Plain-English summary. Client determines why and how end-user data gets collected and used. Company processes that data only to deliver the Services Client has purchased, following Client's instructions, and protects it accordingly. This Data Processing Addendum ("DPA") sets out how.
This DPA is entered into pursuant to, and incorporated by reference into, the Master Services Agreement ("Agreement") between SalesLead AI LLC ("Company") and the client entity that executes a Service Order referencing the Agreement ("Client"), and applies to the extent Company processes personal data on behalf of Client in connection with the Services.
"Personal Data" means any information relating to an identified or identifiable natural person that Company processes on Client's behalf in connection with the Services.
"Processing" means any operation performed on Personal Data, including collection, storage, use, transmission, and deletion.
"Controller" and "Processor" (or "Business" and "Service Provider", as applicable under CCPA) have the meanings given under applicable data protection law.
"Sub-processor" means any third party engaged by Company to process Personal Data in connection with the Services.
"Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Company.
Terms not otherwise defined in this DPA have the meanings given to them in the Agreement. "Client Data" as used in the Agreement includes the Personal Data processed under this DPA.
As between the Parties, Client is the Controller (or Business) with respect to Personal Data processed through the Services, and is responsible for establishing the lawful basis, consent, and notice required to collect and share that data with Company. Company is the Processor (or Service Provider), and processes Personal Data solely on Client's behalf and instructions, as set out in the Agreement, the applicable Service Order, and this DPA.
Company will not sell Personal Data, and will not process Personal Data for any purpose outside the direct business relationship between the Parties, except as permitted under applicable law.
To the extent the California Consumer Privacy Act (CCPA) applies to the Personal Data processed under this DPA, Company certifies that it understands the restrictions in CCPA Section 1798.140 and will comply with them, including by not selling or sharing Personal Data, not retaining, using, or disclosing Personal Data for any purpose other than the specific business purpose of performing the Services, and not combining Personal Data received from Client with personal information received from other sources except as permitted under the CCPA.
Company processes Personal Data as necessary to provide the Services described in the Agreement and the applicable Service Order, including operating CART's messaging and automation infrastructure, storing communications and engagement records, and generating the reporting made available to Client.
Personal Data processed under this DPA originates from Client's own Shopify store. Client authorizes Company to access this data via API integration with Client's Shopify account for purposes of providing the Services. Client's use of Shopify as a platform, and any data Shopify itself holds or processes, is governed by Client's own agreement with Shopify and is outside the scope of this DPA; this DPA governs only Company's processing of the data Client authorizes Company to access and use in connection with the Services.
The categories of Personal Data processed typically include end-user names, phone numbers, mailing addresses (where provided as part of cart or checkout data), cart and transaction data, and message content and metadata generated through use of the Services. Client is responsible for determining what data it provides to or authorizes through the Services.
Client agrees not to knowingly submit or authorize the submission of sensitive or special-category personal data through the Services, including health information, government identification or Social Security numbers, financial account or routing numbers, biometric data, or precise geolocation data, absent Company's express written agreement to process that category of data. The Services are not designed or intended to process sensitive personal data of this kind.
Company will: process Personal Data only on Client's documented instructions, including those reflected in the Agreement and applicable Service Order, unless otherwise required by applicable law; ensure personnel authorized to process Personal Data are subject to confidentiality obligations; implement the technical and organizational security measures described in Section 5; and, taking into account the nature of processing, provide reasonable assistance to Client in responding to data subject requests and in Client's own compliance obligations under applicable data protection law, at Client's reasonable request.
Company implements administrative, technical, and organizational measures designed to protect Personal Data against unauthorized access, loss, misuse, or alteration, including access controls limiting Personal Data access to authorized personnel, encryption of data in transit, confidentiality obligations for personnel and Sub-processors, and monitoring of the infrastructure used to deliver the Services. The underlying infrastructure is built on a load-balanced, containerized architecture with autoscaling and failover contingencies designed to support availability and resilience at scale.
Company's underlying data infrastructure is provided by Supabase, which has obtained SOC 2 Type II certification, audited annually. Supabase's SOC 2 status applies to Supabase's own platform and does not transfer to or certify Company's systems; it does, however, provide assurance that the infrastructure underlying the Services is subject to independently audited controls over data access, security, and management. Company has not independently obtained SOC 2 Type II certification for its own systems as of the date of this DPA.
Client authorizes Company to engage the Sub-processors listed below to process Personal Data in connection with the Services. Company remains responsible for each Sub-processor's compliance with obligations materially equivalent to those set out in this DPA.
Company may update this list from time to time to add or replace Sub-processors. Where Company adds a new Sub-processor with material access to Personal Data, Company will provide notice to Client, and Client may object on reasonable data-protection grounds within fifteen (15) days of notice; the Parties will work in good faith to resolve the objection, which may include Client's right to terminate the affected Service Order if no resolution is reached.
| Sub-processor | Role | Location |
|---|---|---|
| Agentum Solutions LLC (affiliate of Company) | AI infrastructure development, operations, and technical delivery for the Services | United States |
| Supabase | Data infrastructure and database hosting (real-time data layer) | United States |
| HighLevel | Orchestration and pipeline tracking | United States |
| OpenAI | AI language model processing for conversational message generation | United States |
| Twilio | SMS message transmission and carrier connectivity | United States |
| Stripe | Payment processing | United States |
This list is current as of the date above. Company will maintain an up-to-date list and provide it to Client upon request. Locations listed reflect each Sub-processor's primary place of business as of drafting and have not been independently verified against each vendor's specific data-hosting region for Company's account.
In the event Company becomes aware of a Security Incident affecting Client's Personal Data, Company will notify Client without undue delay, and in any case within the timeframe required by applicable law. Notification will include, to the extent known at the time, the nature of the incident, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to address the incident.
Company retains Personal Data only for as long as necessary to provide the Services, fulfill contractual obligations, comply with legal and regulatory requirements, resolve disputes, and enforce applicable agreements.
Upon termination of the Agreement or the applicable Service Order, Company will handle Client Data in accordance with Section 12.5 of the Agreement.
Client is responsible for responding to requests from data subjects seeking to exercise rights under applicable data protection law. Where Company receives such a request directly, Company will promptly notify Client and will not respond directly except as required by law or as instructed by Client.
Company primarily processes Personal Data within the United States through the Sub-processors listed above. To the extent any processing involves a transfer of Personal Data outside the United States, Company will implement measures required under applicable data protection law to ensure the transfer is lawful.
No more than once per twelve-month period, and on reasonable prior written notice, Client may request that Company provide reasonably available documentation demonstrating Company's compliance with this DPA. Company may satisfy this request through existing certifications, audit reports of its Sub-processors, or a written summary of its security measures, in lieu of an on-site audit, except where required by applicable law.
Each Party's liability arising out of or related to this DPA, including in connection with all Security Incidents and data protection claims under this DPA, is subject to the limitations of liability set forth in Section 10 of the Agreement.
This DPA remains in effect for as long as Company processes Personal Data on Client's behalf under the Agreement. If a conflict arises between this DPA and the Agreement solely with respect to the processing of Personal Data, this DPA controls.
Questions about this DPA go to:
This page reflects the current standard terms of the DPA. The signed version executed with each Client governs that Client's relationship with Company.