Skip to content
indraft
Start free

Legal

SCC appendix

The completed annex information for the Standard Contractual Clauses and the UK International Data Transfer Addendum. Version 2026-08-27. Last updated 27 August 2026. It forms part of the data processing agreement.

This is the form material. It is here rather than in the agreement because the agreement is meant to be read, and because incorporating clauses without completing their annexes leaves a customer relying on blanks.

Which module applies

The clauses have four modules and the right one depends on your role, not on ours. Both are incorporated, and the one that governs a given transfer is the one matching your role for that data.

IfModuleThen
You determine the purposes of the processing (the ordinary case)Module TwoYou are the controller and data exporter. O'Shea & Sons is the processor and data importer.
You process the data on behalf of your own clientModule ThreeYou are the processor and data exporter. O'Shea & Sons is the sub-processor and data importer.

Options selected

ClauseSelection
Clause 7, dockingIncluded. A further party may accede with the agreement of both parties.
Clause 9(a), sub-processorsOption 2, general written authorisation. The current sub-processors are listed in Annex III, and we give thirty days' notice before a new one starts processing.
Clause 11(a), independent dispute resolutionThe optional redress-by-independent-body wording is not selected.
Clause 17, governing lawThe law of Ireland, which allows third-party beneficiary rights as the clauses require.
Clause 18(b), forumThe courts of Ireland.

Annex I.A. Parties

Data exporterThe customer that accepted this agreement, identified by the workspace owner's name, organization, and email address as recorded at acceptance and shown in Settings. Activities: use of Indraft as a CRM. Role: controller under Module Two, processor under Module Three.
Data importerO'Shea & Sons, LLC, an Illinois limited liability company, United States. Activities: providing the Indraft CRM. Role: processor under Module Two, sub-processor under Module Three.
Contact for data protectionhello@indraft.io

Annex I.B. Description of the transfer

Categories of data subjects

The people represented in customer personal data may include your users and employees, your customers and prospective customers, your vendors and counterparties, and other people whose information you choose to maintain in the CRM.

Categories of personal data

Sensitive dataIndraft is not designed for special-category data and asks for none. Because custom fields and free-text summaries accept whatever you write, we cannot assert that none is present, and we apply the same measures to everything in the workspace.
Frequency of transferContinuous, for as long as the workspace exists.
Nature and purposeStoring, organizing, indexing, retrieving, relating, attributing, and transmitting CRM records on your instructions, together with the support and security work that keeps the service running.
RetentionFor the life of the workspace. On deletion, destroyed within seven days, with backups and replicas expiring within thirty-five. Erasure of one person's record is within thirty days of your request.
Sub-processor processingEach sub-processor in Annex III processes for the duration of our agreement with them and no longer than the life of your workspace.

Annex I.C. Competent supervisory authority

Determined by Clause 13. Where you are established in an EEA member state, the supervisory authority of that state. Where you are not established in the EEA but your processing falls under the GDPR and you have appointed a representative, the supervisory authority of the member state where that representative is established. Where neither applies, the supervisory authority of the member state where the data subjects whose personal data is transferred are located.

Annex II. Technical and organizational measures

Described as measures rather than as products. What we guarantee is your business; which components we assembled to do it is ours, and naming them would date this page every time we changed one.

MeasureWhat it is
Isolation between customersEach workspace uses a separate database rather than shared tables holding every customer's records. This removes any dependence on row-level tenant filters for isolation and reduces the blast radius of an application-layer query error.
EncryptionPersonal data is encrypted in transit using current TLS, and encrypted at rest by our infrastructure sub-processor.
Access controlAccess to production is limited to the people who operate the service. Inside a workspace, four roles bound what each person may do, and a credential can never hold more than the person who created it holds, evaluated at the time of the request rather than when it was issued.
Credential handlingAPI credentials are stored only as hashes, are displayed once at creation, and are individually revocable. Authentication and authorization are delegated to our identity sub-processor; Indraft stores no passwords.
Logging and accountabilityEvery write is recorded in a change ledger carrying the actor, the access path, the field, the value before and after, and whether the assertion was made by a person or an agent. The ledger is not editable through the product.
Data minimisation by designIndraft provides no dedicated storage or ingestion for email bodies, call transcripts, recordings, attachments, or arbitrary files, and makes no calls to any language model in any code path, which an automated architecture check enforces on every build.
Deletion and portabilityDocumented service levels for workspace deletion, erasure of one person's record, and backup expiry, with a self-serve export the workspace owner can take at any time without asking us.
Resilience and integrityWrites are idempotent under retry and versioned against concurrent modification, so a repeated or racing request cannot silently duplicate or overwrite a record. Schema changes run to completion before a workspace serves any request.
Incident responseAutomated monitoring of the service, with notice to you without undue delay and, where feasible, within twenty-four hours of our becoming aware of a personal data breach affecting your workspace.

We describe controls rather than claiming an outcome. We hold no SOC 2 report and no ISO certification, and we say so plainly rather than implying otherwise.

Annex III. Sub-processors

Authorised under Clause 9(a), Option 2. The full list, with what each one processes and why, is on the sub-processors page, and we give thirty days' notice before a new one starts processing customer data.

Sub-processorProcesses
CloudflareAll CRM data, at rest and in transit, and the email address we send service notices to
WorkOSIdentity: user, organization, membership, and role
StripeBilling contact and payment data

UK International Data Transfer Addendum

For restricted transfers subject to UK data protection law, the Addendum applies to the clauses above with the following tables completed.

Table 1, partiesAs set out in Annex I.A above. The exporter is the customer; the importer is O'Shea & Sons, LLC.
Table 2, selected SCCs and modulesThe European Commission's Standard Contractual Clauses of 4 June 2021, Module Two or Module Three as determined by your role above, including the options recorded above.
Table 3, appendix informationAnnex I, Annex II, and Annex III above.
Table 4, ending the Addendum when the Approved Addendum changesThe exporter may end this Addendum as set out in Section 19 of the Addendum.

What this page does not do

It completes the annexes and describes the measures we operate. It does not award us a compliance verdict, a certification, or a coverage claim, because those are not ours to award. Your counsel is better placed to judge whether this is sufficient for your transfer than our marketing is.