DATA PROCESSING ADDENDUM (Version 1.0)
This Data Processing Addendum (this “Addendum”) is entered into as of the date Client accepts the Agreement (the “Effective Date”) by and between NEMROOT TECHNOLOGIES LLC, a Texas limited liability company (“Provider”), and the dealership identified as Customer in the Order Form or other Subscription Documentation (“Client”), and is incorporated into and made part of the Dealer Terms of Service between the parties (the “Agreement”). Provider and Client may be referred to individually as a “Party” and collectively as the “Parties.”
Article 1 — Definitions
I. Defined terms. Capitalized terms used but not defined in this Addendum have the meanings given to them in the Agreement. For purposes of this Addendum, the following terms apply:
A. “Applicable Privacy Laws” means all United States federal, state, and local laws, rules, and regulations applicable to a Party’s Processing of Personal Data under the Agreement, including, to the extent applicable, comprehensive state consumer privacy laws, state data security and breach notification laws, state biometric privacy laws, state consumer protection laws, the Telephone Consumer Protection Act, CAN-SPAM Act, Telemarketing Sales Rule, and state telemarketing, electronic communications, call-recording, and consent laws.
B. “Client Data” means Personal Data submitted to, collected by, generated through, or otherwise Processed during the provision of Services on behalf of Client, including Consumer Data and Dealer Staff Data, and as further described in the Agreement.
C. “Consumer Data” means Personal Data relating to prospective, current, or former purchasers, lessees, service customers, callers, message recipients, website visitors, leads, or other natural persons who interact with Client or Provider in connection with Client’s dealership operations, whether or not such individuals create an account or log in to the Services.
D. “Controller” means the Party that determines the purposes and means of Processing Personal Data, and includes analogous terms such as “business” under Applicable Privacy Laws.
E. “Dealer Staff Data” means Personal Data relating to Client’s owners, officers, employees, contractors, agents, representatives, and authorized users of the Services, including names, business contact information, credentials, account activity, communications activity, and dashboard or performance-related usage data.
F. “Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable natural person or household, provided that Provider maintains and uses such data in deidentified form and does not attempt to reidentify it except as permitted by Applicable Privacy Laws to test or validate deidentification.
G. “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, and includes “personal information,” “personal data,” and similar terms under Applicable Privacy Laws.
H. “Process” or “Processing” means any operation or set of operations performed on Personal Data, including collection, receipt, access, use, storage, disclosure, transmission, analysis, recording, transcription, summarization, deletion, or return.
I. “Processor” means the Party that Processes Personal Data on behalf of a Controller, and includes analogous terms such as “service provider,” “contractor,” or “processor” under Applicable Privacy Laws.
J. “Security Incident” means a confirmed unauthorized acquisition of, access to, use of, disclosure of, alteration of, or loss of Client Data in Provider’s possession or control that compromises the security, confidentiality, or integrity of such Client Data. Security Incident does not include unsuccessful attempts or activities that do not compromise Client Data, including pings, port scans, blocked firewall attacks, unsuccessful login attempts, denial-of-service attempts, or other immaterial security events.
K. “Sensitive Data” means a category of especially sensitive Personal Data including, racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality or sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, Personal Data from or about a known child under 13 years old, and precise geolocation data.
L. “Services” means Provider’s U.S.-only SaaS or licensed application used by automobile dealerships for day-to-day CRM-related communications and operations, including integrations with dealership websites, CRM systems, DMS systems, DealerCenter, messaging channels, lead sources, AI voice bot functionality, call recording, transcription, summarization, dealership-number calling and texting, department routing, business-hours rules, Facebook Marketplace listing, Meta ad syndication, Google review requests, and related support or professional services, as further described in the Agreement.
M. “Subprocessor” means any third party engaged by Provider to Process Client Data on behalf of Client in connection with the Services.
Article 2 — Scope; Order of Precedence
I. Scope. This Addendum governs Provider’s Processing of Client Data in connection with the Services in the United States only. The Parties do not intend the Services to be used by private buyers as authenticated end users; however, Consumer Data may be Processed when consumers interact with Client or the Services through calls, SMS, web chat, email, Facebook Messenger, Instagram direct messages, WhatsApp, inbound lead records, or other supported channels.
II. Relationship to Agreement. Except as modified by this Addendum, the Agreement remains in full force and effect. If there is a conflict between this Addendum and the Agreement regarding the Processing of Client Data, this Addendum controls. If there is a conflict between this Addendum and an exhibit or schedule to this Addendum, the main body of this Addendum controls unless the exhibit or schedule expressly states that it supersedes a specified provision of this Addendum.
