Effective Date: August 1, 2026
This Data Processing Addendum (the "DPA") forms part of the agreement between Goxee Dealer Corp ("Goxee") and the customer identified in the applicable Subscription Documentation ("Customer") governing Customer's use of Goxee's Services (the "Agreement"). Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Definitions
1.1 Applicable Data Protection Law
"Applicable Data Protection Law" means a United States federal, state, or local law that applies to Goxee's Processing of Customer Personal Data under the Agreement, including, when applicable, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (the "CCPA") and its implementing regulations.
1.2 Customer Personal Data
"Customer Personal Data" means Personal Data contained in Customer Content that Goxee Processes on behalf of Customer to provide the Services. Customer Personal Data does not include information Goxee Processes as an independent controller or business for its own purposes as disclosed in Goxee's Privacy Policy, or information that has been lawfully aggregated or deidentified so that it is no longer Personal Data under Applicable Data Protection Law.
1.3 Personal Data and Processing
"Personal Data" means information defined as "personal information," "personal data," or a similar term under Applicable Data Protection Law. "Process," "Processed," and "Processing" mean any operation performed on Personal Data, including collecting, accessing, organizing, storing, using, transmitting, disclosing, modifying, retrieving, or deleting it.
1.4 Security Incident
"Security Incident" means a confirmed breach of Goxee's security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Security Incident does not include an unsuccessful attempt or activity that does not compromise Customer Personal Data, such as a failed login attempt, ping, port scan, denial-of-service attempt, or other attack blocked by Goxee's safeguards.
1.5 Subprocessor
"Subprocessor" means a third party appointed by or on behalf of Goxee to Process Customer Personal Data to provide the Services. It does not include a Customer-authorized third-party integration with which Customer contracts directly.
The terms "business," "business purpose," "consumer," "contractor," "sell," "service provider," and "share" have the meanings given in the CCPA when the CCPA applies.
2. Scope, Roles, and Priority
This DPA applies only when Goxee Processes Customer Personal Data on behalf of Customer and Applicable Data Protection Law requires a controller-processor, business-service-provider, or similar processing contract.
For that Processing, Customer is the controller or business and Goxee is the processor or service provider. If Customer Processes Personal Data on behalf of another organization, Goxee acts as Customer's subprocessor or subcontractor, and Customer represents that it is authorized to appoint Goxee and give the instructions in the Agreement and this DPA.
If this DPA conflicts with the Agreement concerning the Processing of Customer Personal Data, this DPA controls. The Agreement otherwise remains in effect. Subscription Documentation may impose additional data-protection terms only if it expressly identifies the provision of this DPA that it overrides.
3. Customer Instructions and Responsibilities
Customer instructs Goxee to Process Customer Personal Data only:
1. to provide, configure, secure, support, maintain, and improve the Services purchased by Customer;
2. as initiated or configured by Customer and its authorized users through the Services;
3. to prevent or investigate fraud, abuse, security incidents, and technical problems;
4. to comply with the Agreement and Applicable Data Protection Law; and
5. as further documented in writing by Customer and accepted by Goxee.
Customer is responsible for the lawfulness, accuracy, quality, and source of Customer Personal Data and its instructions. Customer will provide all required notices, establish an appropriate legal basis, obtain all required consents and authorizations, and respond to individuals exercising privacy rights. Customer will not instruct Goxee to Process Customer Personal Data in violation of law.
Customer may submit credit applications, Social Security numbers, driver’s-license information, employment information, income information, and related application details only through a Service expressly designed and authorized for credit-application Processing. Customer is responsible for providing required notices, obtaining required authorization, restricting access, and using that information lawfully. Customer will not submit protected health information governed by HIPAA, bank-account credentials, payment-card authentication data, biometric templates, precise geolocation, information known to concern a minor, or other legally regulated sensitive information unless Goxee expressly authorizes the information in Subscription Documentation. Full payment-card credentials must be submitted directly to the applicable payment processor and not stored in the Services.
4. Goxee Processing Obligations
Goxee will:
1. Process Customer Personal Data only on documented instructions contained in the Agreement, this DPA, Customer's use and configuration of the Services, and other written instructions Goxee accepts;
2. promptly inform Customer if Goxee reasonably believes an instruction violates Applicable Data Protection Law, unless law prohibits that notice;
3. ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations;
4. implement and maintain the safeguards described in Schedule 2;
5. provide reasonable assistance described in this DPA, considering the nature of the Processing and information available to Goxee; and
6. comply with Applicable Data Protection Law in its performance of this DPA.
Goxee may Process aggregated or deidentified information for analytics, security, support, research, and improvement, provided Goxee maintains it in aggregated or deidentified form, does not attempt to reidentify it except to test the effectiveness of deidentification as permitted by law, and does not disclose it in a manner that identifies Customer or an individual.
