Snapshot 48767
Normalized text
Scripts and page chrome removed; this is what change detection compares.
cocorev policies
Clear policies for a privacy-first CRM workflow: GDPR, Data Processing, Legal Notices, and Terms & Conditions, kept simple and practical.
Data Processing Agreement
Effective Date: August 25, 2025
Company: cocorev
Website: https://www.cocorev.com
Contact: legal@cocorev.com
This Data Processing Agreement ("DPA") forms part of the agreement between cocorev ("cocorev", "we", "us") and the customer using the cocorev service ("Customer") where cocorev processes Personal Data on behalf of Customer.
This DPA is intended to meet the requirements of applicable data protection law, including the EU General Data Protection Regulation ("GDPR").
1. Roles
Where cocorev processes Personal Data contained in or obtained from Customer's systems on Customer's behalf:
Customer is the Controller of that Personal Data.
cocorev acts as a Processor.
Customer determines the purposes for which its Personal Data is processed and is responsible for ensuring that it has a lawful basis for providing cocorev with access to that data.
cocorev will process Personal Data only to provide the service, in accordance with Customer's documented instructions, this DPA and applicable law.
2. Nature and purpose of processing
cocorev provides ecosystem intelligence and sales workflow software for B2B companies.
Processing may include accessing and analysing information from Customer's HubSpot account in order to:
Connect cocorev with Customer's CRM
Identify relevant companies and ecosystem signals
Match accounts across authorised partner connections
Identify account overlaps and collaboration opportunities
Surface relevant information and recommended actions
Support cocorev workflows inside HubSpot
Maintain and secure Customer's cocorev account
Provide support and troubleshoot the service
HubSpot remains the primary system in which Customer's underlying CRM records are maintained.
cocorev accesses data from HubSpot as required to provide the service and may process limited identifiers, metadata and generated results necessary to operate the service.
3. Types of data processed
Depending on the features Customer enables, cocorev may process:
HubSpot company data
Company names
Domains and website information
Company properties
Company record identifiers
Industry, location and other company attributes
HubSpot contact data
Contact record identifiers
Names
Business email addresses
Business contact information
Contact properties
Access to contact data does not mean that contact information is shared with connected cocorev partners.
HubSpot deal data
Deal identifiers
Deal stage
Deal amount
Associated company information
Other deal properties required by enabled cocorev features
HubSpot account data
Portal identifiers
HubSpot user information
Assigned users
HubSpot list identifiers
Integration and authorization information
cocorev-generated data
Partner connections
Account matches and overlap results
Ecosystem signals
Recommendations and playbook results
User activity relating to cocorev
4. Categories of Data Subjects
Personal Data processed through the service may relate to:
Customer employees and authorised users
Customer prospects
Customer customers
Business contacts contained in Customer's CRM
Employees or representatives of companies in Customer's ecosystem
cocorev is intended for business use and is not designed to process sensitive or special category personal data.
Customer should not intentionally provide cocorev with special category Personal Data unless expressly agreed in writing.
5. HubSpot data
Customer connects HubSpot to cocorev using HubSpot's authorization framework.
HubSpot remains the primary system in which Customer's underlying CRM records are maintained.
cocorev accesses HubSpot data where necessary to provide enabled functionality and may process limited data derived from HubSpot where required to:
Maintain the integration
Match and identify accounts
Record authorised partner relationships
Generate overlap results
Power cocorev workflows
Display relevant ecosystem intelligence
Maintain service functionality
cocorev does not give connected partners access to Customer's HubSpot portal.
6. Partner sharing
Certain cocorev features allow two companies to connect and identify relevant account overlaps.
Connecting through cocorev does not expose one company's full CRM to the other.
Connected partners do not receive general access to:
Customer's HubSpot portal
Customer's complete customer or prospect list
Customer's contact database
Contact email addresses or phone numbers
Customer's complete pipeline
Unrelated CRM records
cocorev limits information displayed between connected companies to information required for the relevant ecosystem or collaboration workflow.
