Home   Terms of Service   Privacy Policy

Data Processing Agreement

Effective September 8, 2026 · Last updated September 8, 2026

This Data Processing Agreement forms part of the Terms of Service between Eyes Up LLC ("Processor," "we") and the business using AutoCheckups ("Controller," "you"). It takes effect when you begin using the service and needs no separate signature, though we will sign a copy on request.

1.Roles

You are the controller of your customers' personal information. You decide what data is collected, from whom, for what purpose, and on what legal basis. You are responsible for obtaining and documenting the consents described in Section 3 of the Terms of Service.

We are the processor. We handle that information only to deliver the service, only on your documented instructions, and for no purpose of our own.

Where the California Consumer Privacy Act applies, we act as a "service provider" and not as a "third party." We do not sell or share personal information, and we do not retain, use, or disclose it for any purpose other than performing the service or as otherwise permitted by that Act. We certify that we understand and will comply with these restrictions.

2.What is processed

Subject matterAutomated customer follow-up messaging on the Controller's behalf.
DurationThe term of the Terms of Service, plus the deletion periods in Section 8.
Nature and purposeStorage, scheduling, message generation and delivery, feedback collection and routing, reporting, and consent record-keeping.
Categories of data subjectThe Controller's customers.
Categories of personal dataName or initials, email address, mobile phone number, purchase and last-visit dates, customer identifier, message and delivery history, survey ratings and comments, consent and opt-out records.
Special category dataNone. The Controller must not submit health, biometric, financial account, government identifier, or other sensitive data.

3.Our obligations

4.Your obligations

5.Sub-processors

You give general authorisation for us to engage the sub-processors listed below. Each is bound by data protection obligations no less protective than those in this Agreement.

Sub-processorFunctionLocation
Google LLCSpreadsheet storage and accessUnited States
Twilio SendGrid, Inc.Email deliveryUnited States
Twilio Inc.Text message deliveryUnited States
n8n GmbHWorkflow execution and schedulingEuropean Union
Stripe, Inc.Payment processing (Controller billing data only)United States
Netlify, Inc.Website and form hostingUnited States

We will give at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you on an alternative; if none is workable, either party may terminate the affected part of the service without penalty, and we will refund any prepaid unused fees.

6.Data subject requests

If we receive a request from one of your customers to access, correct, delete, or port their data, we will not respond substantively ourselves. We will forward it to you without undue delay and give you the technical assistance needed to respond, including locating, exporting, correcting, or deleting the relevant records.

The exception is opt-out requests. We honour STOP replies and email unsubscribes immediately and automatically, across every Controller on our platform, and record the opt-out. We do this because the alternative is continuing to message someone who has asked us not to.

7.Security incidents

We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what we know about the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the steps taken or proposed.

We will not make public statements or notify your customers about a breach affecting your data without consulting you first, unless required by law.

8.Return and deletion

9.Audit

On reasonable written request, no more than once in any 12-month period, we will provide the information reasonably necessary to demonstrate compliance with this Agreement, including a written description of our security measures and answers to a reasonable security questionnaire. On-site audits are available where required by law, at your expense, on 30 days' notice, during business hours, and subject to confidentiality.

10.International transfers

Personal data is processed primarily in the United States. Our workflow sub-processor operates in the European Union. Where a transfer requires a specific mechanism under applicable law, the parties will put an appropriate one in place, and Standard Contractual Clauses are incorporated by reference where they apply.

11.Liability and precedence

Liability under this Agreement is subject to the limitation of liability in Section 12 of the Terms of Service. Your indemnity in Section 11 of the Terms applies to claims arising from data you provided without valid consent.

If this Agreement conflicts with the Terms of Service on a data protection matter, this Agreement controls. On all other matters, the Terms control.

12.Annex A — Security measures

13.Contact

Eyes Up LLC, d/b/a AutoCheckups
[ADD FULL MAILING ADDRESS BEFORE PUBLISHING]
support@checkup.autos
(908) 310-7143