Skip to main content

Legal

Data Processing Addendum

Last updated 2026-07-23

1. Parties, scope, and order of precedence

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or another written agreement (the “Agreement”) between EFFICIO MARKETING LLC, an Ohio limited liability company(“Efficio”), and the business customer identified in the Agreement (“Customer”). It applies only to the extent Efficio processes Customer Personal Data on Customer’s behalf in providing the Platform.

“Customer Personal Data” means personal data, personal information, or an equivalent regulated category submitted to, collected through, or otherwise processed by the Platform for Customer as controller, business, or equivalent decision-maker. It excludes data for which Efficio independently determines purposes and means as described in the Privacy Policy. “Data Protection Law” means privacy or data-protection law that actually applies to the relevant processing. Statutory terms have the meanings given by that law.

If this DPA conflicts with the Agreement concerning Customer Personal Data, this DPA controls. Nothing in this DPA reduces a protection or right that Data Protection Law makes non-waivable. Requirements tied to a jurisdiction, statutory threshold, regulated industry, or special data category apply only when their legal prerequisites are satisfied.

2. Roles, instructions, and Customer responsibilities

Customer is the controller, business, or equivalent decision-maker for Customer Personal Data. Efficio acts as Customer’s processor, service provider, contractor, or equivalent, except for the limited independent purposes disclosed in the Privacy Policy. Customer is responsible for the lawfulness of its collection, instructions, notices, legal bases, consents, disclosures, and use of Customer Personal Data.

Efficio will process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Customer’s configuration and use of the Platform, and lawful written support requests, unless applicable law requires other processing. Efficio will notify Customer without undue delay and may suspend affected processing if an instruction appears unlawful, exceeds the Platform’s supported scope, or creates a material security, privacy, or safety risk. Efficio is not responsible for independently determining whether Customer’s business, notices, or instructions satisfy laws applicable to Customer.

3. Processing details

  • Subject matter: website creation and hosting, lead capture and delivery, appointment requests, chat, call routing and metadata, analytics, support, security, billing administration, and Customer-configured Platform functions.
  • Duration:the Agreement’s term plus a commercially reasonable period for return, deletion, backup expiry, security, billing, dispute, legal-hold, and legal obligations described in this DPA and the Privacy Policy.
  • Nature and purpose:collecting, recording, organizing, storing, retrieving, displaying, transmitting, securing, troubleshooting, and deleting data to provide, protect, support, and bill for the Platform on Customer’s instructions.
  • Data subjects: Visitors, prospective and actual customers of Customer, callers, appointment requesters, Customer personnel, and other people whose data Customer lawfully submits.
  • Data types: identity and contact details, communications and request content, appointment details, call-routing metadata, page and campaign context, infrastructure-provided IP-derived location, pseudonymized network signals, Customer handling history, and other data Customer configures or submits consistently with the Agreement.
  • Frequency: continuous or event-driven while Customer uses the applicable Platform features.

4. Restricted use, sale, sharing, and deidentified data

Efficio will not sell Customer Personal Data or share it for cross-context behavioral advertising; use it to advertise unrelated products to data subjects; use it to train unrelated general-purpose models; or retain, use, disclose, or combine it outside the direct business relationship except as permitted by the Agreement and Data Protection Law. Efficio may process Customer Personal Data for the business purposes stated in the Agreement, including security, fraud and abuse prevention, billing, support, legal compliance, service quality, and exercising or defending legal claims.

Efficio may create aggregated or deidentified information to operate, secure, understand, and improve the Platform only under measures reasonably designed to prevent identification. Efficio will not attempt to reidentify information that Data Protection Law requires to remain deidentified.

5. Confidentiality and personnel

Efficio will limit access to Customer Personal Data to personnel and service providers who need it for the Agreement, support, security, legal compliance, or another permitted purpose. Authorized personnel must be subject to confidentiality obligations or an equivalent legal duty and must process Customer Personal Data consistently with this DPA.

