Data Processing Addendum

This Data Processing Addendum (“DPA”) is incorporated into the Terms of Service (the “Terms”) between Castro Enterprises Inc. dba IgnyteRT (“IgnyteRT”) and the subscriber identified in the applicable account (“Subscriber”), and governs IgnyteRT’s processing of End-Customer Data. Capitalized terms not defined here have the meanings in the Terms.

1. Definitions

  • “End-Customer Data” means the personal information about Subscriber’s customers and contacts that Subscriber uploads to or transmits through the Service (e.g., names, phone numbers, message content and delivery metadata associated with those contacts).
  • “Process/Processing” means any operation performed on End-Customer Data, such as collection, storage, transmission, or deletion.
  • “Applicable Privacy Laws” means US federal and state privacy laws applicable to the Processing, including the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
  • “Sell,” “Share,” “Business,” “Service Provider,” and “Consumer” have the meanings given in the CCPA.

2. Roles and Scope

2.1 As between the parties, Subscriber is the Business (or controller) with respect to End-Customer Data, and IgnyteRT is a Service Provider (or processor) Processing End-Customer Data solely on Subscriber’s behalf.

2.2 Subject matter and purpose: Processing is limited to providing the Service described in the Terms — hosting contact lists, transmitting messages (SMS/MMS, WhatsApp, RCS, and any future channels the Subscriber adopts) at Subscriber’s direction, receiving and displaying replies, processing opt-outs, and providing related analytics and support (“the Business Purpose”).

2.3 Duration: the term of the Subscriber’s account, plus the deletion period in Section 8.

3. Subscriber Responsibilities

Subscriber is solely responsible for: (a) the accuracy and lawfulness of End-Customer Data it uploads; (b) obtaining and documenting all consents required by Applicable Privacy Laws and messaging laws (including the TCPA) before messaging any contact, as warranted in the Terms; (c) the content, recipients, and timing of all messages; and (d) responding to its End Customers’ privacy rights requests.

4. IgnyteRT Obligations (CCPA Service-Provider Certifications)

IgnyteRT certifies that it will:

  • Process End-Customer Data only for the Business Purpose, on Subscriber’s documented instructions (which include the Terms, this DPA, and configurations Subscriber makes in the Service), and not for any other purpose;
  • not Sell or Share End-Customer Data;
  • not retain, use, or disclose End-Customer Data outside the direct business relationship with Subscriber or for any commercial purpose other than the Business Purpose, except as permitted by the CCPA (e.g., security, legal compliance, internal operations consistent with the CCPA);
  • not combine End-Customer Data with personal information received from other subscribers or other sources, except as permitted by the CCPA for the Business Purpose (e.g., maintaining channel-level opt-out suppression as required by law);
  • notify Subscriber if it determines it can no longer meet its obligations under Applicable Privacy Laws, in which case Subscriber may take reasonable steps to stop and remediate unauthorized Processing; and
  • ensure personnel with access to End-Customer Data are bound by confidentiality obligations.

5. Security

IgnyteRT will implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including: encryption of data in transit (TLS); hashed credential storage; role-based access controls and least-privilege access; logical separation of the marketing website from the application system of record; and vendor security review of subprocessors.

6. Subprocessors

6.1 Subscriber authorizes IgnyteRT to engage subprocessors to Process End-Customer Data for the Business Purpose. Current subprocessors:

6.2 IgnyteRT will update the subprocessor list at https://ignytert.com/dpa before adding a new subprocessor that Processes End-Customer Data. Subscriber’s sole remedy for objecting to a new subprocessor is to cancel the subscription per the Terms. IgnyteRT remains responsible for its subprocessors’ performance under this DPA.

7. Consumer Rights Requests; Opt-Outs

7.1 The Service automatically processes standard messaging opt-out keywords (e.g., STOP) and suppresses opted-out contacts from further messaging by that Subscriber through the Service.

7.2 If IgnyteRT receives a privacy rights request (access, deletion, correction) directly from Subscriber’s End Customer, IgnyteRT will forward it to Subscriber without substantive response (beyond directing the individual to Subscriber) and will provide reasonable assistance, through the Service’s functionality, for Subscriber to respond.

8. Data Deletion and Return

8.1 During the term, Subscriber can access, export, correct, and delete End-Customer Data through the Service.

8.2 Within 120 days after account closure (for any reason), IgnyteRT will delete End-Customer Data associated with the account, except to the extent retention is required by law, needed to maintain legally required suppression/opt-out records, or contained in routine backups (which are deleted on the backup rotation schedule and not restored to production).

9. Security Incidents

IgnyteRT will notify Subscriber without undue delay (and in any event within 72 hours of confirmation) after becoming aware of a breach of security leading to unauthorized access to or disclosure of End-Customer Data, and will provide information reasonably available to help Subscriber meet its own notification obligations. Notification is not an admission of fault.

10. Audits and Information

Upon Subscriber’s reasonable written request (no more than once per 12 months), IgnyteRT will provide information reasonably necessary to demonstrate compliance with this DPA, such as a summary of its security measures and subprocessor list. On-site audits are not provided at this service tier.

11. International Data

The Service is offered to US businesses for messaging US recipients. Subscriber must not upload personal data of individuals located in the European Economic Area, United Kingdom, or Switzerland. If the parties later agree in writing to such Processing, they will execute appropriate transfer mechanisms (e.g., Standard Contractual Clauses) at that time.

12. General

12.1 Order of precedence: if this DPA conflicts with the Terms regarding Processing of End-Customer Data, this DPA controls.

12.2 Liability: each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms (including the 12-month cap and its carve-outs).

12.3 Term: this DPA is effective for as long as IgnyteRT Processes End-Customer Data and terminates automatically upon completion of deletion under Section 8.

12.4 Amendments: IgnyteRT may update this DPA as reasonably necessary to reflect changes in Applicable Privacy Laws, with notice per the Terms.

Castro Enterprises Inc. dba IgnyteRT 115 N Euclid Ave Ste B, Ontario, CA 91762 privacy@ignytert.com