Data Processing Addendum
Version 2026-09-25.2
Draft — attorney review required before commercial launch. Bracketed items are still being filled in.
The short version
- Your agency is in charge of its team and customer information. We process it only to run AgencyHuddleHQ for you, following your instructions.
- We don't sell it, share it for ads, use it for anyone else, or use it to train AI.
- We protect it, tell you quickly if something goes wrong, help you answer privacy requests, and delete it when you leave.
1. Who this is between, and how it fits
This Data Processing Addendum ("DPA") is between AgencyHuddleHQ, LLC, a Colorado limited liability company ("AgencyHuddleHQ," "we"), and the agency or business that subscribes to AgencyHuddleHQ ("Customer," "you"). It is part of the Terms of Service. If the Terms and this DPA disagree about personal information, this DPA wins.
The agency owner accepts this DPA for the Customer during setup and confirms they have authority to do so. We record who accepted, which version, and when.
2. Definitions
- Customer Personal Data: personal information in Customer Data (as defined in the Terms) that we process for the Customer.
- Data Protection Laws: all US privacy and data security laws that apply to the processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations ("CCPA"), the Colorado Privacy Act and its rules ("CPA"), other US state consumer privacy laws, and, where they apply, the Gramm-Leach-Bliley Act and state insurance privacy and data security laws.
- Security Incident: a confirmed breach of security that leads to accidental or unlawful destruction, loss, change, or unauthorized disclosure of, or access to, Customer Personal Data.
- Subprocessor: another company we use that processes Customer Personal Data for us.
- Terms like "business," "controller," "service provider," "contractor," "processor," "consumer," "sell," "share," and "business purpose" mean what the Data Protection Laws say they mean.
3. Roles
- The Customer is the business (CCPA) and controller (CPA and other state laws) for Customer Personal Data.
- AgencyHuddleHQ is the Customer's service provider (CCPA) and processor (CPA and other state laws).
- The Customer is responsible for having a lawful basis to collect Customer Personal Data and put it into the Service, and for giving the notices it owes its team members and customers.
4. What we process, and why
Business purpose. We process Customer Personal Data only to provide the Service described in the Terms, and for the related purposes the CCPA allows a service provider: keeping the Service secure and working, fixing errors, supporting the Customer, and meeting legal obligations. The details are in Annex 1.
Instructions. The Terms, this DPA, and the Customer's settings and actions in the app are the Customer's instructions. We'll tell you if we believe an instruction breaks the law.
5. Service provider and processor commitments
We will not:
- sell or share Customer Personal Data;
- keep, use, or disclose Customer Personal Data for any purpose other than the business purposes in section 4, including any other commercial purpose;
- keep, use, or disclose it outside our direct business relationship with the Customer;
- combine it with personal information we get from anyone else, or from our own interactions with individuals, except as the CCPA regulations allow a service provider;
- use it to train, fine-tune, or improve any artificial intelligence model, or let anyone else do so;
- use it to build profiles for any other business or for advertising.
We will:
- comply with the Data Protection Laws that apply to us and give Customer Personal Data the same level of privacy protection they require of the Customer;
- tell the Customer within 5 business days if we decide we can no longer meet our obligations under the Data Protection Laws;
- allow the Customer to take reasonable, appropriate steps to make sure we use Customer Personal Data consistently with the Customer's obligations, and, after notice, to stop and fix unauthorized use (section 12 describes how);
- require every person who works with Customer Personal Data to keep it confidential;
- help the Customer meet its obligations as described in sections 8 through 11.
We certify that we understand these restrictions and will comply with them.
6. Subprocessors
- The Customer authorizes the Subprocessors in Annex 3.
- Each Subprocessor is bound by a written contract with data protection terms at least as protective as this DPA for the service it provides.
- We'll give at least 30 days' notice (by email to the owner and in the app) before adding or replacing a Subprocessor. If the Customer reasonably objects and we can't resolve it, the Customer may cancel before the change takes effect and won't be charged for any later month.
- We remain responsible for our Subprocessors' work.
7. Where data is processed
Customer Personal Data is stored in the United States (AWS, Oregon region, us-west-2). AI requests are processed in AWS regions in the United States. We won't move Customer Personal Data outside the United States without 30 days' notice to the Customer.
8. Security
We keep reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including the measures in Annex 2. These safeguards are designed to help Customers meet their obligations as insurance licensees overseeing third-party service providers under state insurance data security laws. We may improve our measures over time but won't reduce the overall level of protection.
9. Security Incidents
- We'll notify the Customer without undue delay, and no later than 72 hours, after we confirm a Security Incident affecting its Customer Personal Data.
- We'll share what we know, as we learn it: what happened, what data and people are affected, what we're doing about it, and a contact person.
- We'll take reasonable steps to contain it and prevent it from happening again, and cooperate with the Customer's investigation and any notices it must send.
