Data Processing Agreement.
The contract that governs how we process the personal data you hold in Clockwork CRM.
This is our standard Data Processing Agreement, published in full. It forms part of the agreement under which we provide Clockwork CRM, and it sets out that you are the data controller and we are the data processor for the personal data in your instance.
The sub-processor list referred to in clause 6.2 is published separately at sub-processors, and our security measures are summarised at security.
1. Parties and interpretation
This Data Processing Agreement ("DPA") forms part of, and is subject to, the agreement under which Mythic Software provides the Clockwork CRM service (the "Principal Agreement") between:
(1) Mythic Software Limited, a company registered in England and Wales under company number 13449176, whose registered office is at 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ ("Mythic Software", "we", "us"); and
(2) the Customer, being the organisation that has subscribed to the Service, as identified in the Principal Agreement (the "Customer", "you").
1.1 Definitions
| Term | Meaning |
|---|---|
| Data Protection Legislation | The UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations 2003, and any other applicable data protection or privacy law, each as amended or replaced from time to time. |
| UK GDPR | Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018. |
| Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Supervisory Authority | As defined in the UK GDPR. |
| Customer Personal Data | Personal Data contained within or submitted to the Service by, or on behalf of, the Customer, or otherwise Processed by Mythic Software on the Customer's behalf under the Principal Agreement. |
| Service | The Clockwork CRM software-as-a-service application and associated support, hosting and maintenance services provided under the Principal Agreement. |
| Sub-processor | Any third party engaged by Mythic Software to Process Customer Personal Data on Mythic Software's behalf in connection with the Service. |
| Restricted Transfer | A transfer of Personal Data to which the transfer rules in Chapter V of the UK GDPR apply. |
| Transfer Mechanism | The International Data Transfer Agreement ("IDTA") or the International Data Transfer Addendum to the EU Standard Contractual Clauses ("UK Addendum"), each as issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or any other lawful safeguard under Article 46 UK GDPR. |
1.2 Interpretation
Where this DPA conflicts with the Principal Agreement in relation to the Processing of Customer Personal Data, this DPA takes precedence. Where this DPA conflicts with an applicable Transfer Mechanism, the Transfer Mechanism takes precedence. Where the Data Protection Legislation imposes a stricter obligation than this DPA, the Data Protection Legislation applies.
2. Roles of the parties
2.1 The parties acknowledge and agree that, in respect of the Processing of Customer Personal Data under the Principal Agreement:
- (a) the Customer is the Controller; and
- (b) Mythic Software is the Processor.
2.2 The Customer determines the purposes and means of the Processing. The Customer decides what Personal Data is entered into or collected through the Service, from whom, for what purposes, and for how long it is retained. Mythic Software has no independent purpose of its own for that data.
2.3 Mythic Software makes technical decisions about how the Service operates - including its architecture, the use of a separate database per customer, hosting configuration and software design. The parties agree that these are decisions about the technical means of Processing only and do not make Mythic Software a Controller.
2.4 The Customer is responsible for:
- (a) establishing and maintaining a lawful basis under Article 6 UK GDPR (and, where special category data is Processed, a condition under Article 9) for all Processing it instructs;
- (b) providing all required privacy information to Data Subjects;
- (c) the accuracy, quality and legality of Customer Personal Data and of the means by which it acquired that data; and
- (d) ensuring that its instructions to Mythic Software comply with the Data Protection Legislation.
2.5 Mythic Software acts as a Controller in its own right in respect of data it Processes for its own purposes - including account administration data, billing records, and information about the Customer's authorised users collected for authentication, security and service-management purposes. That Processing is governed by Mythic Software's privacy notice at https://clockworkcrm.com/policies/privacy-policy and is outside the scope of this DPA.
2.6 If Mythic Software determines the purposes and means of any Processing of Customer Personal Data, it will be a Controller in respect of that Processing under Article 28(10) UK GDPR. Mythic Software does not intend to do so and will notify the Customer if circumstances change.