6. Security measures

Taking account of the nature, scope, context, and purposes of processing and the risk to individuals, Efficio will maintain technical and organizational measures designed to provide security appropriate to the risk. The current baseline includes, as applicable to the relevant service:

  • HTTPS/TLS for Platform traffic and provider-managed encryption at rest where supported;
  • authentication, role-based access, tenant authorization checks, database row-level restrictions, and service-role separation;
  • environment and secret separation, limited provider credentials, and signed or secret-protected provider callbacks and workers;
  • input validation, rate limiting, abuse controls, logging, monitoring, and error reporting;
  • change review and automated type, lint, test, and build checks before production release;
  • provider-supplied resilience, backup, and recovery capabilities where configured and available; and
  • data minimization and access limited to operational, support, security, billing, or legal need.

Efficio may update measures as technology and the Platform change, provided the overall protection is not materially reduced. Customer is responsible for securing its credentials and devices, controlling authorized users, configuring the Platform appropriately, and promptly reporting suspected compromise.

7. Subprocessors

Customer generally authorizes Efficio to use the providers identified in the Subprocessor Notice to provide the Platform. A listed provider applies only when the relevant feature or production configuration causes it to process Customer Personal Data.

Efficio will use a written agreement or other legally valid arrangement requiring each subprocessor to protect Customer Personal Data consistently with the processing it performs and applicable law. Efficio remains responsible for its subprocessor obligations to the extent required by Data Protection Law.

Where Data Protection Law or a written order requires advance notice of a material new subprocessor, Efficio will provide reasonable notice through the Platform, Customer’s account email, or another agreed channel. Customer may object on reasonable, documented data-protection grounds. The parties will consider a commercially reasonable alternative; if none is available, either party may terminate the affected service without terminating unaffected services. Current provider information may be requested at privacy@effic.io.

8. Individual rights and compliance assistance

Taking into account the nature of processing and information available to Efficio, Efficio will provide commercially reasonable assistance for Customer to respond to requests that Data Protection Law requires Customer to honor, including applicable access, correction, deletion, portability, restriction, objection, opt-out, limitation, or appeal requests. Assistance may use then-available dashboard functions, exports, support procedures, or reasonable manual measures; this DPA does not promise a self-service rights portal or a particular technical workflow.

If Efficio receives a request concerning Customer Personal Data, Efficio may direct or transmit it to Customer and will not respond on Customer’s behalf unless Customer authorizes the response or law requires it. Customer remains responsible for verifying requests, making legal decisions, communicating with individuals, and meeting deadlines. Efficio may charge reasonable fees for unusually burdensome assistance where permitted by law and the Agreement.

Efficio will provide information reasonably available and necessary for Customer’s required data-protection impact assessments, prior consultations, regulator inquiries, or security assessments. This obligation does not require Efficio to provide privileged material, source code, information about other customers, or information that would create a security risk.

9. Personal Data Breaches

Efficio will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a “Personal Data Breach”). Notice will include information then reasonably available about the nature of the incident, affected data and people, likely consequences, containment or remediation, and a contact for follow-up. Efficio may provide information in phases and will not delay initial notice solely because an investigation is incomplete.

Efficio will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and cooperate with Customer’s legally required assessment and notices. Customer determines whether and how to notify authorities or individuals for processing where Customer is controller. Efficio will not identify Customer publicly without permission unless required by law. A notice is not an admission of fault or liability.

10. Access, return, deletion, backups, and legal holds

During the Agreement, Customer may use available Platform functions and reasonable support requests to access, correct, export, or delete Customer Personal Data. Following termination or a lawful documented instruction, Efficio will delete or return Customer Personal Data within a commercially reasonable period, taking account of the volume, technical dependencies, provider systems, and then-available Platform capabilities, unless law or a permitted purpose requires retention.

