Legal · 04
Data Processing Addendum
Version 1.0 · Effective 4 August 2026
When we build and run your website, your customers' information passes through our hands. Their names, their phone numbers, what they typed into your quote form, the recording of the call they made to your number. That information is yours, not ours. This page is the contract that says so, and says exactly what we are allowed to do with it.
It is written to be read by you, not only by a lawyer. If any of it is unclear, email team@impactranks.com and ask before you sign anything.
On this page
- When this applies, and what it overrides
- Who is who
- What we process, and for how long
- The four things we will never do
- Our people
- Security
- Other companies we use
- Checking that we mean it
- When your customer exercises a right
- If something goes wrong
- Getting your data back, and deletion
- Where the data lives
- Liability, changes, and the fine print
1. When this applies, and what it overrides
This Addendum forms part of the service agreement between you ("you", the client) and Impact Marketing LLC, a Georgia limited liability company trading as Impact ("we", "us"). It applies automatically from the day your service starts. You do not have to ask for it and there is nothing to sign separately.
It applies only to personal information we handle on your behalf: your customers, your leads, your form submissions, your call and message records. It does not cover information we hold about you as our client, or about visitors to our own website. That is covered by our Privacy Policy.
If this Addendum and any other document between us disagree about data protection, this Addendum wins, unless the other document is signed later and says explicitly that it replaces this one.
2. Who is who
You decide why your customers' information is collected and what happens to it. In the language of the various privacy statutes, that makes you the controller, or the business.
We act only on your instructions. That makes us your processor, and under California law your service provider. We are not selling your customers' data and we are not a party you are selling it to. That distinction matters to you more than it matters to us: if we were anything other than a service provider, every lead you route through us would count as a "sale" under California law and would trigger obligations on your business. Section 4 exists to keep that from happening.
3. What we process, and for how long
| Item | Detail |
|---|---|
| Subject matter | Running the website, forms, phone number, text messaging, review requests and lead follow-up that make up your service. |
| Nature and purpose | Collecting, storing, organizing, transmitting, displaying and deleting personal information so that inquiries reach you and so the automations you bought actually run. |
| Duration | For as long as your service is active, plus the wind-down period in section 11. |
| Categories of people | Your customers, your prospective customers, and people who contact your business. |
| Categories of information | Name, phone number, email address, postal or service address, the contents of what they submitted or wrote, call and message metadata, call recordings where you have enabled them, review responses, and technical data such as IP address and browser type from your website's server logs. |
| Sensitive information | We do not ask for it, our forms are not built to collect it, and you should not send it to us. If your business needs to collect health, financial account, biometric, precise location or similar categories, tell us before you start so we can say whether we can support it. Today, the honest answer is that we are not built for it. |
We process this information only on your documented instructions. Your instructions are: this Addendum, your service agreement, your onboarding form, the settings you choose, and anything you subsequently ask us in writing. If the law compels us to process it some other way, we will tell you first unless the law forbids us from telling you.
4. The four things we will never do
These are the commitments that matter. They are short on purpose.
- We will not sell or share your customers' information. Not for money, and not for anything else of value. We will not disclose it to anyone outside the companies listed in section 7, and never for their own purposes.
- We will not market to your customers. Not on our behalf, not on anyone else's. Your customer list is not a lead list. We do not mine it, we do not export it, and we do not use it to sell Impact to anyone.
- We will not use your customers' information for any other client, or for our own purposes. It is not combined with information we receive from other clients, it is not combined with information we collect from our own website, and it is not used to build or improve any product, model or dataset outside of running your service. The one exception is the ordinary one every processor needs: we may generate internal, aggregated and deidentified operating statistics, such as how many form submissions we handled last month, provided nothing in them can be linked back to any individual and we do not attempt to reidentify it.
- We will not retain, use or disclose it outside the direct business relationship between us, or for any purpose other than performing the service you bought, unless a law requires it.
We certify that we understand each of the restrictions above and will comply with them. That sentence is there because California law requires a service provider to state it, and it is easier to write it than to explain later why it is missing.
5. Our people
Access is limited to the people who need it to do their job, and it is removed when they no longer need it or when they leave. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement with us, whether they are an employee or a contractor. Accounts that hold client data are protected by multi-factor authentication.
6. Security
We maintain reasonable and appropriate technical and organizational measures for a business of our size handling the kind of information described in section 3. In practice, today, that means:
- All traffic to your website and to our systems is encrypted in transit over HTTPS.
- Data at rest sits inside the platforms in section 7, each of which encrypts it, and we do not keep shadow copies of your lead data on laptops or in spreadsheets.
- Access is role-limited and protected by multi-factor authentication.
- We do not store card numbers. Payments run through Stripe, which handles card data directly.
- We review who has access to what when someone joins or leaves, and at least once a year regardless.
