This Data Processing Addendum (“DPA”) form part of the agreement governing Customer’s use of the Services (the “Agreement”) entered into by and between LettrLabs, Inc. (“LettrLabs”) and the customer party identified in the Agreement (“Customer”). LettrLabs and Customer are each a “party” and together the “parties. By accepting the Agreement or accessing or using the Services, Customer agrees to be bound by this DPA. In the event of any conflict between this DPA and the Agreement, the provision of this DPA will control. Any capitalized terms used, but not otherwise defined herein shall have the meaning set forth in the Agreement.
This DPA applies only to the extent LettrLabs processes Personal Data on behalf of Customer in connection with the Services. Except where otherwise stated herein, this DPA does not apply to any Processing activities for which LettrLabs acts as a controller, business, or other independent third party under applicable Data Protection Law. Where LettrLabs acts as a controller, business, or other independent third party, such Processing is governed by LettrLabs’ applicable Privacy Policy and other applicable terms.
1. Definitions
- “Data Protection Law” means any U.S. federal or state laws, rules, or regulations relating to privacy, security, or data protection applicable to a party in the performance of its obligations under this DPA, including the California Consumer Privacy Act, as amended ("CCPA"), and any successor or amended legislation.
- “Personal Data” means any Customer Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, or that is personal data, personal information, or similarly protected data as ascribed under Data Protection Law.
- “Subprocessor” means any subcontractor engaged by LettrLabs to help provide the Services and that processes Personal Data on behalf of LettrLabs in connection with Customer’s use of the Services.
Where applicable, the terms “controller,” “business,” “processor,” “service provider,” “consumer,” “process,” “personal data,” “personal information,” “sell,” “share,” “business purpose,” “commercial purpose,” “third party,” “deidentified,” “aggregate consumer information” (or any equivalent terms) shall have the meaning ascribed to them under Data Protection Law.
2. Data Processing
- This DPA applies to the processing of Personal Data by LettrLabs on behalf of Customer. In this context, with respect to Personal Data (i) LettrLabs acts as processor or service provider for Customer; and (ii) Customer acts as controller or as processor to another person.
- Customer hereby instructs LettrLabs to process Personal Data in accordance with (i) the Agreement and this DPA (including the details of data processing set out in Schedule 1); and (ii) any other documented written instructions by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement and this DPA (collectively, “Documented Instructions”). If LettrLabs must process Personal Data as otherwise required by applicable law, LettrLabs shall inform Customer of that legal requirement before processing Personal Data, unless that law prohibits such disclosure on important grounds of public interest.
- The obligations in this subsection apply only to Personal Data that is personal information subject to the CCPA. Customer makes Personal Data available to LettrLabs for the business purposes specified in Schedule 1 below. LettrLabs agrees that: (1) LettrLabs will use the Personal Data only for those limited specified purposes; (2) LettrLabs will provide the same level of privacy protection to the Personal Data as is required of businesses by CCPA; (3) Customer has the right to take reasonable and appropriate steps as outlined in Section 8 of this DPA to help ensure that LettrLabs uses the Personal Data in a manner consistent with Customer’s obligations under CCPA; (4) LettrLabs will notify Customer if it makes a determination that it can no longer meet its obligations under CCPA with respect to the Personal Data; and (5) Customer has the right, upon notice and in accordance with the applicable sections of this DPA, to take reasonable and appropriate steps to stop and remediate unauthorized use of the Personal Data.
- Except as expressly set forth below, LettrLabs acts as a service provider with respect to such Personal Data. Where LettrLabs acts as a service provider, LettrLabs will process Personal Data only for the business purposes specified in Schedule 1 and will not: (1) sell or share the Personal Data; (2) retain, use, or disclose the Personal Data for any purpose, including a commercial purpose, other than the business purposes specified herein; (3) retain, use, or disclose the Personal Data outside of the direct business relationship between LettrLabs and Customer other than for the business purposes specified herein; and (4) combine the Personal Data with personal information that LettrLabs receives from or on behalf of another customer, or collects from its own interaction with the consumer, unless otherwise permitted of a service provider by the CCPA.
