1. Agreement and scope
1.1. Separate agreement. This DPA forms part of the customer’s subscription agreement only when the parties expressly agree to this version through an acceptance record or signed addendum identifying it. Publication on the documentation site, access to a help article, or receipt of a message does not establish acceptance. It does not retrospectively amend an earlier agreement. 1.2. Priority. Capitalized terms not defined here have the meanings in the parties’ agreed Terms of Service. This DPA controls a conflict concerning its specific personal-data processing subject matter. The Terms otherwise remain in effect, including their payment, termination, liability and dispute provisions. An informational security overview, privacy notice or help article does not independently enlarge this DPA’s commitments. 1.3. Defined scope. “Customer Personal Data” means information relating to an identified or identifiable individual that DispoIQ processes on Customer’s behalf in the activities specified in Schedule 1. It can include personal information in Customer Content, Recipient Submissions and associated customer-directed interaction records. Its inclusion does not transfer intellectual property rights or establish ownership of an individual’s information. “Applicable Data Protection Law” means privacy, data-protection and personal-information security law applicable to the relevant party and processing activity. Statutory terms such as controller, processor, business, service provider and contractor have their meanings under the law that actually applies; a functional description in this DPA does not establish a statutory status for every activity. 1.4. Distinct activities. DispoIQ’s own subscriber administration, payment, prospective-customer marketing and other independently determined business processing are described separately in its Privacy Policy. Independently sourcing and supplying Licensed Data is not converted into processing on Customer’s behalf merely by this DPA. Customer-provided lookup inputs and subsequent hosting of lawfully obtained results require an activity-specific assessment; a supplier’s role and rights are not inferred from its API integration. No exclusion here permits DispoIQ to relabel Customer Personal Data to evade applicable processing restrictions. Schedule 1 specifies the covered functions, purposes, individuals, information and processing. The general schedule applies when the actual purchased, enabled processing fits it. If Applicable Data Protection Law or accepted customer restrictions require additional particulars, the parties must record the relevant activities, roles, instructions, required terms and statutory confirmations in their accepted Order or processing schedule before the affected processing, and as part of express acceptance where required. Missing particulars do not exclude actual processing on Customer’s behalf or postpone a duty already due.2. Instructions and permitted processing
2.1. Documented instructions. Customer instructs DispoIQ to perform the enabled, purchased functions specified in Schedule 1, using Customer’s authorized workspace actions and agreed written instructions. Additional processing requires a lawful instruction within the agreed service scope or a separately agreed change. This DPA does not purchase a new feature, authorize a new usage charge, or grant redistribution rights in Licensed Data. 2.2. Processing limits. DispoIQ will process Customer Personal Data for the limited purposes in Schedule 1, to protect and troubleshoot that processing, and as required by applicable law. It will not sell Customer Personal Data, use it for cross-context behavioral advertising, build another customer’s marketing list from it, or use it to train unrelated AI models. These restrictions apply to the covered processing upon express acceptance of this DPA; they do not attest to historical operations or retrospectively change an earlier agreement. Where the CCPA applies to DispoIQ’s processing as a service provider or contractor for Customer, DispoIQ will not sell or share that information, retain, use or disclose it outside the specified business purposes or direct business relationship, or combine it with information from other customers or its own interactions except where the CCPA and its regulations expressly permit. It will provide the privacy protection required by the applicable CCPA provisions. Customer-directed enrichment is not an exception to a restriction that applicable law prohibits. 2.3. Problematic instructions. DispoIQ will inform Customer if it identifies an instruction that conflicts with applicable processing restrictions and will not carry out the unlawful part. The parties will work to establish a lawful alternative within the agreed service scope. If no lawful alternative is available, the affected processing may be restricted under the Agreement; this DPA creates no new fee, forfeiture or termination-refund rule. DispoIQ is not required to provide Customer with legal advice. 2.4. Legal requirements. If law requires processing outside Customer’s instructions, DispoIQ will notify Customer of that requirement where legally permitted and limit the processing to what the requirement permits or requires. This does not remove either party’s own legal obligations.3. Customer responsibilities