3. Scope, duration and instructions
3.1 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.2 Mythic Software shall Process Customer Personal Data only on the Customer's documented instructions, including in relation to any Restricted Transfer, unless required to do otherwise by law to which Mythic Software is subject. Where such a legal requirement applies, Mythic Software will inform the Customer before Processing, unless the law prohibits it from doing so on important grounds of public interest.
3.3 The Principal Agreement, this DPA (including Annex 1), and the Customer's use and configuration of the Service constitute the Customer's complete documented instructions. Additional instructions must be given in writing to privacy@mythic.software and are subject to agreement, which may include reasonable charges where the instruction falls outside the scope of the Service.
3.4 Mythic Software shall inform the Customer if, in its opinion, an instruction infringes the Data Protection Legislation. Mythic Software may suspend the affected Processing until the instruction is confirmed, amended or withdrawn.
3.5 This DPA applies for the duration of the Principal Agreement and for as long as Mythic Software Processes Customer Personal Data thereafter.
4. Confidentiality
4.1 Mythic Software shall ensure that every person authorised to Process Customer Personal Data:
- (a) is subject to a binding duty of confidentiality, whether contractual or statutory, that survives the end of their engagement;
- (b) is granted access only to the extent necessary to perform their role; and
- (c) has received appropriate data protection training.
4.2 Mythic Software shall not disclose Customer Personal Data to any third party except as permitted by this DPA, on the Customer's instructions, or as required by law.
5. Security
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, Mythic Software shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to that risk, as required by Article 32 UK GDPR.
5.2 The measures in place as at the effective date of this DPA are described in Annex 2. Mythic Software may update them from time to time provided the level of security is not materially reduced.
5.3 Mythic Software shall regularly test, assess and evaluate the effectiveness of those measures.
6. Sub-processors
6.1 The Customer gives Mythic Software general written authorisation to engage Sub-processors, subject to this clause 6.
6.2 The Sub-processors engaged as at the effective date are listed in Annex 3 and published at https://clockworkcrm.com/policies/sub-processors. The Customer authorises those Sub-processors.
6.3 Before adding or replacing a Sub-processor, Mythic Software shall give the Customer at least 30 days' notice, by updating the published list at the URL in clause 6.2 and sending email notification to the Customer's account administrator and to any address subscribed for that purpose. The Customer may subscribe additional addresses to sub-processor notifications by writing to privacy@mythic.software.
6.4 The Customer may object to a proposed Sub-processor on reasonable data protection grounds by notifying Mythic Software in writing within 30 days of the notice. The parties shall discuss the objection in good faith. If Mythic Software cannot provide the Service without the Sub-processor and the objection cannot be resolved, the Customer may cancel their subscription from within the Service, in accordance with the Cancellation policy in the Terms of Service.
6.5 Mythic Software shall carry out appropriate due diligence on each Sub-processor and shall put in place a written contract imposing data protection obligations that offer an equivalent level of protection for Customer Personal Data as those set out in this DPA, as required by Article 28(4) UK GDPR.
6.6 Mythic Software remains fully liable to the Customer for the performance of each Sub-processor's data protection obligations.
7. Assistance with Data Subject rights
7.1 Taking into account the nature of the Processing, Mythic Software shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests from Data Subjects exercising rights under Chapter III UK GDPR.
7.2 The Service provides self-service functionality enabling the Customer to access, rectify, export and erase Customer Personal Data. That functionality is described in Annex 4. The Customer shall use it in the first instance.
7.3 Where the Customer cannot fulfil a request through the Service, Mythic Software shall provide reasonable additional assistance. Mythic Software may charge for assistance that is materially beyond the scope of the Service, on notice to the Customer before the charge is incurred.
7.4 If Mythic Software receives a request directly from a Data Subject relating to Customer Personal Data, it shall not respond to the substance of the request but shall notify the Customer without undue delay and direct the Data Subject to the Customer.
