Legal

Data Processing Addendum

Version 1.4 — September 29, 2026 (added §11, U.S. State Privacy Laws — Service-Provider Terms; added Resend — transactional account, billing, and security email — to §4, recording a subprocessor in live use since August 2026; §7 now sets out the organization retention schedule — read-only for 90 days, a final export notice, closing 14 days later, deletion 30 days after closing — and adds the encrypted-backup retention disclosure — deleted data ages out of disaster-recovery backups within up to 35 days)

This Data Processing Addendum (“DPA”) forms part of the DealerMap Terms of Service (or a mutually executed Master Subscription Agreement, if one exists) between No Rest for the Wicked LLC (doing business as DealerMap; the “Processor,” “we,” “us”) and the customer organization using the Service (the “Controller,” “you”). It applies where and to the extent we process Personal Data on your behalf subject to Data Protection Laws (including GDPR, UK GDPR, and comparable U.S. state laws).

1. Definitions

“Personal Data,” “processing,” “controller,” “processor,” “data subject,” and “supervisory authority” have the meanings given in the applicable Data Protection Laws. “Customer Personal Data” means Personal Data contained in Customer Content that we process on your behalf to provide the Service.

2. Roles; scope & details of processing

3. Our obligations as processor

4. Subprocessors

5. International transfers

We are based in the United States and process data on U.S. infrastructure. Where Customer Personal Data is transferred from the EU/UK to the U.S., the parties rely on the EU Standard Contractual Clauses (module two, controller-to-processor), which are incorporated by reference with you as data exporter and us as data importer (and the UK Addendum where UK GDPR applies), and/or on our infrastructure providers' participation in recognized transfer frameworks, consistent with the Privacy Policy.

6. Security measures

Taking into account the state of the art and the nature of the data, we maintain measures including: encryption in transit (HTTPS/TLS); passwords handled by the authentication provider and stored only as one-way hashes; per-row database access controls (row-level security) isolating each organization's data; role-based access within organizations; an append-only audit log of administrative actions; and least- privilege access for operations. Details are described in the Privacy Policy.

7. Deletion & return

The Service provides self-service export (CSV) of your organization's data while its plan is active and while it is read-only. When your organization's free trial ends without a plan, or its subscription or agreement ends, the organization becomes read-only for ninety (90) days, during which its administrators can read and export its data; we then show its members a final export notice in the app and the console, and the organization closes fourteen (14) days later. For thirty (30) days after closing, we will provide an export on your written request. We then delete the organization's data, including the Customer Personal Data in it (its shared notes, reports, imported files, settings, members list, and audit log), within ten (10) business days, except where retention is required by law (such as billing and tax records) and except for aggregated or de-identified data as described in the Terms (Section 4). Paying again before the organization closes stops this schedule. On your written instruction, we will delete Customer Personal Data sooner. Individual user accounts, and notes on an individual's personal (non-organization) account, belong to those individuals under the Terms and are not deleted with the organization. Account deletion by an individual data subject follows the in-app deletion flow; business records that individual contributed stay with the organization in de-identified form, as described in the Privacy Policy and Terms. Customer Personal Data contained in encrypted disaster-recovery backups is deleted through scheduled backup expiration (currently up to thirty-five (35) days) rather than immediate destruction; we do not restore deleted Customer Personal Data to the live Service except transiently as part of a disaster recovery, in which case deletions completed before the restore are re-applied.

8. Audit

On written request no more than once per 12 months, we will make available information reasonably necessary to demonstrate compliance with this DPA (documentation, summaries of measures, and subprocessor attestations where available). Where Data Protection Laws grant you a mandatory audit right that cannot be satisfied by documentation, an audit will be scheduled on reasonable notice, during business hours, no more than annually, at your expense, and subject to confidentiality.

9. Liability; order of precedence; term

Each party's liability under this DPA is subject to the limitations of liability in the Terms (or the MSA, if executed). If this DPA conflicts with the Terms, this DPA controls for data-protection matters. This DPA applies for as long as we process Customer Personal Data on your behalf.

10. Contact

Data-protection questions and notices: support@dealermap.app — No Rest for the Wicked LLC (doing business as DealerMap), Washington, USA.

11. U.S. State Privacy Laws — Service-Provider Terms

11.1 Scope and definitions. This Section 11 applies to Personal Data (called “personal information” under the CCPA) that we process on your behalf and that is subject to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, Cal. Civ. Code §1798.100 et seq., and its implementing regulations (together, the “CCPA”), or to a comparable U.S. state privacy law (including the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Texas Data Privacy and Security Act — each an “Other State Privacy Law”). “Sell,” “share,” “service provider,” “processor,” “business purpose,” “commercial purpose,” “consumer,” and “de-identified” have the meanings given in the applicable law. For personal information within the scope of this Section, you are the “business” (or “controller”) and we act as your “service provider” (or “processor”). If this Section conflicts with any other provision of this DPA, this Section controls for personal information within its scope.

