As of: 2026-08-28 · Version: 1.0 · Change history
This agreement specifies the parties' data-protection obligations in connection with the use of the service “TheY CRM / Kunden-Support CRM” and applies pursuant to Art. 28 GDPR in addition to the Terms of Use.
The controller is the customer (the tenant/company using the service) for the personal data it processes in the service. The processor is The-Y e.U., Thomas Nuri Yilmaz, BSc, Senefeldergasse 25, 1100 Vienna (“The-Y”). The-Y processes personal data solely on the controller's instructions to provide the service.
Subject & purpose: providing and operating an all-in-one CRM and support software (inbox across email/web chat/SMS/WhatsApp/Meta, telephony, contact/company/deal management, invoices, tasks/calendar, marketing, workforce management, reporting, optional AI features).
Duration: for the term of the usage relationship. After termination, section 8 (deletion/return) applies.
Data subjects: the controller's customers/prospects/contacts, its employees/users, contact persons of associated companies.
Data types (as far as the controller enters/creates them):
The-Y processes the data only on the documented instructions of the controller. Use and configuration of the service constitute instructions. If The-Y considers an instruction unlawful, the controller is informed.
Persons authorised to process are bound to confidentiality. Access is limited to what is necessary for operation.
The-Y takes appropriate TOM pursuant to Art. 32 GDPR; see Annex 1.
The controller consents to the use of the sub-processors listed in Annex 2. Additions/changes are notified in advance; the controller may object for good data-protection reasons.
Services connected by the controller itself (own AI provider via BYO key, WhatsApp/Meta, SMS provider, own mail server) are not sub-processors of The-Y: the controller connects and is responsible for these providers via its own account/contract. The-Y merely forwards content to the endpoints configured by the controller.
The-Y assists the controller, as far as possible, with data-subject requests (access, deletion, rectification, export) and with data breaches, and notifies it of any breach it becomes aware of without undue delay. Tools for export (snapshot/CSV) and deletion are available in the service.
After termination the personal data is, at the controller's choice, deleted or returned, unless a statutory retention obligation applies. For retention periods and deletion from backups/logs see the Privacy Policy and Data Deletion.
The-Y provides the information necessary to demonstrate compliance and allows for reasonable audits. In the self-hosting case the controller operates the infrastructure itself; there The-Y is not a processor but a mere software supplier.
Austrian law applies; place of jurisdiction is — where permissible — Vienna. In case of conflict, this DPA prevails over the Terms of Use on data-protection matters.
| Provider | Purpose | Location | Status |
|---|---|---|---|
| The-Y e.U. (self-operated infrastructure) | Hosting/server operation of the service during the Alpha | Austria / EU | active |
| Cloud hosting provider (EU) — planned for the Beta | hosted cloud operation + backup | EU | from Beta 🧑 |
Not listed as sub-processors of The-Y, because connected and controlled by the controller via its own account/key: the chosen AI provider (Anthropic, OpenAI or Google — only with AI enabled, BYO key), WhatsApp/Meta, SMS provider, own email server. Transmission to these providers is governed by their terms; third-country transfer may apply depending on provider choice.
Payment processing (Stripe): Stripe processes payment data for billing between The-Y and the paying customer (The-Y is the controller in that respect) — not for the end-customer data the customer processes in the CRM.