7. Customer instructions
cocorev will process Personal Data only:
As necessary to provide the service;
In accordance with Customer's use and configuration of cocorev;
In accordance with this DPA; or
Where required by applicable law.
If cocorev believes an instruction infringes applicable data protection law, it will inform Customer where legally permitted.
8. Confidentiality
cocorev will ensure that people authorised to process Personal Data are subject to appropriate confidentiality obligations and only have access where required for their role.
9. Security
cocorev will maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include, as appropriate:
Secure authentication
Encryption of data in transit
Access controls
Restriction of production access to authorised personnel
Secure cloud infrastructure
Appropriate software and dependency maintenance
Processes for responding to security incidents
Security measures may evolve as cocorev's service and infrastructure develop.
10. Subprocessors
Customer provides cocorev with general authorisation to use subprocessors where reasonably necessary to provide the service.
cocorev will require subprocessors that process Personal Data on its behalf to provide appropriate data protection and security commitments.
cocorev currently uses Google Cloud Platform and Firebase for elements of its infrastructure, storage and authentication.
Where cocorev adds or replaces a subprocessor that materially affects the processing of Customer Personal Data, cocorev will make updated information available to Customer and provide an opportunity to raise reasonable data protection concerns.
11. International transfers
Where Personal Data is transferred outside the European Economic Area or another jurisdiction requiring transfer safeguards, cocorev will use an applicable lawful transfer mechanism where required, such as:
An adequacy decision
Standard Contractual Clauses
Another transfer mechanism permitted by applicable data protection law
12. Data retention and deletion
cocorev retains Personal Data only for as long as reasonably necessary to provide the service, maintain required records and meet applicable legal obligations.
Following termination of the service or a valid deletion request, cocorev will delete or return Personal Data processed on Customer's behalf where required by applicable law, unless cocorev is legally required to retain it.
Residual copies may remain temporarily in secure backups until those backups are overwritten or deleted in accordance with normal retention processes.
Revoking the HubSpot integration prevents cocorev from making further authorised requests to Customer's HubSpot account using that connection.
13. Data Subject requests
Taking into account the nature of the processing, cocorev will provide reasonable assistance to Customer in responding to requests from Data Subjects exercising their rights under applicable data protection law.
If cocorev receives a request relating to Personal Data for which Customer is the Controller, cocorev may direct the requester to Customer unless legally required to respond directly.
14. Personal Data breaches
cocorev will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed on Customer's behalf.
Where information is available, cocorev will provide reasonable details about:
The nature of the breach
The data potentially affected
The likely consequences
Steps taken or proposed to address the incident
cocorev will reasonably cooperate with Customer in meeting applicable breach notification obligations.
15. Assistance with compliance
Taking into account the nature of the processing and information available to cocorev, cocorev will provide reasonable assistance with Customer's obligations relating to:
Security of processing
Personal Data breaches
Data protection impact assessments
Regulatory consultations where required
16. Audits and information
cocorev will make information reasonably necessary to demonstrate compliance with its obligations as a Processor available to Customer.
Where required by applicable data protection law, Customer may request reasonable additional information or an audit relating to cocorev's processing of Customer Personal Data.
Any audit must be reasonable in scope, subject to appropriate confidentiality requirements and designed to minimise disruption to cocorev's operations.
17. Customer responsibilities
Customer is responsible for:
Ensuring it has a lawful basis to process Personal Data through cocorev
Configuring and using cocorev appropriately
Managing who within its organisation can access cocorev
Ensuring it does not provide unnecessary sensitive information
Complying with its obligations as Controller
18. Duration
This DPA applies for as long as cocorev processes Personal Data on Customer's behalf.
The confidentiality, deletion and other provisions that by their nature should continue after termination will remain applicable after the service ends.
19. Governing law
Unless otherwise agreed in the main agreement between the parties, this DPA is governed by Irish law.
20. Contact
Questions relating to privacy or this DPA can be sent to:
Legal: legal@cocorev.com
Security: security@cocorev.com
Support: support@cocorev.com