11.2 Employee and business-contact data. The parties acknowledge that the CCPA's former employment-related and business-to-business exemptions expired on January 1, 2023. Personal information of your organization's members (your employees, contractors, and sales representatives — names, business email addresses, account identifiers, role and territory assignments, and activity records) and of business contacts recorded in prospecting notes is within the scope of this Section to the extent the CCPA or an Other State Privacy Law applies to you.

11.3 Limited and specified purposes. We process personal information only for the business purposes described in Section 2 of this DPA and in the Agreement — hosting, storage, synchronization, display to authorized organization members, backup, security monitoring, abuse and bug detection, support, and export — and for no commercial purpose of our own. Our retention, use, and disclosure of personal information is limited to what is reasonably necessary and proportionate to provide the Service.

11.4 Prohibitions. We will not:

11.5 Compliance; certification. We certify that we understand the restrictions in Section 11.4 and will comply with them. We will comply with all obligations the CCPA places directly on service providers, including providing the same level of privacy protection as the CCPA requires of you with respect to the personal information.

11.6 Consumer requests. We will assist you, by appropriate technical and organizational measures, in responding to verifiable consumer requests to know, access, correct, delete, and limit the use of personal information (Section 3 of this DPA). The Service's built-in tools form part of that assistance: self-service CSV export of your organization's data; in-app account deletion (which deletes the individual's personal information and de-identifies authorship on business records your organization retains); and administrator controls over organization records. If a consumer request is submitted directly to us concerning data we process on your behalf, we will forward it to you promptly and will not respond on your behalf except at your documented instruction or where the law requires us to respond.

11.7 Notification; your right to remediate. We will notify you without undue delay if we determine that we can no longer meet our obligations under this Section. Upon reasonable notice, you may take reasonable and appropriate steps to ensure that we use personal information in a manner consistent with your obligations under the CCPA, and to stop and remediate any unauthorized use of personal information. The parties agree that the information, documentation, and audit mechanics of Section 8 (Audit) of this DPA are the agreed means of exercising these rights, and satisfy them.

11.8 Subcontractors (subprocessors). We engage the subprocessors listed in Section 4 of this DPA — Supabase, Inc. (cloud database, authentication, and storage); Stripe, Inc. (payment processing); Netlify, Inc. (website hosting and checkout/billing functions); Google LLC (place enrichment for DealerMap Live via our server-side proxy — dealer business names and coordinates only; no personal information of your members or contacts is forwarded); ImprovMX (support-email forwarding); and Resend, Inc. (transactional account, billing, and security email) — under written contracts imposing obligations no less protective than this Section, and we remain responsible for their performance. New or replacement subprocessors follow the notice-and-objection mechanics of Section 4 (at least 30 days' notice). Section 4 is our current subprocessor disclosure for purposes of any Other State Privacy Law that requires one.

11.9 No monetary consideration for data. The parties acknowledge that you do not sell personal information to us and that we provide nothing of value in exchange for it; personal information is disclosed to us only for the business purposes stated in Section 11.3.

11.10 De-identified and aggregated data. Where we create de-identified or aggregated data as permitted by the Agreement (Terms §4), we will: (a) take reasonable measures to ensure the data cannot be associated with a consumer or household; (b) publicly commit — and by this Section do commit — to maintain and use such data only in de-identified form and not to attempt to re-identify it, except as permitted by the CCPA to test the effectiveness of de-identification; and (c) contractually obligate any recipient of such data to comply with the foregoing. Data meeting these conditions is not “personal information,” and nothing in this Section restricts our use of it.

11.11 Other State Privacy Laws — processor duties. For personal information subject to an Other State Privacy Law: we will adhere to your processing instructions as documented in this DPA and the Agreement; ensure each person processing the personal information is subject to a duty of confidentiality; engage subprocessors only under written contract as described in Section 11.8; provide you the information reasonably necessary to conduct and document data protection assessments, taking into account the nature of our processing and the information available to us; at your direction, delete or return personal information as provided in Section 7 of this DPA; and make available the compliance information and audit mechanics of Section 8 of this DPA.

11.12 Sensitive personal information. The Service does not require, and is not intended to collect, sensitive personal information as defined by the CCPA, and you agree not to submit it. The Service does not collect precise geolocation: device location is used on the device only, to center the map, and is never transmitted to or stored on our servers, as stated in the Privacy Policy.