Data Processing Addendum
Effective September 23, 2026
Overview
This Data Processing Addendum ("DPA") supplements the Terms of Service and applies when ASR Enterprises LLC ("we," "Processor") processes data on behalf of a consulting client ("you," "Controller"). This includes situations where we build, host, or manage systems that collect data from your customers, employees, or other third parties.
If there is a conflict between this DPA and the Terms of Service on matters of data handling, this DPA controls. If you have a signed Master Services Agreement with us, that agreement controls over this DPA wherever they conflict.
Definitions
- Client Data: Any data, content, or information submitted to, processed by, or accessible through systems we operate or access on your behalf. Data you supply, and data we obtain for you at your direction and expense, is Client Data.
- ASR Data: Data we obtain on our own account for use across engagements, including licensed voter and consumer data and the lists and audiences we build from it. ASR Data is our own data and is not Client Data.
- Personal Data: Any information relating to an identified or identifiable individual within Client Data.
- Processing: Any operation performed on Client Data, including collection, storage, retrieval, transmission, analysis, and deletion.
- Subprocessor: Any third-party service we use to process Client Data.
Roles
You are the Data Controller. You determine what data is collected, why it is collected, and how it should be handled. We are the Data Processor. We process Client Data only as necessary to provide the services you have engaged us for, and only according to your instructions.
Scope of Processing
We process Client Data only to the extent necessary to perform the consulting, technology, or operational services outlined in our engagement with you. This may include:
- Building and maintaining data collection forms, ticketing systems, or intake workflows on platforms like Airtable.
- Accessing your business platforms (CRM, email marketing, website management) to perform authorized work.
- Exporting data for analysis when required for the engagement.
- Processing voter data or audience data for political campaign targeting and advertising.
We will not process Client Data for any purpose other than providing the agreed-upon services, except where required by law.
Sensitive and Regulated Data
Some engagements involve processing regulated identifiers such as government-issued ID numbers (driver's licenses, federal tax identification numbers) or other data classified as sensitive under applicable breach notification laws. If your engagement involves regulated identifiers or data subject to industry-specific regulations (insurance data, health information, financial records subject to GLBA), identify this during engagement setup so that any additional safeguards can be agreed in the Statement of Work.
Data Security
We maintain administrative, technical and physical safeguards appropriate to the nature of the data and the size of our business, including access limited to personnel who need it, multi-factor authentication on systems that support it, encryption of personal data in transit, and a written incident response plan. Personnel with access to Client Data are bound by confidentiality obligations. A summary of our security program is available on request.
Subprocessors
We use third-party services that may process Client Data in the course of providing our services. The current, authoritative list of these subprocessors, along with their purpose and location, is maintained on our Subprocessors page.
Not all subprocessors apply to every engagement. The specific platforms involved depend on the services we provide to you. We may also connect to industry-specific platforms (insurance CRMs, nonprofit donor systems, scheduling tools, etc.) as required by your engagement. We choose these providers with reasonable care and use them under written confidentiality and security terms suited to the processing.
Data Subject Requests
If we receive a request from an individual to access, correct, or delete their personal data, and that data was collected through a system we operate on your behalf, we will promptly notify you and provide reasonable assistance in responding to the request. We will not respond directly to data subject requests without your authorization, unless required by law.
Data Retention and Deletion
Within 90 days after our agreement with you ends, or after your written request, we will return or delete Client Data under our control. We may keep limited records where needed for legal, accounting or claims purposes, and backup copies expire on their normal cycle. Anything we keep stays protected under this DPA.
Breach Notification
If we become aware of, or reasonably believe there has been, unauthorized access to or loss of Client Data under our control, we will notify you without unreasonable delay, and sooner where the law requires. A first notice may be based on the facts known at the time and updated later. We will cooperate with your investigation. You decide on notices to affected individuals and others, except where the law requires us to give notice ourselves. We may share incident details in confidence with our insurers, insurance broker, and legal and incident-response advisers.
Your Obligations
As the Data Controller, you are responsible for:
- Ensuring you have the legal basis to collect and process the data you instruct us to handle.
- Obtaining any necessary consents from individuals whose data is collected through systems we operate on your behalf.
- Providing clear instructions about how Client Data should be processed.
- Complying with applicable data protection laws, including any restrictions on the types of data that may be collected through your forms and systems.
Engagement-Specific Terms
This DPA provides baseline data processing terms. Individual consulting engagements may include additional data handling requirements (for example, specific retention periods, additional security measures, or restrictions on data use). Where a signed engagement agreement includes data processing terms, those terms control.
Contact
For questions about this addendum or to make a data-related request, contact a@alexreynolds.com.