
Data processing terms
Data Processing Addendum
This DPA describes the processing safeguards used for Greysun’s business-development program. It becomes binding only when incorporated into or executed with a services agreement.
1. Scope and priority
This Data Processing Addendum (“DPA”) applies when Rocket Grow sp. z o.o. (“Processor”) processes Personal Data on behalf of Nigel’s Agency LLC (“Controller”) in connection with website implementation, hosting configuration, analytics configuration, lead routing, CRM integrations, scheduling integrations, communication workflows, technical support, and related marketing operations (the “Services”). This DPA supplements the Parties’ services agreement. If they conflict on data-protection matters, this DPA controls unless the Parties expressly agree otherwise in writing.
2. Definitions
“Data Protection Laws” means privacy and data-protection laws applicable to the Processing, including, where applicable, the GDPR, UK GDPR, US state privacy laws, and their implementing regulations. “Personal Data,” “Process,” “Controller,” “Processor,” and “Data Subject” have the meanings given by applicable Data Protection Laws. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed under this DPA. “Subprocessor” means a third party engaged by Processor to Process Personal Data for the Services.
3. Roles and documented instructions
- Controller determines the purposes and means of Processing and is responsible for its notices, legal bases, consents, instructions, and compliance obligations.
- Processor will Process Personal Data only on Controller’s documented instructions, including the services agreement, this DPA, configuration requests, and support instructions, unless law requires otherwise.
- If Processor believes an instruction violates Data Protection Laws, it will inform Controller unless prohibited by law and may suspend the affected Processing while the Parties resolve the issue.
- Each Party will comply with Data Protection Laws applicable to its role and will not knowingly require the other Party to violate them.
- Controller will not provide claimant medical records, health information, privileged legal files, government identifiers, payment-card data, or other special-category or highly sensitive information unless the Parties first execute written terms specifically authorizing and safeguarding that Processing.
4. Confidentiality and personnel
Processor will ensure that personnel authorized to Process Personal Data are bound by confidentiality obligations, receive appropriate privacy and security guidance, and access Personal Data only as needed to perform the Services. Processor remains responsible for its personnel’s compliance with this DPA.
5. Security
Taking into account the nature, scope, context, and purpose of Processing and the risk to individuals, Processor will maintain reasonable technical and organizational measures designed to protect Personal Data. The current measures are summarized in Annex B. Controller acknowledges that security measures may evolve, provided the overall level of protection is not materially reduced during the applicable term.
6. Subprocessors
- Controller gives Processor general authorization to engage the Subprocessors listed in Annex C for the purposes stated there, but only when the related feature is enabled.
- Processor will impose data-protection obligations appropriate to the relevant Processing on each Subprocessor and remains responsible for the Subprocessor’s performance to the extent required by applicable law and the services agreement.
- Processor will provide reasonable notice of a material new Subprocessor where the Parties have an active services agreement. Controller may object on reasonable data-protection grounds within 10 business days. The Parties will work in good faith on a commercially reasonable alternative; if none is available, either Party may terminate only the affected feature or Processing.
7. Data-subject requests
Taking into account the nature of the Processing, Processor will provide reasonable assistance so Controller can respond to verified requests to access, correct, delete, restrict, object to, or port Personal Data. If Processor receives a request directly concerning Controller data, it will direct the requester to Controller unless law requires another response. Controller is responsible for determining and communicating the substantive response.
8. Compliance assistance
Processor will provide reasonable information and assistance for Controller’s data-protection impact assessments, regulator consultations, records of processing, and other compliance duties relating to the Services, taking into account the information available to Processor and the nature of the Processing. Material assistance beyond the ordinary Services may be subject to mutually agreed fees unless caused by Processor’s breach.
9. Security incidents
Processor will notify Controller without undue delay after confirming a Security Incident affecting Personal Data under this DPA. As information becomes reasonably available, notice will describe the nature of the incident, likely consequences, affected data and individuals where known, and measures taken or proposed. Processor will take reasonable steps to contain, investigate, and remediate the incident and will cooperate with Controller’s legally required notifications. Notice is not an admission of fault or liability.
10. International transfers
If Personal Data protected by the GDPR, UK GDPR, or similar transfer restrictions is transferred to a country without an applicable adequacy decision, the Parties will use a legally recognized transfer mechanism. Where appropriate, this may include the European Commission’s Standard Contractual Clauses, the UK Addendum, the EU–US Data Privacy Framework for participating recipients, or another valid safeguard. The Parties will provide information reasonably needed for a transfer assessment.
