This Data Processing Addendum (“DPA”) forms part of the Terms of Service and any related service agreement (the “Agreement”) between Switchboard LLC (“Switchboard,” “Processor,” “we,” or “us”), a Kansas limited liability company (Entity ID 10078361), and the customer identified in the Agreement (“Client,” “Controller,” or “you”). This DPA governs the processing of Personal Data that Switchboard performs on the Client’s behalf in providing the Service. Where this DPA conflicts with the Agreement on matters of data protection, this DPA controls.
Definitions
1.1 “Personal Data”. means any information relating to an identified or identifiable natural person that Client routes through, submits to, or stores within the Service, including lead names, phone numbers, email addresses, and property or transaction details.
1.2 “Processing”. means any operation performed on Personal Data, including collection, receipt, storage, routing, transmission, and deletion.
1.3 “Data Protection Laws”. means all privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), the General Data Protection Regulation (“GDPR”), and the Telephone Consumer Protection Act (“TCPA”).
1.4 “Sub-processor”. means any third party engaged by Switchboard to process Personal Data on the Client’s behalf in connection with the Service.
1.5 Roles. For Personal Data that Client routes through the Service, Client is the Controller (or business) and Switchboard is the Processor (or service provider). Client determines the purposes and means of processing; Switchboard processes only on Client’s documented instructions.
Scope and Roles of the Parties
2.1 Processor role. Switchboard processes Personal Data solely to provide the Service — capturing inbound leads submitted through Client’s branded intake form, routing that information into Client’s designated CRM, and alerting Client of new leads. Switchboard does not contact, message, or communicate with Client’s leads on its own behalf and is never the voice to the lead.
2.2 Client responsibilities. Client is responsible for the accuracy, quality, and legality of the Personal Data it routes through the Service and for having a lawful basis and any required consent to collect and process that data, including consent required under the TCPA for any SMS communications Client sends.
2.3 Documented instructions. This DPA and the Agreement constitute Client’s complete and final documented instructions to Switchboard for the processing of Personal Data. Switchboard will not process Personal Data for any other purpose unless required by law, in which case it will notify Client where legally permitted.
Switchboard’s Processing Obligations
3.1 Instruction-bound processing. Switchboard will process Personal Data only on Client’s documented instructions and will not sell Personal Data or share it for cross-context behavioral advertising.
3.2 No independent use. Switchboard will not retain, use, or disclose Personal Data routed through the Service for any purpose other than performing the Service, or as otherwise permitted under Data Protection Laws with respect to a service provider.
3.3 Confidentiality. Switchboard will ensure that persons authorized to process Personal Data are bound by appropriate confidentiality obligations.
3.4 Cooperation. Taking into account the nature of the processing, Switchboard will provide reasonable assistance to Client in responding to requests from data subjects and in meeting Client’s obligations under Data Protection Laws.
Sub-processors
4.1 Authorization. Client provides general authorization for Switchboard to engage the Sub-processors listed in Annex B to process Personal Data in connection with the Service.
4.2 Obligations. Switchboard will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for each Sub-processor’s performance.
4.3 Changes. Switchboard will notify Client of any intended addition or replacement of a Sub-processor, giving Client a reasonable opportunity to object on reasonable data-protection grounds.
Data Subject Rights
Switchboard will, to the extent legally permitted, promptly notify Client if it receives a request from a data subject to exercise rights of access, correction, deletion, or portability with respect to Personal Data, and will not respond to such a request itself except on Client’s documented instructions or as required by law. Because Personal Data lands directly in Client’s own CRM, Client generally retains the ability to action such requests directly.
Security Measures
Switchboard will implement and maintain the technical and organizational security measures described in Annex C, designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, appropriate to the risk.
Personal Data Breach
Switchboard will notify Client without undue delay after becoming aware of a Personal Data breach affecting Client’s Personal Data, and will provide Client with information reasonably available to it to assist Client in meeting any breach-notification obligations under Data Protection Laws.
