Data Processing Addendum
Summary
When you put your leads’ and customers’ information into MaxLeadPRO, we process it only for you, only on your instructions, keep it confidential and secure, use vetted sub-processors, tell you about breaches, help you answer privacy requests, and delete it when you are done. This Addendum is part of the Terms of Service.
1. Scope and roles #
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Customer and ROY DIGITAL VENTURES LLC and applies to Contact Data and any other personal information that MaxLeadPRO processes on Customer’s behalf (“Customer Personal Data”). Customer is the business/controller and MaxLeadPRO is the service provider/processor. If this DPA conflicts with the Terms, this DPA controls for Customer Personal Data.
“Data Protection Laws” means U.S. federal and state laws that apply to the processing of Customer Personal Data, including the California Consumer Privacy Act as amended (CCPA) and the comprehensive consumer privacy laws of other states.
2. Processing on instructions #
- We process Customer Personal Data only to provide the Service, on Customer’s documented instructions (the Terms, this DPA, and Customer’s configuration and use of the Service), or as required by law (in which case we will tell Customer unless the law prohibits it).
- The nature and purpose of processing, the categories of data and individuals, and the duration are described in Annex 1.
- Customer is responsible for the lawfulness of its instructions, for providing notices and obtaining consents, and for the accuracy of Customer Personal Data.
3. Service-provider commitments (CCPA and state laws) #
With respect to Customer Personal Data, we will not:
- sell or share it (including for cross-context behavioral advertising);
- retain, use or disclose it for any purpose other than the business purposes specified in the Terms, including any commercial purpose other than providing the Service;
- retain, use or disclose it outside our direct business relationship with Customer; or
- combine it with personal information we receive from others or collect from our own interactions with individuals, except as permitted by Data Protection Laws (for example to detect security incidents or prevent fraud).
We will comply with applicable obligations under Data Protection Laws, provide the same level of privacy protection they require, and notify Customer if we determine we can no longer meet our obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use. We certify that we understand and will comply with these restrictions.
4. Confidentiality and personnel #
We ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate training, and have access only as needed. Support access to a Workspace requires a time-limited, audited grant.
5. Security #
We implement and maintain the technical and organizational measures in Annex 2, appropriate to the risk. We may update them as long as the overall level of protection is not reduced.
6. Sub-processors #
- Customer authorizes us to use the sub-processors listed at /legal/subprocessors.
- We impose data-protection obligations on each sub-processor that are at least as protective as this DPA, and remain responsible for their performance.
- We will give at least 30 days’ notice of a new sub-processor by updating the list and notifying Customer by email or in the Service. Customer may object on reasonable data-protection grounds within that period; if we cannot reasonably accommodate the objection, Customer may terminate the affected Service and receive a pro-rated refund of prepaid fees.
7. Assistance with requests and assessments #
- The Service lets Customer access, correct, export and delete Customer Personal Data and record opt-outs. If we receive a request from an individual about Customer Personal Data, we will direct the individual to Customer (and, for opt-out requests about messaging, may record the opt-out on the platform).
- We will provide reasonable assistance with Customer’s data-protection assessments and with responding to regulators, to the extent Customer cannot do so using the Service.
8. Security incidents #
We will notify Customer without undue delay, and in any event within 72 hours, after confirming a security incident that results in unauthorized access to or disclosure of Customer Personal Data. The notice will describe the incident, the data affected, the measures taken and a contact point, and we will update it as information becomes available. We will take reasonable steps to contain and remediate the incident. Customer is responsible for notifications to individuals and regulators that the law requires of a controller, and we will reasonably assist.
9. Return and deletion #
Customer can export Customer Personal Data at any time during the subscription. After a Workspace is closed, we delete Customer Personal Data within 30 days, except opt-out and suppression records kept in hashed form to prevent unwanted contact, data we must retain by law, and data in backups, which expire automatically (typically within 35 days) and remain protected under this DPA until then.
10. Information and audits #
On reasonable written request, no more than once a year (or after a confirmed security incident or at a regulator’s request), we will provide information necessary to demonstrate compliance with this DPA, such as completed security questionnaires and summaries of our security practices. Any audit must be at Customer’s expense, on reasonable notice, during business hours, subject to confidentiality, and without access to other customers’ data.
11. Data location #
Customer Personal Data is stored and processed in the United States. If Customer instructs us to process data about individuals outside the United States, Customer is responsible for any transfer mechanisms that local law requires.
12. Liability and term #
Each party’s liability under this DPA is subject to the limitations in the Terms. This DPA remains in effect as long as we process Customer Personal Data.
Annex 1 — Details of processing #
| Item | Description |
|---|---|
| Individuals | Customer’s leads, prospects, customers, callers, event attendees and other contacts; Customer’s authorized users |
| Categories of data | Names, phone numbers, email addresses, postal addresses, form responses, notes, tasks, communication content and metadata, call transcripts, call recordings (if enabled), consent and opt-out records, interaction history |
| Sensitive data | None intended. Customer must not submit sensitive data except as permitted by the Terms |
| Nature and purpose | Hosting, storage, organization, display, analysis, transmission of calls, messages and emails, consent and suppression management, follow-up automation, reporting and support |
| Duration | For the term of the Terms and until deletion under section 9 |
Annex 2 — Security measures #
- Encryption in transit (TLS 1.2+) and at rest for databases and file storage.
- Secrets and certificates held in a managed key vault; no secrets in source code.
- Passwords stored with a strong one-way hash; two-step verification required for owners and administrators.
- Role-based access control within each Workspace; strict tenant isolation enforced on every request.
- Least-privilege, time-limited and audited support access.
- Signature validation on telecommunications and billing webhooks.
- Audit logging of security-relevant events, consent changes and approvals.
- Rate limiting and abuse detection; antiforgery protection on web forms.
- Vulnerability management and dependency updates; segregated development, test and production environments.
- Backups with automatic expiry, and documented incident-response procedures.