Data processing terms

Data Processing Addendum

1. Scope and priority

This Data Processing Addendum (“DPA”) applies when Rocket Grow sp. z o.o. (“Processor”) processes Personal Data on behalf of Nigel’s Agency LLC (“Controller”) in connection with website implementation, hosting configuration, analytics configuration, lead routing, CRM integrations, scheduling integrations, communication workflows, technical support, and related marketing operations (the “Services”). This DPA supplements the Parties’ services agreement. If they conflict on data-protection matters, this DPA controls unless the Parties expressly agree otherwise in writing.

2. Definitions

“Data Protection Laws” means privacy and data-protection laws applicable to the Processing, including, where applicable, the GDPR, UK GDPR, US state privacy laws, and their implementing regulations. “Personal Data,” “Process,” “Controller,” “Processor,” and “Data Subject” have the meanings given by applicable Data Protection Laws. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed under this DPA. “Subprocessor” means a third party engaged by Processor to Process Personal Data for the Services.

3. Roles and documented instructions

  1. Controller determines the purposes and means of Processing and is responsible for its notices, legal bases, consents, instructions, and compliance obligations.
  2. Processor will Process Personal Data only on Controller’s documented instructions, including the services agreement, this DPA, configuration requests, and support instructions, unless law requires otherwise.
  3. If Processor believes an instruction violates Data Protection Laws, it will inform Controller unless prohibited by law and may suspend the affected Processing while the Parties resolve the issue.
  4. Each Party will comply with Data Protection Laws applicable to its role and will not knowingly require the other Party to violate them.
  5. Controller will not provide claimant medical records, health information, privileged legal files, government identifiers, payment-card data, or other special-category or highly sensitive information unless the Parties first execute written terms specifically authorizing and safeguarding that Processing.

4. Confidentiality and personnel

Processor will ensure that personnel authorized to Process Personal Data are bound by confidentiality obligations, receive appropriate privacy and security guidance, and access Personal Data only as needed to perform the Services. Processor remains responsible for its personnel’s compliance with this DPA.

5. Security

Taking into account the nature, scope, context, and purpose of Processing and the risk to individuals, Processor will maintain reasonable technical and organizational measures designed to protect Personal Data. The current measures are summarized in Annex B. Controller acknowledges that security measures may evolve, provided the overall level of protection is not materially reduced during the applicable term.

6. Subprocessors

  1. Controller gives Processor general authorization to engage the Subprocessors listed in Annex C for the purposes stated there, but only when the related feature is enabled.
  2. Processor will impose data-protection obligations appropriate to the relevant Processing on each Subprocessor and remains responsible for the Subprocessor’s performance to the extent required by applicable law and the services agreement.
  3. Processor will provide reasonable notice of a material new Subprocessor where the Parties have an active services agreement. Controller may object on reasonable data-protection grounds within 10 business days. The Parties will work in good faith on a commercially reasonable alternative; if none is available, either Party may terminate only the affected feature or Processing.

7. Data-subject requests

Taking into account the nature of the Processing, Processor will provide reasonable assistance so Controller can respond to verified requests to access, correct, delete, restrict, object to, or port Personal Data. If Processor receives a request directly concerning Controller data, it will direct the requester to Controller unless law requires another response. Controller is responsible for determining and communicating the substantive response.

8. Compliance assistance

Processor will provide reasonable information and assistance for Controller’s data-protection impact assessments, regulator consultations, records of processing, and other compliance duties relating to the Services, taking into account the information available to Processor and the nature of the Processing. Material assistance beyond the ordinary Services may be subject to mutually agreed fees unless caused by Processor’s breach.

9. Security incidents

Processor will notify Controller without undue delay after confirming a Security Incident affecting Personal Data under this DPA. As information becomes reasonably available, notice will describe the nature of the incident, likely consequences, affected data and individuals where known, and measures taken or proposed. Processor will take reasonable steps to contain, investigate, and remediate the incident and will cooperate with Controller’s legally required notifications. Notice is not an admission of fault or liability.

10. International transfers

If Personal Data protected by the GDPR, UK GDPR, or similar transfer restrictions is transferred to a country without an applicable adequacy decision, the Parties will use a legally recognized transfer mechanism. Where appropriate, this may include the European Commission’s Standard Contractual Clauses, the UK Addendum, the EU–US Data Privacy Framework for participating recipients, or another valid safeguard. The Parties will provide information reasonably needed for a transfer assessment.

11. Return and deletion

At the end of the Services, Processor will, at Controller’s choice, delete or return Personal Data within its control, except to the extent law requires retention or data remains in secure backups that are isolated from ordinary use and deleted on the normal backup cycle. Processor may retain limited records needed to establish compliance, enforce agreements, or maintain suppression and consent history, subject to continued protection.

12. Information and audits

Processor will make information reasonably necessary to demonstrate compliance with this DPA available to Controller. No more than once annually, unless required by a regulator or following a material Security Incident, Controller may request a reasonable remote audit. Any onsite audit must be necessary, narrowly scoped, scheduled with at least 30 days’ notice, avoid disruption, protect other customers’ information, and be performed by an independent auditor bound by confidentiality. Controller bears its audit costs unless the audit identifies a material Processor breach.

13. Liability, term, and governing terms

This DPA remains effective while Processor Processes Personal Data for the Services. Liability under this DPA is subject to the limitations and exclusions in the applicable signed services agreement, except where law prohibits that limitation. The governing-law and dispute provisions of that agreement apply. If there is no signed services agreement incorporating this DPA, this published page is informational and does not by itself create a processing engagement.

Annex A — Processing details

Annex B — Technical and organizational measures

Annex C — Current and contingent Subprocessors

The following providers may Process Personal Data only when the related feature is configured or used:

Execution

To execute this DPA for a services engagement, contact nigel@greysunpartners.com. Electronic signatures and counterparts are permitted when the Parties execute or incorporate this DPA into their agreement.

Return to the injury-case program