III. No sale or sharing. Provider shall not sell Client Data or share Client Data for cross-context behavioral advertising, targeted advertising, or similar advertising purposes except to the extent expressly authorized in the Agreement or Schedule 1 and permitted under Applicable Privacy Laws. Provider shall not retain, use, or disclose Client Data outside the direct business relationship between Provider and Client except as permitted by this Addendum, the Agreement, Client’s documented instructions, or Applicable Privacy Laws.
IV. No consumer account requirement. The absence of a consumer account, login, or credential does not limit the protections applicable to Consumer Data under this Addendum.
Article 3 — Roles and Responsibilities
I. Client as Controller. As between the Parties, Client is the Controller of Client Data, except to the extent Provider acts as an independent Controller under Section III of this Article 3. Client determines the purposes and means of Processing Client Data in connection with Client’s dealership operations, including which consumers to contact, which channels to use, the content and timing of communications, the configuration of routing and business-hours rules, the creation and management of customer records, and the use of lead and dealership data within Client’s systems.
II. Provider as Processor. Provider shall Process Client Data as a Processor on behalf of Client and only for the following purposes:
A. providing, securing, maintaining, supporting, improving, and troubleshooting the Services;
B. enabling communications by or on behalf of Client through supported channels;
C. receiving, routing, recording, transcribing, summarizing, and storing calls, messages, leads, and related interaction data;
D. integrating with Client’s website, CRM, DMS, DealerCenter environment, lead providers, communications providers, social or messaging platforms, advertising platforms, review-request tools, and other Client-enabled systems;
E. generating operational dashboards, reporting, analytics, and performance information for Client’s dealership locations and staff;
F. complying with Client’s documented instructions and the Agreement; and
G. complying with legal obligations applicable to Provider.
III. Provider as independent Controller. Provider may Process limited Personal Data as an independent Controller for its own legitimate business purposes, including account administration, billing, fraud prevention, security, service improvement, legal compliance, and business records, provided that Provider complies with Applicable Privacy Laws and does not use Client Data for purposes prohibited by this Addendum.
IV. Client compliance responsibilities. Client is responsible for:
A. the accuracy, quality, legality, and lawful source of Client Data;
B. providing legally required notices, privacy disclosures, and consents to Consumers and Dealer Staff, including disclosures regarding automated communications, AI-assisted interactions, call recording, message recording, transcription, summarization, and use of third-party communication channels;
C. determining whether and how to contact Consumers by call, SMS, email, chat, social messaging, review request, or other channel;
D. honoring opt-outs, revocations of consent, do-not-call requests, unsubscribe requests, and similar communication preferences, except to the extent Provider is expressly responsible for automated suppression functionality under the Agreement;
E. ensuring that Client’s instructions to Provider comply with Applicable Privacy Laws; and
F. configuring the Services in accordance with Client’s legal and operational requirements.
V. Provider compliance responsibilities. Provider is responsible for:
A. Processing Client Data in accordance with this Addendum, the Agreement, Client’s documented instructions, and Applicable Privacy Laws applicable to Provider in its role as Processor;
B. implementing and maintaining the security measures described in Article 9 and Schedule 2;
C. ensuring that personnel authorized to Process Client Data are bound by confidentiality obligations;
D. assisting Client as set forth in this Addendum with consumer rights requests, Security Incidents, deletion or return, and compliance assessments; and
E. maintaining reasonable documentation sufficient to demonstrate Provider’s compliance with this Addendum.
Article 4 — Processing Details
I. Processing description. The subject matter, duration, nature, purpose, categories of Personal Data, categories of data subjects, processing activities, subprocessors, retention periods, and applicable service levels are described in Schedule 1.
II. Categories of Consumer Data. Consumer Data may include:
A. names, phone numbers, email addresses, mailing addresses, and other contact details;
B. automobiles of interest, shopping preferences, appointment information, financing-related inquiry content, and trade-in vehicle details;
C. message content and metadata across SMS, web chat, email, Facebook Messenger, Instagram direct messages, WhatsApp, and other supported communications channels;
D. inbound lead records from CarGurus, AutoTrader, Cars.com, TrueCar, Client’s website, third-party marketplaces, advertising campaigns, or other Client-enabled lead sources;
E. phone call audio, call recordings, transcripts, summaries, call timestamps, call duration, call routing data, and customer-record summaries;
F. IP addresses, device identifiers, browser details, usage logs, and similar automated information; and
G. other Personal Data submitted by or on behalf of Client through the Services.
III. Categories of Dealer Staff Data. Dealer Staff Data may include staff names, business contact details, role or department information, credentials, account activity, call and messaging activity, usage logs, dashboard metrics, performance-related activity data, and administrative or support information.
