Data Processing Agreement
Effective September 8, 2026 · Last updated September 8, 2026
This Data Processing Agreement forms part of the Terms of Service between Eyes Up LLC ("Processor," "we") and the business using AutoCheckups ("Controller," "you"). It takes effect when you begin using the service and needs no separate signature, though we will sign a copy on request.
1.Roles
You are the controller of your customers' personal information. You decide what data is collected, from whom, for what purpose, and on what legal basis. You are responsible for obtaining and documenting the consents described in Section 3 of the Terms of Service.
We are the processor. We handle that information only to deliver the service, only on your documented instructions, and for no purpose of our own.
Where the California Consumer Privacy Act applies, we act as a "service provider" and not as a "third party." We do not sell or share personal information, and we do not retain, use, or disclose it for any purpose other than performing the service or as otherwise permitted by that Act. We certify that we understand and will comply with these restrictions.
2.What is processed
| Subject matter | Automated customer follow-up messaging on the Controller's behalf. |
|---|---|
| Duration | The term of the Terms of Service, plus the deletion periods in Section 8. |
| Nature and purpose | Storage, scheduling, message generation and delivery, feedback collection and routing, reporting, and consent record-keeping. |
| Categories of data subject | The Controller's customers. |
| Categories of personal data | Name or initials, email address, mobile phone number, purchase and last-visit dates, customer identifier, message and delivery history, survey ratings and comments, consent and opt-out records. |
| Special category data | None. The Controller must not submit health, biometric, financial account, government identifier, or other sensitive data. |
3.Our obligations
- We process personal data only on your documented instructions, which consist of the Terms, this Agreement, and your service configuration. If we believe an instruction violates applicable law, we will tell you and may pause that instruction.
- We ensure that anyone authorised to process the data is bound by confidentiality.
- We implement appropriate technical and organisational measures, described in Annex A.
- We do not sell, rent, or disclose personal data except as set out in this Agreement.
- We do not use the data to train machine-learning models or to build our own marketing lists.
- We assist you, at your cost where the effort is substantial, in meeting your own obligations for security, breach notification, impact assessments, and regulator consultation.
4.Your obligations
- You warrant that you have a lawful basis and documented consent for every individual whose data you provide, as set out in Section 3 of the Terms.
- You will not submit data outside the categories listed in Section 2.
- You will keep your own copy of consent records and produce them on request.
- You will pass on opt-out and deletion requests you receive directly, promptly.
- You are responsible for the accuracy of the data you provide and for the security of your own Google account and any device that can reach your customer sheet.
5.Sub-processors
You give general authorisation for us to engage the sub-processors listed below. Each is bound by data protection obligations no less protective than those in this Agreement.
| Sub-processor | Function | Location |
|---|---|---|
| Google LLC | Spreadsheet storage and access | United States |
| Twilio SendGrid, Inc. | Email delivery | United States |
| Twilio Inc. | Text message delivery | United States |
| n8n GmbH | Workflow execution and scheduling | European Union |
| Stripe, Inc. | Payment processing (Controller billing data only) | United States |
| Netlify, Inc. | Website and form hosting | United States |
We will give at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you on an alternative; if none is workable, either party may terminate the affected part of the service without penalty, and we will refund any prepaid unused fees.
6.Data subject requests
If we receive a request from one of your customers to access, correct, delete, or port their data, we will not respond substantively ourselves. We will forward it to you without undue delay and give you the technical assistance needed to respond, including locating, exporting, correcting, or deleting the relevant records.
The exception is opt-out requests. We honour STOP replies and email unsubscribes immediately and automatically, across every Controller on our platform, and record the opt-out. We do this because the alternative is continuing to message someone who has asked us not to.
7.Security incidents
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what we know about the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the steps taken or proposed.
We will not make public statements or notify your customers about a breach affecting your data without consulting you first, unless required by law.
8.Return and deletion
- You can export your data at any time during the term; it lives in a spreadsheet in your own account.
- On termination, we will provide a CSV export on request within 30 days.
- We will delete your customer data from active systems within 60 days of termination.
- We retain consent and opt-out records for 5 years after the last message sent, as a legal compliance requirement. This is an exception to deletion and applies notwithstanding a deletion request.
- Backups persist until ordinary expiry and are then overwritten. We will not restore deleted data from backup for operational use.
9.Audit
On reasonable written request, no more than once in any 12-month period, we will provide the information reasonably necessary to demonstrate compliance with this Agreement, including a written description of our security measures and answers to a reasonable security questionnaire. On-site audits are available where required by law, at your expense, on 30 days' notice, during business hours, and subject to confidentiality.
10.International transfers
Personal data is processed primarily in the United States. Our workflow sub-processor operates in the European Union. Where a transfer requires a specific mechanism under applicable law, the parties will put an appropriate one in place, and Standard Contractual Clauses are incorporated by reference where they apply.
11.Liability and precedence
Liability under this Agreement is subject to the limitation of liability in Section 12 of the Terms of Service. Your indemnity in Section 11 of the Terms applies to claims arising from data you provided without valid consent.
If this Agreement conflicts with the Terms of Service on a data protection matter, this Agreement controls. On all other matters, the Terms control.
12.Annex A — Security measures
- Access control. Credentials are held in a managed secret store, not in workflow code. Access is limited to personnel who need it to operate the service.
- Encryption. Data is encrypted in transit using TLS. Storage encryption is provided by the underlying platforms.
- Authentication. Multi-factor authentication is enabled on administrative accounts for the platforms listed in Section 5.
- Link security. Survey and unsubscribe links use single-purpose tokens rather than guessable identifiers, and require a two-step confirmation so that automated mail scanners cannot trigger them.
- Rate limiting. Public endpoints are rate limited to resist enumeration and abuse.
- Separation. Each Controller's customer data is held in a separate spreadsheet, not in a shared table.
- Minimisation. We collect only the fields needed to schedule and send messages, and instruct Controllers not to submit sensitive categories.
- Monitoring. Failed runs and delivery errors raise alerts to the operator.
13.Contact
Eyes Up LLC, d/b/a AutoCheckups
[ADD FULL MAILING ADDRESS BEFORE PUBLISHING]
support@checkup.autos
(908) 310-7143