1. Roles
You are the controller of personal data contained in the files you import and in your Zoho CRM. Dinode is a processor acting on your documented instructions, which are: to provide Sloose as described in the Terms and the Privacy Policy, and any further instruction you give through the product's settings.
2. Scope of processing
| Category | Data | Where processed |
|---|---|---|
| Import rows | Whatever your file contains, which may include customer names, contact details and business data | In your browser and in Zoho CRM only. Not stored by Dinode. |
| User identity | Zoho user ID, email, display name, role | Dinode (Cloudflare) |
| Organisation | Zoho org ID and name, encrypted OAuth refresh token, CRM metadata | Dinode (Cloudflare) |
| Configuration and job metadata | Mappings, rules, helper libraries, job outcomes and error text | Dinode (Cloudflare) |
| AI samples | Column headings, field definitions, a small sample of values | Cloudflare AI Gateway, Anthropic; transient |
| Billing | Stripe customer ID, plan, invoices | Stripe |
3. Dinode's obligations
- Process personal data only on your instructions, unless the law requires otherwise, in which case we tell you first where we can.
- Ensure staff with access are bound by confidentiality and limited to what their role needs.
- Maintain the security measures in section 5.
- Assist you with data subject requests, impact assessments and regulator enquiries, at reasonable cost where the work is substantial.
- Notify organisation administrators without undue delay, and in any case within 72 hours, of a personal data breach affecting your data, with what we know at the time.
- Delete or return personal data at the end of the service on the schedule in the Privacy Policy, except where the law requires retention.
- Make available the information needed to show compliance and allow audits, on reasonable notice and no more than once a year unless a regulator or breach requires otherwise.
4. Sub-processors
You authorise the sub-processors below. We will post changes on this page at least 30 days before a new sub-processor handles your data; if you object on reasonable data protection grounds and we cannot resolve it, you may terminate the service and receive a pro-rata refund of prepaid fees.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database (D1), Durable Objects, edge network, AI Gateway, email routing | Global network; United States headquartered |
| Anthropic, PBC | AI model for mapping and value suggestions | United States |
| Stripe, Inc. | Payments and invoicing | United States, with EU and Australian entities |
| Zoho Corporation | CRM platform, sign-in, Marketplace distribution | Data centre matching your Zoho account region (US, EU, IN, AU, JP) |
5. Security measures
- TLS for all traffic; HSTS on all Sloose hostnames.
- OAuth credentials encrypted at rest with a key stored outside the database.
- Per-organisation scoping on every API route; org API tokens are hashed and revocable.
- Production access limited to named Dinode staff with multi-factor authentication; secrets held in Cloudflare's secret store, never in source control.
- Automated checks that no customer identifiers enter the product codebase.
- Logging of administrative actions; short-retention request logs for security review.
6. International transfers
Where personal data leaves the EU, UK or Australia it is transferred under the sub-processor's standard contractual clauses or an equivalent lawful mechanism. On request we will enter into the EU Standard Contractual Clauses (module two, controller to processor) and the UK Addendum with you; this DPA then incorporates them.
7. Liability
Liability under this addendum is subject to the limits in the Terms of Service, to the extent the law allows.
8. Contact
Data protection enquiries: hello@sloose.com. Security: security@sloose.com. Dinode Pty Ltd, Level 2, 11 York Street, Sydney NSW 2000, Australia.