IV. Sensitive Data. Client shall not submit Sensitive Data to the Services unless the Agreement or Schedule 1 expressly permits such submission and the Parties have agreed on any additional controls required by Applicable Privacy Laws. Provider shall not create voiceprints, speaker-recognition templates, or other biometric identifiers from call recordings and shall not use recordings, transcripts, or audio data for biometric identification or authentication.
V. AI-enabled functionality. Provider may use AI-enabled functionality to answer inbound calls, place outbound calls as configured or instructed by Client, generate transcripts, summarize calls and messages, assist with customer-record creation, route communications, and support dealership workflows. Provider shall not use Client Data to train general-purpose models for use outside Client’s Services environment unless expressly authorized in Schedule 1 or otherwise agreed in writing by Client.
Article 5 — Client Instructions
I. Documented instructions. Client instructs Provider to Process Client Data as necessary to provide the Services, perform the Agreement, comply with this Addendum, and carry out Client’s configuration and authorized-user actions within the Services.
II. Additional instructions. Client may issue additional reasonable written instructions regarding Processing of Client Data. Provider shall comply with such instructions unless Provider reasonably determines that an instruction violates Applicable Privacy Laws or materially exceeds the scope of the Agreement, in which case Provider shall notify Client and the Parties shall cooperate in good faith to resolve the issue.
III. User actions as instructions. Client’s configuration settings, integrations, templates, campaigns, routing rules, message triggers, review requests, lead-source connections, and authorized-user actions within the Services constitute Client’s documented instructions.
IV. Prohibited instructions. Client shall not instruct Provider to Process Client Data in a manner that violates Applicable Privacy Laws, infringes third-party rights, or conflicts with a contractual obligation applicable to a third-party messaging, social, advertising, lead, CRM, DMS, or communications platform.
Article 6 — Communications Compliance; Call Recording; AI Voice
I. Telemarketing and electronic communications. Client is responsible for determining the legal basis for, and obtaining and maintaining any required consents for, calls, texts, emails, review requests, social messages, automated messages, prerecorded or artificial-voice messages, AI-assisted communications, and other communications initiated by or on behalf of Client through the Services. Client shall use the Services in compliance with applicable telemarketing, electronic communications, do-not-call, abandoned-call, caller-identification, opt-out, unsubscribe, quiet-hours, and consent requirements.
II. Provider operational support. Provider shall provide the communications-related functionality expressly described in the Agreement or Schedule 1, which may include suppression, opt-out, routing, business-hours, logging, consent-field, campaign-control, or audit-log features. Client remains responsible for selecting, configuring, and using such features lawfully unless the Agreement expressly assigns a specific compliance obligation to Provider.
III. Call recording consent allocation. Client is responsible for determining whether call recording, transcription, monitoring, AI voice interaction, or call summarization requires notice or consent in each applicable jurisdiction and for providing such notice or obtaining such consent before or during the interaction, except to the extent the Agreement expressly requires Provider to deliver a specific prerecorded disclosure or technical consent prompt. Provider shall not disable any mandatory call-recording disclosure configured by Client.
IV. AI voice disclosures. Client is responsible for determining whether and when Consumers must be informed that they are interacting with an AI bot, virtual assistant, automated system, or recorded line. Provider shall support Client’s configured disclosure scripts and routing rules as set forth in the Agreement or Schedule 1.
V. Opt-outs and revocations. Client shall promptly honor and communicate to Provider, through the Services or another agreed mechanism, opt-outs, unsubscribe requests, consent revocations, do-not-call requests, and similar communication preferences. Provider shall apply opt-out and suppression controls within the Services as described in Schedule 1 and shall not knowingly override Client’s suppression instructions.
VI. Third-party channel rules. Client is responsible for complying with applicable terms, policies, messaging rules, advertising requirements, and data-use restrictions imposed by third-party lead sources, social platforms, messaging providers, email providers, advertising networks, review platforms, CRM systems, DMS systems, and integration partners used by Client with the Services.
Article 7 — Consumer Rights and Privacy Requests
I. Request handling. If Provider receives a request from a Consumer or Dealer Staff member seeking to exercise rights under Applicable Privacy Laws with respect to Client Data, Provider shall, unless legally prohibited, either direct the requester to Client or notify Client using the contact method set forth in Schedule 4.
II. Assistance. Taking into account the nature of the Processing and the information available to Provider, Provider shall provide reasonable assistance to Client, through available functionality or other reasonable means, to enable Client to respond to verified privacy rights requests, including requests to access, delete, correct, obtain a copy of, or opt out of certain Processing of Personal Data.
III. No independent response. Provider shall not substantively respond to a privacy rights request relating to Client Data except on Client’s documented instructions, as required by Applicable Privacy Laws, or to confirm that the request has been directed to Client.