11. Return and deletion
At the end of the Services, Processor will, at Controller’s choice, delete or return Personal Data within its control, except to the extent law requires retention or data remains in secure backups that are isolated from ordinary use and deleted on the normal backup cycle. Processor may retain limited records needed to establish compliance, enforce agreements, or maintain suppression and consent history, subject to continued protection.
12. Information and audits
Processor will make information reasonably necessary to demonstrate compliance with this DPA available to Controller. No more than once annually, unless required by a regulator or following a material Security Incident, Controller may request a reasonable remote audit. Any onsite audit must be necessary, narrowly scoped, scheduled with at least 30 days’ notice, avoid disruption, protect other customers’ information, and be performed by an independent auditor bound by confidentiality. Controller bears its audit costs unless the audit identifies a material Processor breach.
13. Liability, term, and governing terms
This DPA remains effective while Processor Processes Personal Data for the Services. Liability under this DPA is subject to the limitations and exclusions in the applicable signed services agreement, except where law prohibits that limitation. The governing-law and dispute provisions of that agreement apply. If there is no signed services agreement incorporating this DPA, this published page is informational and does not by itself create a processing engagement.
Annex A — Processing details
| Subject matter | Business-development website, qualification forecast, marketing operations, integrations, lead routing, and scheduling support. |
|---|---|
| Duration | The services term plus the period needed for return, deletion, backup expiry, and legally required records. |
| Nature and purpose | Collection, transmission, organization, hosting, configuration, retrieval, analysis, CRM synchronization, scheduling, communication, support, security, and deletion to evaluate and manage potential or active business relationships. |
| Data subjects | Attorneys, law-firm staff, prospective customers, customer representatives, website visitors, and business contacts. |
| Personal Data | Professional identity and contact details; firm and role information; qualification answers; scheduling details; consent and communication records; attribution, device, usage, and security data. |
| Sensitive data | Not intended or authorized. Claimant health information, case files, government identifiers, payment-card data, and privileged content must not be submitted through this site. |
| Frequency | Continuous or event-based during use of the website, integrations, support, and Services. |
| Controller contact | nigel@greysunpartners.com |
| Processor contact | dziemian@rocketgrow.pl |
Annex B — Technical and organizational measures
- Role-based access and least-privilege practices for production services and accounts.
- Strong authentication and multi-factor authentication where supported and appropriate.
- Encryption in transit using modern HTTPS/TLS and provider-managed encryption at rest where available.
- Environment separation, secret-management practices, and controlled production changes.
- Logging, monitoring, abuse prevention, rate limiting, and bot protection where configured.
- Data minimization, purpose limitation, and forms designed to exclude claimant and medical information.
- Vendor assessment and contractual protections appropriate to each enabled provider.
- Backup, resilience, restoration, vulnerability remediation, and incident-response processes appropriate to the Services.
- Confidentiality commitments, access review, and privacy/security guidance for authorized personnel.
- Deletion, return, and retention controls aligned to Controller instructions and provider capabilities.
Annex C — Current and contingent Subprocessors
The following providers may Process Personal Data only when the related feature is configured or used:
| Subprocessor | Purpose | Terms |
|---|---|---|
| Vercel Inc. | Website hosting, content delivery, application infrastructure, logs, abuse prevention, and invisible BotID verification. | Provider privacy information |
| HighLevel / LeadConnector | CRM records, lead routing, workflow automation, communications, and opportunity management when enabled. | Provider privacy information |
| Cal.com, Inc. | Strategy-call scheduling, booking details, calendar availability, and appointment notifications. | Provider privacy information |
| Google LLC / Google Ireland Limited | Analytics and advertising measurement when the visitor permits analytics or marketing technologies. | Provider privacy information |
| Meta Platforms, Inc. / Meta Platforms Ireland Limited | Advertising attribution, campaign measurement, and audience tools when the visitor permits marketing technologies. | Provider privacy information |
| Plus Five Five, Inc. (Resend) | Transactional email and internal lead notifications when enabled. | Provider privacy information |
Execution
To execute this DPA for a services engagement, contact nigel@greysunpartners.com. Electronic signatures and counterparts are permitted when the Parties execute or incorporate this DPA into their agreement.