Data Processing Addendum
This DPA forms part of the Terms of Service between the customer ("Controller") and DataVonix Private Limited ("Processor") and applies where the Processor processes personal data in the Controller's HighLevel sub-accounts.
1. Subject matter and duration
Processing necessary to provide the service, for as long as the Controller uses it.
2. Nature and purpose
Reading and, on the Controller's confirmed instructions, modifying records in HighLevel through its API; sending messages the Controller approves; recording an activity log.
3. Types of data and data subjects
Contact details, tags, appointments, opportunities and message metadata of the Controller's customers and leads; identifiers of the Controller's staff.
4. Processor obligations
The Processor will: process only on documented instructions; ensure staff confidentiality; implement the security measures in Annex 1; assist with data-subject requests and breach notifications; notify personal data breaches without undue delay; delete or return data at the end of the service; and make available information needed to demonstrate compliance.
5. Sub-processors
The Controller authorises the sub-processors listed in the Privacy Policy. The Processor will give [30] days' notice of changes, during which the Controller may object.
6. International transfers
Standard Contractual Clauses (EU 2021/914, Module 2 or 3 as applicable) and the UK Addendum are incorporated by reference where required.
Annex 1 — Security measures
TLS in transit; encryption at rest for GoHighLevel sessions; hashed passwords and access tokens; role-based access; per-tenant data isolation with automated tests; audit logging of all tool calls and operator actions; incident response procedure.
Annex 2 — Contacts
Processor privacy contact: hello@datavonix.com. Controller contact: as set in the account's billing details.