Data Processing Addendum
SCHEDULE B
DATA PROCESSING ADDENDUM
Version 1.1
Effective Date: July 9, 2026
This Data Processing Addendum (“DPA”) forms part of the Kliqbot™ Terms of Service between Kliqbot LLC (“Processor”) and the customer identified in the applicable agreement (“Controller” or “you”).
This DPA applies where Kliqbot processes Personal Data on behalf of the Controller in connection with the Kliqbot™ platform and services.
1. Definitions
Terms used but not defined in this DPA shall have the meanings given to them in the GDPR, UK GDPR, or the Controller’s agreement with Kliqbot. Key terms include “Personal Data”, “Processing”, “Processor”, “Controller”, and “Data Subject”.
2. Roles and Scope
2.1 Roles
The Controller determines the purposes and means of the processing of Personal Data. Kliqbot acts as a Processor when processing Personal Data on behalf of the Controller in connection with the Services. Where the Controller is an agency using the Agency OS plan, the Controller remains responsible for ensuring it has all necessary authority and consents from its own clients (see the Agency OS Addendum).
2.2 Subject Matter, Duration, Nature and Purpose of Processing
Kliqbot processes Personal Data for the duration of the Controller’s subscription to the Services in order to provide the Platform, including but not limited to: analyzing publicly available website content, building and optimizing Google Ads campaigns subject to the three-tier autonomy model, generating and hosting landing pages, tracking and analyzing calls and leads, uploading conversion data to Google (respecting consent signals), providing reporting, alerts, and dashboard functionality, and preventing fraud and ensuring platform security.
2.3 Categories of Data Subjects and Personal Data
Data subjects include the Controller’s customers, leads, website visitors, and (where applicable) the Controller’s own personnel. Categories of Personal Data include contact information, Google Ads data, lead and call data, website content, and technical/usage data.
3. Obligations of the Processor
Kliqbot shall:
- Process Personal Data only on documented instructions from the Controller (including via the Platform configuration and the three-tier approval model), unless required to do so by applicable law.
- Ensure that persons authorized to process Personal Data are subject to confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures (detailed in Annex II).
- Assist the Controller, to the extent reasonably possible, in responding to data subject requests and fulfilling obligations under Articles 32–36 of the GDPR.
- Notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a Personal Data breach.
- Delete or return all Personal Data to the Controller upon termination of the Services (subject to legal retention requirements), and delete existing copies unless retention is required by law.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits (subject to reasonable notice and confidentiality).
4. Security Measures
Kliqbot implements appropriate technical and organizational measures to protect Personal Data, including (but not limited to):
- Encryption of sensitive data in transit and at rest (including AES-256-GCM encryption of Google Ads credentials).
- Tenant isolation using database Row-Level Security.
- Strict access controls and authentication.
- Regular security monitoring and assessments.
- Secure credential storage and health monitoring for Google OAuth tokens.
Full details are set out in Annex II – Technical and Organizational Measures.
5. Sub-processors
5.1 General Authorization
The Controller authorizes Kliqbot to engage sub-processors to assist in providing the Services. Kliqbot shall maintain an up-to-date list of sub-processors and provide it to the Controller upon request (or via the publicly available List of Sub-processors).
5.2 Sub-processor Obligations
Kliqbot shall enter into written agreements with sub-processors that impose data protection obligations no less protective than those in this DPA and shall remain fully liable to the Controller for the performance of its sub-processors.
A current list of sub-processors is available in Annex III – List of Sub-processors.
6. Data Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, Kliqbot shall ensure appropriate safeguards are in place, such as Standard Contractual Clauses (or the UK Addendum where applicable), or another valid transfer mechanism under applicable data protection law.
7. Data Subject Rights
Kliqbot shall, to the extent legally permitted and upon the Controller’s request, provide reasonable assistance to enable the Controller to respond to requests from data subjects exercising their rights under the GDPR.
8. Personal Data Breach Notification
Kliqbot shall notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any Personal Data breach affecting Personal Data processed under this DPA.
9. Audit Rights
The Controller may, no more than once per calendar year and upon reasonable written notice, request an audit of Kliqbot’s compliance with this DPA. Kliqbot may provide relevant third-party audit reports (e.g., SOC 2) in lieu of an on-site audit where appropriate.
10. Return and Deletion of Personal Data
Upon termination or expiration of the Services, Kliqbot shall, at the Controller’s choice, return or securely delete all Personal Data processed under this DPA, unless retention is required by applicable law.
11. Liability
Each party’s liability under this DPA shall be subject to the limitations and exclusions set out in the Kliqbot Terms of Service.
12. Term and Termination
This DPA shall remain in effect for as long as Kliqbot processes Personal Data on behalf of the Controller under the applicable agreement.
13. Hierarchy
In the event of any conflict between this DPA and the Kliqbot Terms of Service, this DPA shall prevail with respect to the processing of Personal Data.
IN WITNESS WHEREOF, the parties have executed this Data Processing Addendum as of the date of the Controller’s acceptance of the Kliqbot Terms of Service.
Annex I – Details of Processing
(As described in Section 2 above, including processing subject to the three-tier autonomy model.)
Annex II – Technical and Organizational Security Measures
Kliqbot maintains the following categories of security measures:
- Access control and authentication
- Encryption (in transit and at rest)
- Tenant isolation and logical separation of customer data
- Logging, monitoring, and incident response
- Regular vulnerability management and security assessments
- Secure development practices
Annex III – Sub-processors
A current list of sub-processors is available at the List of Sub-processors.
End of Schedule B – Data Processing Addendum