This Data Processing Addendum ("DPA") forms part of the Agreement between KeyBolt Inc., a New York corporation, doing business as LeadLatch ("LeadLatch"), and the business identified as Customer in the applicable Order Form ("Customer"). It applies when LeadLatch processes Customer Personal Data to provide the Service.
Capitalized terms not defined in this DPA have the meanings given in the Terms of Service.
1. Scope, roles, and precedence
1.1 Scope
This DPA applies to Customer Personal Data that LeadLatch processes on Customer's behalf in connection with the Service. It does not apply to Account Data that LeadLatch processes as an independent controller for contracting, authentication, account administration, security, support, and billing purposes.
1.2 Roles
Customer is the controller, business, or equivalent party that determines the purposes and means of processing Customer Personal Data. LeadLatch is Customer's processor, service provider, contractor, or equivalent party. Each party remains responsible for obligations applicable directly to it.
1.3 Incorporation and precedence
This DPA becomes effective when Customer accepts the Agreement or signs an Order Form incorporating it. If this DPA conflicts with the Terms or Order Form about personal-data processing or binding security obligations, this DPA controls. A signed amendment overrides this DPA only where it expressly identifies the provision being changed. A mandatory international transfer instrument controls for the transfer it covers.
2. Definitions
"Applicable Data Protection Law" means a privacy, data-protection, or data-security law that applies to a party's processing of Customer Personal Data under this DPA.
"Consumer Request" means a verified request by a Data Subject to exercise a right under Applicable Data Protection Law.
"Customer Personal Data" means Personal Data that LeadLatch processes on Customer's behalf under the Agreement, principally Caller Data and any technician or other individual data contained in Customer Configuration Data. Customer Personal Data excludes Account Data that LeadLatch processes as an independent controller.
"Data Subject" means an identified or identifiable individual to whom Customer Personal Data relates.
"Personal Data" means information protected as personal data, personal information, or an equivalent term under Applicable Data Protection Law.
"Process" or "Processing" means an operation performed on Personal Data, including collection, access, use, analysis, transmission, storage, alteration, disclosure, or deletion.
"Security Incident" means a confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in LeadLatch's or its Subprocessor's custody or control. It excludes unsuccessful attempts that do not result in a compromise, such as blocked scans, pings, failed login attempts, and denial-of-service attempts that do not compromise Customer Personal Data.
"Subprocessor" means a third party LeadLatch engages to Process Customer Personal Data on Customer's behalf.
3. Processing details and instructions
3.1 Customer instructions
LeadLatch will Process Customer Personal Data only:
- to provide, secure, maintain, and support the Service as described in the Agreement and Annex I;
- according to Customer's configuration and other documented lawful instructions;
- to prevent or address fraud, abuse, or a Security Incident; or
- as required by law.
If law requires Processing outside Customer's instructions, LeadLatch will notify Customer before the Processing unless law prohibits notice. If LeadLatch reasonably believes an instruction violates Applicable Data Protection Law, it will notify Customer and may suspend the affected instruction while the parties address it.
3.2 Customer responsibility
Customer is responsible for the lawfulness, fairness, and transparency of its collection and use of Customer Personal Data, including its relationship with Callers, its notices, and the lawfulness of its instructions. Customer will not instruct LeadLatch to Process Personal Data that is unnecessary for the Service or prohibited by the Agreement.
3.3 Details
The subject matter, nature, purpose, duration, Data Subjects, data categories, and operations are in Annex I.
4. Purpose limitation and prohibited uses
LeadLatch will not:
- sell or share Customer Personal Data as those terms are defined by the CCPA;
- use Customer Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by Applicable Data Protection Law;
- combine Customer Personal Data with Personal Data obtained from another source or from LeadLatch's independent interaction with a Data Subject except as permitted by Applicable Data Protection Law and necessary for the specific purposes in Annex I;
- use identifiable call audio, transcripts, service addresses, or Caller details for unrelated marketing or general product analytics; or
- permit a Subprocessor to Process Customer Personal Data for a purpose inconsistent with this DPA.
LeadLatch may create deidentified or aggregated data under Section 15.
5. CCPA and CPRA service-provider terms
This Section applies when LeadLatch Processes Customer Personal Data as a service provider or contractor under the California Consumer Privacy Act and its regulations ("CCPA").
5.1 Limited and specified purposes
LeadLatch may Process the relevant Customer Personal Data only for the limited and specified purposes in Annex I. A generic reference to the Agreement does not expand those purposes.
5.2 Restrictions
LeadLatch is prohibited from selling or sharing the relevant Customer Personal Data. LeadLatch will not retain, use, or disclose it for a purpose other than the limited and specified purposes in Annex I, for a commercial purpose outside those purposes, or outside the direct business relationship, including through prohibited combination with other Personal Data.