IV. Verification and exceptions. Client is responsible for verifying requesters, determining whether a request is valid, applying exemptions or exceptions, and communicating responses to requesters, unless otherwise expressly agreed in Schedule 1.
V. Timing. Provider shall use commercially reasonable efforts to provide assistance within the response periods set forth in Schedule 1 or, if none are specified, within a reasonable time sufficient to allow Client to meet applicable legal deadlines.
Article 8 — Confidentiality and Personnel
I. Confidentiality. Client Data is Client’s Confidential Information. Provider shall protect Client Data in accordance with the confidentiality obligations in the Agreement and this Addendum.
II. Authorized access. Provider shall restrict access to Client Data to personnel, contractors, and Subprocessors who have a need to know such Client Data for purposes permitted by this Addendum and/or the Agreement.
III. Personnel obligations. Provider shall ensure that personnel authorized to Process Client Data are subject to written confidentiality obligations or professional obligations of confidentiality no less protective than those set forth in the Agreement.
IV. Training. Provider shall maintain commercially reasonable privacy and security awareness measures for personnel with access to Client Data.
Article 9 — Security
I. Security program. Provider shall implement and maintain a written information security program containing administrative, technical, and physical safeguards designed to protect Client Data against Security Incidents and appropriate to the nature, scope, and sensitivity of the Client Data Processed.
II. Minimum controls. Provider’s security program shall include, at a minimum, the security controls described in Schedule 2, including controls relating to access management, authentication, encryption, logging, vulnerability management, incident response, backups, availability, secure development, vendor management, and employee security.
III. Security changes. Provider may update its security controls from time to time, provided that such updates do not materially reduce the overall level of protection for Client Data during the term of the Agreement.
IV. Client responsibilities. Client is responsible for maintaining the security of its own systems, credentials, devices, networks, websites, CRM, DMS, DealerCenter environment, third-party accounts, communication channels, and integrations, and for managing authorized-user access to the Services.
V. No prohibited data. Client shall not submit payment card data, government identification numbers, protected health information, children’s data, or other regulated data categories not expressly contemplated by Schedule 1 unless the Parties have agreed in writing to additional controls and responsibilities for such data.
Article 10 — Security Incident Notification
I. Notification. Provider shall notify Client without undue delay, and in any event within forty-eight (48) hours after confirming that a Security Incident may have occurred involving Client Data.
II. Notice contents. Provider’s notice shall include, to the extent known at the time and subject to law-enforcement, forensic, security, and confidentiality limitations:
A. a general description of the Security Incident;
B. the categories of Client Data and individuals affected or reasonably believed to be affected;
C. the approximate date or period of the Security Incident;
D. the steps Provider has taken or plans to take to investigate, contain, and remediate the Security Incident;
E. information reasonably necessary for Client to assess its notification obligations; and
F. a Provider contact for follow-up communications.
III. Updates. Provider shall provide reasonable updates as material information becomes available.
IV. Cooperation. Provider shall reasonably cooperate with Client’s investigation, mitigation, and legally required notifications relating to a Security Incident involving Client Data.
V. No admission. Provider’s notice of, or response to, a Security Incident is not an admission of fault, liability, or violation of law.
VI. Client notifications. Client is responsible for determining whether notice to individuals, regulators, consumer reporting agencies, attorneys general, business partners, or other third parties is required, and for providing such notice.
Article 11 — Subprocessors and Third-Party Integrations
I. Authorization. Client generally authorizes Provider to engage Subprocessors to Process Client Data in connection with the Services, subject to this Article 11 and Schedule 3.
II. Subprocessor list. Provider shall maintain a list of Subprocessors in Schedule 3 or another written mechanism made available to Client, including the categories of services performed and, where applicable, Processing locations.
III. Subprocessor obligations. Provider shall enter into a written agreement with each Subprocessor that imposes data protection obligations materially no less protective of Client Data than those imposed on Provider under this Addendum, taking into account the nature of the Subprocessor’s services.
IV. Provider responsibility. Provider remains responsible for its Subprocessors’ performance of obligations relating to Client Data to the same extent Provider would be responsible if performing such obligations itself.
V. Changes. Provider shall provide notice of new or replacement Subprocessors as set forth in Schedule 3. Client may object to a new Subprocessor on reasonable data protection grounds within fifteen (15) days after notice. If Client timely objects, the Parties shall work in good faith to resolve the objection, which may include use of an alternative Subprocessor, configuration changes, or termination of the affected Services as set forth in the Agreement or Schedule 3.