- The Customer decides whether and how to notify its team members, customers, carriers, and regulators, unless the law requires us to notify someone directly.
- Our notice isn't an admission of fault.
10. Helping with privacy requests and assessments
- Individual requests. The app lets the owner and office managers see, correct, export, and remove information about team members and customers. If we receive a request directly about Customer Personal Data, we'll tell the person to contact the Customer, and send the request to the Customer within 5 business days (with the person's permission, where needed). We won't respond on the Customer's behalf except as the Customer directs.
- Assessments. We'll give the Customer information it reasonably needs for its data protection assessments, risk assessments, and vendor security questionnaires.
- Regulators. We'll cooperate with reasonable requests from regulators, through the Customer when possible.
11. Returning and deleting data
- The owner can export Customer Data from the app at any time, and for 30 days after the account ends.
- After that, we delete Customer Personal Data within 60 days. Backup copies are overwritten within 35 days after that.
- We may keep information only where the law requires, and then only for as long as it requires, and we'll keep protecting it under this DPA.
- On request, we'll confirm deletion in writing.
12. Showing compliance (audits)
- We'll answer a reasonable written security and privacy questionnaire once a year, and provide our most recent independent assessment report (such as a penetration test summary or audit report) when we have one.
- If that isn't enough to show compliance, the Customer (or an independent auditor bound by confidentiality) may audit once a year with 30 days' notice, during business hours, at the Customer's cost, in a way that doesn't expose other customers' data. The once-a-year limit doesn't apply after a Security Incident or when a regulator requires an audit.
13. Government and legal requests
If a government or court asks us for Customer Personal Data, we'll send it to the Customer when we can, notify the Customer before we respond unless the law prohibits it, and disclose only what we're legally required to.
14. Liability and term
This DPA lasts as long as we process Customer Personal Data. The liability terms in the Terms of Service apply to this DPA. Sections that by their nature should survive (such as 5, 9, 11, and 13) survive.
Annex 1: Details of processing
| Subject matter | Providing the AgencyHuddleHQ Service |
| Duration | The Customer's subscription, plus the export and deletion periods in section 11 |
| Nature of processing | Storing, organizing, calculating, displaying, exporting, backing up, and deleting |
| Purposes | Activity tracking, win-the-day goals, leaderboards and office TV displays, sales log and pipeline, household multiline grouping, team pay plans and payroll reports, carrier commission tracking, budgets, profit and loss, cash flow, marketing reports, AI setup and help features, account security, and support |
| People the data is about | The Customer's owners, office managers, and team members; the Customer's customers and leads (by name only) |
| Types of personal data | Team: name, work email, role, office, activity counts, sales credited, performance results, pay plan terms, pay rates, hours, payroll amounts, change history. Customers and leads: name, products bought, premium and deposit amounts, sale status, lead source. Accounts: sign-in email, password hash, sign-in history, IP address, browser type. |
| Sensitive data | Account log-in credentials only, used only for sign-in and security |
| Data the Customer must not enter | Social Security, driver's license, and passport numbers; dates of birth; policy, bank, or card numbers; health information; customers' contact details |
Annex 2: Security measures
In place today:
- TLS 1.2 or newer on every connection; TLS 1.0 and 1.1 refused; plain HTTP redirected to HTTPS.
- Stored data encrypted, including the database and its backups.
- The database sits on a private network with no internet access and requires TLS 1.2+.
- Passwords stored only as bcrypt hashes. Session, invite, reset, and office TV tokens stored only as hashes.
- Each agency's data is separated from every other agency's by a single enforced access layer in the code, backed by database checks that refuse cross-agency links, and tested automatically.
- Role-based access checked on the server for every sensitive page and action; team members can see only their own pay.
- A change history (who, when, before and after) for sales, credits, activity, settings, and payroll; payroll months lock after approval.
- Nightly backups with deletion protection.
- Credentials kept in a secrets manager, not in code. Deployments use short-lived credentials.
- Customer data is never used for AI training, and AI prompt logging is off.
[Draft note: being added before commercial launch, per the security plan] two-step sign-in (required for owners and managers first), sign-in rate limits and lockouts, emailed reset links, account-wide security monitoring and alerts, a write-once security activity trail, longer backup retention with tested restores, browser security headers, a web firewall, container vulnerability scanning, database row-level security, an app-only database user, and a written incident response plan. Once these are live, move them into the list above.
Annex 3: Subprocessors
| Subprocessor | What it does | Where |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, file storage, backups, logs, email delivery (Amazon SES), and AI (Amazon Bedrock, running Anthropic Claude models inside AWS) | United States |
| Stripe, Inc. (when billing is live) | Subscription billing and card payments. Receives the owner's billing contact details, not team or customer data. | United States |
Anthropic, the maker of the Claude models, does not receive Customer Personal Data: the models run inside AWS, and AWS doesn't share Bedrock inputs or outputs with model providers.
