The terms on which DealDoctor PLLC processes personal data for CARMAgree™ customers, and the sub-processors it uses.
This Data Processing Addendum (“DPA”) supplements the CARMAgree™ End User License Agreement (the “Agreement”) between DealDoctor PLLC (“DealDoctor” or “Processor”) and the customer that has accepted the Agreement (“Customer” or “Controller”). It applies to the extent Applicable Data Protection Law applies to Personal Data that Processor processes on Controller’s behalf in providing the Software. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
(a) “Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under this DPA, including the GDPR (EU) 2016/679, the UK GDPR, the CCPA, and any other applicable privacy or data protection legislation.
(b) “Personal Data” means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller in connection with the Software.
(c) “Processing” means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
(d) “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under this DPA.
(e) “Sub-processor” means a third party engaged by Processor to process Personal Data on behalf of the Controller.
(f) “Certificate of Execution” means the record of signer identity, consents, signing actions, timestamps and the document hash that the Software appends to each executed PDF.
(a) Controller and Processor. You are the Controller of Customer Data. DealDoctor is the Processor. We process Personal Data only as necessary to provide the Software and related services under the Agreement.
(b) Processing Instructions. Processor will process Personal Data only on documented instructions from the Controller, unless required by Applicable Data Protection Law. The Agreement, this DPA, and your use of the Software constitute your documented instructions.
(c) Purpose Limitation. Processor will process Personal Data solely for the purpose of providing, maintaining, and supporting the Software as described in the Agreement. Processor will not intentionally process Personal Data for any other purpose without Controller’s prior written consent.
(d) Signers and Counterparties. Where Controller sends a document for signature, Controller determines who receives it and what it contains. The Personal Data of Controller’s signers and of the parties named in the document is Customer Data, and Processor processes it on Controller’s instructions under this DPA.
(e) Service Data and Derived Data. Service Data and Derived Data, as defined in the Agreement, are designed not to include Personal Data. Data from which no individual can be identified does not constitute Personal Data under this DPA.
(a) Security Measures. Processor will implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage, including: (i) encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2+); (ii) storage of Controller’s CARMAgree™ data in a database provisioned for Controller alone, separate from the database of every other Customer; (iii) role-based access controls; (iv) audit logging of administrative access; (v) restriction of employee access to Personal Data on a need-to-know basis; (vi) use of HttpOnly, Secure session cookies with automatic expiration for authentication in the Web Application, and storage of sign-in tokens in an encrypted store on the device (the iOS Keychain, and on Android an encrypted preferences file whose key is held in the Android Keystore) in the Mobile Applications; (vii) a SHA-256 hash of each executed document, printed on its Certificate of Execution, together with a cryptographic integrity seal and trusted timestamp applied to the executed PDF, so that any alteration after execution is detectable; and (viii) daily automatic infrastructure snapshots, retained on a rolling basis, for disaster recovery.
(b) Confidentiality. Processor will use commercially reasonable efforts to ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
(c) Security Reviews. Processor will use commercially reasonable efforts to regularly review and update its security measures to address evolving threats.
(a) Authorized Sub-processors. Controller authorizes Processor to engage the following Sub-processors: (i) Amazon Web Services, Inc. (United States, US East (N. Virginia) region), cloud infrastructure for the hosting and storage of Customer Data; (ii) AC PM LLC, the operator of Postmark (United States), delivery of transactional email: account email (email-verification, password-reset and account-deletion links, carrying the account holder’s address) and envelope email (signing invitations, reminders, partial-signature notices and execution notices, carrying the recipient’s name and email address, the sender’s name, the document name and the signing link and, on the execution notice, the executed PDF as an attachment); (iii) Stripe, Inc. (United States), processing of payments made through the Web Application, where payment card information is entered on Stripe’s own page and is not stored by Processor; and (iv) DigiCert, Inc. (United States), RFC 3161 timestamping of the platform seal, which receives a cryptographic hash of the executed PDF and nothing else.
(b) Mobile Application Purchases. Purchases made inside a Mobile Application are processed by Apple or Google under that App Store’s own terms. Processor receives the purchase record needed to credit the purchase to Controller’s account and does not receive payment card information.
(c) New Sub-processors. Processor will notify Controller of any new Sub-processors at least thirty (30) days before engagement by posting updates at https://carmagree.com/dpa. If Controller objects, the parties will discuss in good faith. If no resolution is reached, Controller may terminate the affected services.
(d) Sub-processor Obligations. Processor will impose data protection obligations on Sub-processors that are no less protective than those in this DPA.
(e) Public-Record Sources. When Controller runs the CARMAscan™ integrity screen on a document, the names of the parties to that document may be submitted to public-record sources operated by third parties: United States government sanctions and federal-exclusions lists, a public archive of United States federal court records, and a United States government securities-filings registry. Only the party name is transmitted; the document is not. Where a party is identified as an individual, the court-records and securities-registry lookups are not run. These sources answer a query on their own terms and do not process Personal Data on Processor’s instructions; they are not Sub-processors, and their handling of a query is governed by their own terms.
(f) No Artificial-Intelligence Providers. The Software does not transmit Customer Data to any artificial-intelligence service provider, and Processor engages no such provider as a Sub-processor for the Software.
(a) Assistance. Processor will use commercially reasonable efforts to assist Controller in responding to data subject requests to exercise their rights under Applicable Data Protection Law (access, rectification, erasure, portability, restriction, objection).
