Carom
Unified inbox & calendarEvery mailbox and calendar, one curated view AI agents & insightsBriefings, summaries, and tasks that file themselves Auto-assembled recordsAll the data, none of the entry Working togetherShared is everywhere, yours is yours
The Anti-CRMWhy customer context should not depend on data entry SecurityHow Carom handles your email
Business developmentWin relationship-driven work Account managementServe every client as one team Projects & engagementsKeep the work and its history together
Solutions overviewSee how Carom supports each stage of client work
Field notes Pricing Start your free month

Data Processing Addendum

How we process personal data on our customers’ behalf, and what we commit to as a processor

This Data Processing Addendum ("DPA") forms part of the Customer Terms of Service between Bankshot Software, LLC, doing business as Carom ("Carom"), and the customer identified in the applicable account or order form ("Customer"). It applies automatically to every Customer—there is nothing to sign or request.

It is written for the person reviewing Carom on a customer’s behalf, so it is more formal than our other policies. The Privacy Policy covers the same ground in plainer language.

Last updated: July 26, 2026

1. Definitions

“Applicable Data Protection Law” means the privacy and data protection laws of the United States applicable to the processing under this DPA, including the California Consumer Privacy Act as amended by the CPRA (“CCPA”) and comparable state statutes, in each case to the extent they apply.

“Customer Content,” “Account Data,” “Service Data,” and “Feedback Data” have the meanings given in the Privacy Policy.

“Customer Personal Data” means personal data within Customer Content that Carom processes on Customer’s behalf.

“Personal data,” “processing,” “controller,” “processor,” and “data subject” carry their ordinary meanings under Applicable Data Protection Law. To the extent the CCPA applies to a given Customer, “personal data” includes “personal information,” that Customer is a “business,” and Carom is a “service provider.” Not every Customer meets the CCPA’s thresholds, and this DPA applies regardless.

“Subprocessor” means a third party engaged by Carom to process Customer Personal Data.

2. Roles

2.1 For Customer Content, Customer is the controller and Carom is the processor. Carom processes it only on Customer’s documented instructions. The Customer Terms, this DPA, and Customer’s configuration and use of the Services together constitute those instructions.

2.2 For Account Data and Service Data, Carom is an independent controller. This covers billing records, support correspondence, authentication records, security and audit logs, and operational telemetry. Carom determines the purposes of that processing, which are described in the Privacy Policy, and remains subject to the confidentiality and security obligations in the Customer Terms.

2.3 Feedback Data is processed on the basis of the submitting individual’s specific, item-by-item consent, for the purpose for which it was submitted.

2.4 Carom will notify Customer if it believes an instruction violates Applicable Data Protection Law, and may pause that instruction until the question is resolved.

2.5 Carom does not sell or share Customer Personal Data. Carom does not retain, use, or disclose it for any purpose other than performing the Services and the limited purposes in Section 3, does not use it outside its direct business relationship with Customer, and does not combine it with personal information from other sources except as a service provider may under the CCPA. Carom certifies that it understands and will comply with these restrictions.

2.6 Customer is responsible for the lawfulness of the personal data it and its Users bring into the Services, including data about third parties who appear in mailboxes, calendars, and contacts, and for any notices or consents required.

2.7 Carom will provide the same level of privacy protection required of Customer by Applicable Data Protection Law with respect to Customer Personal Data.

2.8 Carom will notify Customer promptly if it determines it can no longer meet its obligations under this DPA or Applicable Data Protection Law. On such notice, or where Customer reasonably believes Carom is processing Customer Personal Data in an unauthorized manner, Customer may direct Carom to stop and to remediate the unauthorized processing, and Carom will do so.

2.9 Customer may take reasonable and appropriate steps to confirm Carom’s processing is consistent with Customer’s obligations, using the mechanisms in Section 9.

3. Permitted processing

3.1 Carom processes Customer Personal Data to provide, maintain, secure, and support the Services; to prevent and address security, technical, and support issues; to comply with law; and to carry out Customer’s other documented instructions.

3.2 Carom does not use Customer Personal Data to train, fine-tune, or otherwise develop machine learning or artificial intelligence models, its own or a third party’s, and engages AI infrastructure vendors only under terms that prohibit the use of inputs and outputs for model training. Carom’s AI features currently run on AWS Bedrock.

3.3 Carom does not use Customer Personal Data for its own research, product development, analytics, marketing, or profiling.