8. Personal Data Breaches
8.1 Mythic Software shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The procedure by which Mythic Software assesses and notifies breaches is set out in its Security Incident and Personal Data Breach Procedure; the timescale in this clause and the timescale in that procedure must be kept identical.
8.2 The notification shall include, to the extent known at the time and updated as further information becomes available:
- (a) a description of the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned;
- (b) the likely consequences of the breach;
- (c) the measures taken or proposed to address the breach and mitigate its adverse effects; and
- (d) the name and contact details of a point of contact at Mythic Software.
8.3 Mythic Software shall provide reasonable assistance to enable the Customer to meet its own obligations under Articles 33 and 34 UK GDPR, including any notification to the Information Commissioner within 72 hours and any communication to affected Data Subjects.
8.4 Mythic Software shall not notify a Supervisory Authority or any Data Subject of a breach affecting Customer Personal Data on the Customer's behalf unless the Customer instructs it to, or unless Mythic Software is required to do so by law.
8.5 Mythic Software shall document all Personal Data Breaches and make that record available to the Customer on request.
9. Data protection impact assessments
9.1 Taking into account the nature of the Processing and the information available to it, Mythic Software shall provide reasonable assistance to the Customer with:
- (a) data protection impact assessments under Article 35 UK GDPR; and
- (b) prior consultation with the Information Commissioner under Article 36 UK GDPR.
9.2 Assistance under this clause is limited to Processing carried out by Mythic Software and may be subject to reasonable charges where it is materially beyond the scope of the Service.
10. Deletion and return of data
10.1 On termination or expiry of the Principal Agreement, Mythic Software shall, at the Customer's choice, either delete or return all Customer Personal Data, and delete existing copies, unless required to retain it by law.
10.2 The Customer may export its data through the Service, and through the Service API, at any time while the subscription is active. The export functionality available to the Customer is described in Annex 4.
10.3 On expiry of the paid term following termination, the Customer's instance is suspended and enters a retrieval period of one calendar month, during which the Customer may reactivate the subscription and thereby restore full access to Customer Personal Data. The Customer acknowledges that the Service is not available for normal use, and that self-service export cannot be performed, while the instance is suspended. Mythic Software shall notify the Customer's account contact by email at 14, 7, 3 and 1 days before the end of the retrieval period.
10.4 Where the Customer elects the return of Customer Personal Data under clause 10.1, it must notify Mythic Software in writing at privacy@mythic.software before the end of the retrieval period. Mythic Software shall provide a complete extract, free of charge, within 5 working days of the request, in the format described in Annex 4.
10.5 At the end of the retrieval period Mythic Software shall delete Customer Personal Data from active systems within 24 hours. Deletion is performed by an automated process that runs daily and comprises dropping the Customer's database, deleting the Customer's file storage container, removing the Customer's published assets from the shared public assets container, dropping the dedicated database login created for the Customer's instance, releasing any telephone numbers allocated to the Customer, and deleting the Customer's catalogue records.
10.5A Customer Personal Data ceases to be reachable through the Service, or by any published URL, on completion of the process in clause 10.5. Two platform-level recovery features apply at the storage layer for a limited period afterwards: a deleted storage container is retained by the hosting platform and is restorable by Mythic Software for 14 days, and an individually deleted file is retained for 90 days. These features exist to make accidental deletion recoverable. Data retained under them is not accessible through the Service and is not otherwise Processed.
10.6 Copies of Customer Personal Data held in backups are deleted on the expiry of the applicable backup rotation cycle and in any event within 90 days of termination. The rotation is daily restore points retained 10 days, weekly restore points retained 4 weeks, and monthly restore points retained 3 months; the 90-day figure is the worst case, being termination immediately following a monthly restore point. Data held in backups pending deletion remains encrypted, remains subject to the security measures in Annex 2, is not accessible through the Service, and is not otherwise Processed.