(b) Data Export. The Software provides built-in export allowing Controller to download each executed document together with its Certificate of Execution, and each CARMAscan™ report, in PDF format, to support data portability rights.
(c) Account Deletion Controls. The Software provides Controller with built-in account deletion: an account holder may request deletion from Settings in the Web Application or in a Mobile Application, and the request is completed through a one-time confirmation link sent to the account’s email address. The effect of deletion is described at https://carmagree.com/support.
(d) Account Data Deletion. Upon Controller’s verified written request, Processor will delete Controller’s Personal Data within thirty (30) days, subject to legal retention requirements, to the retention of executed documents and their evidence records described in Section 6(e) and at https://carmagree.com/support, and to the persistence of deleted data in infrastructure snapshots described in Section 6(e)(ii). Upon termination, Controller has sixty (60) days to export data before deletion, as described in Section 6(e) of this DPA.
(e) Derived Data. Derived Data, as defined in the Agreement, is anonymized and aggregated, contains no identifier linking it to any individual, document or Customer, and is therefore not subject to deletion requests.
(a) Categories of Data Subjects. Controller’s Authorized Users; signatories; counterparties and other individuals named in documents sent for signature through the Software; and other individuals referenced in Customer Data.
(b) Types of Personal Data. Account Data as defined in the Agreement; signer names, email addresses, titles and organizations; the typed signature applied; IP addresses and browser user-agent strings captured for the ESIGN/UETA audit trail; the IP address recorded when an Authorized User accepts the Agreement or requests or confirms account deletion; sending, viewing, consent and signing timestamps; the party names read from a document for the CARMAscan™ integrity screen; and any personal information contained in documents uploaded for signature, such as names, contact information, titles and roles.
(c) Processing Operations. Storage of uploaded documents; the CARMAscan™ integrity screen (a rule-based examination of the document and, where enabled on the Software’s servers, the public-record lookups described in Section 4(e)); delivery of signing invitations, reminders and notices by email; capture of signatures, consents and the audit trail; generation of the executed PDF and its Certificate of Execution; sealing and timestamping of the executed PDF; storage of executed documents, Certificates of Execution, CARMAscan™ reports and the audit trail in Controller’s database; account administration; and related support functions as described in the Agreement.
(d) Duration. Personal Data is processed for the duration of the Agreement, plus the post-termination export period described in the Agreement.
(e) CARMAgree™ Storage and Retention.
(i) Storage. CARMAgree™ signed documents and related data are stored in a database provisioned for Controller alone, separate from the database of every other Customer, consistent with Section 3(a)(ii) of this DPA.
(ii) Retention. CARMAgree™ data is retained for the duration of Controller’s active account. Upon closure, cancellation or termination, Controller has sixty (60) days to export CARMAgree™ data through the Software. After that period, CARMAgree™ data is permanently deleted; deleted data may remain in Processor’s infrastructure snapshots until those snapshots are deleted in the ordinary course, currently seven (7) days for the daily snapshots. Where Controller holds no active Subscription, the availability period in Section 6.a(iii)(C) of the Agreement applies.
(iii) Copies Held by Signatories. A copy of each executed document and its Certificate of Execution is delivered by email to every signatory at execution. Those copies are held by the signatories and are outside Processor’s control once delivered.
(iv) ESIGN and UETA Compliance. Electronic signatures captured via CARMAgree™ are intended to comply with the U.S. Electronic Signatures in Global and National Commerce Act, 15 U.S.C. § 7001 et seq., and the Uniform Electronic Transactions Act as adopted by each applicable State. Processor preserves an audit record of signer identity, signing actions, and timestamps for each signed document.
(a) Notification. Processor will notify Controller without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Data Breach affecting Controller’s Personal Data.
(b) Content. The notification will include, to the extent known: the nature of the breach, categories and approximate number of affected data subjects, likely consequences, and measures taken or proposed to address the breach.
(c) Cooperation. Processor will use commercially reasonable efforts to assist Controller in fulfilling its own breach notification obligations under Applicable Data Protection Law.
(a) Transfer Mechanisms. To the extent that processing involves the transfer of Personal Data from the EEA, UK, or Switzerland to the United States, Processor will use commercially reasonable efforts to ensure that appropriate transfer mechanisms are in place, including Standard Contractual Clauses as approved by the European Commission.
(b) Data Residency. Customer Data is hosted in the United States, in the US East (N. Virginia) region of Amazon Web Services. Controller is responsible for ensuring the hosting region meets its regulatory requirements.
(a) Information. Upon Controller’s reasonable written request (no more than once per twelve-month period), Processor will provide information reasonably necessary to demonstrate compliance with this DPA.
(b) Audit. Controller may, at its own expense and upon at least thirty (30) days’ written notice, engage a qualified independent auditor to audit Processor’s compliance with this DPA. The audit will be conducted during normal business hours and will not unreasonably interfere with Processor’s operations. The auditor must execute a confidentiality agreement acceptable to Processor.
(a) Precedence. In the event of any conflict between this DPA and the Agreement, this DPA will prevail with respect to the processing of Personal Data.
(b) Term. This DPA will remain in effect for the duration of the Agreement and for so long as Processor retains any Personal Data on behalf of Controller.
(c) Governing Law. This DPA is governed by the same governing law as the Agreement.
(d) Amendments. This DPA may be updated to reflect changes in Applicable Data Protection Law. Material changes will be notified through the Software or by email.
(e) Contact. Data-protection questions, Sub-processor objections and data-subject requests: privacy@dealdoctor.pro.