Data Processing Addendum
Last updated August 14, 2026
This Data Processing Addendum ("DPA") is part of our Terms of Service and applies whenever you use Cervan to store or process personal information about other people, such as your customers, leads and team members. It takes effect automatically when you accept the Terms. No signature is required.
1. Roles
You are the controller (or "business" under California law) of the personal information you put into Cervan. You decide what to collect, why, and how long to keep it. Cervan is the processor (or "service provider") and acts on your instructions.
Cervan is a separate controller only for its own account and billing data, such as your login, subscription and support history. That is covered by our Privacy Policy.
2. Your obligations as controller
You confirm that you have a lawful basis and, where required, consent to collect and use the personal information you enter or import, and to contact those people by text, email or phone through Cervan. You are responsible for providing any notice your customers are entitled to and for honoring their choices, including opt-outs.
Do not upload special categories of data through Cervan, including health records, precise biometric identifiers, government identification numbers, full payment card numbers, or information about children under 13.
3. What Cervan does with the data
Cervan processes personal information only to:
- provide, maintain and secure the Service for you;
- send the messages and documents you trigger;
- process payments through your own connected payment account;
- provide support you request;
- comply with law.
Cervan does not sell personal information, does not share it for cross-context behavioral advertising, and does not use it for its own purposes outside the Service. Data from one account is never used to serve another account.
4. Account isolation and access
Every account's data is scoped to that account and enforced at the database layer. Cervan personnel access account data only when needed to operate the Service, investigate a security or abuse issue, comply with law, or respond to a support request you make.
5. Security
Cervan maintains technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest for stored data, row-level access controls, access restricted to personnel who need it, optional two-factor authentication on accounts, and logging of administrative activity. Security measures may change over time; changes will not materially reduce protection.
You are responsible for security within your control: your passwords, who you invite to your account, what permissions you grant them, and removing access when a team member leaves.
6. Incident notification
If Cervan becomes aware of a security breach affecting personal information you control, we will notify you without undue delay and provide the information reasonably available to us so you can meet your own notification obligations. Notice is not an admission of fault.
7. Subprocessors
You authorize Cervan to use subprocessors to deliver the Service. The current list is on our Subprocessors page. Cervan imposes data protection obligations on each subprocessor and remains responsible for their performance of the processing we delegate to them. We will update that page before adding a new subprocessor that processes personal information you control.
8. Data subject requests
You can access, correct, export and delete the personal information in your account directly in the Service. If someone contacts Cervan with a request about data in your account, we will refer them to you. If you need help responding to a request you cannot complete yourself, email support and we will provide reasonable assistance.
9. International transfers
Cervan and its subprocessors operate in the United States and may process data in other countries where they run infrastructure. Where a transfer mechanism is required by law, the applicable standard contractual clauses are incorporated by reference and this DPA serves as the transfer terms between you and Cervan.
10. Retention and deletion
Cervan keeps personal information for as long as your account is active. You can delete individual records at any time. When you delete your account, account data is deleted or irreversibly anonymized within a reasonable period, except where we must retain records to comply with law, resolve disputes or enforce our agreements, and except for routine backups that expire on their own schedule.
Export anything you need before you delete your account.
11. Audits
On reasonable written request, and no more than once in any 12-month period, Cervan will provide the information reasonably necessary to demonstrate compliance with this DPA. Cervan may satisfy that request with written responses or available third-party reports rather than on-site access.
12. Liability and order of precedence
The disclaimers and limitation of liability in the Terms of Service apply to this DPA and to any claim relating to personal information. If this DPA conflicts with the Terms of Service on a data protection matter, this DPA controls for that matter only.
Questions? Email support@joincervan.com.