5.3 Same level of protection
LeadLatch will comply with applicable CCPA requirements and provide the same level of privacy protection required of businesses for the relevant Customer Personal Data. This includes reasonable security and, where applicable to Customer's use of the Service, cooperation with Consumer Requests, cybersecurity audits, risk assessments, and automated decisionmaking technology requirements.
5.4 Customer oversight
Customer may take reasonable and appropriate steps to verify that LeadLatch Processes Customer Personal Data consistently with Customer's CCPA obligations. Those steps are subject to Section 13 and reasonable confidentiality, security, and disruption protections.
5.5 Inability to comply
LeadLatch will notify Customer if LeadLatch determines it can no longer meet an applicable CCPA obligation.
5.6 Stop and remediate
Customer may require LeadLatch to take reasonable and appropriate steps to stop and remediate an unauthorized use of Customer Personal Data.
5.7 Consumer Requests
LeadLatch will enable Customer to comply with applicable Consumer Requests or, where Customer must provide information or an instruction, will notify Customer and cooperate as required by law.
5.8 Subcontractors
LeadLatch will use a written contract with each Subprocessor that Processes CCPA-covered Customer Personal Data and will impose obligations required by the CCPA and its regulations.
6. Other United States privacy laws
Where another applicable United States state privacy law requires a controller-processor contract, this DPA includes:
- Customer's instructions and each party's rights and obligations;
- the nature, purpose, type, duration, and subject matter of Processing in Annex I;
- confidentiality obligations under Section 7;
- security measures under Section 8 and Annex II;
- Consumer Request and assessment assistance under Sections 9 and 10;
- deletion or return under Section 12;
- information and audit rights under Section 13; and
- Subprocessor authorization and flow-down obligations under Section 11.
7. Confidentiality and personnel
LeadLatch will limit access to Customer Personal Data to personnel who need it to provide support, operate or secure the Service, debug an issue, perform targeted quality assurance, satisfy a legal obligation, or address a legal or security matter. Authorized personnel will be bound by confidentiality obligations and receive instructions appropriate to their role.
LeadLatch does not represent that Customer Personal Data is accessed only by machines. Human access may occur for the limited purposes above.
8. Security
8.1 Measures
LeadLatch will maintain the technical and organizational measures in Annex II. The measures are designed for the nature, scope, context, and purposes of Processing and the risks presented by Customer Personal Data.
8.2 Changes
LeadLatch may update Annex II as technology and the Service change, provided that an update does not materially reduce the overall protection of Customer Personal Data during the Subscription Term.
8.3 No certification or SLA
LeadLatch does not represent that it is SOC 2 certified, has completed an external penetration test, or provides an uptime or incident-response-time SLA. These limitations do not reduce a binding obligation expressly stated in this DPA.
9. Security Incidents
9.1 Notice
LeadLatch will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will be sent to Customer's account owner or designated security contact.
9.2 Information
As information becomes reasonably available, LeadLatch will describe:
- the nature of the Security Incident;
- affected data and Data Subject categories;
- likely consequences known to LeadLatch;
- mitigation and remediation taken or planned; and
- a contact for follow-up.
LeadLatch may provide information in phases and may withhold information where disclosure would create a security risk, violate law, or compromise a legal privilege.
9.3 Cooperation
LeadLatch will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident and will reasonably assist Customer with legally required notifications relating to LeadLatch's Processing. Notice is not an admission of fault or liability.
10. Assistance
10.1 Consumer Requests
If LeadLatch receives a Consumer Request concerning Customer Personal Data, LeadLatch will not respond substantively except on Customer's documented instruction or as required by law. LeadLatch will direct the requester to Customer where practicable and provide reasonable assistance appropriate to the nature of the Processing.
10.2 Assessments and consultations
Taking into account the nature of Processing and information available to LeadLatch, LeadLatch will provide reasonable assistance required by Applicable Data Protection Law for Customer's data protection impact assessment, risk assessment, cybersecurity audit, automated decisionmaking technology analysis, or regulator consultation relating specifically to the Service.
Assistance beyond standard documentation or reasonable remote cooperation may be subject to agreed Fees when permitted by law and when the need was not caused by LeadLatch's breach.
11. Subprocessors
11.1 General authorization
Customer generally authorizes LeadLatch to use the Subprocessors in the current Subprocessor Register.
11.2 Notice
LeadLatch will provide at least 30 days' advance email notice before a new Subprocessor begins Processing Customer Personal Data when practicable. If an urgent replacement is reasonably necessary for security or continuity, LeadLatch may give shorter or retrospective notice as promptly as practicable.
11.3 Objection
Customer may object within the notice period on reasonable, documented data-protection grounds. LeadLatch will work in good faith to address the objection through additional information, safeguards, or a commercially reasonable alternative. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a prorated refund of prepaid Fees for the unused affected period.