- To the extent LettrLabs provides Services that do not constitute processing as a service provider under the CCPA (for example, combining Personal Data with personal data collected from other sources through its enrichment services), LettrLabs acts as a third party with respect to such processing. Such processing is outside the scope of LettrLabs service provider obligations under this Addendum and will be governed by the parties’ applicable terms and disclosures relating to that processing activity. Where required by the CCPA, Customer will notify LettrLabs of any consumer requests to opt out of the sale or sharing of their Personal Data that relate to the services. Upon receiving notice of a consumer opt out request (either directly or indirectly from Customer), LettrLabs will thereafter process the Personal Data only as permitted of a service provider under the CCPA, and will direct any downstream recipients of the Personal Data to do the same.
- As between the parties, Customer is solely responsible for the accuracy, quality, and legality of Personal Data. Customer agrees that: (i) Customer has provided all necessary notice and choice, and secured all necessary rights, consents, and privileges for the processing of Personal Data as contemplated under the Agreement (including by LettrLabs and its Subprocessors); (ii) Customer has complied (and will continue to comply) with all Data Protection Laws and applicable third party terms; (iii) Customer will not provide to LettrLabs or cause LettrLabs to process any sensitive category of Personal Data (such as data concerning health, finances, sex life or sexual orientation, children or teens, or other data defined as sensitive under Data Protection Law) unless expressly set out in Schedule 1 below; (iv) to the extent Customer uses the Services in a manner that involves the collection, use, storage, or other processing of biometric identifiers or biometric information (as defined under applicable law), Customer has provided all legally required notices and disclosures, obtained all required express or written consents, and complied with all applicable biometric privacy laws, including any applicable requirements relating to data retention and destruction; and (v) LettrLabs’ processing of Personal Data in accordance with Customer’s instructions will not violate or cause LettrLabs to violate any Data Protection Laws or applicable third party terms. Notwithstanding anything to the contrary, to the extent permitted by Data Protection Law, LettrLabs may use and retain any deidentified or aggregate consumer information related to the Services for any purpose in accordance with Data Protection Law, including but not limited to developing analytics and improving the Services.
3. Security
LettrLabs shall implement and maintain security procedures and practices appropriate to the nature of the Personal Data designed to protect the Personal Data from a Security Incident. LettrLabs shall ensure that persons authorized to carry out processing have committed themselves to confidentiality or are under the appropriate statutory obligation of confidentiality.
4. Security Incidents
LettrLabs shall notify Customer without undue delay after becoming aware of an accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data in possession or control of LettrLabs (a “Security Incident”). LettrLabs shall make reasonable efforts to identify the cause of such Security Incident and take steps as LettrLabs deems necessary and reasonable in order to remediate the cause of such Security Incident to the extent the remediation is within LettrLabs’ reasonable control and required by law.
5. Subprocessors
Customer provides general written authorization for LettrLabs to engage Subprocessors to process Personal Data in connection with the Services. A current list of LettrLabs’ Subprocessors is available upon written request (the “Subprocessor List”). LettrLabs will enter into a written agreement with each Subprocessor containing data protection obligations no less protective than those in this DPA with respect to the protection of Personal Data. LettrLabs shall make available notice of any intended addition or replacement of a Subprocessor by updating the Subprocessor List. Customer may object to a new Subprocessor on reasonable grounds by providing written notice to LettrLabs within ten (10) days following notice of the updated Subprocessor List. If Customer reasonably objects to a new Subprocessor and the parties are unable to resolve the objection, LettrLabs shall use commercially reasonable efforts to make the affected Services available without the objected-to Subprocessor within thirty (30) days. If LettrLabs is unable to do so, Customer's sole remedy shall be to terminate the affected Services upon written notice. LettrLabs shall be liable for the acts and omissions of its Subprocessors to the same extent LettrLabs would be liable if performing the services of each Subprocessor directly under the terms of this DPA.
