedule (approximately 14 daily and 8 weekly snapshots), after which it is permanently gone.
Where data is processed
The Service is operated from the United States, and our subprocessors process Service data primarily in the United States (with edge network delivery handled globally by our CDN provider). Calibrate is built for U.S. dealers; we do not currently offer EU/UK-specific transfer mechanisms such as Standard Contractual Clauses.
Related documents
See also our Privacy Policy, Terms of Service, and the current subprocessor list. Questions about this DPA can be sent to privacy@calibratedms.com.