Impact

Data processing

Legal · 04

Data Processing Addendum

Impact Marketing LLC · Athens, Georgia
Version 1.0 · Effective 4 August 2026

When we build and run your website, your customers' information passes through our hands. Their names, their phone numbers, what they typed into your quote form, the recording of the call they made to your number. That information is yours, not ours. This page is the contract that says so, and says exactly what we are allowed to do with it.

It is written to be read by you, not only by a lawyer. If any of it is unclear, email team@impactranks.com and ask before you sign anything.

1. When this applies, and what it overrides

This Addendum forms part of the service agreement between you ("you", the client) and Impact Marketing LLC, a Georgia limited liability company trading as Impact ("we", "us"). It applies automatically from the day your service starts. You do not have to ask for it and there is nothing to sign separately.

It applies only to personal information we handle on your behalf: your customers, your leads, your form submissions, your call and message records. It does not cover information we hold about you as our client, or about visitors to our own website. That is covered by our Privacy Policy.

If this Addendum and any other document between us disagree about data protection, this Addendum wins, unless the other document is signed later and says explicitly that it replaces this one.

2. Who is who

You decide why your customers' information is collected and what happens to it. In the language of the various privacy statutes, that makes you the controller, or the business.

We act only on your instructions. That makes us your processor, and under California law your service provider. We are not selling your customers' data and we are not a party you are selling it to. That distinction matters to you more than it matters to us: if we were anything other than a service provider, every lead you route through us would count as a "sale" under California law and would trigger obligations on your business. Section 4 exists to keep that from happening.

Where you are the one responsible. You are responsible for having the right to collect your customers' information in the first place, for the notices on your own website, and for the lawfulness of what you ask us to do. We will tell you if an instruction looks to us like it breaks the law, and we will not carry it out until it is resolved. But we are not your compliance department and we do not audit your business.

3. What we process, and for how long

ItemDetail
Subject matterRunning the website, forms, phone number, text messaging, review requests and lead follow-up that make up your service.
Nature and purposeCollecting, storing, organizing, transmitting, displaying and deleting personal information so that inquiries reach you and so the automations you bought actually run.
DurationFor as long as your service is active, plus the wind-down period in section 11.
Categories of peopleYour customers, your prospective customers, and people who contact your business.
Categories of informationName, phone number, email address, postal or service address, the contents of what they submitted or wrote, call and message metadata, call recordings where you have enabled them, review responses, and technical data such as IP address and browser type from your website's server logs.
Sensitive informationWe do not ask for it, our forms are not built to collect it, and you should not send it to us. If your business needs to collect health, financial account, biometric, precise location or similar categories, tell us before you start so we can say whether we can support it. Today, the honest answer is that we are not built for it.

We process this information only on your documented instructions. Your instructions are: this Addendum, your service agreement, your onboarding form, the settings you choose, and anything you subsequently ask us in writing. If the law compels us to process it some other way, we will tell you first unless the law forbids us from telling you.

4. The four things we will never do

These are the commitments that matter. They are short on purpose.

  1. We will not sell or share your customers' information. Not for money, and not for anything else of value. We will not disclose it to anyone outside the companies listed in section 7, and never for their own purposes.
  2. We will not market to your customers. Not on our behalf, not on anyone else's. Your customer list is not a lead list. We do not mine it, we do not export it, and we do not use it to sell Impact to anyone.
  3. We will not use your customers' information for any other client, or for our own purposes. It is not combined with information we receive from other clients, it is not combined with information we collect from our own website, and it is not used to build or improve any product, model or dataset outside of running your service. The one exception is the ordinary one every processor needs: we may generate internal, aggregated and deidentified operating statistics, such as how many form submissions we handled last month, provided nothing in them can be linked back to any individual and we do not attempt to reidentify it.
  4. We will not retain, use or disclose it outside the direct business relationship between us, or for any purpose other than performing the service you bought, unless a law requires it.

We certify that we understand each of the restrictions above and will comply with them. That sentence is there because California law requires a service provider to state it, and it is easier to write it than to explain later why it is missing.

5. Our people

Access is limited to the people who need it to do their job, and it is removed when they no longer need it or when they leave. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement with us, whether they are an employee or a contractor. Accounts that hold client data are protected by multi-factor authentication.

6. Security

We maintain reasonable and appropriate technical and organizational measures for a business of our size handling the kind of information described in section 3. In practice, today, that means:

What we are not claiming. We are not SOC 2 certified, we are not ISO 27001 certified, and we do not carry out annual third-party penetration testing. We are a small company and we would rather you know that now than discover it during a questionnaire. If you need a vendor with those certifications, we are not the right vendor, and we will say so on the call.

