Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the RouterJet Terms of Service and applies whenever RouterJet processes personal data on a customer’s behalf. It consists of this Cover Page and the Common Paper DPA Standard Terms, Version 1.1, which are incorporated by reference. If the Cover Page and the Standard Terms conflict, the Cover Page controls. Capitalized terms are defined in the Standard Terms.

You accept this DPA when you accept the Terms of Service; no signature is needed. If you require a countersigned copy, email hello@routerjet.com.

Last updated: 17 September 2026

Cover Page

Term Value
Provider Kenton Hirowatari, doing business as Hirowatari Consulting (“RouterJet”)
Customer The person or organization that accepted the Agreement
Agreement The RouterJet Terms of Service at routerjet.com/terms, as accepted by Customer
Approved Subprocessors The list at routerjet.com/subprocessors
Provider Security Contact hello@routerjet.com
Security Policy Provider will use commercially reasonable efforts to protect Customer Personal Data, including the measures in Annex II
Limitation of Liability As stated in the Agreement
Governing Law and Chosen Courts As stated in the Agreement: the laws of the Province of British Columbia and the federal laws of Canada applicable therein; courts located in Vancouver, British Columbia
Service Provider Relationship To the extent the California Consumer Privacy Act applies, Provider acts as Customer’s service provider and does not sell or share Customer Personal Data
Governing Member State (EEA transfers) Ireland
Governing State (UK transfers) England and Wales

Changes to the Standard Terms

  1. Subprocessor notice (Section 2.6.1). “at least 10 business days in advance and in writing” is replaced with “at least 24 hours in advance, by updating the Approved Subprocessors list and by emailing each Customer that has asked the Provider Security Contact to be notified of changes”.

Annex I(A): List of Parties

Data importer (Processor)

  • Name: Kenton Hirowatari, doing business as Hirowatari Consulting (“RouterJet”)
  • Address: 3-35307 Munroe Ave., Abbotsford, BC V3G 1L4, Canada
  • Contact: Kenton Hirowatari, Owner, hello@routerjet.com

Data exporter (Controller, or Processor acting for its own clients)

  • Customer, using the name, address and contact details on its RouterJet account.

Annex I(B): Description of Transfer and Processing

  • Service: RouterJet, which automatically routes, assigns and sends notifications about records in Customer’s CRM (Pipedrive or Close).
  • Categories of Data Subjects:
    • Customer’s employees and contractors who are users of its CRM.
    • Customer’s prospects, leads and contacts held in its CRM.
  • Categories of Personal Data:
    • CRM users: name, email address, phone or WhatsApp number, Slack user ID, Telegram chat ID and first name, time zone, working hours and availability, sign-in IP addresses and times, and assignment history.
    • Prospects, leads and contacts: name, CRM record identifiers, deal and lead titles, and links to CRM records. Other CRM field values are evaluated against Customer’s routing rules as they arrive and are not stored.
  • Special Category Data: None. Customer will not use special category data in routing rules or in deal or lead titles.
  • Frequency of Transfer: Continuous.
  • Nature and Purpose of Processing: Receiving, storing, evaluating against Customer’s rules, assigning record ownership in the CRM, sending notifications to CRM users, reporting, and deletion.
  • Duration of Processing: The term of the Agreement, and afterwards until Customer instructs Provider to delete Customer Personal Data.

Annex I(C): Competent Supervisory Authority

As set out in the Standard Terms.

Annex II: Technical and Organizational Security Measures

  • Encryption in transit: All traffic to RouterJet is served over TLS, and connections to subprocessors use HTTPS.
  • Encryption at rest: The production database and its backups are encrypted at rest by the hosting provider.
  • Authentication: Users sign in through their CRM’s OAuth flow. Passwords, where used, are stored only as salted bcrypt hashes.
  • Access control: Customer data is segregated by account. Access to production systems is limited to the owner of the business and protected by multi-factor authentication.
  • Logging: Passwords, tokens, keys and email parameters are filtered from application logs and error reports. Webhook gateway logs are retained for 14 days.
  • Data minimization: RouterJet stores only the names, identifiers, titles and links of CRM records needed for routing. Other CRM field values are not stored.
  • Retention: CRM records belonging to inactive accounts are deleted automatically after approximately six months of inactivity.
  • Erasure: Customer may request deletion of its data at any time by emailing the Provider Security Contact.
  • Resilience and recovery: The production database has continuous protection with point-in-time recovery.
  • Change management: Changes pass an automated test suite and a staging environment before release. New third-party software releases are held for a waiting period before being adopted.

Attribution

This DPA incorporates the Common Paper Data Processing Agreement Standard Terms, Version 1.1, free to use under CC BY 4.0. It has been modified as described under “Changes to the Standard Terms”.

background

Start your free trial

No credit card required.

Assign leads automatically and free up your time.

Copyright © 2026 RouterJet. All rights reserved.