5. California Service-Provider Terms
When the CCPA applies to Customer Personal Data, the parties agree that Customer discloses Customer Personal Data to Goxee only for the limited and specified business purposes described in Section 3 and Schedule 1. Goxee will:
1. not sell or share Customer Personal Data;
2. not retain, use, or disclose Customer Personal Data outside the direct business relationship between Goxee and Customer or for a commercial purpose other than the limited and specified business purposes in this DPA, except as the CCPA permits;
3. not combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from Goxee's own interaction with an individual, except as the CCPA expressly permits;
4. provide the same level of privacy protection for Customer Personal Data as the CCPA requires of Customer;
5. notify Customer if Goxee determines it can no longer meet its obligations under the CCPA;
6. permit Customer to take reasonable and appropriate steps, as described in Section 9, to help ensure Goxee uses Customer Personal Data consistently with Customer's CCPA obligations;
7. cooperate with Customer's reasonable request to stop and remediate unauthorized use of Customer Personal Data;
8. comply with applicable restrictions concerning the sale or sharing of Personal Data and with a consumer's opt-out or limitation request that Customer communicates to Goxee; and
9. require each Subprocessor that Processes Customer Personal Data to comply with privacy obligations consistent with this DPA and Applicable Data Protection Law.
The parties acknowledge that the Customer Personal Data is disclosed to Goxee only for the business purposes described in this DPA and not as consideration for services or other value.
6. Security
Taking into account the nature of the Customer Personal Data, the state of available safeguards, implementation costs, and risks to individuals, Goxee will maintain reasonable administrative, technical, organizational, and physical safeguards designed to protect Customer Personal Data from a Security Incident. Goxee may update the safeguards as technology and risks evolve, provided the overall level of protection is not materially reduced during a Subscription Term.
Customer is responsible for using available security features appropriately, protecting credentials, configuring access, managing authorized users, maintaining secure Customer-controlled systems and integrations, and promptly notifying Goxee of suspected unauthorized access.
7. Security-Incident Response
Goxee will notify Customer without undue delay after confirming a Security Incident and within any shorter period Applicable Data Protection Law requires. Notice will be sent to Customer's administrative or security contact on file unless Customer designates another contact in writing.
As information becomes reasonably available, Goxee's notice will describe the nature of the Security Incident, the categories of affected Customer Personal Data and individuals, the likely consequences, measures taken or proposed, and a contact for follow-up. Goxee may provide information in phases and will take reasonable steps to contain, investigate, and remediate the Security Incident.
Customer is responsible for determining whether it must notify an individual, regulator, or other party. Goxee will provide reasonable cooperation, considering the nature of the Processing and information available to it. Goxee's notification or response is not an admission of fault or liability.
8. Individual Requests and Compliance Assistance
Considering the nature of the Processing and functionality of the Services, Goxee will reasonably assist Customer with requests to access, know, correct, delete, obtain a copy of, opt out of, or limit the use of Customer Personal Data as required by Applicable Data Protection Law. Where available, Customer will first use the Services' self-service tools.
If Goxee receives a request directly from an individual concerning Customer Personal Data, Goxee will, unless legally required to respond differently, direct the individual to Customer or notify Customer and will not respond substantively without Customer's instruction. Customer is responsible for verifying the request and determining the appropriate response.
Goxee will provide information reasonably necessary for Customer to perform a legally required privacy-impact, data-protection, or similar assessment relating to the Services. Any material work beyond Goxee's standard documentation and reasonable assistance may be subject to mutually agreed fees.
9. Information and Audits
Upon reasonable written request, Goxee will provide information reasonably necessary to demonstrate compliance with this DPA, which may include a current security summary, relevant third-party assessment or certification, or a completed reasonable security questionnaire.
No more than once in any twelve-month period, Customer may request an audit of Goxee's compliance if the documentation is reasonably insufficient. Additional audits are permitted following a Security Incident affecting Customer Personal Data or when required by a regulator or Applicable Data Protection Law. An audit must:
1. be conducted by Customer or an independent auditor subject to confidentiality obligations;
2. occur on at least thirty (30) days' notice during normal business hours, unless a shorter period is legally required;
3. be limited to systems and records relevant to Customer Personal Data;
4. avoid access to another customer's data, Goxee trade secrets unrelated to compliance, or information that would compromise security; and
5. avoid unreasonable interference with Goxee's operations.
Customer bears its audit costs and Goxee's reasonable costs for assistance beyond its standard compliance materials, unless an audit identifies Goxee's material breach of this DPA. The parties will work in good faith on reasonable remediation of a substantiated finding.
10. Subprocessors
Customer generally authorizes Goxee to appoint and replace Subprocessors as reasonably necessary to provide the Services. Goxee will enter into a written agreement requiring each Subprocessor to protect Customer Personal Data through confidentiality, security, and data-processing obligations appropriate to the services the Subprocessor performs. Goxee remains responsible for the Subprocessor's performance of those obligations to the same extent Goxee would be responsible if it performed the Processing itself.