VI. Third-party integrations. The Services may interoperate with Client-enabled third-party platforms, including websites, CRM systems, DMS systems, DealerCenter, communications providers, lead sources, marketplaces, social platforms, advertising platforms, messaging channels, and review platforms. To the extent Client authorizes an integration, Client instructs Provider to disclose and receive Client Data through that integration. Provider is not responsible for the acts, omissions, privacy practices, security practices, or independent Processing of third-party platforms that are not Provider’s Subprocessors.
Article 12 — Deidentified and Aggregated Data
I. Permitted use. Provider may create and use Deidentified Data or aggregated data derived from Client Data for analytics, benchmarking, security, service improvement, product development, operational reporting, and similar business purposes, provided that such data does not identify Client, a dealership location, a Consumer, or Dealer Staff except as authorized in the Agreement.
II. No reidentification. Provider shall not attempt to reidentify Deidentified Data except to test or validate deidentification or as otherwise permitted by Applicable Privacy Laws.
III. No disclosure of identifiable data. Provider shall not disclose Deidentified Data or aggregated data in a manner that reasonably permits identification of Client, Consumers, or Dealer Staff, except as authorized by Client or the Agreement.
Article 13 — Retention; Deletion; Return
I. Retention. Provider shall retain Client Data for the periods described in Schedule 1 or as otherwise configured by Client, required to provide the Services, required by law, necessary for dispute resolution, or permitted under the Agreement.
II. Deletion during term. Provider shall delete Client Data upon Client’s reasonable written request to the extent technically feasible and legally permissible, subject to the retention periods, backup practices, archival processes, and legal exceptions described in Schedule 1.
III. Return or deletion at termination. Upon termination or expiration of the Agreement, Provider shall, at Client’s election and subject to Schedule 1, return or delete Client Data within the period set out in Schedule 4, unless retention is required by law or permitted for backup, archival, security, fraud prevention, legal, accounting, or dispute-resolution purposes.
IV. Backups. Client Data retained in backups or archival systems shall remain protected under this Addendum and shall be deleted in accordance with Provider’s ordinary-course backup retention schedule described in Schedule 1 or Schedule 2.
V. Survival. Provider’s obligations under this Addendum continue for so long as Provider retains Client Data.
Article 14 — Audits and Compliance Assessments
I. Information. Upon Client’s reasonable advanced written request, Provider shall make available information reasonably necessary to demonstrate Provider’s compliance with this Addendum, subject to reasonable confidentiality, security, and privilege limitations.
II. Assessment reports. Provider may satisfy audit or assessment requests by providing summaries, certifications, questionnaires, or independent assessment reports identified in Schedule 2, if any, provided that such materials reasonably address the subject matter of Client’s request.
III. Client audit. If the materials provided under Section II of this Article 14 are insufficient to demonstrate compliance with this Addendum, Client may request a reasonable audit, no more than once per year unless required by Applicable Privacy Laws or following a Security Incident. Any audit shall be conducted during normal business hours, on reasonable prior notice, in a manner that does not unreasonably disrupt Provider’s operations or compromise the security or confidentiality of Provider’s systems or other customers’ data.
IV. Costs. Audit costs shall be allocated as set forth in the Agreement or Schedule 4. If no allocation is specified, each Party shall bear its own costs, and Client shall be responsible for third-party assessor costs unless the audit reveals a material uncured breach of this Addendum by Provider.
V. Remediation. Provider shall use commercially reasonable efforts to remediate confirmed material deficiencies identified through an audit within a reasonable period commensurate with the severity and complexity of the deficiency.
Article 15 — International Transfers and Processing Location
I. U.S.-only services. The Services are intended for use in the United States only by automobile dealerships for their own dealership locations. Client shall not use the Services outside the United States or submit Personal Data relating to non-U.S. residents unless authorized in writing by Provider.
II. Processing location. Provider shall Process Client Data in the United States except as expressly described in Schedule 1 or Schedule 3 or as otherwise approved in writing by Client.
III. Support access. Remote access to Client Data from outside the United States is prohibited unless expressly described in Schedule 3, required for emergency support, or otherwise approved in writing by Client, and in each case subject to appropriate confidentiality and security controls.
Article 16 — Representations and Warranties
I. Mutual representations. Each Party represents and warrants that:
A. it has the authority to enter into and perform this Addendum;
B. it will comply with Applicable Privacy Laws applicable to its Processing of Personal Data under the Agreement; and
C. it will not knowingly cause the other Party to violate Applicable Privacy Laws.
II. Client representations. Client represents and warrants that:
A. Client has provided, and will provide, all notices and obtain, maintain, and honor all consents, authorizations, opt-outs, and preferences required for Client’s use of the Services;
B. Client has the right to provide Client Data to Provider and to instruct Provider to Process Client Data as contemplated by this Addendum;
C. Client’s use of lead sources, messaging channels, social platforms, advertising tools, review requests, telephone numbers, call recordings, AI voice functionality, and integrations will comply with Applicable Privacy Laws and applicable third-party terms; and
D. Client will not use the Services for unlawful discrimination, unlawful profiling, unlawful credit eligibility determinations, or other purposes not authorized by the Agreement.
