Data Processing Addendum

1stContact.ai LLC  ·  Effective Date: January 1, 2026  ·  Last Updated: January 1, 2026

This Customer Data Processing Addendum, including its exhibits and appendices (the "Addendum") is entered into between 1stContact.ai LLC, a limited liability company, and its relevant Affiliates ("1stContact.ai"), and the counterparty accepting this Addendum ("Customer") (each, a "Party" and, collectively, the "Parties") by virtue of the Customer signing and accepting the Terms of Service Agreement (the "Agreement"). As of the effective date of the Agreement (the "Effective Date"), the terms of this Addendum shall be incorporated by reference and be part of the Agreement. In case of any conflict or inconsistency with the terms of the Agreement, this Addendum will take precedence over the terms of the Agreement to the extent of such conflict or inconsistency, and it will supersede any previous Addendum. For clarity, the Standard Contractual Clauses prevail over any other term of the Addendum terms. Except where the context requires otherwise, references in this Addendum to the Agreement are to the Agreement as amended or supplemented by, and including, this Addendum.

1. Definitions

For the purpose of interpreting this Addendum, the following terms (and their applicable cognates) shall have the meanings set out below:

  • "Account" means any accounts or instances created by, or on behalf of, Customer or its Affiliates within the Services.
  • "Affiliate" means any entity within a controlled group of companies that directly or indirectly, through one or more intermediaries, is controlling, controlled by, or under common control with one of the Parties.
  • "Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Customer Personal Data, including but not limited to the laws and regulations identified in Exhibit B hereto as may be amended, modified, or supplemented from time to time, as applicable.
  • "Contracted Processor" means any third party appointed by or on behalf of 1stContact.ai (including underlying software infrastructure, hosting, telecom, and sub-processor providers) to Process Customer Personal Data in connection with the Services.
  • "Customer Personal Data" means Personal Data contained within Customer Data that 1stContact.ai Processes by or on behalf of Customer to provide the Services in accordance with the Agreement. Customer Personal Data does not include Customer's Account information.
  • "Data Exporter" and "Data Importer" shall have the same meanings assigned to them in Part A of Exhibit A.
  • "GDPR" means the EU GDPR and UK GDPR as those terms are defined within Exhibit B, as applicable.
  • "Jurisdiction Specific Terms" means all terms applicable to the Processing of Personal Data that apply to the extent that 1stContact.ai Processes Customer Personal Data originating from, or protected by, Applicable Data Protection Laws in one of the jurisdictions identified in these terms. The Jurisdiction Specific Terms are currently available as Exhibit B to this Addendum.
  • "Restricted Transfer" means any transfer of Customer Personal Data protected by Applicable Data Protection Laws to a Third Country or an international organization in a Third Country (including data storage on foreign servers).
  • "SCCs" or "Standard Contractual Clauses" are the model clauses for Restricted Transfers adopted from time to time by the relevant authorities of the jurisdictions indicated in Exhibit B, insofar as their use is approved by the relevant authorities as an appropriate mechanism or safeguard for Restricted Transfers.
  • "Services" means the platform services, software, marketing tools, and other activities carried out by or on behalf of 1stContact.ai for Customer upon Customer's creation of an Account, whether through a free trial or paid subscription. For the avoidance of doubt, Services exclude services 1stContact.ai performs as a Controller, such as managing customer relationships, account administration, and providing public areas of its website accessible without creation of an Account.
  • "Sub-Processor" means a direct Processor of a Processor. For the avoidance of doubt, Contracted Processors (including underlying infrastructure and cloud hosting partners) are Sub-Processors.

The terms "Controller", "Data Protection Assessment", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing", "Processor", "Rights of the Data Subjects", "Supervisory Authority", and "Third Country" shall have the same meanings as under Applicable Data Protection Laws, and their cognate and corresponding terms shall be construed accordingly.

Capitalized terms which are used but not defined herein shall have the meanings given to them in the Agreement. Except as modified or supplemented above, the definitions of the Agreement shall remain in full force and effect.