Deletion and Return of Data
Upon termination of the Service, or upon Client’s written request, Switchboard will delete or return Personal Data processed on Client’s behalf within a commercially reasonable period, except to the extent retention is required by law. Because leads route directly into Client’s CRM, Client’s primary record of Personal Data remains under Client’s control at all times.
Audits
Switchboard will make available to Client information reasonably necessary to demonstrate compliance with this DPA. Any audit right will be exercised on reasonable prior written notice, no more than once per twelve-month period absent a documented security incident, during business hours, and in a manner that does not disrupt Switchboard’s operations.
International Transfers
Switchboard processes Personal Data in the United States. Where Personal Data originating in a jurisdiction with cross-border transfer restrictions is processed, the parties will cooperate to put in place any transfer mechanism required by applicable Data Protection Laws.
CCPA / CPRA Service Provider Terms
11.1 Service provider status. With respect to Personal Data subject to the CCPA, Switchboard is a “service provider” and processes such data solely to perform the Service on Client’s behalf under the business purpose described in the Agreement.
11.2 Restrictions. Switchboard will not: (a) sell or share Personal Data; (b) retain, use, or disclose it for any purpose other than performing the Service, including for any commercial purpose other than the Service; or (c) combine it with Personal Data received from other sources, except as permitted for a service provider under the CCPA.
11.3 Certification. Switchboard certifies that it understands and will comply with the restrictions in this Section 11.
TCPA and SMS Consent
The Service alerts Client of inbound leads; it does not send marketing or solicitation messages to leads on Switchboard’s behalf. Client is solely responsible for obtaining and maintaining any consent required under the TCPA and related regulations for any text or call communications Client sends to leads, and for honoring opt-out requests. Client will indemnify Switchboard against claims arising from Client’s communications with leads.
General
This DPA is governed by the laws of the State of Kansas, without regard to conflict-of-laws principles. If any provision is found unenforceable, the remainder remains in effect. This DPA may be executed by acceptance at checkout, incorporation by reference into the Agreement, or signature below; any of these binds the parties.
Signatures
For arrangements requiring formal execution, the parties sign below. For standard purchases, acceptance of the Agreement at checkout constitutes acceptance of this DPA.
| Switchboard LLC (Processor) | Client (Controller) |
|---|---|
| Signature: ______________________ | Signature: ______________________ |
| Name: __________________________ | Name: __________________________ |
| Title: ___________________________ | Title: ___________________________ |
| Date: ___________________________ | Date: ___________________________ |
Annex A — Details of Processing
| Element | Detail |
|---|---|
| Subject matter | Provision of the Switchboard lead intake and routing Service |
| Duration | For the term of the Agreement, plus any legally required retention period |
| Nature and purpose | Capture of inbound leads via branded form; routing into Client’s CRM; new-lead alerts to Client |
| Categories of data subjects | Client’s prospective real estate leads and contacts |
| Categories of Personal Data | Name, phone number, email address, property/transaction interest, and any fields Client configures on the intake form |
| Special categories | None intended; Client instructed not to route special-category data through the Service |
Annex B — Approved Sub-processors
| Sub-processor | Function | Location |
|---|---|---|
| HighLevel Inc. (GoHighLevel) | CRM, form hosting, workflow automation, data storage | United States |
| Zapier Inc. | Data pass-through / integration between systems | United States |
| Twilio Inc. | SMS alert delivery to Client | United States |
Annex C — Technical & Organizational Security Measures
| Area | Measure |
|---|---|
| Access control | Access to Personal Data limited to authorized personnel on a need-to-know basis, protected by strong authentication |
| Encryption | Data encrypted in transit via industry-standard TLS; at-rest encryption provided by underlying sub-processor platforms |
| Sub-processor security | Reliance on established platforms (GoHighLevel, Zapier, Twilio) maintaining their own recognized security programs |
| Data minimization | Only the lead fields Client configures are collected; no unnecessary Personal Data is requested |
| Incident response | Documented process to detect, assess, and notify Client of Personal Data breaches without undue delay |
| Retention & deletion | Personal Data deleted or returned on termination or request, subject to legal retention requirements |