10.7 Mythic Software shall certify deletion in writing on request, at no charge, stating the date on which deletion from active systems completed and, where the Customer requires it, the date on which the last backup copy expired.
10.8 Mythic Software retains, as Controller in its own right and outside the scope of this DPA, the billing records described in clause 2.5, for the period required by UK tax law. No Customer Personal Data from within the Customer's instance is retained for that purpose.
11. Audit and demonstrating compliance
11.1 Mythic Software shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and this DPA.
11.2 Mythic Software shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Such audits are subject to the following:
- (a) the Customer shall give at least 30 days' written notice;
- (b) audits shall take place no more than once in any 12-month period, except following a Personal Data Breach affecting the Customer or where required by a Supervisory Authority;
- (c) audits shall be conducted during normal business hours, without unreasonable disruption to Mythic Software's operations;
- (d) the auditor shall not be a competitor of Mythic Software and shall enter into a reasonable confidentiality undertaking;
- (e) the scope shall not extend to data, systems or premises of Mythic Software's other customers, or to information whose disclosure would breach Mythic Software's obligations to third parties; and
- (f) the Customer shall bear its own costs, and shall reimburse Mythic Software's reasonable costs where the audit exceeds 2 working days of Mythic Software's time.
11.3 Mythic Software may satisfy an audit request in whole or in part by providing its Cyber Essentials certificate, by completing the Customer's security questionnaire, or by providing written responses and evidence of the measures described in Annex 2, where this reasonably addresses the Customer's request.
12. International transfers
12.1 Mythic Software shall not make a Restricted Transfer of Customer Personal Data without ensuring that an appropriate safeguard under Chapter V UK GDPR is in place.
12.2 Customer Personal Data is hosted in the United Kingdom (Microsoft Azure, UK South). Databases, file storage, message queues, secret management, email delivery and call transcription are all configured to the United Kingdom. Where a Sub-processor Processes Customer Personal Data outside the UK, the location is identified in Annex 3 together with the applicable Transfer Mechanism.
12.2A Where a Sub-processor Processes Customer Personal Data in a country covered by UK adequacy regulations made under section 17A of the Data Protection Act 2018, including the EEA, that Processing is not a Restricted Transfer and no additional Transfer Mechanism is required. Annex 3 identifies which rows this applies to.
12.3 Where a Transfer Mechanism is required between the parties, the parties shall enter into the IDTA or the UK Addendum as appropriate, and Mythic Software shall complete a transfer risk assessment.
12.3A The optional AI assistance features of the Service (described in Annex 1) transmit the content of the Customer's prompt to a Sub-processor located in the United States. Those features are used only where a user of the Service invokes them. The applicable Transfer Mechanism is identified in Annex 3.
12.4 Mythic Software shall notify the Customer before changing the hosting region for Customer Personal Data.
13. Liability
13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement, except to the extent that such limitation is not permitted by law.
13.2 Nothing in this DPA relieves either party of its own direct responsibilities and liabilities under the Data Protection Legislation.
13.3 Where one party has paid compensation for damage caused by Processing, it is entitled to claim back from the other party that part of the compensation corresponding to the other party's share of responsibility, in accordance with Article 82 UK GDPR.
14. General
14.1 This DPA is governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
14.2 Mythic Software may update this DPA where necessary to reflect changes in the Data Protection Legislation, regulatory guidance, or the Service, provided the update does not materially reduce the protections afforded to Customer Personal Data. Material changes take effect on 30 days' notice.
14.3 If any provision is held invalid or unenforceable, the remainder continues in force.
14.4 This DPA takes effect on the effective date stated above and remains in force for as long as Mythic Software Processes Customer Personal Data.
This agreement applies automatically. It is incorporated into our Terms of Service and forms part of them, so it governs our processing of your data from the start of your subscription. No signature is required and there is nothing you need to do.