6. Requests and Assistance
To the extent legally permitted, LettrLabs shall: (a) promptly notify Customer if LettrLabs receives a request from a Consumer to exercise their rights under Data Protection Law or receives a request or complaint from a regulator or other third party (“Request”); and (b) not respond to the Request without written approval from Customer. Taking into account the nature of the processing, LettrLabs shall reasonably assist Customer in the fulfilment of Customer’s obligation to respond to the Request. Upon request by Customer, LettrLabs shall reasonably assist Customer as necessary to carry out data protection impact assessments (or equivalent as required by Data Protection Law) related to Customer’s use of the Services, and in the cooperation or prior consultation with regulators in the performance of LettrLabs’ tasks relating to the data protection impact assessments. To the extent legally permitted, Customer shall be responsible for any costs arising from LettrLabs’ provision of assistance hereunder. Customer acknowledges that LettrLabs may not be able to fulfill Requests where doing so would interfere with LettrLabs’ ability to comply with applicable law or legal obligation, or protect its rights or those of a third party. Each party shall provide reasonable assistance to the other party as necessary for the other party to fulfill its obligations under Data Protection Law.
7. Return and Deletion
Upon Customer’s written request, and no later than sixty (60) days following termination or expiration of the Agreement, LettrLabs shall return or delete (at Customer’s discretion) all Personal Data in its possession or control. LettrLabs may retain Personal Data (i) where necessary for Customer to comply with applicable law or legal obligation, (ii) to establish, exercise, or defend legal claims, or otherwise protect its rights or those of a third party; and (iii) in backup systems, archives, and disaster recovery environments maintained in accordance with LettrLabs' standard retention and security practices, provided that any retained Personal Data will remain subject to the confidentiality, security, and other applicable protections set forth in this DPA until deleted.
8. Audit
Upon Customer's written request, LettrLabs will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports, certifications, or summaries of security measures. Customer shall only have the right to conduct an audit where required by applicable Data Protection Law.
9. Liability
To the maximum extent permitted by applicable law, and notwithstanding anything to the contrary, each party’s liability under this DPA is subject to the disclaimers and limitations of liability in the Agreement.
10. Modification
LettrLabs may modify this DPA from time to time by providing notice to Customer, which may be given by posting the modified DPA in its online portal or by email to the email address associated with Customer’s account. Unless otherwise stated by LettrLabs, modifications will become effective upon Customer’s continued access to or use of the Services after the effective date of the modified DPA. Customer may not modify this DPA unless otherwise agreed in a written amendment by the parties.
Schedule 1 — Details of Processing Activities
- Subject Matter. The subject matter of the processing is Personal Data.
- Duration. The duration of the processing is until the earlier of (i) request by Customer to stop further processing; (ii) expiration/termination of the DPA; or (iii) when processing is no longer necessary for purposes of LettrLabs performing its obligations pursuant to the DPA.
- Categories of Consumers. The categories of Consumers whose Personal Data is processed may include: (i) end users of Customer; (ii) personnel and agents of Customer; (iii) personnel and agents of Customer’s customers, business partners, and vendors; and (iv) any other natural persons authorized by Customer.
- Categories of Personal Data. The categories of Personal Data processed may include: Names, mailing addresses, email addresses, telephone numbers, customer identifiers, marketing audience data, demographic data, enrichment data, campaign response information, and related customer or contact information provided by Customer or Processed on Customer’s behalf.
- Frequency of Transfers. The frequency of the transfer of Personal Data from Customer to LettrLabs will be on a continuous basis.
- Nature of Processing. The nature of the processing is the Services as described in the Agreement.
- Purpose. The purpose of the processing is for LettrLabs to provide the Services to Customer as set out in the Agreement.
- Business Purpose. The business purpose as defined by CCPA is performing services on behalf of Customer, including data hygiene, address validation, audience/list processing, campaign preparation, fulfillment, delivery support, analytics, and related service operations.
- Location. The Services are intended to cover the United States.
- Retention. LettrLabs may retain Personal Data through the duration as described above, and after the duration where applicable law requires retention of the Personal Data, and subject to the obligations in the DPA.
- Sensitive Data. The Services are not intended for the processing of sensitive Personal Data, and Customer shall not provide sensitive Personal Data unless otherwise expressly agreed by the parties.
- Subprocessors. Any transfer of Personal Data from LettrLabs to Subprocessors will be in accordance with the obligations set out in the DPA. The subject matter, nature, and duration of the processing by Subprocessors are as described above.