1Definitions
For purposes of this DPA:
“Applicable Data Protection Law” means privacy and data-protection laws applicable to the processing of Personal Data under the Agreement.
“Controller” means the person or organization that determines the purposes and means of processing Personal Data, or the equivalent term under applicable law.
“Processor” means a person or organization that processes Personal Data on behalf of a Controller, or the equivalent term under applicable law.
“Business” and “Service Provider” have the meanings assigned under applicable U.S. state privacy laws where relevant.
“Customer Data” means data submitted to, stored in, transmitted through, or otherwise processed by the Services on behalf of Customer.
“Personal Data” means information relating to an identified or identifiable individual, or other information defined as personal information, personal data, or an equivalent term under Applicable Data Protection Law.
“Processing” means any operation performed on Personal Data, including collecting, recording, organizing, storing, accessing, modifying, retrieving, using, transmitting, disclosing, restricting, deleting, or destroying Personal Data.
“Data Subject” means the individual to whom Personal Data relates.
“Subprocessor” means a third party engaged by 255 to process Personal Data on behalf of Customer in connection with the Services.
“Personal Data Breach” means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed under this DPA, as defined by Applicable Data Protection Law.
2Roles of the Parties
Customer and 255 acknowledge that their respective privacy roles depend on the context in which Personal Data is processed.
For Personal Data that Customer submits to or processes through the Services for its own business purposes:
- Customer generally acts as the Controller or Business.
- 255 generally acts as the Processor or Service Provider on Customer’s behalf.
Customer determines the purposes for which Customer Personal Data is processed and is responsible for ensuring that its instructions comply with Applicable Data Protection Law.
255 will process such Personal Data on Customer’s documented instructions, including as necessary to provide the Services under the Agreement and this DPA.
255 may separately act as an independent Controller for certain information processed for its own legitimate business purposes, such as account administration, direct customer relationships, security, billing, fraud prevention, and legal compliance. Such processing is governed by the 255 Privacy Policy and applicable law.
3Customer Instructions
Customer instructs 255 to process Personal Data as reasonably necessary to:
- Provide the Services
- Operate the 255 Business Platform
- Maintain Customer accounts
- Host and store Customer Data
- Provide CRM functionality
- Facilitate customer communications
- Provide scheduling and appointment functionality
- Execute configured automations
- Provide integrations requested by Customer
- Provide technical and customer support
- Maintain security
- Prevent fraud and abuse
- Troubleshoot technical issues
- Perform obligations under the Agreement
- Comply with applicable legal obligations
Additional documented instructions may be agreed between Customer and 255.
If 255 reasonably believes that a Customer instruction violates Applicable Data Protection Law, 255 may notify Customer and, where legally appropriate, suspend the affected processing until the issue is resolved.
4Customer Responsibilities
Customer is responsible for ensuring that its collection and processing of Personal Data through the Services complies with Applicable Data Protection Law.
Customer represents and warrants, as applicable, that it:
- Has appropriate authority to provide Personal Data to 255
- Has provided legally required privacy notices
- Has obtained legally required consent
- Has an appropriate legal basis for processing
- Complies with applicable marketing and communication laws
- Honors applicable opt-out requests
- Maintains appropriate records of consent where required
- Provides lawful processing instructions
- Does not instruct 255 to process Personal Data unlawfully
Customer is responsible for determining whether the Services are appropriate for Customer’s particular legal, regulatory, and industry requirements.
5Details of Processing
The nature and scope of processing depend on the Services selected and configured by Customer.
Subject Matter
Processing of Personal Data necessary to provide the Services requested by Customer.
Duration
For the duration of the Agreement and any additional period during which 255 is authorized or legally required to retain Personal Data.
Nature of Processing
Processing may include:
- Collection
- Receipt
- Recording
- Organization
- Storage
- Retrieval
- Consultation
- Use
- Transmission
- Communication
- Synchronization
- Analysis
- Automation
- Modification
- Export
- Restriction
- Deletion
depending on the Services used.