III. Provider representations. Provider represents and warrants that:
A. Provider will Process Client Data in accordance with this Addendum and Client’s documented instructions;
B. Provider will implement and maintain the security measures required by Article 9; and
C. Provider will not create voiceprints or use call recordings for biometric identification or authentication.
Article 17 — Indemnity
I. Provider indemnity. Subject to the Agreement’s indemnity procedures, exclusions, and limitations, Provider shall defend, indemnify, and hold harmless Client and its officers, directors, managers, employees, and agents from and against third-party claims, damages, fines, penalties, costs, and expenses, including reasonable attorneys’ fees, to the extent arising from Provider’s material breach of this Addendum, Provider’s willful violation of Applicable Privacy Laws in its role as Processor, or a Security Incident caused by Provider’s failure to maintain the security measures required by Article 9.
II. Client indemnity. Subject to the Agreement’s indemnity procedures, exclusions, and limitations, Client shall defend, indemnify, and hold harmless Provider and its officers, directors, managers, employees, and agents from and against third-party claims, damages, fines, penalties, costs, and expenses, including reasonable attorneys’ fees, to the extent arising from Client’s instructions, Client’s use of the Services, Client’s violation of Applicable Privacy Laws, Client’s failure to provide required notices or obtain or honor required consents or opt-outs, Client’s communications with Consumers, Client’s use of call recording or AI voice functionality, or Client’s use of third-party integrations, lead sources, messaging channels, social platforms, advertising platforms, or review-request tools.
III. Allocation. If a claim arises from both Parties’ acts or omissions, liability shall be allocated between the Parties in proportion to their respective responsibility, subject to the Agreement’s limitations of liability and other applicable terms.
IV. Regulatory proceedings. A regulatory inquiry, investigation, subpoena, civil investigative demand, or enforcement action shall be treated as a third-party claim for purposes of this Article 17 to the extent it seeks penalties, fines, damages, or mandatory relief from an indemnified Party arising from an indemnifying Party’s conduct described in this Article 17.
Article 18 — Limitation of Liability
I. Coordination with Agreement. Except as expressly stated in this Addendum, each Party’s liability arising out of or relating to this Addendum is subject to the exclusions, disclaimers, limitations, caps, procedures, and allocation-of-risk provisions in the Agreement.
II. Privacy cap. The Parties agree that claims arising out of or relating to this Addendum are subject to the limitation of liability in Section 21 of the Agreement, as set out in Schedule 4.
III. No duplicate recovery. A Party may not recover duplicative damages or amounts for the same loss under both this Addendum and the Agreement.
IV. No expansion. This Addendum does not expand either Party’s liability beyond the liability expressly assumed under the Agreement except to the extent expressly stated in Section II of this Article 18.
Article 19 — Term and Termination
I. Term. This Addendum begins on the Effective Date and continues for so long as Provider Processes Client Data.
II. Termination. This Addendum terminates automatically upon termination or expiration of the Agreement, except that provisions intended by their nature to survive shall survive for so long as Provider retains Client Data or as otherwise necessary to give effect to such provisions.
III. Suspension. Provider may suspend Processing or the affected Services if Provider reasonably determines that Client’s use of the Services violates Applicable Privacy Laws, poses a material security risk, infringes third-party rights, violates third-party channel rules, or materially exceeds the scope of the Agreement, subject to any notice and cure provisions in the Agreement unless immediate suspension is reasonably necessary to prevent harm.
Article 20 — General Provisions
I. Governing law. This Addendum is governed by the laws of the State of Texas, without regard to conflict-of-law principles that would require the application of another jurisdiction’s laws.
II. Venue. Any dispute arising out of or relating to this Addendum shall be resolved in the forum specified in the Agreement.
III. Notices. Notices under this Addendum shall be provided in accordance with the Agreement and to the privacy and security contacts identified in Schedule 4.
IV. Amendments. This Addendum may be amended only by a written instrument signed by authorized representatives of both Parties, except that Provider may update Schedules 2 and 3 as permitted by this Addendum.
V. Severability. If any provision of this Addendum is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the Parties shall replace the invalid or unenforceable provision with a valid and enforceable provision that most closely reflects the Parties’ original intent.
VI. Counterparts; electronic signatures. This Addendum may be executed in counterparts, each of which is deemed an original and all of which together constitute one instrument. Electronic signatures have the same force and effect as original signatures.
