Ennijo Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the applicable agreement governing use of Ennijo between 29in5 LLC, provider of the Ennijo product and service ("Ennijo," "Processor," "Service Provider," "Contractor," "we," "us," or "our"), and the applicable customer ("Customer," "Controller," "Business," "you," or "your").
The applicable agreement may include the Ennijo Beta Program Agreement and, when applicable, Ennijo's Terms of Service, order form, subscription agreement, or other agreement governing use of Ennijo.
This DPA governs Ennijo's processing of Customer Personal Data on behalf of Customer.
If there is a conflict between this DPA and another applicable agreement concerning the processing of Customer Personal Data, this DPA controls to the extent of that conflict.
1. Definitions
For purposes of this DPA:
"Applicable Data Protection Law" means privacy, data protection, and data security laws applicable to the processing of Customer Personal Data under this DPA, including, where applicable:
- The European Union General Data Protection Regulation, Regulation (EU) 2016/679 ("EU GDPR")
- The United Kingdom GDPR and Data Protection Act 2018
- The California Consumer Privacy Act, as amended ("CCPA")
- Other applicable U.S. state privacy laws
- Other applicable privacy and data protection laws
"Authorized User" means an individual permitted by Customer to access Customer's Ennijo account.
"Controller" means the person or organization that determines the purposes and means of processing Personal Data, including a "business" or similar responsible party under applicable U.S. privacy law.
"Customer Personal Data" means Personal Data processed by Ennijo on behalf of Customer in connection with Customer's use of Ennijo.
Customer Personal Data includes CRM Contact Data.
"CRM Contact Data" means Personal Data relating to prospects, clients, past clients, referral partners, vendors, professional contacts, sphere contacts, and other individuals whose information Customer enters, imports, synchronizes, receives, or maintains through Ennijo.
"Data Subject" means an identified or identifiable individual to whom Personal Data relates, including a "consumer" or similar term under applicable U.S. privacy law.
"Personal Data" means information relating to an identified or identifiable individual and includes "personal information," "personal data," and similar terms under Applicable Data Protection Law.
"Personal Data Breach" means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.
"Process," "Processing," and "Processed" have the meanings assigned under Applicable Data Protection Law.
"Processor" means an entity that processes Personal Data on behalf of a Controller, including a "service provider" or "contractor" where applicable.
"Service" means the Ennijo relationship management and customer relationship management product and related customer-facing features, tools, integrations, and support services provided by 29in5 LLC.
"Subprocessor" means a third party engaged by Ennijo to Process Customer Personal Data on behalf of Customer.
2. Roles of the Parties
For Customer Personal Data:
- Customer acts as the Controller, Business, or equivalent responsible party.
- 29in5 LLC, through Ennijo, acts as the Processor, Service Provider, Contractor, or equivalent party processing Personal Data on Customer's behalf.
Customer determines:
- Which individuals are placed into Ennijo
- Why their information is maintained
- Which Personal Data is recorded
- How Customer uses that information
- Which Authorized Users may access it
- Which communications Customer sends to those individuals
Ennijo processes Customer Personal Data to provide the Service and in accordance with Customer's documented instructions.
For information Ennijo processes for its own business purposes, such as account administration, billing, security records, and certain support information, 29in5 LLC may act as an independent Controller or Business as described in the Ennijo Privacy Policy.
3. Customer Instructions
Customer instructs Ennijo to Process Customer Personal Data as reasonably necessary to:
- Host and maintain CRM records
- Authenticate and manage Authorized Users
- Provide relationship management functionality
- Provide tasks, reminders, follow-up tools, and workflow functionality
- Record authorized relationship activity
- Provide Customer-authorized integrations
- Provide AI-assisted coaching and prioritization
- Provide Customer-requested exports
- Secure, monitor, maintain, troubleshoot, and support Ennijo
- Prevent fraud, abuse, and unauthorized access
- Comply with lawful Customer requests
- Perform other Processing reasonably necessary to provide functionality selected by Customer
The applicable agreement, Customer's configuration and use of Ennijo, and written instructions submitted by authorized Customer representatives constitute Customer's documented instructions.
