LEGAL

Rocket Driver CRM Data Processing Agreement

Version 1.0 · Date of Last Revision: August 10, 2026

This Data Processing Agreement (“DPA“) forms part of the agreement between Rocket Driver and the Client identified in the applicable Order (the “Agreement“) and applies where, and to the extent that, Rocket Driver Processes Personal Information on the Client’s behalf in connection with a Rocket Driver Platform, including the Rocket Driver CRM.

Access to a Platform such as the Rocket Driver CRM may be included as an optional part of a Client’s broader relationship with Rocket Driver, including the Rocket Driver White Label Partnership. A Client that does not use such a Platform is not receiving a Processing service under this DPA merely because access is available to it; this DPA’s operative obligations apply if and when Rocket Driver actually Processes Personal Information on the Client’s behalf through a Platform. For the Rocket Driver CRM as currently offered, this DPA becomes contractually applicable when the Client’s authorized representative — the Client’s organization owner — completes the electronic CRM activation acceptance on the Client’s behalf and Rocket Driver Processes Personal Information on the Client’s behalf through the CRM.

This DPA is incorporated into the Agreement by reference, including through the Client’s electronic organizational acceptance at CRM activation. No separate handwritten or electronic signature document is required for it to apply. Rocket Driver will countersign a copy on request.

Capitalized terms not defined here have the meanings given in the Rocket Driver Terms of Service.

1. Definitions

1.1 “Applicable Privacy Law” means the privacy and data protection laws of the United States and its states that apply to the Client’s use of the Services, including the California Consumer Privacy Act as amended, and the comprehensive consumer privacy laws of other states.

1.2 “Personal Information” means information within Platform Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular individual or household, as defined under Applicable Privacy Law.

1.3 “Platform Data” has the meaning given in the Terms of Service: data, records, content and materials that the Client, its users, or its customers store in or submit to a Platform.

1.4 “Process” and “Processing” mean any operation performed on Personal Information, including collection, storage, use, transmission, disclosure, and deletion.

1.5 “Security Incident” means a breach of Rocket Driver’s security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Information Processed by Rocket Driver under this DPA. A Security Incident does not include an unsuccessful attempt or an activity that does not compromise the security of Personal Information, such as pings, port scans, failed log-in attempts, denial-of-service attempts, or packet sniffing that does not result in access beyond headers.

1.6 “Subprocessor” means a third party engaged by Rocket Driver to Process Personal Information on Rocket Driver’s behalf in providing the Services.

1.7 “Services” means the Rocket Driver Platform or Platforms provided to the Client under the Agreement.

2. Roles and scope

2.1 The Client determines the purposes and means of the Processing of Personal Information contained in Platform Data. Rocket Driver Processes that Personal Information on the Client’s behalf. Where the CCPA applies to the Client’s Processing, the Client acts as the business — or as a third party acting on a business’s behalf — determining the purposes of Processing, and Rocket Driver acts as a service provider with respect to Personal Information Processed on the Client’s behalf. The protections and restrictions in this DPA apply to Personal Information Processed on the Client’s behalf regardless of whether the Client is itself subject to the CCPA or any particular Applicable Privacy Law.

2.2 Data Rocket Driver controls. Rocket Driver acts for its own purposes, and not as the Client’s service provider, with respect to: (a) account records for the Client’s users, including name, business email address, telephone number, time zone, assigned role, notification preferences, authentication credentials, and multi-factor authentication enrollment; (b) security, log, and technical records generated by operating the Services, including IP addresses, sign-in and authentication events, rate-limiting records, and application logs; (c) the Client’s own business, billing, contracting, and support relationship with Rocket Driver; and (d) aggregated or de-identified data derived from operating the Services that does not identify the Client, its users, its customers, or any individual. Rocket Driver’s handling of that information is described in the Rocket Driver Privacy Policy.

What this means when the Client’s organization is deleted. Paragraph (a) describes the purposes for which Rocket Driver handles those records; it does not mean they exist independently of the Client’s organization in the Services, and it is not a statement that they are retained. The account, authentication-credential, and multi-factor-authentication-enrollment records described in (a) belong to the Client’s organization in the Services and are deleted together with that organization’s other data when the organization is deleted. The records Rocket Driver may retain after that deletion are the ones that are genuinely separate from the Client’s organization in the Services: the business, billing, contracting, tax, and support records described in (c); and those security, log, and technical records described in (b) that Rocket Driver holds outside the customer database, in Rocket Driver’s own log and security storage. Rocket Driver also records the completion of a deletion in a deletion ledger kept outside the customer database — a minimal entry stating that a deletion was completed, identifying the organization and the date of completion, and containing no contents of any customer record. Retention of the records Rocket Driver controls is a matter of Rocket Driver’s own retention practice as described in the Rocket Driver Privacy Policy; Section 9 governs Personal Information Processed on the Client’s behalf.