Customer determines the lawful customer purposes, audiences, content and instructions for its use of the Service. It must have the permissions and legal grounds necessary to disclose the relevant information, give required collection and engagement notices, maintain appropriate records, and honor applicable individual rights. Customer must manage its Authorized Users and sharing settings, protect accounts and personalized deal links, and avoid submitting unnecessary sensitive information. Publishing a deal or file can disclose its contents to the intended audience or people with the relevant resource URL. This DPA does not promise that every file is protected by a deal-page token. A sourced phone number, an imported contact, a submitted offer, a DNC result or messaging registration is not itself permission to send marketing communications. Customer must follow the Agreement’s consent, suppression and permitted-use requirements. These responsibilities do not excuse DispoIQ from its own obligations under this DPA or applicable law.4. Confidentiality and security
DispoIQ will limit access to Customer Personal Data to persons who need it for the agreed processing and who are subject to appropriate confidentiality obligations. It will implement security measures appropriate to the nature of that processing and applicable law. For the covered processing, these measures will include appropriate account and workspace authorization, restrictions on staff access, and safeguards for handling credentials and request or incident information. Measures will be proportionate to the processing risks and will be maintained and adjusted as appropriate. Personal Data Incidents will be handled under clause 7. This DPA does not promise a certification, dedicated database per customer, database-enforced isolation, universal encryption of every record, a backup frequency, an uptime percentage or a recovery deadline. Customer’s sharing instructions and access to lawfully retained records remain subject to applicable security and privacy duties.5. Subprocessors and other recipients
“Subprocessor” means a provider DispoIQ engages to process Customer Personal Data on its behalf for the covered processing. A provider performing its own independent purposes, an intended message recipient, a public deal visitor or a service Customer engages directly is not classified as a Subprocessor merely because it receives information. General authorization. By agreeing to this DPA, Customer generally authorizes DispoIQ to engage and replace Subprocessors at any time for any lawful business reason consistent with this DPA. Except as required by Applicable Data Protection Law or a separately accepted agreement between the parties, DispoIQ need not give advance or other change notice, obtain individual approval, or offer an objection right for an engagement or replacement. Where such law or agreement requires notice, an opportunity to object, specific authorization or identifying information, DispoIQ will provide it and satisfy the requirement before engagement where required. This general authorization does not waive those requirements. DispoIQ will require a covered Subprocessor to undertake written processing, confidentiality and security protections at least equivalent to the applicable protections under this DPA for the delegated activities, including any mandatory downstream contract terms. Engaging a Subprocessor does not relieve DispoIQ of its own obligations under this DPA. Necessary onward disclosures to carriers, registration services or other recipients must be described according to their actual role and permissions; not every recipient is promised to act solely on DispoIQ’s instructions. An engagement or replacement does not authorize a new processing purpose, expand the agreed instructions or permit a transfer without an applicable required safeguard. The Service Categories Overview describes functions and information categories; it does not identify a complete Subprocessor roster or establish acceptance of this DPA. Required Subprocessor-identification information and mandatory change procedures remain governed by this DPA, Applicable Data Protection Law and any separately accepted agreement between the parties. DispoIQ will maintain the actual covered Subprocessor identities, delegated functions, relevant information categories and material processing locations, together with the operative downstream processing terms. It will provide identifying and other processing information required by Applicable Data Protection Law or a separately accepted agreement through an appropriate agreed channel; requests may be sent to support@dispoiq.app. Required information, notice, objection opportunities or specific authorizations must be supplied or completed before engagement or acceptance where required. A generic category list or an unaccepted preview of terms does not establish the required identification or operative protections. These information obligations do not create an optional change-notice or individual-approval right beyond the general-authorization terms above.6. Individual requests, assistance and compliance information