Ennijo will not Process Customer Personal Data for purposes materially inconsistent with those instructions unless required by applicable law.
If Ennijo is legally required to Process Customer Personal Data contrary to Customer's instructions, Ennijo will notify Customer before doing so unless applicable law prohibits that notice.
If Ennijo reasonably believes a Customer instruction violates Applicable Data Protection Law, Ennijo may suspend performance of that instruction and inform Customer of the concern.
4. Customer Responsibilities
Customer represents and warrants that:
- Customer has the authority and lawful basis necessary to provide Customer Personal Data to Ennijo
- Customer's instructions comply with Applicable Data Protection Law
- Customer will provide legally required privacy notices
- Customer will obtain legally required consent
- Customer will honor applicable opt-out, unsubscribe, do-not-call, deletion, and other privacy requests
- Customer will not instruct Ennijo to Process Personal Data unlawfully
Customer remains responsible for determining whether it has legal permission to contact a CRM Contact.
The availability of an Ennijo feature does not establish that Customer has legal permission to contact any particular person.
5. Processing Limitations
Ennijo will Process Customer Personal Data only:
- To provide the Service;
- For the limited and specified purposes described in this DPA and the applicable agreement;
- On Customer's documented instructions; or
- As otherwise permitted or required by Applicable Data Protection Law.
Ennijo will not:
- Sell Customer Personal Data
- Share Customer Personal Data for cross-context behavioral advertising
- Use CRM Contact Data to independently market Ennijo or third-party products to Customer's CRM Contacts merely because those contacts appear in Ennijo
- Treat Customer's CRM Contacts as Ennijo sales leads merely because their information is stored in Ennijo
- Retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by Applicable Data Protection Law
- Combine Customer Personal Data with Personal Data received from another person or collected from Ennijo's own interaction with an individual except where permitted by Applicable Data Protection Law and reasonably necessary to provide the Service
Ennijo does not acquire ownership of Customer Personal Data.
6. Confidentiality
Ennijo will ensure that personnel authorized to Process Customer Personal Data:
- Have access only where reasonably necessary for their responsibilities
- Are subject to appropriate confidentiality obligations
- Receive appropriate instructions regarding protection of Personal Data
- Process Customer Personal Data only for authorized purposes
Customer Personal Data will be treated as Customer's confidential information.
These obligations survive termination of the applicable agreement for as long as Ennijo retains Customer Personal Data or as otherwise required by law.
7. Security
Taking into account the nature of Processing, information available to Ennijo, implementation costs, the state of available technology, and risks to individuals, Ennijo will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data.
Current security measures are described in Schedule B.
Ennijo may update its security measures as technology and the Service evolve, provided that Ennijo does not materially reduce the overall level of protection for Customer Personal Data during the applicable service term.
No electronic system can guarantee absolute security.
8. Personal Data Breaches
Ennijo will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Where reasonably available, the notification will include:
- The nature of the Personal Data Breach
- Categories of affected Personal Data
- Categories or approximate number of affected Data Subjects, where known
- Likely consequences, where reasonably identifiable
- Measures taken or proposed to investigate, contain, and remediate the breach
- A contact point for additional information
Information may be provided in phases as the investigation develops.
Ennijo will take reasonable steps to investigate, contain, mitigate, and remediate the incident.
Notification does not constitute an admission of fault or liability.
Customer remains responsible for determining whether notices must be provided to Data Subjects, regulators, clients, insurers, or other parties unless Applicable Data Protection Law provides otherwise.
Ennijo will provide reasonable assistance with legally required notifications, taking into account the nature of Processing and information available to Ennijo.
9. Data Subject Requests
Taking into account the nature of Processing, Ennijo will provide reasonable assistance to Customer in responding to verified Data Subject requests where required by Applicable Data Protection Law.
Requests may concern:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Portability
- Opt-out rights
- Other applicable privacy rights
If Ennijo receives a request directly from a Data Subject concerning Customer-controlled Customer Personal Data, Ennijo may:
- Refer the individual to Customer;
- Notify Customer of the request; or
- Respond as directed by Customer or required by law.