7. Other companies we use

We cannot run your service alone. The companies that help us are called subprocessors, and the current list is published at subprocessors.html. By starting your service you authorise the ones on that list.

Before we add a new one or replace an existing one, we will update that page and give you at least 30 days' notice by email. If you object on reasonable data protection grounds within those 30 days, tell us and we will try to find a way around it. If we cannot, you may cancel the affected part of your service without penalty, and section 11 applies. Continuing to use the service after 30 days counts as acceptance.

Every subprocessor is placed under written obligations at least as protective as this Addendum. We remain responsible to you for what they do, to the same extent as if we had done it ourselves.

8. Checking that we mean it

You may take reasonable and appropriate steps to satisfy yourself that we are handling your customers' information the way this Addendum says. Concretely:

9. When your customer exercises a right

If one of your customers contacts us asking to see, correct, delete or stop the processing of their information, we will not answer them on our own. We will tell them to contact you, and we will forward the request to you promptly.

When you need to answer one of these requests, we will help. Tell us what you need and we will search our systems, produce what we hold, correct it or delete it. We do this at no charge for a reasonable volume of requests. If it ever became a substantial ongoing burden we would talk to you about it first, not invoice you by surprise.

We will also give you the information you reasonably need in order to carry out a data protection assessment or similar exercise about the parts of the processing we perform.

Consent does not transfer, in either direction. We will not text or call your customers using consent that those people gave to us, and we will not text or call our own leads using consent they gave to you. If we run a text campaign to a list you provide, you are certifying that you hold the consent required for those messages, that the list contains only people who agreed to receive them, and that you will tell us immediately when someone withdraws. We will honor every opt-out we receive, on every list, and we keep the record for at least five years. This is the single most expensive clause in this document to get wrong, so ask us about it before your first campaign rather than after.

10. If something goes wrong

If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your customers' information, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. We will notify you by email to your account contact and, if it is serious, by telephone as well.

The notice will tell you what we know: what happened, when, which categories and roughly how many people are affected, what the likely consequences are, what we have done, and what we are doing next. If we do not have all of it in 72 hours we will send what we have and follow up rather than wait.

We will cooperate with you in investigating and remediating, and we will not make a public statement identifying you or your customers without your consent unless a law requires it. Notifying the people affected, or a regulator, is your decision to make as the controller. We will help you make it and we will not sit on information you need in order to make it.

11. Getting your data back, and deletion

You can ask for an export of your leads, form submissions and contact records at any time, including on the day you leave, and we will provide it in a common machine-readable format within seven business days.

After your service ends we keep your customers' information for 30 days so that a change of mind or a late export request does not become a disaster, and then we delete it from our active systems. Backups age out on their normal cycle, within 90 days, and nothing is restored from them except to recover from a failure. You can ask us to delete sooner and we will.

We keep three things longer, and only these three: records of opt-outs and do-not-contact requests, because we are required to honor them for years; the minimum billing and tax records the law requires us to hold; and anything a law or a legal hold specifically requires us to preserve. None of it is used for any other purpose.

Your domain name stays registered to you in your own account throughout. Your Google Business Profile stays owned by you, and we hand manager access back within seven business days of you asking, whatever the state of your account with us.

12. Where the data lives

Your customers' information is stored and processed in the United States. Our subprocessors may operate infrastructure in other countries; where they do, it is stated on the subprocessors page.

We do not currently offer a service designed for personal data protected by the GDPR or the UK GDPR. Our clients are home service businesses serving customers in the United States. If you expect to collect data from people in the EU or the UK, tell us before you sign, because the honest answer today is that we have not put the transfer mechanisms in place and we would rather turn the work down than pretend otherwise.

Liability. Each party's liability under this Addendum is subject to the limitations and exclusions in the service agreement, and those limits apply to the two documents in aggregate rather than separately. Nothing here limits liability that the law does not allow us to limit.

Changes. We may update this Addendum to reflect a change in the law or in how the service works. If a change materially reduces your protections we will give you at least 30 days' notice by email first, and if you object you may cancel the affected part of the service without penalty. We will keep the version number and effective date at the top current, so you can always tell what changed and when.

Survival. Sections 4, 5, 10, 11 and 13 survive the end of your service agreement.

Governing law. This Addendum is governed by the law stated in the service agreement, and disputes go to the same place.

Severability. If a court finds any part of this unenforceable, the rest still stands, and the unenforceable part is read as narrowly as needed to make it work.

Impact Marketing LLC
Athens, Georgia, United States
team@impactranks.com
Version 1.0 · Effective 4 August 2026