Legal
SCC appendix
The completed annex information for the Standard Contractual Clauses and the UK International Data Transfer Addendum. Version 2026-08-27. Last updated 27 August 2026. It forms part of the data processing agreement.
This is the form material. It is here rather than in the agreement because the agreement is meant to be read, and because incorporating clauses without completing their annexes leaves a customer relying on blanks.
Which module applies
The clauses have four modules and the right one depends on your role, not on ours. Both are incorporated, and the one that governs a given transfer is the one matching your role for that data.
| If | Module | Then |
|---|---|---|
| You determine the purposes of the processing (the ordinary case) | Module Two | You are the controller and data exporter. O'Shea & Sons is the processor and data importer. |
| You process the data on behalf of your own client | Module Three | You are the processor and data exporter. O'Shea & Sons is the sub-processor and data importer. |
Options selected
| Clause | Selection |
|---|---|
| Clause 7, docking | Included. A further party may accede with the agreement of both parties. |
| Clause 9(a), sub-processors | Option 2, general written authorisation. The current sub-processors are listed in Annex III, and we give thirty days' notice before a new one starts processing. |
| Clause 11(a), independent dispute resolution | The optional redress-by-independent-body wording is not selected. |
| Clause 17, governing law | The law of Ireland, which allows third-party beneficiary rights as the clauses require. |
| Clause 18(b), forum | The courts of Ireland. |
Annex I.A. Parties
| Data exporter | The customer that accepted this agreement, identified by the workspace owner's name, organization, and email address as recorded at acceptance and shown in Settings. Activities: use of Indraft as a CRM. Role: controller under Module Two, processor under Module Three. |
| Data importer | O'Shea & Sons, LLC, an Illinois limited liability company, United States. Activities: providing the Indraft CRM. Role: processor under Module Two, sub-processor under Module Three. |
| Contact for data protection | hello@indraft.io |
Annex I.B. Description of the transfer
Categories of data subjects
The people represented in customer personal data may include your users and employees, your customers and prospective customers, your vendors and counterparties, and other people whose information you choose to maintain in the CRM.
Categories of personal data
- Names, job titles, and the organizations people belong to
- Business contact details: email addresses, telephone numbers, and postal or web addresses
- Relationship and pipeline data: opportunity values, stages, owners, and outcomes
- Interaction summaries written by you or your agents, with their author and assertion kind, and a bounded evidence snippet
- Tasks, notes, and the values held in custom fields and custom object types you define
- The change ledger: who changed which field, when, from what to what, and by which access path
| Sensitive data | Indraft is not designed for special-category data and asks for none. Because custom fields and free-text summaries accept whatever you write, we cannot assert that none is present, and we apply the same measures to everything in the workspace. |
| Frequency of transfer | Continuous, for as long as the workspace exists. |
| Nature and purpose | Storing, organizing, indexing, retrieving, relating, attributing, and transmitting CRM records on your instructions, together with the support and security work that keeps the service running. |
| Retention | For the life of the workspace. On deletion, destroyed within seven days, with backups and replicas expiring within thirty-five. Erasure of one person's record is within thirty days of your request. |
| Sub-processor processing | Each sub-processor in Annex III processes for the duration of our agreement with them and no longer than the life of your workspace. |
Annex I.C. Competent supervisory authority
Determined by Clause 13. Where you are established in an EEA member state, the supervisory authority of that state. Where you are not established in the EEA but your processing falls under the GDPR and you have appointed a representative, the supervisory authority of the member state where that representative is established. Where neither applies, the supervisory authority of the member state where the data subjects whose personal data is transferred are located.
Annex II. Technical and organizational measures
Described as measures rather than as products. What we guarantee is your business; which components we assembled to do it is ours, and naming them would date this page every time we changed one.
| Measure | What it is |
|---|---|
| Isolation between customers | Each workspace uses a separate database rather than shared tables holding every customer's records. This removes any dependence on row-level tenant filters for isolation and reduces the blast radius of an application-layer query error. |
| Encryption | Personal data is encrypted in transit using current TLS, and encrypted at rest by our infrastructure sub-processor. |
| Access control | Access to production is limited to the people who operate the service. Inside a workspace, four roles bound what each person may do, and a credential can never hold more than the person who created it holds, evaluated at the time of the request rather than when it was issued. |
| Credential handling | API credentials are stored only as hashes, are displayed once at creation, and are individually revocable. Authentication and authorization are delegated to our identity sub-processor; Indraft stores no passwords. |
| Logging and accountability | Every write is recorded in a change ledger carrying the actor, the access path, the field, the value before and after, and whether the assertion was made by a person or an agent. The ledger is not editable through the product. |
| Data minimisation by design | Indraft provides no dedicated storage or ingestion for email bodies, call transcripts, recordings, attachments, or arbitrary files, and makes no calls to any language model in any code path, which an automated architecture check enforces on every build. |
| Deletion and portability | Documented service levels for workspace deletion, erasure of one person's record, and backup expiry, with a self-serve export the workspace owner can take at any time without asking us. |
| Resilience and integrity | Writes are idempotent under retry and versioned against concurrent modification, so a repeated or racing request cannot silently duplicate or overwrite a record. Schema changes run to completion before a workspace serves any request. |
| Incident response | Automated monitoring of the service, with notice to you without undue delay and, where feasible, within twenty-four hours of our becoming aware of a personal data breach affecting your workspace. |
We describe controls rather than claiming an outcome. We hold no SOC 2 report and no ISO certification, and we say so plainly rather than implying otherwise.
Annex III. Sub-processors
Authorised under Clause 9(a), Option 2. The full list, with what each one processes and why, is on the sub-processors page, and we give thirty days' notice before a new one starts processing customer data.
| Sub-processor | Processes |
|---|---|
| Cloudflare | All CRM data, at rest and in transit, and the email address we send service notices to |
| WorkOS | Identity: user, organization, membership, and role |
| Stripe | Billing contact and payment data |
UK International Data Transfer Addendum
For restricted transfers subject to UK data protection law, the Addendum applies to the clauses above with the following tables completed.
| Table 1, parties | As set out in Annex I.A above. The exporter is the customer; the importer is O'Shea & Sons, LLC. |
| Table 2, selected SCCs and modules | The European Commission's Standard Contractual Clauses of 4 June 2021, Module Two or Module Three as determined by your role above, including the options recorded above. |
| Table 3, appendix information | Annex I, Annex II, and Annex III above. |
| Table 4, ending the Addendum when the Approved Addendum changes | The exporter may end this Addendum as set out in Section 19 of the Addendum. |
What this page does not do
It completes the annexes and describes the measures we operate. It does not award us a compliance verdict, a certification, or a coverage claim, because those are not ours to award. Your counsel is better placed to judge whether this is sufficient for your transfer than our marketing is.