Ennijo will not independently decide the substantive merits of a Customer-controlled privacy request unless authorized by Customer or required by law.
10. Regulatory and Compliance Assistance
Taking into account the nature of Processing and information available to Ennijo, Ennijo will provide reasonable assistance with obligations concerning:
- Data protection impact assessments
- Regulatory consultations
- Security assessments
- Data breach investigations
- Responses to supervisory authorities
- Demonstrating compliance with Applicable Data Protection Law
Customer will reimburse Ennijo for extraordinary assistance requiring substantial resources unless the assistance is necessary because of Ennijo's breach of this DPA or Applicable Data Protection Law.
11. Subprocessors
Customer provides general authorization for Ennijo to engage Subprocessors.
Ennijo maintains its current Subprocessor and service-provider list at:
https://ennijo.com/subprocessors
Ennijo will require each Subprocessor that materially Processes Customer Personal Data on Ennijo's behalf to enter into a written agreement containing data protection obligations appropriate to the services performed and materially consistent with the applicable obligations imposed on Ennijo under this DPA.
Ennijo remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
Notice of Changes
Ennijo will provide at least 30 days' notice before engaging a new material Subprocessor or replacing an existing material Subprocessor.
Notice may be provided by:
- Email to Customer's designated administrator
- An in-product notice
- Updating the Subprocessor page together with appropriate Customer notice
Objections
Customer may object within the 30-day notice period on reasonable and documented data protection grounds.
The parties will work in good faith to address the objection.
If a valid objection cannot reasonably be resolved, Ennijo may:
- Modify the affected Processing
- Offer a reasonable alternative where available
- Permit Customer to terminate the affected Service without penalty for the portion that cannot reasonably be provided without the disputed Subprocessor
Customer may not require Ennijo to redesign the Service or incur commercially unreasonable costs.
12. Artificial Intelligence Processing
Ennijo uses Anthropic as the Subprocessor supporting Ennijo's AI Coach functionality.
AI-assisted features may include:
- Coaching suggestions
- Relationship prioritization
- Follow-up recommendations
- Summaries
- Organizational assistance
Depending on the feature used, Ennijo may transmit limited Customer Personal Data to Anthropic, including information such as:
- Contact name or first name
- Relationship stage
- Rating
- Lead source
- Tags
- City or state
- Days since prior contact
- Planned next action
- Contact preferences
- Activity summaries
- Customer-created CRM notes
Where reasonably possible, Ennijo seeks to minimize Personal Data transmitted to AI providers.
Ennijo does not authorize Customer Personal Data to be used for third-party general-purpose foundation-model training.
Customer remains responsible for reviewing AI-generated output before relying on it.
13. Google Workspace Integration
Where authorized by Customer or Customer's Google Workspace administrator, Ennijo may access limited Google Workspace information to provide Customer-requested functionality.
For Gmail activity logging, Ennijo currently accesses limited email header information, including:
- Recipient information
- Email subject
- Date sent
Ennijo does not access or store the email body through this Gmail activity-logging workflow.
Where a sent email is matched to a CRM Contact, Ennijo may store an activity record associated with that contact, including the email subject.
Email subject lines may contain Personal Data.
Google Workspace authorization may be provided through administrator-approved domain-wide delegation.
Customer's Google Workspace administrator controls the underlying authorization and may remove or modify it through Google administrative controls.
Information received through Google APIs is handled in accordance with applicable Google API Services User Data Policy requirements and the Ennijo Privacy Policy.
14. Government and Legal Requests
If Ennijo receives a legally binding request from a government authority or other third party for Customer Personal Data, Ennijo will, unless legally prohibited:
- Notify Customer before disclosure
- Limit disclosure to information legally required
- Take reasonable steps to challenge requests Ennijo reasonably determines are unlawful or overbroad where appropriate
Nothing in this Section requires Ennijo to violate applicable law or obstruct a lawful request.
15. Return, Export, and Deletion
Upon cancellation, termination, or expiration of Customer's use of Ennijo, Customer will have 30 days to export available Customer Data.