6Categories of Data Subjects
Depending on Customer’s use of the Services, Data Subjects may include:
- Customer’s customers
- Prospective customers
- Leads
- Contacts
- Website visitors
- Appointment participants
- Employees
- Contractors
- Authorized users
- Business representatives
- Communication recipients
- Other individuals whose Personal Data Customer lawfully processes through the Services
7Categories of Personal Data
Depending on the Services used and Customer configuration, Personal Data may include:
- Names
- Email addresses
- Telephone numbers
- Business information
- Contact details
- CRM records
- Lead information
- Opportunity information
- Appointment information
- Communication history
- SMS and messaging data
- Email communications
- Form submissions
- Notes
- Tags
- Tasks
- Customer interactions
- Account identifiers
- Device and technical information
- IP-related information
- Transaction-related information
- Marketing preferences
- Consent records
- Other Personal Data submitted by Customer
255 does not require Customer to provide categories of Personal Data that are unnecessary for the Services.
8Sensitive Personal Data
Customer must not submit sensitive or specially protected Personal Data unless:
- the applicable Services are designed and authorized to process such information;
- Customer has a valid legal basis for doing so;
- all required safeguards, notices, agreements, and consents are in place; and
- such processing complies with the Agreement and Applicable Data Protection Law.
Customer is responsible for determining whether sector-specific or heightened requirements apply to its data.
Use of the Services does not, by itself, establish compliance with HIPAA, GLBA, FERPA, or any other sector-specific regulatory framework.
9Confidentiality
255 will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Personal Data will be limited to personnel and service providers who require access for legitimate purposes related to providing, maintaining, securing, or supporting the Services.
10Security Measures
255 will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful access, disclosure, alteration, destruction, or loss.
Depending on the nature of the Services and systems involved, safeguards may include measures relating to:
- Access controls
- Authentication
- Authorization
- Credential management
- Network security
- Application security
- Encryption where appropriate
- Logging and monitoring
- Infrastructure security
- Backup and recovery
- Vulnerability management
- Security updates
- Incident management
- Employee access controls
- Vendor management
- Business continuity
Security measures may evolve over time as technologies, threats, and Services change.
255 will not materially reduce the overall security of the Services during the applicable subscription term without appropriate justification.
11Access to Personal Data
255 will limit access to Customer Personal Data to individuals and Subprocessors who reasonably require access to:
- Provide the Services
- Maintain infrastructure
- Provide support
- Investigate technical issues
- Maintain security
- Prevent abuse
- Comply with legal obligations
Access will be subject to appropriate authorization and confidentiality requirements.
12Subprocessors
Customer generally authorizes 255 to engage Subprocessors as necessary to provide the Services.
Subprocessors may provide services such as:
- Cloud hosting
- Infrastructure
- Database services
- Communications
- Email delivery
- SMS delivery
- Payment processing
- Analytics
- Security
- Customer support
- Authentication
- Integrations
- Other technical services
255 will require Subprocessors that process Customer Personal Data on its behalf to be subject to data-protection obligations appropriate to the nature of their processing.
255 remains responsible for its obligations under this DPA with respect to processing performed by its Subprocessors to the extent required by Applicable Data Protection Law.
13Subprocessor List
255 may maintain a current list of applicable Subprocessors at:
www.255adv.com/legal/subprocessors
The list should identify, where appropriate:
- Subprocessor name
- Purpose
- Type of service
- Location or processing region where relevant
255 should not list a provider as a Subprocessor unless that provider actually processes Customer Personal Data on behalf of 255.
14Changes to Subprocessors
Where required by Applicable Data Protection Law or contractual commitments, 255 will provide appropriate notice of material changes involving Subprocessors.
If Customer has a legally recognized right to object to a new Subprocessor, Customer may raise a reasonable data-protection objection by contacting:
support@255adv.com
The parties will work in good faith to address legitimate concerns.
15Third-Party Integrations Selected by Customer
The Services may allow Customer to connect third-party applications, platforms, or services.
When Customer independently chooses to enable a third-party integration, Customer instructs 255 to transmit or make available relevant Personal Data as necessary to provide that integration.
Independent third-party services may process information under their own terms and privacy policies.
Customer is responsible for evaluating third-party services it chooses to connect.
16Data Subject Requests
Taking into account the nature of the processing and the functionality available through the Services, 255 will provide reasonable assistance to Customer in responding to applicable Data Subject requests where required by Applicable Data Protection Law.
Such requests may include requests relating to:
- Access
- Correction
- Deletion
- Portability
- Restriction
- Objection
- Opt-out rights
Where a Data Subject contacts 255 directly regarding Personal Data processed on behalf of Customer, 255 may direct the request to Customer unless applicable law requires 255 to respond directly.
Customer remains responsible for determining the appropriate response to requests relating to Customer-controlled Personal Data.
17Assistance With Compliance
Taking into account the nature of processing and information reasonably available to 255, 255 will provide reasonable assistance to Customer with applicable data-protection obligations where legally required.