VII. Entire addendum. This Addendum, together with the Agreement and all schedules and exhibits incorporated into this Addendum, constitutes the entire agreement between the Parties regarding the Processing of Client Data and supersedes all prior or contemporaneous agreements on that subject.
Article 21 — Signatures
Client accepts this Addendum by signing an Order Form that references it or by otherwise accepting the Agreement. No separate signature by Client is required.
NEMROOT TECHNOLOGIES LLC
By: /s/ Selcuk Kaya
Name: Selcuk Kaya
Title: Founder & Managing Member
Date: September 10, 2026
Name:
Title:
Schedule 1 — Processing Details
I. Subject matter. Provider’s Processing of Client Data for the provision of a U.S.-only SaaS or licensed application used by automobile dealerships for CRM-related communications, lead management, call handling, messaging, AI voice functionality, call recording, transcription, summarization, routing, reporting, integrations, marketplace listing, advertising syndication, review requests, and related services.
II. Duration. The term of the Agreement plus any period during which Provider retains Client Data in accordance with the Agreement, this Addendum, legal requirements, backup schedules, or as required by applicable law(s).
III. Nature and purpose. Provider Processes Client Data to provide, secure, support, maintain, improve, and troubleshoot the Services; enable Client-authorized communications; create and update customer records; generate transcripts, summaries, logs, dashboards, and reports; integrate with Client-enabled systems and channels; and comply with legal obligations.
IV. Categories of data subjects. Consumers; prospective customers; current customers; former customers; callers; message recipients; website visitors; inbound leads; dealership owners, officers, employees, contractors, agents, representatives, and authorized users; and other individuals whose Personal Data is submitted to or generated through the Services.
V. Categories of Personal Data. Names; phone numbers; email addresses; mailing addresses; vehicle interests; trade-in vehicle details; lead records; message content and metadata; call audio; recordings; transcripts; summaries; customer-record notes; IP addresses; device and browser details; usage logs; call timestamps; call duration; staff names; staff contact details; role information; credentials; account activity; communications activity; dashboard metrics; and other Client-submitted data.
VI. Sources. Client; Consumers; Dealer Staff; Client websites; CRM systems; DMS systems; DealerCenter; SMS; web chat; email; Facebook Messenger; Instagram direct messages; WhatsApp; CarGurus; AutoTrader; Cars.com; TrueCar; Facebook Marketplace; Meta ad syndication; Google review request workflows; and other Client-enabled sources.
VII Data retention and deletion details. During the term, Provider retains Client Data as necessary to provide the Services and as configured by Client. After termination or expiration, Client may export Client Data for thirty (30) days as provided in Section 10.5 of the Agreement. Provider then deletes Client Data from active systems within thirty (30) days after that export period ends. Copies in backups are overwritten or deleted in the ordinary course on a rolling cycle not exceeding ninety (90) days. Records Provider must keep by law, such as billing and 10DLC registration records, are retained for the period the law requires.
VIII. Client-specific instructions. None, unless stated in Client's Order Form.
IX. AI and model-use restrictions. Provider sends Client Data to the AI service providers listed in Schedule 3 only to provide the Services, such as answering calls, drafting messages, transcribing and summarizing. Provider uses those providers under business or API terms that do not permit them to use Client Data to train their own models. Provider does not use Client Data to train general-purpose models. Provider may use Deidentified Data and aggregated data as permitted by Article 12 and Section 10.2 of the Agreement. Provider personnel may review AI inputs and outputs only to support, secure, troubleshoot or improve the Services for Client.
Schedule 2 — Security Controls
I. Security exhibit. Provider shall maintain the administrative, technical, and physical safeguards described below and in any additional security exhibit attached to the Agreement. No additional security exhibit applies unless stated in Client's Order Form.
II. Access controls. Access to production systems and Client Data is limited to named personnel who need it for their role, using individual accounts. Shared accounts are not used. Access rights are reviewed at least every six (6) months and removed promptly when no longer needed.
III. Authentication and authorization. Authorized Users sign in through Provider's authentication service with individual credentials. Multi-factor authentication is required for Provider personnel on cloud, source-code, telephony and email administration accounts. Role-based permissions control what each Authorized User can see and do within Client's account.
IV. Encryption. Client Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 or equivalent encryption provided by Provider's hosting and communications Subprocessors.
V. Logging and monitoring. Provider uses cloud audit logs and application logs to record administrative access and significant system events, and monitors its systems for errors, abuse and unauthorized access.
VI. Vulnerability and patch management. Provider keeps software dependencies and platform components up to date, applies critical security patches within fourteen (14) days and other security patches within thirty (30) days of availability, where reasonably practicable.