Data may remain temporarily in protected backups, logs, security records, billing records, legal archives, or provider systems until the applicable lifecycle expires. While retained, it will remain subject to this DPA and will not be restored to ordinary use except for recovery, security, legal compliance, or another permitted purpose. A litigation hold, regulator request, preservation duty, billing dispute, fraud investigation, or other legal obligation may delay deletion; the ordinary disposition process resumes when the hold ends.

Where applicable to a lawful Customer instruction, Efficio will communicate the relevant correction, deletion, return, or restriction instruction to subprocessors that process the affected Customer Personal Data and will provide information about the result that is reasonably available to Efficio. A provider may retain information where independently required or permitted by law or until a protected backup lifecycle expires.

11. International transfers

Each party will comply with transfer restrictions that apply to it. If Customer Personal Data subject to the EU GDPR, UK GDPR, or another transfer restriction is processed in a country lacking a legally sufficient adequacy basis, the parties will use a valid transfer mechanism required for that processing, which may include the European Commission’s then-current Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved safeguard.

Where execution of a particular transfer module, annex, assessment, localization measure, or supplementary safeguard is legally required, the parties will complete it before commencing the affected Customer use or as otherwise required by law. Efficio may suspend an affected transfer or feature if no lawful and commercially reasonable mechanism is available.

12. Information, reviews, and audits

Efficio will make available information reasonably necessary to demonstrate compliance with this DPA, such as relevant summaries, policies, questionnaires, or independent reports when available. Customer must first use that information and reasonable written questions.

If Data Protection Law requires an audit and the available information is insufficient, Customer may request a proportionate audit by an independent, qualified auditor bound by confidentiality. Unless a regulator or confirmed Personal Data Breach reasonably requires otherwise, an audit may occur no more than once annually, must use reasonable advance notice, must avoid exposing other customers’ data, source code, privileged or security-sensitive material, and must not unreasonably disrupt operations. Customer bears its costs unless the audit establishes Efficio’s material breach.

13. Government and third-party demands

Unless prohibited by law, Efficio will notify Customer of a binding demand specifically seeking Customer Personal Data, refer the requester to Customer where appropriate, review the demand for facial legal validity, challenge an invalid or materially overbroad demand where reasonably appropriate, and disclose no more than legally required. Nothing requires Efficio to violate law, compromise an emergency response, or disclose privileged legal advice.

14. U.S. state privacy commitments

Where Customer Personal Data is subject to an applicable U.S. state privacy law and Customer is a covered business or controller, Efficio will act as a service provider, contractor, or processor as applicable; process the data only for the limited and specified purposes in the Agreement; comply with applicable restrictions; provide the level of protection required by law; notify Customer if Efficio determines it can no longer meet those obligations; and cooperate with reasonable steps required to verify, stop, and remediate unauthorized processing.

15. Excluded regulated uses

This DPA is not a HIPAA business associate agreement and does not authorize processing protected health information, consumer-health programs requiring specialized consent or infrastructure, child-directed data, payment-card credentials, government identifiers, biometric templates, precise GPS or device location, or another specially regulated category prohibited by the Agreement. Customer must not use the Platform for those purposes unless Efficio expressly approves the use in a separate written agreement and the parties complete any required compliance terms before processing begins.

16. Liability, termination, survival, and contact

The Agreement’s liability limitations and dispute terms apply to this DPA to the maximum extent permitted by law, without reducing non-waivable rights or regulatory powers. Either party may suspend or terminate affected processing if the other party materially breaches this DPA and does not cure within a reasonable period after written notice, unless immediate action is required by law or an urgent material risk. This DPA survives for as long as Efficio retains Customer Personal Data.

Privacy and DPA notices may be sent to privacy@effic.io; formal legal notices may be sent to legal@effic.io and 6708 Main Street, Cincinnati, OH 45244, United States. Customer notices go to the account contact unless Customer designates another address in writing.