Customer is responsible for handling requests concerning its own processing. DispoIQ will assist with covered requests as required by Applicable Data Protection Law and the agreed procedure. It will coordinate a request received directly with the relevant Customer where appropriate, without disclosing other customers’ records or disregarding an obligation that applies directly to DispoIQ. Requests may be sent to support@dispoiq.app. The requester should identify the relevant workspace or interaction without including identity documents or unnecessary sensitive information in the initial message. The route does not require an account or paid subscription. Support manages covered requests: logging receipt, identifying the relevant processing and Customer, applying proportionate identity or workspace-authority checks where appropriate, and coordinating secure fulfillment with authorized technical staff as needed. Additional evidence must be limited to what the request and applicable law require and supplied through an appropriate channel. Work beyond support’s authority is escalated for technical handling. Representative requests, opt-outs, required preference signals and response periods follow Applicable Data Protection Law; this procedure imposes no blanket identity-document requirement or delay of a mandatory deadline pending verification. DispoIQ will provide information and cooperation required by applicable processor-contract obligations, including relevant assessments, compliance checks and required audits or inspections. Safeguards for the scope of a review, confidential information, other customers’ data and safe operation of the Service must be consistent with Applicable Data Protection Law and must not prevent a legally required review. Where the CCPA applies to the covered relationship, Customer may take reasonable and appropriate steps to check permitted use and, on notice, stop and remediate unauthorized use. DispoIQ will notify Customer if it determines that it can no longer meet its applicable CCPA obligations. This does not authorize unrestricted access to another customer’s information or unsafe testing of the Service. No unspecified audit charge or extra assistance fee is authorized by this DPA. An agreed procedure cannot prevent a legally required review, assistance or individual right. This clause sets no discretionary response-time guarantee or audit cadence and does not promise an instant export or complete erasure through a single record-level control.7. Personal-data incidents
“Personal Data Incident” means unauthorized access to, disclosure, alteration, loss or destruction of Customer Personal Data in DispoIQ’s covered processing. An unsuccessful attempt with no such effect is not by itself a Personal Data Incident; the definition does not require Customer to prove resulting financial harm. Reports may be sent to support@dispoiq.app. Support will record and triage reports and escalate suspected incidents for authorized technical assessment. DispoIQ will assess the affected information and systems, take appropriate containment and corrective steps, and coordinate necessary cooperation with Customer and relevant Subprocessors. DispoIQ will notify Customer without unreasonable delay after becoming aware of a Personal Data Incident and provide the relevant information then available about its nature, affected information, likely consequences and response. It will supplement that information with material updates as they become available to support Customer’s required response. Notice will use the applicable agreed customer notice route, without displacing a legally required method. Any earlier or additional notice, information or cooperation required by Applicable Data Protection Law or a separately accepted processing commitment remains required. An investigation must not be used to defer required notice until all details are known or past an applicable deadline. Customer remains responsible for notices it is legally required to give, while DispoIQ remains responsible for its own required notices. Neither party may purport to speak for the other without authority. Incident notification does not by itself constitute an admission of liability or change the Agreement’s liability allocation.8. Return, deletion and lawful retention
The agreed processing continues while the Service and lawful retention require it, subject to Customer’s valid instructions and applicable law. After paid subscription access ends, Customer has a 90-day window measured from that end of paid access to request an export of information it is entitled to receive. Contact support@dispoiq.app with sufficient information to verify authority. This window does not extend ordinary paid application access or enlarge source-data export rights. A request received within the 90-day request window is not canceled merely because that window expires. DispoIQ will preserve the information it is authorized to provide and needs to fulfill that request until the request is fulfilled or otherwise lawfully resolved, except to the extent an earlier deletion obligation requires a different result. Routine deletion after 180 days will not by itself defeat such a timely request. DispoIQ may delete eligible workspace records after 180 days measured from the end of paid subscription access. This is not a promise that every copy is erased on day 180. These windows do not delay an individual-rights request or override an earlier return/deletion obligation under applicable law. DispoIQ will carry out Customer’s lawful return or deletion instructions for covered Customer Personal Data through the support-managed procedure in clause 6, coordinating with authorized technical staff and relevant Subprocessors as needed. Where Applicable Data Protection Law or a separately accepted processing commitment requires return or deletion at the end of the covered processing, DispoIQ will do so, at Customer’s choice where required, except for retention required by law. The commercial request and deletion windows above do not defer those duties or an earlier binding source-licence obligation. Fulfillment will identify the covered information