2. Scope and Applicability

  1. Duration: This Addendum shall take effect on the Effective Date and shall continue concurrently for the duration that Personal Data is Processed by 1stContact.ai pursuant to the Agreement.
  2. Scope: This Addendum will apply to the Processing of all Customer Personal Data, regardless of country of origin, place of Processing, location of Data Subjects, or any other factor. The Processing of Personal Data that does not constitute Customer Personal Data is outside the scope of this Addendum.
  3. Exhibits and Appendices: This Addendum includes the following exhibits and appendices:
    • Exhibit A – Details of Processing;
    • Appendix I to Exhibit A – Technical and Organizational Security Measures;
    • Exhibit B – Jurisdiction Specific Terms; and
    • Appendix I to Exhibit B – Supplemental Clauses to the Standard Contractual Clauses.

3. Processing of Customer Personal Data

  1. Roles of the Parties: 1stContact.ai will act as a Processor of Customer Personal Data. Customer will act as the Controller of Customer Personal Data. To the extent Customer acts as a Processor to other parties when processing Customer Personal Data, 1stContact.ai will act as the Sub-Processor to Customer.
  2. 1stContact.ai Obligations: 1stContact.ai shall:
    • Comply with all Applicable Data Protection Laws in the Processing of Customer Personal Data;
    • Not Process Customer Personal Data other than on Customer's relevant documented instructions, including to provide and improve the Services set forth in the Agreement (for clarity, such instructions include authorization to anonymize, deidentify, or aggregate Customer Personal Data and to provide AI features used for the Services), unless such Processing is permitted or required by Applicable Data Protection Laws; and
    • Immediately inform Customer in the event that, in 1stContact.ai's reasonable opinion, a Processing instruction given by Customer may infringe Applicable Data Protection Laws.
  3. Details of Processing: All necessary information relating to the details of Processing is set out within Exhibit A.
  4. Instructions: Customer instructs 1stContact.ai (and authorizes 1stContact.ai to instruct each Contracted Processor it engages) to Process Customer Personal Data and, in particular, transfer Customer Personal Data to any country or territory, only as reasonably necessary for the provision of the Services and consistent with the Agreement and this Addendum.

4. Personnel

1stContact.ai shall take reasonable steps to ensure:

  1. The reliability of any employee, agent, or contractor who may have access to Customer Personal Data;
  2. That access to Customer Personal Data is strictly limited to those individuals who need to know or access it, as strictly necessary to fulfill the documented instructions given to 1stContact.ai by Customer or to comply with Applicable Data Protection Laws; and
  3. That all such individuals are subject to formal confidentiality undertakings, professional obligations of confidentiality, or statutory obligations of confidentiality.

5. Security of Processing

1stContact.ai shall implement and maintain (and require its primary platform sub-processors to implement and maintain) the administrative, technical, and organizational security measures identified within Appendix I to Exhibit A, which ensure a level of security appropriate to the risk of Processing and take into account: the state of the art, costs of implementation, and the nature and purposes of Processing; the risk of varying likelihood and severity to the rights and freedoms of natural persons; and the risks presented by the Processing activities, particularly those risks related to Personal Data Breaches.

6. Contracted Processors (Sub-Processors)

  1. Authorization for Existing Contracted Processors: Customer authorizes 1stContact.ai to continue using those Contracted Processors and infrastructure providers engaged as of the Effective Date (including cloud hosting, software engine infrastructure, and telecom integrations), and further authorizes 1stContact.ai and its Contracted Processors to appoint additional Contracted Processors, provided the obligations of this Section 6 are met.
  2. Notice of Appointment: 1stContact.ai will make available to Customer an updated list of Sub-Processors or provide written notice prior to appointing any new Contracted Processor.
  3. Objection to Contracted Processors:
    • Customer will be deemed to have consented to an additional Contracted Processor if no objection is received within thirty (30) days of notice or publication. Customer may object by providing a written statement of reasonable grounds for objection.
    • If an objection is received, the Parties will work together in good faith to achieve a commercially reasonable resolution. If no resolution is available, Customer may terminate the Agreement upon written notice with no further fees due other than what has accrued up to the date of termination.
  4. Requirements for Appointing Contracted Processors: With respect to each Contracted Processor, 1stContact.ai shall bind such Contracted Processor to written terms that offer at least the same level of data protection as those set out in this Addendum. 1stContact.ai shall remain liable to Customer for the performance of its Contracted Processors' data protection obligations under Applicable Data Protection Laws.

7. Rights of the Data Subjects

Taking into account the nature of the Processing, 1stContact.ai shall assist Customer by implementing appropriate technical and organizational measures, insofar as possible, to respond to valid requests to exercise Rights of the Data Subjects under Applicable Data Protection Laws.