3.4 Carom may generate and retain aggregated or de-identified data derived from Account Data and Service Data for its own operational purposes, provided it cannot reasonably be used to identify Customer or any data subject. Carom will not attempt to re-identify it. Carom may also record volumetric and performance measures about the operation of the Services — counts, sizes, and timings — which are not derived from the contents of any communication. Carom does not derive analytics, models, or other work product from Customer Content for its own purposes, aggregated or otherwise.

4. Confidentiality and personnel access

4.1 Carom limits access to Customer Personal Data to personnel who need it, and binds them to written confidentiality obligations that survive their engagement.

4.2 Carom personnel do not read the contents of Customer’s messages, attachments, calendars, or contacts in the ordinary course. Human access to Customer Content occurs only: (a) with the specific prior consent of Customer or the relevant User, in response to a support request; (b) where an individual submits Feedback Data; (c) where reasonably necessary to investigate a security incident or abuse; or (d) where legally required. Access under (a)–(d) is limited in scope, time-boxed, and recorded in an audit log available to Customer on request.

4.3 Automated processing — including by AI models operating within Carom’s and its Subprocessors’ infrastructure — is not subject to Section 4.2 and occurs as necessary to deliver the Services.

5. Security

5.1 Carom implements and maintains the technical and organizational measures in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.

5.2 Carom may update those measures provided the overall level of protection is not materially reduced.

6. Security incidents

6.1 A security incident means unauthorized access to, or the acquisition, loss, disclosure, destruction, or alteration of, Customer Personal Data. Routine unsuccessful events — blocked attacks, failed logins, scans, pings — are not security incidents.

6.2 Carom will notify Customer without undue delay after becoming aware of a security incident affecting Customer Personal Data, and in any event within 72 hours of discovery, or sooner where Applicable Data Protection Law requires.

6.3 The notification will describe, so far as known, the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. Carom will provide updates as it learns more rather than delaying notice for completeness.

6.4 Carom will reasonably assist Customer with Customer’s own notification obligations. Notification is not an acknowledgment of fault or liability.

7. Subprocessors

7.1 Customer generally authorizes Carom to engage Subprocessors. The current list, with the data each receives and where it is stored, is published in the Privacy Policy.

7.2 Carom imposes on each Subprocessor data protection obligations no less protective than those in this DPA, and remains liable for its Subprocessors’ performance.

7.3 Carom will update the published list and notify each affected Customer by email before a new Subprocessor begins processing Customer Personal Data, except where a Subprocessor must be replaced urgently for security or service continuity, in which case Carom will notify promptly afterward.

7.4 Customer may object to a new Subprocessor on reasonable data protection grounds within 30 days. The parties will discuss in good faith; if the objection cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.

8. Data subject requests

8.1 Taking into account the nature of the processing, Carom will assist Customer, so far as possible, in responding to requests from data subjects exercising their rights.

8.2 If Carom receives a request directly from a data subject relating to Customer Personal Data, it will not respond substantively beyond acknowledging receipt and directing the requester to Customer, and will notify Customer promptly unless legally prohibited.

9. Assistance and audits

9.1 Carom will provide Customer with information reasonably necessary to demonstrate compliance with this DPA, and will assist with data protection impact assessments and regulator consultations, taking into account the nature of the processing and the information available to Carom.

9.2 Customer may audit compliance no more than once per year, on 30 days’ written notice, at Customer’s expense, during business hours, subject to confidentiality, and without unreasonably disrupting Carom’s operations. Carom may satisfy an audit request by providing a current third-party audit report or a completed security questionnaire.

10. Deletion

10.1 Customer may delete Customer Personal Data through the Services at any time during the term.

10.1a At termination, Customer may request return of Customer Personal Data rather than deletion, so far as technically feasible and subject to Section 10.3. Requests must reach legal@carom.io before the account closes; absent a request, Carom deletes as described below.

10.2 On termination, Carom deletes Customer Personal Data as described in the Privacy Policy: Customer Content imported from connected mailboxes and content created in the account is deleted seven days after the account closes. Encrypted backups expire within 45 days, and Carom maintains a deletion record outside its database so that any restore re-applies deletions.

10.3 Carom may retain Customer Personal Data where required by law or subject to a legal hold, and will continue to protect it under this DPA for as long as it is retained.

11. General

11.1 This DPA supplements and forms part of the Customer Terms. Where they conflict on the processing of personal data, this DPA controls. An order form does not override this DPA unless it says so explicitly.

11.2 Each party’s liability under this DPA is subject to the limitations and exclusions in the Customer Terms.

11.3 This DPA is governed by the law specified in the Customer Terms, except where Applicable Data Protection Law requires otherwise.

