Et al Solutions LLC Data Processing Addendum
1. Scope
This Data Processing Addendum ("DPA") supplements the agreement between Et al Solutions LLC, DBA SIMPLIFAI ("Et al") and the customer identified in that agreement ("Customer") when Et al processes Personal Data on Customer's behalf in connection with a service that references this DPA.
This DPA becomes binding only when it is executed by both parties or incorporated into an applicable written or electronic agreement. If there is a conflict concerning the processing of Personal Data, this DPA controls over the conflicting provision of the agreement.
2. Definitions
Applicable Data Protection Law means privacy or data-protection law applicable to the processing covered by this DPA.
Customer Data means information submitted to a covered service by or for Customer.
Personal Data means information relating to an identified or identifiable individual and included in Customer Data.
Process, Controller, Processor, Data Subject, and Supervisory Authority have the meanings provided by Applicable Data Protection Law.
Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Et al for Customer. It does not include unsuccessful attempts that do not compromise Personal Data.
Subprocessor means a third party engaged by Et al to process Personal Data on Customer's behalf.
3. Roles and Instructions
Customer is the Controller or Processor that determines and provides the lawful instructions for processing Customer Data. Et al acts as a Processor or Subprocessor, as applicable.
Et al will process Personal Data only to provide, secure, support, maintain, and improve the covered services; follow Customer's documented instructions; comply with the agreement and this DPA; or satisfy applicable law. The agreement, Customer's authorized use of the service, and written instructions accepted by Et al constitute documented instructions.
If Et al believes an instruction violates Applicable Data Protection Law, Et al may suspend the affected processing and notify Customer unless prohibited by law.
4. Customer Responsibilities
Customer is responsible for:
- providing legally sufficient notices and establishing a lawful basis for processing;
- ensuring its instructions and use of the services comply with Applicable Data Protection Law;
- limiting Personal Data submitted to what is appropriate for the service;
- responding to Data Subjects and Supervisory Authorities as Controller; and
- protecting credentials, devices, accounts, and integrations under its control.
The services are not intended for highly sensitive or regulated data unless the applicable agreement expressly authorizes that processing.
5. Confidentiality and Access
Et al will limit access to Personal Data to people and systems that need it to provide, secure, support, or maintain the service. People authorized to process Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality.
6. Security
Et al will maintain commercially reasonable administrative, technical, and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures are selected in light of the nature of the service, available technology, implementation cost, and processing risk.
Current categories of measures include, where applicable:
- encrypted transport for supported production connections;
- password hashing, random session identifiers, secure cookie settings, verification, passkeys, and rate limits;
- account authorization and product-level tenant or workspace isolation;
- managed secrets, environment separation, controlled deployment, and least-privilege service access;
- signed provider requests, human verification, abuse controls, security headers, logging, and health checks;
- queued processing, backup and recovery capabilities, vulnerability testing, dependency maintenance, and incident procedures.
No security measure can eliminate every risk. Customer remains responsible for configuring and using the service securely.
7. Subprocessors
Customer provides general authorization for Et al to use the Subprocessors listed in the current Subprocessor and Service Provider List.
Et al will require a Subprocessor that processes Personal Data on Customer's behalf to protect that information through applicable contractual or data-protection terms. Et al remains responsible for its obligations under this DPA to the extent required by applicable law and the agreement.
Et al may update the list as services and providers change. A Customer with a legally required objection to a new Subprocessor may contact privacy@etal.solutions promptly after learning of the change. The parties will work in good faith toward a reasonable resolution, which may include limiting the affected feature or terminating it where no reasonable alternative exists.
8. Data Subject Requests
If Et al receives a request from a Data Subject concerning Personal Data processed solely for Customer, Et al may direct the requester to Customer. Taking into account the nature of the processing and information available, Et al will provide reasonable assistance for Customer to respond where required by Applicable Data Protection Law.
Customer remains responsible for verifying the requester, deciding how to respond, and providing lawful instructions.
9. Security Incidents
Et al will investigate a suspected Security Incident and take reasonable steps to contain and remediate confirmed impact. If a Security Incident affects Personal Data processed for Customer, Et al will notify Customer without undue delay after confirmation when notice is required by Applicable Data Protection Law or the agreement.
Notice may describe the nature of the incident, affected information, known or likely consequences, and measures taken or proposed, as information becomes available. Notification is not an admission of fault or liability.
10. Assistance and Compliance Information
Taking into account the nature of processing and information available, Et al will provide reasonable assistance with legally required impact assessments, regulatory consultations, and compliance inquiries relating to Et al's processing.
Upon reasonable written request, Et al will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit must protect confidential information, avoid unreasonable disruption, and use existing reports or documentation first. Additional or unusually burdensome assistance may be subject to reasonable fees where permitted by the agreement and law.
11. Return and Deletion
During an active service relationship, Customer may use available product export and deletion functions. After termination or a valid deletion instruction, Et al will delete or return Personal Data as required by the agreement and Applicable Data Protection Law.
Limited information may remain in backups, security records, suppression records, transaction records, or systems where retention is required by law or reasonably necessary to establish, exercise, or defend legal claims. Retained information remains protected and is removed through the applicable retention or backup-rotation process.
12. International Processing
Et al and its Subprocessors may process Personal Data in the United States and other countries. Where Applicable Data Protection Law requires a transfer mechanism, the parties will use an applicable lawful mechanism, which may include standard contractual clauses or another recognized safeguard.
If legally required Standard Contractual Clauses apply, they are incorporated to the extent necessary, with Customer acting as data exporter and Et al acting as data importer in their applicable roles. The parties will complete required selections in the applicable agreement or written addendum.
13. Government Requests
Unless prohibited by law, Et al will notify Customer of a legally binding request for Personal Data processed for Customer. Et al may challenge a request that it reasonably believes is unlawful or overbroad and will disclose only information legally required.
14. Liability and Order of Precedence
The liability limitations and exclusions in the applicable agreement apply to this DPA to the maximum extent permitted by law. This DPA does not create liability beyond that agreement unless Applicable Data Protection Law requires otherwise.
15. Processing Details
| Subject matter | Providing, securing, supporting, maintaining, and improving the covered services as directed by Customer. |
|---|---|
| Duration | The service term and any limited retention period required by the agreement, law, security, backup rotation, suppression, transactions, or dispute resolution. |
| Nature and purpose | Hosting, organizing, transmitting, retrieving, securing, supporting, and deleting Customer Data; administering accounts and service operations. |
| Data Subjects | Customer's owners, authorized users, employees, contractors, customers, clients, contacts, message recipients, and other individuals whose information Customer submits. |
| Personal Data | Names, business and contact details, account and workspace identifiers, authentication and security records, service details, communications, review-request activity, delivery events, support content, subscription and transaction metadata, device and diagnostic information, and other information Customer chooses to submit. |
| Sensitive data | Not intentionally required for ordinary use. Customer must not submit sensitive or regulated information unless expressly authorized for the applicable service. |
| Frequency | Continuous or intermittent, according to Customer's use and instructions. |
16. Contact
Questions or requests concerning this DPA may be directed to privacy@etal.solutions. Do not send passwords, private keys, complete payment-card numbers, or unnecessary sensitive information by email.