Legal

Data Processing Addendum

Version 1.3 — July 26, 2026 (subprocessor notice extended to 30 days; added Google — place enrichment for DealerMap Live — and ImprovMX — support-email forwarding)

This Data Processing Addendum (“DPA”) forms part of the DealerMap Terms of Service (or a mutually executed Master Subscription Agreement, if one exists) between No Rest for the Wicked LLC (doing business as DealerMap; the “Processor,” “we,” “us”) and the customer organization using the Service (the “Controller,” “you”). It applies where and to the extent we process Personal Data on your behalf subject to Data Protection Laws (including GDPR, UK GDPR, and comparable U.S. state laws).

1. Definitions

“Personal Data,” “processing,” “controller,” “processor,” “data subject,” and “supervisory authority” have the meanings given in the applicable Data Protection Laws. “Customer Personal Data” means Personal Data contained in Customer Content that we process on your behalf to provide the Service.

2. Roles; scope & details of processing

3. Our obligations as processor

4. Subprocessors

5. International transfers

We are based in the United States and process data on U.S. infrastructure. Where Customer Personal Data is transferred from the EU/UK to the U.S., the parties rely on the EU Standard Contractual Clauses (module two, controller-to-processor), which are incorporated by reference with you as data exporter and us as data importer (and the UK Addendum where UK GDPR applies), and/or on our infrastructure providers' participation in recognized transfer frameworks, consistent with the Privacy Policy.

6. Security measures

Taking into account the state of the art and the nature of the data, we maintain measures including: encryption in transit (HTTPS/TLS); passwords handled by the authentication provider and stored only as one-way hashes; per-row database access controls (row-level security) isolating each organization's data; role-based access within organizations; an append-only audit log of administrative actions; and least- privilege access for operations. Details are described in the Privacy Policy.

7. Deletion & return

The Service provides self-service export (CSV) of your organization's data at any time. On termination of the agreement, or on your written instruction, we will delete Customer Personal Data, except where retention is required by law and except that de-identified organization business records are handled as described in the Privacy Policy and Terms. Account deletion by an individual data subject follows the in-app deletion flow.

8. Audit

On written request no more than once per 12 months, we will make available information reasonably necessary to demonstrate compliance with this DPA (documentation, summaries of measures, and subprocessor attestations where available). Where Data Protection Laws grant you a mandatory audit right that cannot be satisfied by documentation, an audit will be scheduled on reasonable notice, during business hours, no more than annually, at your expense, and subject to confidentiality.

9. Liability; order of precedence; term

Each party's liability under this DPA is subject to the limitations of liability in the Terms (or the MSA, if executed). If this DPA conflicts with the Terms, this DPA controls for data-protection matters. This DPA applies for as long as we process Customer Personal Data on your behalf.

10. Contact

Data-protection questions and notices: support@dealermap.app — No Rest for the Wicked LLC (doing business as DealerMap), Washington, USA.