7. Other companies we use
We cannot run your service alone. The companies that help us are called subprocessors, and the current list is published at subprocessors.html. By starting your service you authorise the ones on that list.
Before we add a new one or replace an existing one, we will update that page and give you at least 30 days' notice by email. If you object on reasonable data protection grounds within those 30 days, tell us and we will try to find a way around it. If we cannot, you may cancel the affected part of your service without penalty, and section 11 applies. Continuing to use the service after 30 days counts as acceptance.
Every subprocessor is placed under written obligations at least as protective as this Addendum. We remain responsible to you for what they do, to the same extent as if we had done it ourselves.
8. Checking that we mean it
You may take reasonable and appropriate steps to satisfy yourself that we are handling your customers' information the way this Addendum says. Concretely:
- Once in any twelve-month period, you may send us a written data protection questionnaire, and we will answer it within 30 days.
- Once in any twelve-month period, you may ask us for a written summary of our security measures, our access controls and our current subprocessor list, and we will provide it within 30 days.
- If you have a specific, documented reason to believe we are not complying, you may ask for an on-site or remote inspection. We will not unreasonably refuse. Inspections happen during business hours, on at least 30 days' notice, are limited to what is relevant, must not disturb our other clients' data, and are at your cost unless the inspection finds a material failure on our side, in which case we pay.
- You may also take reasonable steps to stop and remediate any unauthorised use of your customers' information by us. That right is in California's statute and we are not going to contract around it.
9. When your customer exercises a right
If one of your customers contacts us asking to see, correct, delete or stop the processing of their information, we will not answer them on our own. We will tell them to contact you, and we will forward the request to you promptly.
When you need to answer one of these requests, we will help. Tell us what you need and we will search our systems, produce what we hold, correct it or delete it. We do this at no charge for a reasonable volume of requests. If it ever became a substantial ongoing burden we would talk to you about it first, not invoice you by surprise.
We will also give you the information you reasonably need in order to carry out a data protection assessment or similar exercise about the parts of the processing we perform.
10. If something goes wrong
If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your customers' information, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. We will notify you by email to your account contact and, if it is serious, by telephone as well.
The notice will tell you what we know: what happened, when, which categories and roughly how many people are affected, what the likely consequences are, what we have done, and what we are doing next. If we do not have all of it in 72 hours we will send what we have and follow up rather than wait.
We will cooperate with you in investigating and remediating, and we will not make a public statement identifying you or your customers without your consent unless a law requires it. Notifying the people affected, or a regulator, is your decision to make as the controller. We will help you make it and we will not sit on information you need in order to make it.
11. Getting your data back, and deletion
You can ask for an export of your leads, form submissions and contact records at any time, including on the day you leave, and we will provide it in a common machine-readable format within seven business days.
After your service ends we keep your customers' information for 30 days so that a change of mind or a late export request does not become a disaster, and then we delete it from our active systems. Backups age out on their normal cycle, within 90 days, and nothing is restored from them except to recover from a failure. You can ask us to delete sooner and we will.
We keep three things longer, and only these three: records of opt-outs and do-not-contact requests, because we are required to honor them for years; the minimum billing and tax records the law requires us to hold; and anything a law or a legal hold specifically requires us to preserve. None of it is used for any other purpose.
Your domain name stays registered to you in your own account throughout. Your Google Business Profile stays owned by you, and we hand manager access back within seven business days of you asking, whatever the state of your account with us.
12. Where the data lives
Your customers' information is stored and processed in the United States. Our subprocessors may operate infrastructure in other countries; where they do, it is stated on the subprocessors page.
We do not currently offer a service designed for personal data protected by the GDPR or the UK GDPR. Our clients are home service businesses serving customers in the United States. If you expect to collect data from people in the EU or the UK, tell us before you sign, because the honest answer today is that we have not put the transfer mechanisms in place and we would rather turn the work down than pretend otherwise.
13. Liability, changes, and the fine print
Liability. Each party's liability under this Addendum is subject to the limitations and exclusions in the service agreement, and those limits apply to the two documents in aggregate rather than separately. Nothing here limits liability that the law does not allow us to limit.
Changes. We may update this Addendum to reflect a change in the law or in how the service works. If a change materially reduces your protections we will give you at least 30 days' notice by email first, and if you object you may cancel the affected part of the service without penalty. We will keep the version number and effective date at the top current, so you can always tell what changed and when.
Survival. Sections 4, 5, 10, 11 and 13 survive the end of your service agreement.
Governing law. This Addendum is governed by the law stated in the service agreement, and disputes go to the same place.
Severability. If a court finds any part of this unenforceable, the rest still stands, and the unenforceable part is read as narrowly as needed to make it work.
Athens, Georgia, United States
team@impactranks.com
Version 1.0 · Effective 4 August 2026