11.4 Customers with obligations outside the United States. Carom offers the Services in the United States only and has not implemented the Standard Contractual Clauses, an Article 27 representative, or the other machinery required for European personal data. If your organization has obligations under the GDPR, UK GDPR, or a comparable regime, contact legal@carom.io before bringing that data into Carom.


Annex I — Details of processing

Controller: Customer. Processor: Bankshot Software, LLC d/b/a Carom, c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713.

Subject matter: Provision of the Carom relationship intelligence platform.

Duration: The term of the Customer Terms, plus the deletion periods in Section 10.

Nature and purpose: Collection, storage, organization, structuring, retrieval, analysis — including automated summarization, classification, and extraction — display, transmission, and erasure of email, calendar, contact, and file data, in order to provide the Services.

Categories of data subjects: Customer’s authorized Users; and individuals who correspond with, meet with, or are referenced by those Users, including their contacts, clients, candidates, counterparties, and colleagues.

Types of personal data: Names; email addresses; telephone numbers and other contact details; employer and job title; message content, subjects, snippets, headers, and metadata; attachment content, file names, and metadata; calendar event details, times, locations, and attendee lists; user-generated content such as comments, tasks, notes, and tags; and summaries, tags, and other inferences generated by the Services.

Not covered by this Annex: Account Data and Service Data — billing contacts, authentication records, IP addresses, device and browser information, and usage and error telemetry — for which Carom is an independent controller under Section 2.2 rather than a processor.

Special categories: Not intentionally collected. Because the Services process general-purpose mailboxes, sensitive information may incidentally be present. Customer determines what it brings into the Services. The Customer Terms prohibit using the Services to handle protected health information on behalf of a covered entity or business associate.

Frequency: Continuous, for the duration of the Customer Terms.

Annex II — Technical and organizational measures

Encryption. TLS for data in transit. Encryption at rest for stored content. Mailbox credentials and OAuth tokens encrypted with AES-256-GCM under separately managed, rotatable keys.

Access control. Row-level tenant isolation enforced at the database. Least-privilege IAM. Multi-factor authentication for production access. No standing personnel access to Customer Content, per Section 4.2. Audit logging of privileged access.

Authentication. OAuth-based provider authorization; Carom never receives mailbox passwords. Tokens revocable by the User at the provider at any time.

Network and infrastructure. Production hosted with Ubicloud and Amazon Web Services in the United States. Administrative access restricted to a private network. Backup write credentials scoped to write-only, unable to read, list, delete, or decrypt.

Resilience and recovery. Managed database backups with point-in-time recovery, 7-day retention. Independent off-provider nightly encrypted dumps, expiring within 45 days. Deletion ledger maintained outside the database so restores re-apply deletions.

Application security. Dependency pinning and monitoring for components parsing untrusted input. Sanitization of imported HTML. Content isolation controls for untrusted content supplied to language models. Filtering of credentials and sensitive values from application logs.

Vulnerability management. Published security contact (security@carom.io) with a good-faith researcher safe harbor. Error and performance monitoring via Sentry and AppSignal.

Subprocessor management. Published subprocessor list with notice of additions and contractual flow-down of protections.

Annex III — Vendors and Subprocessors

Only vendors that process Customer Personal Data are Subprocessors as defined in Section 1. The rest receive Account Data or Service Data, for which Carom is an independent controller under Section 2.2, and Section 7 does not apply to them.

Vendor Role Purpose Data Location
Amazon Web Services Subprocessor Object storage, backups, and AWS Bedrock model inference Customer Content United States
Ubicloud Subprocessor Application and database hosting Customer Content, Account Data, Service Data United States
Apple Subprocessor Push notification delivery Device tokens; notification content, which can include Customer Content United States
Stripe Vendor Payment processing Account Data United States
Postmark Vendor Transactional email Account Data United States
Sentry Vendor Error tracking Service Data United States
PostHog Vendor Product analytics Service Data United States
AppSignal Vendor Performance monitoring Service Data Netherlands
Better Stack Vendor Log management Service Data European Union
Google Ads Vendor Ad conversion measurement Ad click identifiers and signup conversion events United States

AppSignal and Better Stack are European and hold the Service Data they receive in the EU. Customer Content is not sent to either, and no Subprocessor holds Customer Content outside the United States.

Product

  • Product overview
  • The Anti-CRM
  • Security
  • Pricing

Solutions

  • Solutions overview
  • Business development
  • Account management
  • Projects & engagements

Explore

  • Live demo
  • Field notes
  • Start your free month

Legal & support

  • Privacy Policy
  • Terms of Service
  • User Terms
  • Data Processing Addendum
  • support@carom.io

© 2026 Bankshot Software, LLC. All rights reserved.

Carom