This page is the current version, dated and versioned above, and is suitable for your own GDPR records. If your procurement process requires a counter-signed copy, email privacy@mythic.software.
Annex 1 - Details of the Processing
(Required by Article 28(3) UK GDPR)
Subject matter of the Processing The provision of the Clockwork CRM service: hosting, storage, maintenance and support of the Customer's customer-relationship-management database and associated functionality.
Duration of the Processing The term of the Principal Agreement, plus the retrieval and deletion periods set out in clause 10 (a retrieval period of one calendar month, deletion from active systems within 24 hours thereafter, and expiry of backup copies within the period stated in clause 10.6).
Nature of the Processing Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, backup, restoration, erasure and destruction - carried out by automated means through the Service, and by Mythic Software personnel where necessary for support, maintenance, migration and incident resolution.
Purpose of the Processing To provide the Service and to fulfil Mythic Software's obligations under the Principal Agreement, in accordance with the Customer's instructions. Mythic Software does not Process Customer Personal Data for its own commercial purposes, for profiling, or for the training of machine learning models.
Optional features that involve additional Processing The following features Process Customer Personal Data only when the Customer enables or invokes them, and are identified separately because each engages a Sub-processor:
- Telephony and SMS - outbound and inbound calling and messaging, including call recording where the Customer enables it.
- Call transcription - transcription of call recordings by a speech-to-text service.
- Email sending and receiving - delivery of transactional, notification and marketing email, and retrieval of the Customer's mailbox content where the Customer connects a mailbox.
- Mailing list cleaning - validation of recipient email addresses before a bulk email send, where the Customer runs the list cleaner. Addresses are submitted to an email verification Sub-processor.
- AI assistance - text and image generation invoked by a user. The content of the user's prompt is transmitted to the AI Sub-processor. Prompts may contain Customer Personal Data if the user includes it. See clause 12.3A.
- Website analytics - analytics for pages served by the Service. Visitor identification is cookieless and derived from a keyed hash of IP address and user agent using a salt that is rotated daily and discarded after approximately two days; raw IP addresses and user agent strings are not persisted.
- Contact enrichment and data migration - retrieval of company information from public registers, and import of records from a third-party CRM where the Customer initiates a migration.
Categories of Data Subjects Determined by the Customer, but typically include:
- the Customer's customers, clients and prospective customers
- contacts at the Customer's supplier and partner organisations
- the Customer's employees and authorised users of the Service
- individuals who submit enquiries through the Customer's forms, landing pages or website
- individuals who correspond with the Customer by email, telephone or SMS through the Service
Types of Personal Data Determined by the Customer, but typically include:
- identity and contact data (name, job title, employer, postal address, email address, telephone number)
- correspondence content (emails, notes, case comments, SMS messages, call recordings and transcriptions, where those features are enabled)
- commercial and transactional data (sales opportunities, quotes, orders, invoices, case and project records)
- account data for the Customer's authorised users (username, credentials, access permissions, activity logs)
- website and marketing interaction data (form submissions, landing-page views, email engagement, analytics data)
- any other Personal Data the Customer chooses to enter into custom fields or upload as attachments
Special category data and criminal offence data The Service is not designed or marketed for the Processing of special category data under Article 9 UK GDPR or criminal offence data under Article 10. The Customer must not enter such data into the Service without first notifying Mythic Software in writing and agreeing any additional measures required.
Annex 2 - Technical and organisational measures
(Required by Articles 28(3)(c) and 32 UK GDPR)
Tenant separation Each customer's data is held in a separate, dedicated PostgreSQL database, owned by a database role and credentials unique to that customer, on dedicated PostgreSQL infrastructure operated by Mythic Software on Microsoft Azure virtual machines in UK South. Uploaded files are held in a separate storage container per customer. There is no shared table holding several customers' records, and no application-level tenancy filtering of customer records.