During that period, Ennijo will provide Customer with either:
- Access sufficient to use available Ennijo export functionality; or
- An export of available Customer Data upon request to support@ennijo.com
After the 30-day export period, Ennijo will begin deleting Customer Personal Data from active production systems.
Ennijo intends to complete deletion from active production systems no later than 60 days after cancellation, termination, or expiration, unless longer retention is:
- Required by law
- Necessary to resolve a dispute
- Necessary for security or fraud prevention
- Requested or authorized by Customer
- Otherwise permitted under Applicable Data Protection Law
Backups
Customer Personal Data remaining only in backups may be retained until those backups expire through their normal lifecycle.
Backup data remains subject to this DPA while retained and will not be restored except as reasonably necessary for disaster recovery, security, or system restoration.
Current backup practices may be described in the Ennijo Privacy Policy or applicable security documentation and may change as Ennijo's infrastructure develops.
Subprocessor Retention
Customer Personal Data Processed by a Subprocessor may remain subject to that Subprocessor's applicable backup or deletion lifecycle after Ennijo initiates deletion, provided the Subprocessor remains subject to applicable contractual and legal safeguards.
16. Audits and Compliance Information
Upon reasonable written request, Ennijo will make available information reasonably necessary to demonstrate compliance with this DPA and applicable Processor obligations.
Ennijo may satisfy this obligation through materials such as:
- Security documentation
- Policies and procedures
- Subprocessor information
- Security questionnaires
- Independent assessments or certifications if available
- Other reasonable compliance evidence
Where Applicable Data Protection Law requires an audit:
- Customer must first use available documentation where reasonably sufficient
- Audits must occur during normal business hours
- Customer must provide reasonable advance notice
- Audits must not unreasonably interfere with Ennijo's operations
- Auditors must be subject to confidentiality obligations
- Audits may not expose other customers' information or system vulnerabilities
- Customer will bear reasonable audit costs unless an audit reveals a material breach by Ennijo
Except where required by law or following a material security incident affecting Customer Personal Data, Customer may not conduct more than one audit in any 12-month period.
Nothing restricts a competent regulator's lawful audit authority.
17. International Data Transfers
Customer acknowledges that 29in5 LLC is based in the United States and that Customer Personal Data may be Processed in the United States or other countries in which authorized Subprocessors operate.
Where Applicable Data Protection Law requires an international transfer mechanism, the parties will use an applicable recognized mechanism.
European Economic Area
Where Customer transfers Personal Data subject to the EU GDPR to Ennijo and the transfer requires safeguards under Chapter V of the EU GDPR, the parties incorporate the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914.
Unless another module applies based on the parties' actual roles:
- Module Two, Controller to Processor, applies
- Customer is the data exporter
- 29in5 LLC is the data importer
- Clause 7, Docking Clause, applies
- Clause 9, Option 2, General Written Authorization, applies
- The Subprocessor notice period is 30 days
- Schedule A provides applicable Annex I information
- Schedule B provides applicable Annex II information
- Ennijo's current Subprocessor list provides applicable Annex III information to the extent permitted
If the Standard Contractual Clauses conflict with another provision of this DPA, the Standard Contractual Clauses control for the restricted transfer.
United Kingdom
Where UK Data Protection Law applies and an international transfer safeguard is required, the parties will use the applicable UK International Data Transfer Addendum to the EU Standard Contractual Clauses or another mechanism recognized under UK law.
18. U.S. State Privacy Requirements
Where Ennijo qualifies as a Service Provider, Contractor, or Processor under applicable U.S. state privacy law, Ennijo agrees to comply with obligations applicable to that role.
California
Where the CCPA applies:
- Customer discloses Customer Personal Data to Ennijo only for the limited and specified business purposes identified in this DPA.
- Ennijo will not sell or share Customer Personal Data as those terms are defined under the CCPA.
- Ennijo will not retain, use, or disclose Customer Personal Data for purposes other than:
- The limited and specified purposes in this DPA
- Another purpose permitted by the CCPA
- A purpose required by law
- Ennijo will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except where permitted by law.