With regard to Data Subject requests, 1stContact.ai shall:

  • Promptly notify Customer if it receives a direct request from a Data Subject regarding Customer Personal Data;
  • Not respond directly to that request except on documented instructions from Customer or as required by law; and
  • Promptly comply with documented instructions from Customer regarding responding to Data Subject requests.

8. Personal Data Breaches

  1. Breach Response: If 1stContact.ai discovers, is notified of, or has reason to suspect a Personal Data Breach affecting Customer Personal Data under its or its Contracted Processors' control, 1stContact.ai will:
    1. Immediately implement measures to mitigate and stop unauthorized access;
    2. Secure Customer Personal Data; and
    3. Notify Customer without undue delay and, in any event, within seventy-two (72) hours of becoming aware of such suspected Personal Data Breach.
  2. Breach Obligations: Upon providing notice, 1stContact.ai shall describe the nature of the breach, affected categories of data/individuals, measures taken, and assist Customer in fulfilling its statutory notification obligations under Applicable Data Protection Laws.
  3. No Acknowledgement of Fault: Notification of a Personal Data Breach will not be construed as an acknowledgement of fault or liability by 1stContact.ai.

9. Data Protection Assessment and Prior Consultation

1stContact.ai shall provide Customer with reasonable information and documentation to assist Customer in conducting data protection impact assessments or prior consultations with Supervisory Authorities when required pursuant to Applicable Data Protection Laws, taking into account the nature of Processing and information available to 1stContact.ai.

10. Deletion or Return of Personal Data

1stContact.ai shall provide Customer with technical means (or support) to delete or export Customer Personal Data during the term of the Agreement.

Following termination or cessation of the Services, 1stContact.ai shall promptly delete or return all Customer Personal Data to Customer, except to the extent retention is required by applicable laws or retained on secure system back-ups (which shall be securely isolated until overwritten).

11. Audit Rights

1stContact.ai shall allow for and contribute to reasonable audits or information requests by Customer (or an independent third-party auditor mandated by Customer) regarding compliance with this Addendum. To the extent legally permitted, Customer shall reimburse 1stContact.ai for reasonable time expended for any such audit at 1stContact.ai's standard professional service rates.

12. Jurisdiction Specific Terms

To the extent 1stContact.ai Processes Customer Personal Data originating from or protected by Applicable Data Protection Laws in a jurisdiction listed in Exhibit B (e.g., GDPR, CCPA/CPRA, Australia Privacy Act), the terms and definitions in Exhibit B shall apply.

13. Restricted Transfers

Restricted Transfers of Customer Personal Data under this Addendum shall be conducted in accordance with Exhibit B, utilizing valid transfer mechanisms such as Standard Contractual Clauses (SCCs) or applicable Privacy Frameworks adopted by underlying cloud infrastructure providers.

14. No Selling of Customer Personal Data

1stContact.ai acknowledges and confirms that it does not receive Customer Personal Data as consideration for any Services provided. As between Customer and 1stContact.ai, Customer retains all rights and interests in Customer Personal Data. 1stContact.ai agrees not to sell or share Customer Personal Data in violation of Applicable Data Protection Laws.

15. Amendments & Online Hosting

1stContact.ai may update this Addendum or its online exhibits provided prior notice is given to Customer. If Customer does not object within fourteen (14) days, Customer is deemed to have consented to the update.

16. Liability

Subject to Applicable Data Protection Laws, the liability of each Party under this Addendum shall be subject to the exclusions and limitations of liability set out in the main Agreement.

17. General Terms

  • Notice: Notices under this Addendum shall be sent to the Data Protection Contacts listed in Exhibit A.
  • Prior Existing Agreement: This Addendum supersedes any prior data processing agreements between the Parties regarding the subject matter herein.
  • Severability & Conflicts: If any provision is invalid, the remainder remains in effect. In the event of conflict, this Addendum takes precedence over the main Terms of Service with respect to data privacy obligations.

Exhibit A: Details of Processing

A. List of Parties

Data Importer (Processor):

  • Name: 1stContact.ai LLC (and its relevant Affiliates)
  • Address: 331 South 2nd Ave, Suite 400, Minneapolis, MN 55401
  • Data Protection Contact: Nick Rustad, Founder — privacy@1stcontact.ai

Data Exporter (Controller):

  • Name: Customer Name (as defined in Customer's Terms of Service / Agreement)
  • Address: Customer address as specified in Customer's Account profile.
  • Data Protection Contact: Customer's primary contact specified in Customer's Account.

