Version 1.3 — July 26, 2026 (subprocessor notice extended to 30 days; added Google — place enrichment for DealerMap Live — and ImprovMX — support-email forwarding)
This Data Processing Addendum (“DPA”) forms part of the DealerMap
Terms of Service (or a mutually executed Master Subscription
Agreement, if one exists) between No Rest for the Wicked LLC (doing
business as DealerMap; the “Processor,” “we,” “us”) and the customer organization using
the Service (the “Controller,” “you”). It applies where and to the extent we process
Personal Data on your behalf subject to Data Protection Laws (including GDPR, UK GDPR,
and comparable U.S. state laws).
1. Definitions
“Personal Data,” “processing,” “controller,” “processor,” “data subject,” and
“supervisory authority” have the meanings given in the applicable Data Protection Laws.
“Customer Personal Data” means Personal Data contained in Customer Content that we
process on your behalf to provide the Service.
2. Roles; scope & details of processing
- Roles: you are the controller of Customer Personal Data; we are
your processor. Each party complies with its own obligations under Data Protection
Laws.
- Subject matter & duration: provision of the DealerMap Service
for the term of the agreement.
- Nature & purpose: hosting, storage, synchronization, display to
authorized organization members, backup, security monitoring, abuse and bug
detection, support, and export — as described in the Terms and the
Privacy Policy.
- Categories of data subjects: your organization's members (sales
representatives, managers, administrators) and business contacts recorded in
prospecting notes (dealership personnel).
- Categories of Personal Data: names, business email addresses,
account identifiers, role and territory assignments, activity records, and business
contact details contained in notes. No special categories of data are
intended or required by the Service.
3. Our obligations as processor
- We process Customer Personal Data only on your documented instructions
— the Terms, this DPA, and your organization's configuration and use of the Service
are your instructions — unless processing is required by law (in which case we inform
you unless prohibited).
- We ensure persons authorized to process Customer Personal Data are bound by
confidentiality obligations.
- We implement appropriate technical and organizational measures (Section 6).
- We assist you, taking into account the nature of the processing, in responding to
data-subject requests (access, rectification, erasure, portability, restriction,
objection) and, insofar as information is available to us, with your obligations
regarding security, breach notification, and data-protection impact assessments.
- We notify you without undue delay after becoming aware of a
Personal Data breach affecting Customer Personal Data, with the information reasonably
available to us as it becomes available.
4. Subprocessors
- You give general authorization for our use of subprocessors. Current subprocessors:
Supabase, Inc. (cloud database, authentication, and storage
infrastructure; USA); Stripe, Inc. (payment processing for
organization subscriptions — billing contact, address, tax ID, and transaction data;
USA; PCI DSS Level 1); Netlify, Inc. (website hosting and the
serverless functions that operate checkout and billing flows — routing of billing
contact and subscription metadata; USA); Google LLC (place data
enrichment for DealerMap Live via our server-side proxy — dealer business names and
coordinates are sent to Google's Places service, ratings and hours are returned;
USA; active for organizations with DealerMap Live enrichment); and
ImprovMX (support-email forwarding — the sender's name, address,
and message content of mail to our support addresses transit it; EU/USA).
Cardholder data is captured directly by Stripe and never transits our systems or
our host's functions.
- We will impose data-protection obligations on subprocessors that are no less
protective than this DPA and remain responsible for their performance.
- We will give at least 30 days' notice (via this page's version history or email)
before adding or replacing a subprocessor; you may object on reasonable
data-protection grounds, and if we cannot accommodate the objection you may terminate
the affected service.
5. International transfers
We are based in the United States and process data on U.S. infrastructure. Where
Customer Personal Data is transferred from the EU/UK to the U.S., the parties rely on
the EU Standard Contractual Clauses (module two, controller-to-processor), which are
incorporated by reference with you as data exporter and us as data importer (and the UK
Addendum where UK GDPR applies), and/or on our infrastructure providers' participation
in recognized transfer frameworks, consistent with the Privacy Policy.
6. Security measures
Taking into account the state of the art and the nature of the data, we maintain
measures including: encryption in transit (HTTPS/TLS); passwords handled by the
authentication provider and stored only as one-way hashes; per-row database access
controls (row-level security) isolating each organization's data; role-based access
within organizations; an append-only audit log of administrative actions; and least-
privilege access for operations. Details are described in the Privacy Policy.
7. Deletion & return
The Service provides self-service export (CSV) of your organization's data at any time.
On termination of the agreement, or on your written instruction, we will delete Customer
Personal Data, except where retention is required by law and except that de-identified
organization business records are handled as described in the Privacy Policy and Terms.
Account deletion by an individual data subject follows the in-app deletion flow.
8. Audit
On written request no more than once per 12 months, we will make available information
reasonably necessary to demonstrate compliance with this DPA (documentation,
summaries of measures, and subprocessor attestations where available). Where Data
Protection Laws grant you a mandatory audit right that cannot be satisfied by
documentation, an audit will be scheduled on reasonable notice, during business hours,
no more than annually, at your expense, and subject to confidentiality.
9. Liability; order of precedence; term
Each party's liability under this DPA is subject to the limitations of liability in the
Terms (or the MSA, if executed). If this DPA conflicts with the Terms, this DPA controls
for data-protection matters. This DPA applies for as long as we process Customer
Personal Data on your behalf.
10. Contact
Data-protection questions and notices: support@dealermap.app
— No Rest for the Wicked LLC (doing business as DealerMap), Washington, USA.