VII. Incident response. Provider maintains a documented incident response process covering detection, containment, investigation, remediation and notice, and notifies Client of Security Incidents as required by Article 10.
VIII. Backup, disaster recovery, and availability. Provider uses managed cloud infrastructure with automated backups of its production database and can restore Client Data from backup in the event of data loss. Service availability and support are described in Section 12 of the Agreement.
IX. Secure development. Source code is kept in a private, access-controlled repository. Changes are reviewed before release to production, and development and test work is done separately from production Client Data where reasonably practicable.
X. Vendor management. Provider reviews the security and privacy terms of each Subprocessor before engaging it and enters into written terms as required by Article 11.
XI. Personnel security. All Provider personnel and contractors with access to Client Data sign written confidentiality and invention-assignment agreements and receive privacy and security guidance. Their access is removed within one (1) business day after their engagement ends.
XII. Assessment materials. Provider does not currently hold a third-party security certification. On reasonable request, Provider will complete a standard security questionnaire once per twelve (12) months.
Schedule 3 — Subprocessors and Processing Locations
I. Approved Subprocessors. (1) Google LLC (Google Cloud and Firebase): hosting, database, authentication, file storage and AI services (Gemini/Vertex AI), United States. (2) Twilio Inc.: telephone numbers, voice calls, SMS and MMS, call recording and A2P 10DLC registration, United States. (3) OpenAI, L.L.C.: AI language, speech and transcription services, United States. (4) Anthropic, PBC: AI language services, United States. (5) ElevenLabs, Inc.: AI voice generation, United States. (6) Deepgram, Inc.: speech-to-text transcription, United States. (7) Resend, Twilio SendGrid and Google Workspace: transactional and campaign email delivery, United States. (8) Stripe, Inc.: subscription billing and payment processing for Client's account, United States. (9) Provider's independent contractor engineering and support personnel located in Türkiye: remote access to Provider's U.S.-hosted systems for software development, maintenance and technical support, under written confidentiality and invention-assignment agreements. Client Data remains hosted in the United States. The current list is also published at nemroot.com/subprocessors.
II. Categories of Subprocessors. Cloud hosting; communications carriers; SMS providers; email providers; call recording and telephony providers; transcription providers; AI service providers; customer support tools; analytics and logging tools; CRM, DMS, and DealerCenter integration services; lead-source connectors; social and messaging platform integrations; advertising and marketplace integrations; and other service providers identified by Provider: none.
III. Processing locations. Client Data is hosted and Processed in the United States. Remote access for development, maintenance and technical support is permitted from Türkiye as described in Section I of this Schedule 3, which Client approves for purposes of Article 15.
IV. Notice of changes. Provider shall notify Client of new or replacement Subprocessors by email to Client's notice email address and by updating the list at nemroot.com/subprocessors at least fifteen (15) days before authorizing the Subprocessor to Process Client Data, unless exigent circumstances require shorter notice.
V. Objection procedure. Client may object to a new or replacement Subprocessor within fifteen (15) days after notice by providing reasonable written detail regarding the data protection basis for the objection.
Schedule 4 — Contacts; Notice; Business Terms
I. Client privacy contact. The authorized signer and notice email stated in Client's Order Form.
II. Client security contact. The authorized signer and notice email stated in Client's Order Form.
III. Provider privacy contact. Selcuk Kaya, Founder & Managing Member, info@nemroot.com, (346) 666-7377, 14507 FM 529, Suite H, Houston, TX 77095.
IV. Provider security contact. Selcuk Kaya, Founder & Managing Member, support@nemroot.com, (346) 666-7377, 14507 FM 529, Suite H, Houston, TX 77095.
V. Security Incident notice period. Forty-eight (48) hours, as set out in Article 10.
VI. Privacy rights assistance response period. Ten (10) business days after Provider receives Client's written request.
VII. Audit frequency. Once per twelve (12) months, as set out in Article 14.
VIII. Audit cost allocation. As set out in Section IV of Article 14.
IX. Subprocessor change notice mechanism. Email to Client's notice email address and update of the list at nemroot.com/subprocessors.
X. Subprocessor change notice period. Fifteen (15) days.
XI. Subprocessor objection period. Fifteen (15) days.
XII. Post-termination return or deletion period. Client Data is available for export for thirty (30) days after termination or expiration and is deleted from active systems within thirty (30) days after that export period ends.
XIII. Privacy liability cap. The limitation of liability in Section 21 of the Agreement applies to all claims under this Addendum.
XIV. Excluded claims from cap. Only those claims excluded from the cap in Section 21 of the Agreement.
XV. Additional negotiated business terms. None, unless stated in Client's Order Form.