Activities Relevant to Transferred Data: Processing activities relating to the provision of white-label platform services, CRM operations, AI automations, lead management, and marketing tools as set forth in the Agreement.

Controllership Role:

  • Customer as Controller & 1stContact.ai as Processor: Applies when Customer directly determines the purpose of processing consumer data.
  • Customer as Processor & 1stContact.ai as Sub-Processor: Applies to the extent Customer processes data on behalf of its own downstream clients.

B. Details of Processing

  • Subject Matter: The Processing of Customer Personal Data in connection with providing the 1stContact.ai platform services.
  • Nature & Purpose: Collecting, storing, organizing, automating, communicating, and managing lead and client data as instructed by Customer via the platform.
  • Retention Duration: For the duration of Customer's active subscription, plus post-termination account closeout periods in accordance with Section 10.
  • Categories of Data Subjects: Customers, business leads, end-users, employees, or contacts submitted into the platform by Customer.
  • Categories of Personal Data: Contact information (names, emails, phone numbers), communications, transactional data, user logs, and custom field entries entered by Customer.
  • Special Categories of Data / Sensitive Information: Social Security Numbers, financial data, or health details are not anticipated unless Customer specifically configures custom fields and provides prior notice to 1stContact.ai to ensure appropriate security safeguards are active.

Appendix I to Exhibit A: Technical and Organizational Security Measures

Throughout the term of the Agreement and for so long as 1stContact.ai has access to any Customer Personal Data, 1stContact.ai shall implement and maintain at least the following (or superior) technical and organizational security measures ("TOMs") to safeguard such Customer Personal Data:

Type of MeasureDescription of Security Measures
Pseudonymization & EncryptionPersonal data at rest is encrypted with AES 256 CBC. Personal data in transit is encrypted with TLS V1.2+.
Confidentiality, Integrity & AvailabilityEndpoint protection on user devices, uptime monitors, Role-Based Access Control (RBAC), and managed services (AWS, Google Cloud).
Restoration of AvailabilityPersonal data backed up on AWS and Google Cloud with five-minute granularity to enable rapid restoration in case of an incident.
Testing & AssessingThird-party vulnerability scans, annual third-party penetration testing, and standard patch management processes.
User Identification & AuthorizationEncrypted signed tokens, role-based authorizations, and password protection.
Protection During TransmissionSSL certificates and HTTPS are used during data transmission, protected with TLS v1.2+.
Protection During StoragePersonal data is encrypted at rest with AES-256 CBC encryption.
Physical SecurityUses managed services (AWS, Google Cloud) physical security infrastructure as described in their respective Terms and Conditions.
Events LoggingLogging for all user actions and audit logs using Google Cloud Ops and AWS Cloudwatch.
System ConfigurationConfigurations stored in version control. Standardized container images managed, updated, and patched automatically by Google Cloud.
IT Security GovernanceIn-house team managing IT Security and a third-party MSSP for SOC monitoring.
Certification / AssuranceThe platform infrastructure holds a HIPAA Seal of Compliance Certificate.
Data Minimization & QualityMinimum data requirements set by Processor; users can opt out of optional fields. 2FA and application monitoring active.
Data RetentionData retention limits can be configured with respect to specific individuals by the customer administrator.
Accountability & AccessProcessor access to personal data is strictly restricted based on assigned roles.
Portability & ErasureCustomers can download their data within the Service or request a copy/deletion upon separation via support tickets.

Exhibit B: Jurisdiction Specific Terms

1. Australia

When applicable, the Processing of Customer Personal Data shall be compliant with the Australian Privacy Principles, the Australian Privacy Act (1988), and any other applicable law, regulation, or decree of Australia pertaining to the protection of such information.

2. Brazil

Wherever the Processing pursuant to the Addendum falls within the scope of Brazil's Lei Geral de Proteção de Dados (Law No. 13.709) (collectively "Brazilian Data Protection Laws"), the following applies:

  • Restricted Transfers: With regard to any Restricted Transfer, the transfer mechanisms shall apply in the following precedence: A valid adequacy decision by the ANDP; the Standard Contractual Clauses adopted by ANDP; recognized foreign SCCs; or another lawful mechanism.
  • Standard Contractual Clauses: The Addendum incorporates the Brazilian SCCs by reference. For Clause 3, the Parties choose Option B (process for onward transfer is outlined in Section 6 of the Addendum). For Clause 4, Option A is chosen, and "Exporter" is selected for 4.1 (a), (b), and (c). In conflicts between the Addendum and Brazilian SCCs, the SCCs prevail.