Customer is entitled to receive or have deleted, use an appropriate secure return method, and protect other customers’ and individuals’ information. Removing or archiving a visible record is not by itself proof of complete erasure. DispoIQ will provide the outcome and any required information about remaining lawful retention or further action under Applicable Data Protection Law and the accepted processing terms. Any retention exception or hold must be limited to the information and period justified by its lawful purpose. Retained copies remain protected, may be used only for that purpose or another lawful agreed instruction, and will be deleted when the justification ends, subject to applicable requirements. Backup and onward copies must be addressed as required by Applicable Data Protection Law and the accepted processing terms; restoring a copy does not remove applicable deletion, correction or suppression duties. This clause promises no fixed backup-erasure cycle or instant deletion of every copy. Suppression and compliance records may be retained only to the extent justified by applicable duties. Lawfully retained Customer Personal Data remains subject to this DPA’s applicable confidentiality, security and processing restrictions. Financial records needed to maintain purchased wallet entitlements are not forfeited by a data-deletion window. Source records, Customer’s separately retained copies and recipients’ copies require their own applicable treatment; DispoIQ does not promise to erase records beyond its control simply by deleting a workspace contact.9. Locations and transfers
Business subscriptions are offered to US customers. Customers currently use DispoIQ to manage and message contacts in the US and Canada; eligible messaging destinations are limited to those countries through enabled routes. This does not establish every individual’s location, actual processing locations or which international-law requirements apply. DispoIQ will identify and document the actual processing destinations and onward access relevant to the covered processing, and provide material location and transfer information to Customer where Applicable Data Protection Law or a separately accepted agreement requires it. The parties must record the necessary roles, recipients and required transfer terms before the relevant processing or acceptance where required. DispoIQ will complete any required safeguards and mandatory transfer terms before the affected transfer. This DPA does not itself incorporate standard contractual clauses, designate unverified importer/exporter roles, claim a transfer certification or authorize a transfer with an unmet safeguard. A missing location record or transfer instrument does not waive a mandatory current duty.10. Liability, disputes and continuing obligations
This DPA creates no separate security/privacy supercap, independent incident indemnity or insurance promise. The agreed Terms’ liability system applies to covered customer contract claims, including their single overall cap per Agreement and the adopted exceptions. Expressly owed refunds remain payable in full outside the damages cap. Mandatory duties, independent individual claims and regulatory powers are not reduced by that commercial allocation. The Agreement’s Florida-law and AAA dispute framework governs disputes between the agreeing parties, subject to its exceptions and mandatory law. This DPA does not bind a recipient or other non-party to arbitration. Processing restrictions, confidentiality and security continue for Customer Personal Data still lawfully held. Changes to this DPA require the parties’ agreed amendment process; a newly posted page does not independently amend it. Termination and any resulting payment or refund rights remain governed by the Agreement and applicable law.Schedule 1. Covered customer-directed processing
This schedule specifies the covered activities for purchased, enabled functions under Customer’s documented instructions. It does not establish that every function is enabled, that every record contains every category, or that a new legal regime applies. A supported automation remains within the covered function and purpose it performs; this schedule grants no separate automation or channel entitlement.
Processing can be repeated during use of the enabled functions. Duration and post-access handling follow clause 8. Support and troubleshooting involving these records remain limited to the covered processing; unrelated subscriber administration is distinct. Confidentiality, security, recipient information, assistance, incidents, retention and transfer obligations follow clauses 4–9; this table does not certify particular infrastructure or locations.
When Customer requests an enabled lookup or enrichment function, customer-supplied lookup identifiers and subsequent hosting of lawfully obtained contact results are covered to the extent DispoIQ processes them on Customer’s behalf for the contact-management purpose above. Inputs and hosted results are limited to relevant supported contact, identity and property fields. Independently sourcing or licensing the underlying information remains a distinct activity under clause 1.4. Actual roles, permitted outputs and reuse restrictions must be identified in required processing particulars before the affected processing; absence of a record does not exempt actual on-behalf processing from this DPA or applicable law. This schedule supplies no blanket Licensed Data redistribution permission, unrelated advertising purpose or AI-training authorization.