2.3 This DPA does not apply to information the Client provides outside a Platform, to Third-Party Products the Client connects, or to services the Client obtains directly from a third party.

3. Rocket Driver’s Processing obligations

3.1 Processing on instruction. Rocket Driver will Process Personal Information only: (a) as necessary to provide, secure, maintain, support, back up, restore, and troubleshoot the Services; (b) as otherwise instructed by the Client in writing; and (c) as required by law. The Client’s instructions consist of the Agreement, this DPA, the configuration and settings the Client selects in the Platform, and the actions the Client’s authorized users take in the Platform.

3.2 Restrictions. Rocket Driver will not:

(a) sell Personal Information, or share it for cross-context behavioral advertising, as those terms are used under Applicable Privacy Law;
(b) retain, use, or disclose Personal Information for any purpose other than the business purposes specified in this DPA and the Agreement, including for a commercial purpose other than providing the Services;
(c) retain, use, or disclose Personal Information outside the direct business relationship between Rocket Driver and the Client;
(d) use Personal Information for Rocket Driver’s own marketing or advertising;
(e) use Personal Information to train artificial intelligence or machine learning models; or
(f) combine Personal Information received from the Client with personal information received from or on behalf of another person, or collected from Rocket Driver’s own interactions with an individual, except as permitted under Applicable Privacy Law to perform a business purpose.

3.3 Same level of protection. Rocket Driver will comply with the obligations applicable to it under Applicable Privacy Law and will provide the same level of privacy protection as Applicable Privacy Law requires of the Client with respect to the Personal Information it Processes.

3.4 Notice of inability to comply. Rocket Driver will notify the Client if it determines that it can no longer meet its obligations under Applicable Privacy Law with respect to Personal Information Processed under this DPA.

3.5 Client remediation rights. The Client may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information by Rocket Driver, including requiring Rocket Driver to cease a specific Processing activity, correct it, or delete the affected Personal Information.

3.6 Unlawful instructions. If Rocket Driver believes an instruction from the Client would violate Applicable Privacy Law, Rocket Driver will inform the Client and may suspend performance of that instruction until it is resolved.

3.7 Legally required disclosure. If Rocket Driver is required by law to disclose Personal Information, Rocket Driver will, unless prohibited by law, inform the Client before disclosing, provide the Client with a copy of the demand, and disclose only what is legally required.

4. Confidentiality and personnel

4.1 Rocket Driver will treat Personal Information as the Client’s Confidential Information under Section 31 of the Terms of Service.

4.2 Rocket Driver will limit access to Personal Information to personnel who need it to perform Rocket Driver’s obligations, and will ensure those personnel are bound by written confidentiality obligations or equivalent professional duties.

4.3 Support and operational access. Rocket Driver personnel who operate, secure, support, back up, restore, or troubleshoot the Services may be able to access Personal Information in the course of that work, including through access to the systems and databases on which the Services run. Rocket Driver limits such access to personnel who require it for those purposes.

5. Subprocessors

5.1 The Client generally authorizes Rocket Driver to engage Subprocessors to Process Personal Information in providing the Services.

5.2 Rocket Driver maintains a current list of Subprocessors that Process Personal Information for the Rocket Driver CRM at https://www.rocketdriver.com/subprocessors/.

5.3 Rocket Driver will update that list before engaging a new Subprocessor that will Process Personal Information, and will provide notice at least 30 days in advance. Notice may be given by updating the list and notifying Clients who have subscribed to updates, by email to the account’s administrative contact, or by notice in the Platform.

5.4 If the Client reasonably objects to a new Subprocessor on data protection grounds within 30 days of notice, the Client and Rocket Driver will discuss the objection in good faith. If it cannot be resolved, the Client may terminate the affected Services on written notice.