This may include assistance concerning:
- Security
- Personal Data Breaches
- Data Subject requests
- Data protection impact assessments
- Regulatory consultations
Assistance beyond standard Service functionality may be subject to reasonable fees where permitted by the Agreement and applicable law.
18Personal Data Breach
255 will maintain procedures designed to identify and respond to security incidents.
If 255 becomes aware of a Personal Data Breach affecting Customer Personal Data for which notification to Customer is required under Applicable Data Protection Law, 255 will notify Customer without undue delay.
Where reasonably available, notification may include information concerning:
- The nature of the incident
- Categories of affected information
- Potential consequences
- Measures taken or proposed
- Relevant contact information
255 may provide information in phases as additional details become available.
Notification of a security incident does not constitute an admission of fault or liability.
Customer is responsible for determining whether notification to individuals, regulators, customers, or other parties is legally required unless applicable law provides otherwise.
19Data Return and Deletion
Upon termination or expiration of the applicable Services, Customer may lose access to Customer Personal Data.
Where available, Customer should export information it wishes to retain before account termination.
Upon termination and subject to applicable law, 255 will delete or return Customer Personal Data in accordance with:
- The Agreement
- Service functionality
- Applicable retention periods
- Legal obligations
- Security requirements
- Backup procedures
255 may retain Personal Data where required or permitted by applicable law.
Data contained in backups may remain until deleted or overwritten according to applicable backup-retention processes.
20Data Portability and Export
Where supported by the Services, Customer may export certain Customer Data using available functionality.
Customer is responsible for performing required exports before terminating its account.
255 does not guarantee that every category of information can be exported in every format unless expressly required by applicable law or agreement.
21International Data Transfers
Customer acknowledges that 255 and its authorized Subprocessors may process Personal Data in the United States and other jurisdictions.
Where an international transfer requires a legally recognized transfer mechanism, the parties will use an appropriate mechanism as required by Applicable Data Protection Law.
22European Economic Area Transfers
Where Customer Personal Data subject to the GDPR is transferred from the European Economic Area to a country that does not benefit from an applicable adequacy decision, the parties will use an appropriate transfer mechanism where required.
This may include the European Commission's applicable Standard Contractual Clauses (“SCCs”).
Where SCCs are legally required, they will be incorporated into this DPA or executed separately as applicable.
The parties will cooperate reasonably regarding supplementary measures required by applicable law.
23United Kingdom Transfers
Where Personal Data subject to UK data-protection law is transferred internationally and an appropriate transfer mechanism is required, the parties will use an applicable legally recognized mechanism.
This may include the UK International Data Transfer Addendum or another approved transfer mechanism where applicable.
24U.S. State Privacy Laws
Where 255 processes Personal Data on behalf of Customer and applicable U.S. state privacy law treats Customer as a Business or Controller and 255 as a Service Provider, Contractor, or Processor, 255 will process such Personal Data consistent with applicable contractual requirements.
Where applicable, 255 will not:
- Sell Customer Personal Data for monetary consideration
- Retain, use, or disclose Customer Personal Data outside the purposes permitted by the Agreement and applicable law
- Combine Customer Personal Data with other information where prohibited by applicable law
255 will process Customer Personal Data for the limited and specified purposes described in the Agreement, this DPA, and Customer's documented instructions.
25California Privacy Requirements
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), applies to processing under this DPA, the parties intend that 255 act as a Service Provider or Contractor, as applicable, for Customer Personal Information processed on Customer’s behalf.
255 will process such Personal Information only for the limited and specified business purposes permitted by the Agreement, this DPA, and applicable law.
255 will not sell or share Customer Personal Information as those terms are defined by applicable California law, except as permitted by law and Customer’s documented instructions.
255 will notify Customer if it determines that it can no longer meet applicable obligations under this section where required by law.
Customer may take reasonable and appropriate steps permitted by applicable law to help ensure that 255 processes Customer Personal Information consistently with Customer's obligations.
26Audits and Compliance Information
Upon reasonable request and where required by Applicable Data Protection Law, 255 will make available information reasonably necessary to demonstrate compliance with its obligations as a Processor or Service Provider.
Where legally required, 255 may permit reasonable audits subject to appropriate:
- Confidentiality protections
- Security requirements
- Scope limitations
- Advance notice
- Scheduling requirements
- Protection of other customers
- Protection of proprietary information
The parties should first use available documentation, certifications, reports, or questionnaires where these reasonably satisfy the applicable requirement.