Access control
- Role-based access control within the application, administered by the Customer, including a separate administrator role
- Two-factor authentication (TOTP) is available to every user, and an administrator can require a specified user to enrol
- Password policy enforced at set and reset: minimum 8 characters, with upper case, lower case, numeric and special characters required
- Mythic Software staff access to production is limited to named individuals on a least-privilege basis, requires MFA, and is logged
- Production access is reviewed every 6 months, and is revoked within 24 hours of a person ceasing to require it
Encryption
- In transit: TLS 1.2 and TLS 1.3 only for all connections to the Service. HTTP Strict Transport Security is enabled, HTTP requests are redirected to HTTPS, and session cookies are marked Secure
- At rest: the virtual machine disks hosting the PostgreSQL databases, the Azure Storage account holding customer files, and the Azure Backup vault holding restore points are each encrypted at rest with platform-managed keys under Azure Storage Service Encryption (AES-256)
- Application secrets, including per-customer database credentials and storage keys, are held in Azure Key Vault and encrypted at the application layer with AES-256 using a key derived by PBKDF2-SHA256 (100,000 iterations)
- Two-factor authentication seeds are encrypted at rest with a key held in Azure Key Vault
- User passwords are hashed with Argon2id, the memory-hard algorithm recommended by OWASP, using a random per-password salt and parameters at or above OWASP's current guidance. Passwords are never stored or recoverable in readable form. Two-factor authentication is available to every user and can be required by an administrator
Hosting and infrastructure
- Hosted on Microsoft Azure, region UK South
- PostgreSQL databases, Azure Blob Storage, Azure Service Bus and Azure Key Vault, fronted by nginx
- Production hosts are separated by role across dedicated virtual machines: application and reverse proxy, database, background job processing, and realtime messaging
- Each host is protected by an Azure network security group that permits only the ports required for its role. The PostgreSQL and connection-pooler ports on the database host are restricted to named source addresses and are not reachable from the public internet, as are the administrative and realtime-messaging ports on the other hosts
- Azure platform DDoS protection applies to all public endpoints
- Operating system, runtime and application dependency security updates are applied monthly, and out of cycle for vulnerabilities rated high or critical
Backup and resilience
- All production hosts, including the database host, are backed up daily at 02:00 UTC by Azure Backup into a Recovery Services vault in UK South, encrypted at rest
- Retention: daily restore points for 10 days, weekly restore points for 4 weeks, monthly restore points for 3 months. This is the rotation referred to in clause 10.6
- In addition, each customer database is dumped individually every two hours, stored encrypted in UK South and retained for 30 days. Per-database dumps allow one customer's instance to be restored without involving any other customer's data
- Recovery point objective: up to 2 hours from the per-database dumps, falling back to up to 24 hours from the host-level backup alone
- Restores are tested at least annually
- Recovery time objective: 8 hours for restoration of service from backup
- Storage-level recovery features provide an additional safety net against accidental deletion: container soft-delete for 14 days and file soft-delete for 90 days, as described in clause 10.5A
Logging and monitoring
- Application error and performance monitoring with automated alerting (Sentry)
- Field-level change history is recorded within the application for core record types, giving a per-record audit trail of what changed, when and by which user
- Infrastructure metric alerting on every production host, covering host availability, CPU, available memory, disk IOPS saturation and network throughput, with automated email alerting to the engineering team
- Azure Activity Log alerting on changes to production resources
- Application error reports are retained by the error monitoring provider on its standard retention cycle, and infrastructure metrics are retained by the Azure Monitor platform for 93 days
Data minimisation in the product
- Website analytics is first-party. Visitor identity is a keyed hash of site, IP address and user agent under a salt rotated every UTC day and discarded after approximately two days; raw IP addresses and user agent strings are never persisted, and no tracking cookie is set
- IP-to-location resolution for analytics is performed offline against a locally held database; no visitor IP address is sent to a third party for this purpose
- Card details are never received or stored by the Service; payment card data is collected directly by the payment processor and Mythic Software holds only that processor's tokens and identifiers
Secure development
- Separate development, staging, pre-production and production environments, deployed through an automated pipeline
- Automated test suite run as part of the build
- Changes reach production through version control and an automated build and release pipeline, with an automated test suite of over 2,300 tests run as part of every build
- Dependency vulnerability scanning runs as part of the build
- All changes reach production through a merge request on a branch, reviewed before merge
- Live customer data is never copied into development or staging. Those environments use generated test data
Organisational measures
- Confidentiality obligations in all staff and contractor contracts
- All personnel are subject to contractual confidentiality obligations and are individually named for production access, which together with role-based access control are the operative personnel controls
- Documented incident response procedure - see the Security Incident and Personal Data Breach Procedure
- Record of Processing Activities maintained under Article 30(2) UK GDPR
- Named data protection contact: privacy@mythic.software
Certifications
Mythic Software holds Cyber Essentials certification.