3. Canada

When applicable, the Processing of Customer Personal Data shall be compliant with the Canadian Federal Personal Information Protection and Electronic Documents Act (PIPEDA) and any other applicable Canadian privacy laws.

4. European Economic Area (EEA)

  • Definitions: "EEA Data Protection Laws" means the EU GDPR and applicable local laws. "EU 2021 SCCs" means the contractual clauses adopted by the Commission Implementing Decision (EU) 2021/914.
  • Restricted Transfers: Relies on a valid adequacy decision, appropriate SCCs, or another lawful data transfer mechanism.
  • Standard Contractual Clauses: The Addendum incorporates the EU 2021 SCCs. The Parties apply Module Two (Controller-to-Processor) and Module Three (Processor-to-Sub-Processor). Clause 9(a) uses Option 2 (General Written Authorization). The competent Supervisory Authority is the European Data Protection Board, governed by the laws and courts of the Republic of Ireland.

5. Switzerland

  • Definitions: "Swiss Data Protection Laws" includes the Federal Act on Data Protection (FADP). "FDPIC" means the Swiss Federal Data Protection and Information Commissioner.
  • Restricted Transfers: Relies on a valid adequacy decision, appropriate SCCs adopted by the FDPIC, or another lawful mechanism.
  • Standard Contractual Clauses: Incorporates the EU 2021 SCCs adapted for Switzerland. The competent authority is the FDPIC, governed by the laws and courts of Switzerland.

6. United Kingdom

  • Definitions: "UK Data Protection Laws" includes the Data Protection Act 2018 and the UK GDPR. "UK ICO" means the UK Information Commissioner's Office.
  • Restricted Transfers & SCCs: Incorporates the EU 2021 SCCs modified by the UK Transfer Addendum. The competent authority is the UK ICO, governed by the laws and courts of England and Wales.

7. United States

  • Applicability: Applies to Processing within the scope of enacted state and federal laws (e.g., CCPA/CPRA, Colorado Privacy Act, Virginia Consumer Data Protection Act, etc.).
  • Processing of Customer Personal Data: Customer discloses Personal Data to 1stContact.ai solely for valid Business Purposes. 1stContact.ai shall not Sell or Share Customer Personal Data, nor retain, use, or disclose it except to provide the Services specified in the Agreement. 1stContact.ai certifies that it understands these prohibitions and agrees to comply with them.
  • Termination: Upon termination, 1stContact.ai shall destroy all Customer Personal Data it has Processed on behalf of Customer, unless applicable law requires storage.

Appendix I to Exhibit B: Supplemental Clauses to the Standard Contractual Clauses

By this Exhibit, the Parties provide additional safeguards and redress to the Data Subjects whose Personal Data is transferred pursuant to SCCs.

  1. Definitions. "EO 12333" means the U.S. Executive Order 12333. "FISA" means the U.S. Foreign Intelligence Surveillance Act. "Schrems II Judgment" means the judgment of the European Court of Justice in Case C-311/18.
  2. Applicability of Surveillance Laws. Data Importer represents that it has not received national security orders of the type described in the Schrems II judgment. Data Importer reasonably believes it is not eligible to be required to provide information under FISA Section 702. EO 12333 does not provide the U.S. government the ability to order bulk collection, and Data Importer shall take no action pursuant to it.
  3. Backdoors. Data Importer certifies that it has not purposefully created backdoors for governmental agencies, changed business processes to facilitate governmental access, and is not required by national law to do so. Data Exporter may terminate the contract if Data Importer fails to reveal the existence of any backdoors.
  4. Information About Legal Prohibitions. Data Importer will provide Data Exporter information about the legal prohibitions on Data Importer to provide information under this Exhibit.
  5. Additional Measures to Prevent Access. Data Importer will implement internal policies requiring an official, signed document before considering a request for access to transferred data. Data Importer shall scrutinize every request for legal validity, respond as narrowly as possible, and notify Data Exporter upon receipt of such requests (unless legally prohibited).
  6. Termination. This Exhibit shall automatically terminate if a competent regulator approves a different transfer mechanism that does not require these additional safeguards.