5.5 Rocket Driver will engage each Subprocessor under a written agreement that imposes on the Subprocessor data protection obligations substantially similar to those in this DPA and, in any event, sufficient to enable Rocket Driver to meet its obligations under this DPA and Applicable Privacy Law with respect to the Personal Information the Subprocessor Processes. Rocket Driver remains responsible for its Subprocessors’ performance of those obligations to the same extent as if the Processing were performed by Rocket Driver. The data protection terms published by each current Subprocessor are identified on the Subprocessor List.

6. Security

6.1 Rocket Driver will implement and maintain reasonable administrative, technical, and organizational measures designed to protect Personal Information against a Security Incident, appropriate to the nature of the information and the size and complexity of Rocket Driver’s operations. The measures in effect as of the Date of Last Revision are described in Schedule 2.

6.2 Rocket Driver may change those measures as the Services develop, provided it does not materially reduce the overall level of protection.

6.3 The Client is responsible for its own configuration and use of the Services, including which users it invites, what roles and record access it assigns, removing access when it is no longer needed, maintaining multi-factor authentication where required, and the security of its own devices, networks, and credentials.

6.4 Rocket Driver makes no representation that the Services are certified against, or assessed under, any particular security standard or framework, and holds no such certification as of the Date of Last Revision.

7. Security Incidents

7.1 Rocket Driver will notify the Client of a Security Incident affecting the Client’s Personal Information without undue delay after becoming aware of it, and in all cases within any shorter period required by a law applicable to Rocket Driver as a maintainer, processor, or third-party agent of that Personal Information.

7.2 Notification will include the information reasonably available to Rocket Driver at the time, including the nature of the incident, the categories of Personal Information involved to the extent known, the steps Rocket Driver has taken, and a Rocket Driver contact. Rocket Driver will provide further information as the investigation progresses.

7.3 Rocket Driver will take reasonable steps to investigate, contain, and remediate the incident, and will reasonably cooperate with the Client’s own investigation and notification obligations.

7.4 Rocket Driver’s notification is not an acknowledgment of fault or liability.

7.5 The Client is responsible for determining whether the incident requires notification to individuals or regulators, and for making those notifications. Rocket Driver will not notify the Client’s individuals or regulators on the Client’s behalf unless the Client instructs it to do so in writing and the parties agree on the terms.

7.6 Reporting to Rocket Driver. If the Client believes there has been unauthorized access to its Personal Information in the Services, or discovers a security vulnerability, it should report it to team@rocketdriver.com with “Security” in the subject line, with enough detail for Rocket Driver to investigate.

8. Assistance with individual rights requests

8.1 If Rocket Driver receives a request from an individual to access, correct, delete, or otherwise act on Personal Information that Rocket Driver Processes on the Client’s behalf, Rocket Driver will not respond substantively to the request other than to acknowledge receipt and, where Rocket Driver can identify the responsible Client, to promptly direct the individual to that Client or forward the request to it. Rocket Driver maintains an internal record of such requests and their disposition.

8.2 The Client is responsible for responding to requests from individuals about Personal Information in its Platform. The Client can access, correct, and delete records directly in the Platform using its own administrative access.

8.3 Where the Client cannot fulfill a request using the Platform’s own functions, Rocket Driver will provide reasonable assistance on written request, taking into account the nature of the Processing and the information available to Rocket Driver. Rocket Driver may charge for assistance that is disproportionate or repeated.

8.4 Rocket Driver will assist the Client with data protection impact assessments, risk assessments, cybersecurity audits, and similar assessments required of the Client by Applicable Privacy Law, to the extent the required information relates to Rocket Driver’s Processing and is reasonably available to Rocket Driver.

8.5 On the Client’s request made in accordance with an individual’s authenticated request under Applicable Privacy Law, Rocket Driver will stop Processing the affected Personal Information, except to the extent retention or continued Processing is required by law, and subject to the return, deletion, and retention provisions of Section 9.

9. Return and deletion

9.1 During the term, the Client may access, correct, and delete records directly in the Platform.

9.2 Export. The Platform provides a self-service export of certain record types in a commonly used format. It does not currently provide a self-service export covering all record types. On written request made before the Client’s access ends, or within 30 days after it ends, Rocket Driver will provide the Client with a copy of the Client’s remaining Platform Data in a commonly used format.

9.3 Deletion. After the Client’s access ends, Rocket Driver will, at the Client’s written direction, delete or return the Personal Information Processed on the Client’s behalf, and will confirm in writing when deletion is complete, except where retention is required by law or is necessary to establish, exercise, or defend legal claims, or to resolve an outstanding payment dispute. If the Client requests an export under Section 9.2, deletion follows delivery of that export. If the Client gives no direction within 60 days after its access ends, Rocket Driver may delete the Personal Information.