27Government and Legal Requests
255 may disclose Personal Data where required by applicable law, court order, subpoena, or other legally binding government request.
Where legally permitted and appropriate, 255 may notify Customer before disclosing Customer Personal Data in response to such a request.
255 may challenge requests that it reasonably believes are unlawful or excessive where appropriate.
28No Sale of Customer Personal Data
255 does not acquire ownership of Customer Personal Data merely by processing it through the Services.
255 will not sell Customer Personal Data for monetary consideration while acting as Customer’s Processor or Service Provider.
Any independent processing performed by 255 as a Controller is governed by our Privacy Policy and Applicable Data Protection Law.
29Data Ownership
As between Customer and 255, Customer retains all rights it possesses in Customer Data.
This DPA does not transfer ownership of Customer Data to 255.
Customer grants 255 only those rights reasonably necessary to process Customer Data to provide, secure, maintain, and support the Services and fulfill applicable legal obligations.
30Confidential Business Information
Customer Data may contain confidential business information in addition to Personal Data.
255 will handle such information according to applicable confidentiality obligations contained in the Agreement.
31Liability
The liability of each party arising from or relating to this DPA is subject to the applicable limitations and exclusions of liability contained in the Agreement, except to the extent such limitations are prohibited by Applicable Data Protection Law.
32Term and Termination
This DPA becomes effective when it applies to processing under an Agreement between Customer and 255.
It remains in effect for as long as 255 processes Customer Personal Data subject to the DPA.
Provisions that by their nature should survive termination will remain effective for as long as necessary to fulfill applicable legal or contractual obligations.
33Order of Precedence
If there is a conflict concerning data protection between:
- applicable mandatory law;
- legally required transfer mechanisms;
- this DPA; and
- the Agreement,
the higher-priority requirement will control to the extent of the conflict.
34Changes to This DPA
255 may update this DPA to reflect changes in:
- Applicable law
- Regulatory requirements
- Services
- Security practices
- Processing activities
- Subprocessor arrangements
Material changes affecting Customer's data-protection rights will be communicated where required by applicable law or contractual commitments.
The Last Updated date will reflect the most recent revision.
35Contact
Questions concerning this DPA, privacy, security, or data-processing matters may be directed to:
255 Advertising Agency & Marketing LLC
Registered Office
400 E Royal Lane, Suite 104
Irving, TX 75039
United States
Privacy & Support Email
Website
Support Center
Schedule 1 — Details of Processing
بالـDPA أنصح يكون فيه Schedule رسمي في النهاية:
Item
Details
Controller / Business
The applicable 255 Customer
Processor / Service Provider
255 Advertising Agency & Marketing LLC
Subject Matter
Processing necessary to provide the contracted 255 Services
Duration
Duration of the applicable Agreement plus permitted/required retention
Purpose
Providing, securing, maintaining, supporting, and improving contracted Services
Data Subjects
Customers, leads, contacts, employees, users, website visitors, appointment participants and other individuals whose data Customer submits
Personal Data
Contact information, CRM data, communications, appointments, forms, account identifiers, consent information, technical data and other Customer-submitted information
Sensitive Data
Only where expressly supported, authorized and legally permitted
Processing Operations
Collection, storage, organization, retrieval, transmission, communication, automation, modification, export and deletion
Frequency
Continuous or as initiated/configured by Customer
Retention
For the Service term and applicable retention period
Schedule 2 — Technical and Organizational Measures
ما نحط شهادات أمنية مش موجودة. نكتب فقط ما يمكن لـ255 إثباته فعليًا.
الفئات التي يجب توثيقها:
Access Control
Role-based access, account authentication, administrative access controls, and access restriction based on operational need where implemented.
Data Protection
Appropriate protection of data in transit and at rest based on the architecture and services used.
Infrastructure Security
Hosting, network, infrastructure, and environment security measures provided directly by 255 and applicable infrastructure providers.
Application Security
Secure development, dependency management, vulnerability remediation, and production access practices where implemented.
Logging & Monitoring
Appropriate operational and security logging and monitoring.
Backup & Recovery
Backup and recovery procedures appropriate to the Services.
Incident Response
Processes for investigating, containing, remediating, and communicating applicable security incidents.
Vendor Management
Reasonable assessment and contractual controls for Subprocessors handling Customer Personal Data.
Personnel Security
Confidentiality and access restrictions for personnel with access to Customer Personal Data.