| Certified entity | Mythic Software Limited |
| Scope | Whole Organisation |
| Certified by | The IASME Consortium Ltd, through certification body Baseel |
| Date of certification | 2 February 2026 |
| Valid to | 2 February 2027 |
| Certificate ID | 30bf3ff7-e0eb-475e-8aa1-5a754d0e8fc9 |
The certificate is independently verifiable at https://registry.blockmarktech.com/certificates/30bf3ff7-e0eb-475e-8aa1-5a754d0e8fc9/ and a copy is provided on request.
Mythic Software completes customer security questionnaires on request and will provide written evidence of any measure described above.
Annex 3 - Sub-processors
(Required by Article 28(2) and (4) UK GDPR)
The providers below are those that may Process Customer Personal Data in connection with the Service.
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Microsoft Ireland Operations Limited (Azure) | Cloud hosting, virtual machines, file storage, message queue, secret management and backup | All Customer Personal Data | United Kingdom (UK South). Microsoft support access may be global | Microsoft Products and Services DPA; EU SCCs and UK Addendum for support access |
| Microsoft Ireland Operations Limited (Azure AI Speech) | Speech-to-text transcription of call recordings | Call audio and resulting transcripts | United Kingdom (UK South) | As above |
| Microsoft Ireland Operations Limited (Azure Communication Services) | Delivery of system and notification email | Recipient name and email address, message content | United Kingdom (resource data location verified as UK) | As above |
| Amazon Web Services EMEA SARL (Amazon SES) | Delivery of system, notification and marketing email | Recipient name and email address, message content, delivery and engagement events | eu-west-2 (London) | AWS DPA; EU SCCs and UK Addendum if support access is non-UK |
| Hertza L.L.C. (ZeroBounce) | Verification that recipient email addresses are deliverable, where the Customer runs the mailing list cleaner before a bulk email send | Email addresses submitted for validation, retained by ZeroBounce for no more than 30 days | European Union. ZeroBounce personnel in the United States may access account registration data | ZeroBounce UK DPA. EU processing covered by UK adequacy regulations for the EEA; EU SCCs and UK Addendum for United States access |
| Twilio Ireland Limited | Inbound and outbound calling and SMS, telephone number provisioning | Phone numbers, call metadata, SMS content, and call recordings transiently | United States (us1) | Twilio DPA; SCCs and UK Addendum |
| Stripe Payments Europe Limited | Subscription billing and payment processing | Billing name, address, email, payment method tokens, transaction history. No CRM record data. Processed by Mythic Software as Controller, not as Processor, see clause 2.5 | Ireland and United States | Stripe DPA; SCCs and UK Addendum |
| OpenAI Ireland Limited | Optional AI text and image generation invoked by a user | Content of the user's prompt, which may contain Customer Personal Data | United States | OpenAI DPA; SCCs and UK Addendum. Prompts are not used to train OpenAI's models under the API terms |
| Functional Software, Inc. (Sentry) | Application error and performance monitoring | Incidental Personal Data contained in error reports, stack traces and request context | Germany (EU region). Verified as the configured region | Covered by UK adequacy regulations for the EEA; no additional Transfer Mechanism required for the hosting location. Sentry DPA applies |
| Companies House | Lookup of company registration data when a user searches for a company | Company name or registration number submitted by the user | United Kingdom | Not applicable, UK |
| Google Ireland Limited (reCAPTCHA) | reCAPTCHA on public forms and landing pages served by the Service | IP address and interaction signals of the form visitor | United States | Google DPA; SCCs and UK Addendum |
Locations verified. The Location column has been confirmed against the live configuration rather than assumed.