9.4 Backups. Personal Information deleted from the live Services remains in Rocket Driver’s routine system backups. Rocket Driver does not delete individual records from within existing backup files and does not restore records from backups in order to preserve them after deletion. A backup copy is removed only when that backup is itself removed. Backup copies held in off-site object storage are retained for 35 days and are then deleted on a scheduled basis. Personal Information remaining in backups remains subject to this DPA for as long as it is retained.

9.5 Rocket Driver may retain Personal Information where required by law, and will continue to protect it in accordance with this DPA for as long as it is retained.

10. Information and audit

10.1 On the Client’s reasonable written request, and no more than once in any twelve-month period unless required by Applicable Privacy Law or following a Security Incident affecting the Client, Rocket Driver will provide information reasonably necessary to demonstrate its compliance with this DPA, including a description of its security measures and its current Subprocessor list.

10.2 Rocket Driver does not currently hold a third-party security certification or attestation report, and none is claimed. If Rocket Driver later obtains an independent security certification or assessment report, Rocket Driver may make appropriate materials available to Clients, subject to applicable confidentiality, licensing, and disclosure restrictions.

10.3 The Client may, on reasonable notice and at its own expense, request an on-site or remote assessment of Rocket Driver’s Processing where Applicable Privacy Law requires the Client to be able to conduct one. The parties will agree in advance on scope, timing, duration, and confidentiality, and any assessment will be conducted in a manner that does not disrupt Rocket Driver’s operations or compromise the confidentiality of other customers’ data.

11. Description of Processing

The subject matter, nature, purpose, duration, categories of Personal Information, and categories of individuals are described in Schedule 1.

12. General

12.1 This DPA is subject to the Agreement. In the event of a conflict between this DPA and any other part of the Agreement, this DPA controls with respect to the Processing of Personal Information.

12.2 This DPA takes effect when the Client is provided access to a Platform, imposes operative obligations to the extent Rocket Driver Processes Personal Information on the Client’s behalf, and continues for as long as Rocket Driver Processes or retains such Personal Information. Sections 2, 3, 4, 6, 7, 8.5, 9, and 12 survive termination for as long as Rocket Driver retains any Personal Information Processed under this DPA, including copies held in backups — so the confidentiality, security, Processing-restriction, incident-notification, and return/deletion obligations of this DPA continue to apply to that Personal Information for as long as it is retained. Survival under this section does not extend any unrelated commercial obligation.

12.3 Rocket Driver may update this DPA. Rocket Driver will not make a change that materially reduces the protections this DPA provides for Personal Information without advance notice to affected Clients as described in Section 45 of the Terms of Service.

12.4 Questions about this DPA: team@rocketdriver.com.


SCHEDULE 1 — Description of Processing

Subject matter. Rocket Driver’s provision of the Rocket Driver CRM and related Platforms to the Client.

Duration. For the term of the Agreement, and thereafter only as described in Section 9.

Nature and purpose of Processing. Hosting, storing, organizing, retrieving, displaying, transmitting, backing up, restoring, securing, supporting, and deleting Platform Data so that the Client can operate its customer relationship management activities; importing data at the Client’s direction; sending outbound messages and integration events the Client configures; and generating reports the Client requests.

Categories of Personal Information. As determined by the Client. The Platform’s record structure supports:

CategoryFields
Contact recordsFirst name, last name, email address, telephone number, job title, source, tags, and Client-defined custom fields
Company recordsCompany name, website, telephone number, address, industry, status, tags, and Client-defined custom fields
Opportunity recordsOpportunity name, monetary value, expected close date, outcome, assigned user, and links to company and contact records
Activity recordsActivity type (note, call, email, meeting) and free-text or structured activity content, linked to contact, company, or opportunity records
Task recordsTitle, description, due date, assignee, and linked record
Conversation and message recordsChannel, counterparty email address or telephone number, message subject, message body, direction, timestamps, and provider metadata
Lead submissionsInformation submitted through forms the Client publishes, which creates contact and activity records
Client account recordsThe Client’s own client-account structure and the names, email addresses, and roles of client-account users the Client invites
Report recordsReport definitions, runs, results, snapshots, generated documents, and share links concerning businesses the Client selects
Free-text fieldsNotes, task descriptions, custom fields, tags, addresses, and message bodies may contain any information the Client’s users enter

Categories of individuals. As determined by the Client. Typically: the Client’s own personnel and authorized users; the Client’s contacts, leads, prospects, and customers; individuals at companies the Client records; individuals who submit the Client’s published forms; and, where the Client enables client-account access, the Client’s own clients’ personnel.