- Ennijo will comply with applicable CCPA obligations and provide the legally required level of privacy protection for Customer Personal Data.
- Customer may take reasonable and appropriate steps to help ensure Ennijo uses Customer Personal Data consistently with Customer's CCPA obligations.
- Ennijo will notify Customer if Ennijo determines it can no longer meet its applicable CCPA obligations.
- Where permitted by law, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
- Ennijo will not combine Customer Personal Data received from Customer with Personal Data received from another person or collected through Ennijo's own interaction with a Data Subject except where permitted by the CCPA.
19. Aggregated and De-Identified Data
Ennijo may create aggregated or de-identified information derived from Customer Data where the resulting information cannot reasonably identify Customer or an individual Data Subject.
Where required by Applicable Data Protection Law, Ennijo will:
- Maintain such information in de-identified form
- Take reasonable measures to prevent re-identification
- Not attempt to re-identify it except where legally permitted
Aggregated and de-identified information may be used for:
- Product improvement
- Security
- Reliability analysis
- Performance analysis
- Usage statistics
- Research
- Business planning
20. Liability
Liability arising under this DPA is subject to the limitation-of-liability provisions in the applicable agreement governing Customer's use of Ennijo, except where Applicable Data Protection Law prohibits application of those limitations.
Nothing in this DPA creates liability that would not otherwise exist under the applicable agreement or law.
21. Term and Survival
This DPA begins when Ennijo first Processes Customer Personal Data on behalf of Customer and remains effective for as long as Ennijo Processes Customer Personal Data.
Provisions concerning confidentiality, security, deletion, international transfers, regulatory cooperation, audit rights, and obligations that logically survive termination remain effective for as long as required by law or while Ennijo retains Customer Personal Data.
22. Changes to this DPA
29in5 LLC may update this DPA where reasonably necessary to reflect:
- Changes in Applicable Data Protection Law
- Changes in Ennijo
- Changes in Processing practices
- Changes in international transfer mechanisms
- Regulatory guidance
Ennijo will provide reasonable notice of material changes that reduce Customer's contractual data protection rights.
23. Order of Precedence
For matters involving Processing of Customer Personal Data, the following order of precedence applies:
- Mandatory international transfer terms
- This DPA
- The applicable agreement governing Customer's use of Ennijo, including the Beta Program Agreement and, when applicable, the Terms of Service or subscription agreement
- The Ennijo Privacy Policy
The Privacy Policy remains controlling for independent Processing where 29in5 LLC acts as Controller rather than Processor.
24. Contact
Ennijo
A product of 29in5 LLC
4648 S Biltmore Ln
Madison, WI 53718
United States
Privacy: privacy@ennijo.com
Support: support@ennijo.com
Schedule A — Details of Processing
Subject Matter
Ennijo Processes Customer Personal Data to provide relationship management and customer relationship management functionality.
Duration
Processing begins when Customer begins using Ennijo or provides Customer Personal Data to the Service.
Processing continues during Customer's use of Ennijo and for the limited retention periods described in this DPA.
Nature and Purpose
Processing may include:
- Collection
- Import
- Recording
- Organization
- Storage
- Retrieval
- Display
- Updating
- Tagging
- Classification
- Relationship tracking
- Communication activity logging
- Follow-up scheduling
- Task management
- AI-assisted analysis
- Contact prioritization
- Summarization
- Export
- Backup
- Security monitoring
- Troubleshooting
- Deletion
Purposes include:
- Providing CRM functionality
- Helping Customer manage business relationships
- Providing reminders and tasks
- Tracking relationship activity
- Providing AI-assisted coaching and prioritization
- Providing Customer-authorized integrations
- Supporting and securing Ennijo
- Providing Customer-requested exports
Categories of Data Subjects
Customer Personal Data may relate to:
- Prospects
- Current clients
- Past clients
- Sphere contacts
- Referral partners
- Vendors
- Professional contacts
- Business partners
- Other contacts entered by Customer
- Authorized Users, where their data is Processed on Customer's behalf
Categories of Personal Data
Customer may Process information such as:
- Name
- Email address
- Telephone number
- Mailing address
- Property address
- City and state
- Relationship type
- Lead source
- Tags
- Ratings
- Contact preferences
- Relationship notes
- Activity summaries
- Communication activity
- Follow-up information
- Tasks
- Important dates
- Referral information
- Property-related information
- Birth month and day, where entered
- Names of family members or pets, where entered
- Other relationship information entered by Customer
- Gmail-derived recipient, subject, and date-sent information where authorized
- Authorized User identifiers and access information
Highly Sensitive Data
Ennijo is not intended as a repository for highly sensitive Personal Data.
