Data Processing Addendum
Effective October 8, 2026
data-processing-2026-10-08-v1
This addendum forms part of the Terms between KeepCarrier LLC and the organization represented by an authorized customer. It applies when KeepCarrier processes customer-controlled personal data on that organization's behalf. For that processing the customer is the controller and KeepCarrier is the processor, or the corresponding roles under applicable law. Mandatory legal obligations prevail over conflicting commercial terms.
On this page
Processing schedule
The subject matter is providing the customer's carrier-sales workspace, lead assignment, outreach history, collaboration, website publishing, billing-linked access and support. Processing includes receiving, storing, organizing, displaying, transmitting on instruction, securing, exporting and deleting data. It lasts while service is provided and during the restricted return, deletion or lawful-retention process afterwards.
Data can include staff names and work contact details, customer-entered carrier contacts, lead notes and statuses, communication content and metadata, uploaded files and website inquiries. Data subjects include the customer's staff, contacts and website visitors. The product is not designed to receive sensitive health, biometric, financial-card or other special-category data. Account administration, our own security/billing records and independently compiled public registry data are addressed separately in the Privacy Policy where KeepCarrier determines their purposes.
Documented instructions and confidentiality
The accepted Terms, this addendum, supported settings and authorized support requests are the customer's documented instructions. We process customer-controlled personal data only on those instructions unless applicable law requires otherwise. We will inform the customer of such a legal requirement where permitted and flag an instruction we reasonably believe violates applicable data-protection law. We do not sell customer-controlled personal data or use customer content to train a shared AI model.
The customer is responsible for a lawful basis, accurate notices, outreach permissions, minimizing uploaded data and communicating lawful instructions. People authorized to process customer data must be subject to confidentiality obligations and access only what their duties require.
Security, rights and incident assistance
KeepCarrier implements appropriate technical and organizational safeguards as described in the Data Protection and Security Policy. Taking account of the processing and information available, we reasonably assist the customer with data-subject requests, security duties, breach notifications, impact assessments and consultations required by applicable law.
Requests received directly from individuals about customer-controlled data are referred to the customer where appropriate, unless law requires us to respond. We do not independently disclose another person's tenant data. We notify the customer without undue delay upon awareness of a personal-data breach affecting its processed data, with available details about its nature, impact and mitigation, supplementing them as the investigation progresses.
Subprocessors and international processing
The customer authorizes the service providers in the published Subprocessor and Third-party Services Notice for their stated purposes. We require relevant subprocessors to protect the processed data under contractual obligations appropriate to their work and the applicable law, and remain responsible for their processing obligations to the extent required by law. Customer-selected calling or mailbox providers process under the customer's own agreements and documented instructions.
We provide advance notice of a material new or replacement subprocessor where practicable, ordinarily 30 days, through the customer contact or product. A customer may promptly object on reasonable data-protection grounds; the parties will discuss an alternative or lawful termination if the issue cannot be resolved. An urgent security or legally required replacement may require shorter notice, with explanation.
The main application database and object storage are in the United States; authorized operations and service providers may process data internationally. A required restricted transfer must use a lawful mechanism and any necessary assessment or supplementary measures. This addendum by itself is not an executed EU Standard Contractual Clauses document, UK IDTA, adequacy decision or certification. Contact support before a use requiring a specific transfer agreement; access or continued use is not a substitute for a legally required safeguard.
Return, deletion and retained evidence
At the customer's verified request after service ends, we will arrange return or deletion of customer-controlled personal data, subject to applicable law and the customer's lawful instructions. This is a support-assisted process, not an automatic deletion triggered by overdue billing. Backups remain restricted until their configured expiry; data retained under a legal obligation remains protected and is processed only for that obligation.
Our independent billing, acceptance, security and suppression evidence is governed by the Privacy Policy and applicable retention duties, rather than being erased by an instruction that would destroy a lawful dispute record or opt-out. Each request is scoped and recorded; blanket disabling of commercial-evidence protections is not a deletion method.
Information, audits and precedence
We provide information reasonably necessary to demonstrate the obligations in this addendum and allow or contribute to audits and inspections required by applicable law. The parties coordinate proportionate scope, confidentiality and timing, and protect other tenants; contractual coordination cannot remove a mandatory legal audit right. No term relieves either party of its own statutory duties.
For customer-controlled personal-data processing, this addendum takes precedence over conflicting general Terms. The commercial liability provisions apply only to the extent lawful and do not restrict an individual's or authority's mandatory remedies. A staff member's personal acceptable-use acknowledgement alone cannot enter this addendum for the organization; acceptance requires an authorized organization representative.