Prohibited categories. The Client must not submit the categories of information prohibited by the Rocket Driver CRM Service Terms, including health information, biometric or genetic information, government identification numbers, financial account or payment card numbers, precise geolocation, information about children, information revealing racial or ethnic origin, religious or philosophical beliefs, political opinions, union membership, sexual orientation or sex life, criminal history, or immigration status. Rocket Driver does not inspect or filter free-text fields and cannot prevent such information from being entered.

Frequency. Continuous for the duration of the Agreement.


SCHEDULE 2 — Security measures

The measures below are those in effect as of the Date of Last Revision. Each is a measure Rocket Driver actually operates. Rocket Driver makes no representation as to any measure not listed.

Access control and authentication
– Accounts are individually identified and authenticated. Public self-registration is not enabled.
– Account passwords are stored using a one-way salted hash (bcrypt) and are not stored or recoverable in readable form.
– Authenticator-application multi-factor authentication (TOTP) is required for organization owner accounts and for Rocket Driver privileged administrative accounts. Recovery codes are stored hashed and are single-use. There is no mechanism that allows an account subject to this requirement to sign in without completing multi-factor authentication. A designated Rocket Driver administrator can reset a user’s multi-factor enrollment — for example, where a user has lost their authenticator device — which clears that user’s existing enrollment and recovery codes and ends that user’s active sessions; the user must then complete a new enrollment before signing in again. Such a reset does not disclose the user’s existing authentication secrets and does not permit sign-in without multi-factor authentication.
– Role-based permissions determine what each user can see and do within their organization’s records. Records are additionally scoped by client account and assignment where applicable. A small number of Rocket Driver administrative functions — limited to account and multi-factor-enrollment administration, and conferring no access to Client records — are governed by a separate platform-administrator designation rather than by organization roles.
– Each customer organization’s Platform Data is logically separated from every other organization’s Platform Data, and this separation is covered by an automated end-to-end test in Rocket Driver’s continuous integration pipeline. Rocket Driver’s own administration of user accounts and multi-factor enrollment (Section 2.2(a)) operates across organizations by design.
– Elevating a user’s privileges invalidates that user’s existing sessions.

Network and transport security
– Connections between browsers and the Services use HTTPS/TLS with certificates from a public certificate authority, with HTTP Strict Transport Security enabled.
– Cross-origin access is restricted to an allowlist of permitted origins.
– Standard security response headers, including a restrictive permissions policy, are applied.
– Rate limiting is applied to authentication, password reset, invitation, public form submission, and inbound integration endpoints, backed by a shared store across application instances.
– Outbound connections initiated by the Services — webhook deliveries, tenant mail server connections — are validated to block requests to internal, loopback, private, and link-local network addresses.

Secret handling
– Credentials a customer provides for mail and connected-account integrations are encrypted at the application layer before storage.
– Application and operational logs are redacted so that passwords and form submission payloads are not written to logs.
– Error responses are sanitized so that internal details are not returned to clients.

Application runtime hardening
– Application components run in containers pinned to immutable image digests.
– The background worker runs as a non-root user with Linux capabilities dropped except one required capability, under a repository-controlled seccomp profile, with memory and process limits applied.
– Production deployment does not run database migrations automatically at startup; releases are governed by a documented, evidence-recorded process.

Backup
– The production database is backed up on a scheduled basis using PostgreSQL’s dump facility, with a cryptographic checksum recorded and verified for each backup.
– Backups are copied to third-party object storage separate from the application host.
– Restore has been rehearsed on an isolated system.
– Backups are compressed. Rocket Driver does not currently apply its own encryption to backup files. The object-storage provider’s own server-side encryption (SSE-S3) is enabled on the destination bucket and applies to the stored backup objects.

Personnel
– Access to production systems is limited to personnel who require it to operate and support the Services, and such personnel are bound by confidentiality obligations.

Incident handling
– Rocket Driver maintains an internal, documented incident-response procedure covering triage, containment, assessment, notification and post-incident review.