Call recordings and the United States. Twilio is configured to the us1 region, so call metadata and SMS content are processed in the United States. Call recordings are held there only transiently: once a recording has been durably stored in the customer's own UK file storage, Clockwork CRM deletes it from Twilio. That deletion is best-effort, so if it fails the recording remains with Twilio until removed manually.
AI features and the United States. The optional AI text and image generation features are the only routine transfer of Customer Personal Data outside the United Kingdom and the EEA. No data is sent unless a user of the Service invokes one of those features, and the transfer is limited to the content of that user's prompt. It is covered by the Standard Contractual Clauses and the UK Addendum, as recorded in the table above and in clause 12.3A. At the Customer's request, Mythic Software will disable these features for the Customer's instance, in which case no such transfer occurs.
Customer-directed integrations. The following are connected by the Customer to their own accounts. Mythic Software processes the resulting data within the Service but does not contract with the provider on the Customer's behalf, and the Customer's own relationship with the provider governs it. They are listed for completeness, not as Mythic Software Sub-processors: Microsoft 365 / Microsoft Graph and Google Workspace (mailbox and calendar synchronisation); HubSpot, Pipedrive and Capsule (one-off data migration into Clockwork CRM, initiated by the Customer).
Not sub-processed. Website analytics is first-party: analytics data is stored in the Customer's own database and IP-to-location resolution is performed offline against a locally held database, so no visitor data is sent to an analytics provider. Support is handled by Mythic Software over email and is not routed through a third-party ticketing platform.
Annex 4 - Export functionality available to the Customer
(Referred to in clauses 10.2 and 10.4, and describing the means by which the Customer may exercise the choice between deletion and return under clause 10.1.)
Self-service export within the Service. Users may export record data subject to their permissions. Exports are generated in the background and downloaded from the export list; a generated file remains available for 24 hours.
- Formats: CSV, Excel (XLSX), TSV, JSON, XML, HTML, PDF.
- Record types: people, companies, sales, cases, projects, project tasks, project time, products, services, case lists, campaign email records, bulk email recipients, form submissions, sequence contacts, landing page views, website analytics activity.
API. The Clockwork CRM REST API (v1) provides programmatic access to contacts, companies, sales, cases, projects, tasks, products, services, tags, calendar activities, notes, email, SMS and call records, knowledge base articles, marketing records, and file and attachment downloads. An administrator may issue an API key.
Scope of the export tools. The export tools produce tabular record data. They do not package file attachments, mailbox content, call recordings or call transcriptions into a single archive; those are retrieved individually through the Service or through the API.
Full extract on request. Where the export tools and the API do not meet the Customer's needs, Mythic Software will produce a complete extract of the Customer's instance, free of charge, comprising a compressed PostgreSQL dump of the Customer's database and a ZIP archive of the Customer's entire file storage container (including attachments, generated documents, stored call recordings and published assets).
- Lead time: within 5 working days of a written request to privacy@mythic.software from an administrator on the account.
- Charge: none.
- Delivery: by time-limited secure download link issued to the requesting administrator.
- Deadline: at any time while the subscription is active, and at any point during the retrieval period in clause 10.3. An extract cannot be produced once the instance has been deleted.