A third-party integration, platform, or provider that Customer independently selects or connects to its account is not Goxee's Subprocessor. Customer is responsible for its relationship with that provider and for authorizing any transfer of Customer Personal Data to it. Goxee is not required to publish a Subprocessor list or provide advance notice of a Subprocessor change unless Applicable Data Protection Law or Subscription Documentation expressly requires otherwise.
11. Government and Legal Requests
Goxee may disclose Customer Personal Data when required by law, subpoena, or court order. Unless prohibited by law, Goxee will notify Customer before disclosure and provide reasonable assistance, at Customer's expense, if Customer seeks protective treatment. Goxee will disclose only the information legally required.
12. Return and Deletion
During the Subscription Term, Customer may access or export Customer Personal Data using available Service functionality. Following expiration or termination of the applicable Service, Goxee will delete Customer Personal Data from active production systems within thirty (30) days and from backups within ninety (90) days, except to the extent a longer period is required by law or necessary to preserve information relating to an active dispute, security incident, or legal hold. Retained Customer Personal Data remains protected by this DPA and will be used only for the applicable retention purpose.
Goxee may retain lawfully aggregated or deidentified information that is not Customer Personal Data. Goxee may also retain billing records indefinitely in its independent business capacity; those records exclude full payment-card credentials. Customer is responsible for exporting Customer Personal Data it requires before its access to the Service ends.
13. Liability
Each party's liability arising out of or relating to this DPA is subject to the exclusions, limitations, and other liability provisions in the Agreement. Claims under this DPA and the Agreement are aggregated for purposes of applying any liability cap. Nothing in this DPA limits liability that cannot lawfully be limited.
14. Term and General Provisions
This DPA begins when it becomes part of the Agreement and continues while Goxee Processes Customer Personal Data. Provisions that by their nature should survive—including confidentiality, deletion, audit, liability, and restrictions on Processing—survive termination for as long as Goxee retains Customer Personal Data.
The governing-law, dispute-resolution, notice, assignment, severability, and waiver provisions of the Agreement apply to this DPA. If a change to Applicable Data Protection Law requires an amendment, the parties will cooperate in good faith to make the amendment reasonably necessary for compliance.
Schedule 1 — Processing Details
A. Subject Matter and Duration
Goxee Processes Customer Personal Data to provide the Services described in the Agreement and Subscription Documentation for the Subscription Term, followed by the thirty (30)-day production and ninety (90)-day backup deletion periods in Section 12 or any longer retention required under a stated exception.
B. Nature and Purpose
Processing may include collecting, importing, organizing, hosting, storing, retrieving, accessing, transmitting, displaying, routing, analyzing, securing, troubleshooting, supporting, backing up, exporting, and deleting Customer Personal Data for the following specific purposes:
1. creating and administering Customer and authorized-user accounts;
2. operating, configuring, hosting, maintaining, and supporting the purchased Services;
3. transmitting and managing Customer-directed calls, messages, emails, forms, appointments, requests, reviews, and other communications or workflows;
4. integrating the Services with systems and third-party services selected by Customer;
5. providing Customer support and resolving technical issues;
6. measuring Service performance, maintaining availability, and improving functionality for Customer;
7. detecting, preventing, and investigating fraud, abuse, security incidents, and violations of the Agreement; and
8. complying with Customer's documented instructions and applicable legal obligations.
C. Categories of Individuals
Depending on Customer's use of the Services, individuals may include:
• Customer's authorized users, administrators, employees, contractors, and representatives;
• Customer's current and prospective customers, leads, website visitors, and communication recipients; and
• individuals whose information Customer imports from an authorized integration or other lawful source.
D. Categories of Customer Personal Data
Depending on Customer's configuration and purchased Services, Customer Personal Data may include:
• names, telephone numbers, email addresses, postal addresses, and other contact identifiers;
• account, dealership, vehicle, lead, inquiry, appointment, transaction, and relationship information;
• message, email, form, review, call, recording, transcription, and other communication content and metadata;
• consent, opt-out, preference, suppression, and communication-history records;
• credit applications, Social Security numbers, driver’s-license information, employment information, income information, and related application details submitted through an authorized credit-application Service;
• authorized-user account, role, authentication, activity, device, log, and support information; and
• data Customer elects to import from its systems or authorized third-party integrations.
Customer may not submit the prohibited or specially regulated data identified in Section 3 except as that section expressly permits.
E. Frequency
Processing may occur continuously or intermittently as Customer and its authorized users access, configure, or use the Services.
Schedule 2 — Security Measures
As appropriate to the applicable Service, the nature of the Customer Personal Data, and the risk, Goxee maintains the following confirmed safeguards:
1. Encryption: encryption of Customer Personal Data in transit and at rest.
2. Access management: unique user identities, role-based and least-privilege access, access reviews, and multifactor authentication for privileged production access.
3. Logging and monitoring: security logging and monitoring of relevant production, administrative, and security events.
4. Availability and recovery: backup and recovery procedures appropriate to the applicable Service.
5. Provider agreements: standardized contractual confidentiality, security, and privacy terms with Subprocessors appropriate to the services they perform.