Customer should not intentionally store information such as:
- Social Security numbers
- Taxpayer identification numbers
- Bank account numbers
- Credit or debit card numbers
- Banking credentials
- Passwords
- Authentication secrets
- Passport copies
- Full driver's license numbers or copies
- Medical records
- Protected health information
- Biometric templates
- Full tax returns
- Wire-transfer credentials or instructions
Schedule B — Technical and Organizational Measures
Ennijo maintains safeguards appropriate to the current nature and scale of the Service.
This Schedule describes categories of safeguards and does not guarantee that every control applies to every system or that a particular implementation will remain unchanged.
Access Control
Measures may include:
- User authentication
- Role-based or permission-based access
- Database access controls
- Restricted administrative access
- Tenant-based data access controls
- Service-account controls for authorized integrations
Application and Database Security
Measures may include:
- Authenticated application access
- Database authorization controls
- Row-level security or equivalent tenant isolation
- Secure server-to-database communications
- Restricted privileged database access
- Controlled use of server-side credentials
Encryption and Transmission Security
Ennijo uses secure protocols designed to protect Personal Data during transmission.
Managed infrastructure providers may also provide encryption at rest.
Infrastructure
Ennijo uses managed infrastructure and hosting providers identified on the public Subprocessor page.
Ennijo relies in part on the physical, environmental, and infrastructure security controls maintained by those providers.
Logging and Monitoring
Ennijo maintains operational and security logs as part of operating, troubleshooting, and protecting the Service.
Depending on the function and event being logged, those records may contain technical information, account identifiers, or Customer Personal Data.
Ennijo reviews its logging practices as the Service develops and may reduce or modify logged fields where appropriate for security, troubleshooting, privacy, or operational purposes.
Development and Change Management
Measures may include:
- Source control
- Code review
- Preview or test deployments
- Controlled production deployment
- Testing of material changes where appropriate
Backups and Resilience
Ennijo uses managed database backup functionality to support recovery from certain failures.
Backups are not intended to replace Customer's own business continuity or record-retention practices.
Incident Response
Ennijo maintains procedures designed to:
- Identify suspected incidents
- Investigate incidents
- Contain affected systems
- Remediate identified vulnerabilities
- Notify affected Customers where required
Vendor Management
Ennijo evaluates service providers that materially Process Customer Personal Data and requires contractual privacy and security obligations appropriate to the services provided.
Data Minimization
Ennijo seeks to limit Processing to information reasonably necessary for the applicable functionality.
AI Processing
Ennijo uses Anthropic for authorized AI Coach functionality.
Ennijo does not authorize Customer Personal Data to be used for third-party general-purpose foundation-model training.
Google Workspace Controls
Where Google Workspace functionality is enabled:
- Access may be authorized through Customer-administered domain-wide delegation
- Ennijo accesses only information reasonably necessary for authorized functionality
- Gmail activity logging uses recipient, subject, and date-sent information
- Gmail activity logging does not access or store email body content
- Customer's Workspace administrator controls authorization
- Google-derived information is subject to applicable Google Limited Use requirements
Personnel Confidentiality
Personnel authorized to access Customer Personal Data are expected to maintain confidentiality and use information only for authorized purposes.
Schedule C — Subprocessors
Customer provides general authorization for Ennijo to use the Subprocessors identified at:
https://ennijo.com/subprocessors
The current online Subprocessor and service-provider list is incorporated into this DPA by reference.
Ennijo will provide notice and an opportunity to object to material Subprocessor changes as described in Section 11.