Version 2.4 • Effective Date: September 16, 2026

Data Processing Agreement (DPA)

This Data Processing Addendum (“DPA”) supplements the PropelRoot AI Master Subscription Agreement / Terms of Service entered into by and between PropelRoot AI (“Processor”) and the subscriber entity or contractor (“Customer” or “Controller”). This DPA governs the processing of Personal Data uploaded, captured, or ingested through the PropelRoot AI Voice, SMS, and Omnichannel Communications Platform.

B2B Enterprise Compliance Guarantee: PropelRoot AI acts strictly as a Data Processor / Service Provider with respect to homeowner and consumer data processed on behalf of Customer. PropelRoot AI never sells, retains, leases, or cross-monetizes consumer phone numbers, call audio, or lead records for advertising or third-party marketing.

1. Roles and Scope of Processing

1.1. Principal Roles: Customer is the Data Controller of Customer Personal Data under Applicable Data Protection Law (including CCPA, CPRA, and GDPR where applicable), and PropelRoot AI is the Data Processor acting solely on Customer's documented instructions.

1.2. Scope: Processor shall process Customer Personal Data exclusively for the purpose of providing, maintaining, and executing automated conversational voice calls, transactional SMS text-backs, appointment booking, and CRM synchronization as authorized under the Principal Agreement.

1.3. CCPA/CPRA Service Provider Certification: Processor certifies that it understands and complies with the restrictions of a Service Provider under the California Consumer Privacy Act. Processor shall not retain, use, disclose, or sell Customer Personal Data outside the direct business relationship with Customer.

2. Categories of Data and Data Subjects

2.1. Data Subjects: Homeowners, commercial property managers, prospective inbound sales leads, service callers, and Customer's personnel.

2.2. Data Categories Processed:

3. Technical and Organizational Security Measures (TOMs)

Processor has implemented and maintains comprehensive technical and organizational safeguards designed to protect Customer Personal Data against unauthorized disclosure, alteration, loss, or destruction:

4. Authorized Downstream Sub-Processors

Customer provides general written authorization for Processor to engage downstream infrastructure providers (“Sub-Processors”) essential to executing carrier telephony, speech recognition, and cloud database operations:

Sub-Processor Role / Service Category Data Center Region
Google Cloud Platform (GCP) Cloud Compute VPS Host & Edge Delivery Northern Virginia, USA
Supabase Inc. (AWS) Regional PostgreSQL Database & Storage North Virginia (us-east-1), USA
WorkOS Inc. Enterprise AuthKit, SSO & RBAC USA
Vonage Inc. (Ericsson) PSTN Voice Trunks & WebSocket Audio USA
SignalWire Inc. A2P 10DLC SMS Carrier Rails USA
TextGrid LLC Dedicated Direct REST Messaging Rails USA (Microsoft Azure)
AssemblyAI Inc. Universal Streaming Speech-to-Text USA
Deepgram Inc. Aura Neural Text-to-Speech Engine USA
OpenAI LLC Conversational Reasoning (Zero-Retention) USA
Resend Inc. Transactional Customer Care Email USA
Svix Inc. Enterprise HMAC-Signed Webhook Ingest USA

5. Security Incident and Data Breach Notification

5.1. Rapid Notification: In the event of a confirmed Security Incident involving Customer Personal Data on Processor systems, Processor shall notify Customer via email without unreasonable delay, and in any event within seventy-two (72) hours of becoming aware of the breach.

5.2. Remediation & Information: Processor shall take prompt remedial action to contain and mitigate the incident, and provide Customer with detailed information regarding the nature of the breach, affected records, and remediation steps.

6. Data Subject Rights (DSR) Assistance

Processor shall provide Customer with reasonable technical assistance to enable Customer to respond to consumer requests to exercise rights of access, correction, deletion, or portability under Applicable Data Protection Law. If a consumer contacts Processor directly, Processor shall redirect the consumer to Customer within forty-eight (48) hours.

7. Deletion and Return of Customer Personal Data

Upon termination of the Principal Agreement or upon Customer's written request, Processor shall securely delete or return all Customer Personal Data within thirty (30) days, except to the extent retention is required by applicable telecommunications regulatory record-keeping laws (e.g. TCPA 4-year consent records or 10DLC campaign audit trails).

8. Governing Law & Precedence

This DPA shall be governed by and construed in accordance with the governing law specified in the Master Subscription Agreement. In the event of any conflict between this DPA and the Master Agreement regarding personal data processing, this DPA shall prevail.

9. Contact & Data Protection Officer

For data protection inquiries, DPA execution requests, or sub-processor notifications, contact:

Data Protection Officer
PropelRoot AI
Email: [email protected] / [email protected]
Address: 8 The Green, Ste B, Dover, DE 19901, United States