Data Processing Agreement
Support access only
Version 1.0 · Effective date: 13 September 2026
1. What this agreement is, and what it is not
This data processing agreement ("DPA") forms part of the AZ Goals Terms and Conditions (the "Terms") between AZMT Digital Solutions, Lda., NIPC 517 649 357, with registered office at Rua Albino da Costa Reis, n.º 118, 3.º Dto. Fte., 4430-748 Oliveira do Douro, Vila Nova de Gaia, Portugal ("Azimute", "we", the "Processor") and the Customer identified in the Terms ("you", the "Controller"). It is entered into for the purposes of article 28(3) of Regulation (EU) 2016/679 ("GDPR").
The AZ Goals managed package runs entirely inside your Salesforce organisation and transmits no data to us. We are therefore not a processor of the personal data that the Application handles, and this DPA does not apply to it. You are the sole controller of that data, and your processor for the platform on which it sits is Salesforce, Inc., under your own agreement with them.
This DPA applies only where you grant us access to your Salesforce organisation, or to data extracted from it, in the course of a support request ("Support Access"), and only for as long as that access lasts. Nothing in this DPA extends our role beyond Support Access, and nothing in it is an admission that we process personal data on your behalf in any other circumstance.
Licence and subscription records that Salesforce provides to us through its License Management Application are processed by us as a controller in our own right, for the purposes described in our Privacy Policy, and are outside the scope of this DPA.
2. Our obligations as processor
In respect of Support Access we will:
- process personal data only on your documented instructions, which comprise the Terms, this DPA and the support request through which you granted the access, and inform you if we consider an instruction to infringe the GDPR or other applicable data protection law;
- access only what is necessary to investigate and resolve the request, and not copy, extract or retain personal data except where doing so is necessary for that purpose and you have agreed to it;
- ensure that only those of our personnel who need the access have it, that each of them is bound by an obligation of confidentiality that survives the end of their engagement, and that each has been instructed on the limits of the access;
- implement and maintain the technical and organisational measures described in Annex II, which are appropriate to the risk of the limited processing this DPA covers;
- assist you, taking into account the nature of the processing, in complying with your obligations under articles 32 to 36 of the GDPR, including in respect of data protection impact assessments and consultation of a supervisory authority;
- assist you in responding to requests from data subjects in respect of anything we processed under Support Access, and forward to you without undue delay any such request we receive directly, without responding to it ourselves except to confirm that it has been forwarded;
- notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under Support Access, and provide the information reasonably available to us to help you meet your obligations under articles 33 and 34 of the GDPR;
- at the end of Support Access, and at your choice, delete or return any personal data we hold as a result of it, and delete existing copies unless Union or Member State law requires storage;
- make available to you the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as set out in section 6.
3. Sub-processors
We will not engage another processor for Support Access without your prior specific or general written authorisation. Where we use a general authorisation, we will inform you of any intended addition or replacement in advance, and you may object. The current list of providers that may be involved, to the limited extent Support Access requires it, is published at azgoals.com/subprocessors.
Any sub-processor we engage will be bound by written terms imposing data-protection obligations equivalent to those in this DPA. We remain fully liable to you for the sub-processor's performance of those obligations.
4. International transfers
We will not transfer personal data processed under Support Access outside the European Economic Area except where you have instructed or authorised us to do so, and where an appropriate safeguard under Chapter V of the GDPR is in place — including the European Commission's standard contractual clauses, an adequacy decision, or another lawful transfer mechanism, together with supplementary measures where appropriate.
5. Your obligations as controller
You are responsible for the lawfulness of the processing that takes place in your Salesforce organisation, including any decision to grant us Support Access. You will ensure that the instructions you give us are lawful, and that you have a lawful basis for any personal data we may process under Support Access.
6. Audit
Upon reasonable written notice, and no more than once in any twelve-month period unless a personal data breach or a supervisory-authority investigation requires otherwise, you may audit our compliance with this DPA. Audits will be limited to information and systems relevant to Support Access, conducted during Portuguese business hours, and subject to confidentiality. We may satisfy an audit request by providing recent third-party audit reports or other documentation that reasonably demonstrates compliance, where that is sufficient for your purposes.
7. Duration and termination
This DPA applies for as long as Support Access lasts, and terminates automatically when Support Access ends and any personal data we held as a result of it has been deleted or returned under section 2. Provisions that by their nature should survive — including confidentiality and liability — continue in accordance with the Terms.
8. Governing law and precedence
This DPA is governed by the same law and dispute-resolution provisions as the Terms. In the event of conflict between this DPA and the Terms on a matter of data protection, this DPA prevails.
Annex I — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Temporary access to the Customer's Salesforce organisation, or to data extracted from it, for the purpose of investigating and resolving a support request |
| Duration | From the moment Support Access is granted until it is revoked or the support request is closed, whichever is earlier |
| Nature and purpose | Viewing (and, only where agreed, limited modification of) configuration and records necessary to diagnose and resolve the reported issue |
| Types of personal data | Whatever personal data happens to be present in the records or screens we are granted access to — typically names, work email addresses, and activity or performance data associated with Salesforce users or with records the Customer has configured goals against. We do not seek special categories of data and ask that you do not grant access to them unless the issue requires it |
| Categories of data subjects | The Customer's employees, contractors and other Salesforce users; and, where goals or related records contain them, individuals whose data the Customer processes in Salesforce |
| Obligations and rights of the Controller | As set out in the Terms, this DPA and the GDPR |
Annex II — Technical and organisational measures
Given the limited and temporary nature of Support Access, we maintain at least the following measures:
- Access to any customer organisation is granted only after the Customer's documented consent for that specific request, and is time-limited.
- Access is restricted to personnel who need it for the request, under confidentiality obligations.
- Multi-factor authentication on our systems used to communicate with customers and to hold any support materials.
- Encryption in transit for support communications.
- No standing credentials or persistent connections into customer organisations.
- Deletion or return of any personal data obtained through Support Access when the access ends, unless retention is required by law.
- Logging of support access grants and closures to the extent reasonably practicable.
AZMT Digital Solutions, Lda. · Rua Albino da Costa Reis, n.º 118, 3.º Dto. Fte., 4430-748 Oliveira do Douro, Vila Nova de Gaia, Portugal · NIPC 517 649 357 · support@azimute.eu