11.4 Flow-down and responsibility
LeadLatch will enter into a written agreement requiring each Subprocessor to protect Customer Personal Data consistently with the obligations applicable to its Processing under this DPA. LeadLatch remains responsible for a Subprocessor's performance to the extent required by Applicable Data Protection Law and the Agreement.
12. Return and deletion
12.1 During the Subscription Term
LeadLatch will delete or return Customer Personal Data on Customer's documented instruction when required by Applicable Data Protection Law and technically feasible, subject to identity and authority verification, legal obligations, legal holds, security needs, and disclosed provider limitations.
12.2 After termination
At Customer's choice, LeadLatch will delete or return Customer Personal Data after termination, unless applicable law requires continued retention. Customer must request a return within 30 days after termination. LeadLatch will then begin deletion from active systems and complete it without unreasonable delay, taking into account current technical capabilities, legal holds, provider-side copies, and backup cycles. LeadLatch does not promise a fixed maximum deletion or backup-expiration period until the corresponding controls have been implemented and verified.
12.3 Category-specific periods
- Unsaved recordings: the current scheduled process targets recordings matched to call records for deletion after approximately 30 days; unmatched provider recordings may not be reached.
- Transcripts: currently retained without a defined deletion schedule.
- Structured call and booking records: currently retained in the Customer account without a defined post-termination schedule.
- Acceptance, invoice, credit, and legal records: retained as reasonably necessary to administer and enforce the Agreement and comply with law.
12.4 Provider copies
Deletion from LeadLatch systems may not immediately remove data retained by a Subprocessor under a legal requirement, fixed security-retention period, or technically disclosed backup cycle. LeadLatch will document material limitations in the Subprocessor Register and will instruct Subprocessors as required by Applicable Data Protection Law and its contracts.
13. Information and audits
13.1 Standard information
LeadLatch will provide information reasonably necessary to demonstrate compliance with this DPA, including the public Security Overview, current Subprocessor Register, completed reasonable questionnaires, and available internal or independent assessment summaries.
13.2 Customer audit
If standard information is insufficient, Customer may conduct one reasonable audit in a 12-month period, and an additional audit after a Security Incident or when required by a regulator. An audit must:
- be preceded by reasonable written notice;
- occur during normal business hours;
- use an independent auditor bound by confidentiality;
- avoid access to another customer's data, source code, or information that would create a security risk; and
- avoid unreasonable disruption.
Customer bears its audit costs unless the audit identifies LeadLatch's material breach of this DPA. The parties will agree a reasonable scope and method, including remote review where appropriate.
14. Government demands
If LeadLatch receives a binding demand for Customer Personal Data, LeadLatch will, where legally permitted:
- notify Customer before disclosure;
- direct the authority to Customer when appropriate;
- disclose only data responsive to the demand; and
- reasonably assist Customer in seeking appropriate protection.
LeadLatch may act without advance notice when law prohibits notice or where necessary to address an imminent threat to life or safety.
15. Deidentified data
LeadLatch may create aggregate or deidentified data from Customer Personal Data for internal security, reliability, capacity planning, and service analytics only when the data cannot reasonably be linked to a Data Subject or Customer. LeadLatch will maintain deidentification, publicly commit not to reidentify the data, and contractually restrict recipients from reidentifying it where required by law.
16. International processing module
This base DPA does not assume that the GDPR, UK GDPR, or an international transfer mechanism applies merely because a provider is headquartered outside the United States.
If Customer and LeadLatch determine that the GDPR, UK GDPR, or another international transfer law applies, the parties will execute an appropriate module, including controller-processor terms and a transfer mechanism where required. That module will control for covered Processing.
17. Liability and general terms
Liability arising from this DPA is subject to the Terms, except where Applicable Data Protection Law prohibits a limitation. This DPA does not independently create an uncapped privacy or security liability category.
The governing law, venue, notices, assignment, waiver, severability, and amendment provisions of the Terms apply to this DPA. A material reduction of Customer's data-protection rights requires the notice and reacceptance process for material Agreement changes.
Annex I: Processing details
| Topic | Description |
|---|---|
| Subject matter | Operating and supporting an AI voice receptionist for Customer's locksmith business |
| Duration | Subscription Term plus the return, deletion, backup, legal-hold, and provider periods described in Section 12 |
| Purpose | Answer inbound calls; collect requested job information; determine service-area eligibility using routed drive time; communicate configured price and availability; hold appointment windows; create Booked Jobs; send operational notifications; support, secure, debug, and perform targeted quality assurance for the Service |
| Data Subjects | Callers; Customer technicians and other individuals included in configuration or booking data |
| Caller data | Phone number, name, service address, derived coordinates, job and access details, audio, conversation content, transcript, qualification and tool results, quoted price, routed drive time, availability, held window, Booked Job, timestamps, call status, provider identifiers, and technical telemetry |
| Other Customer Personal Data | Technician name and contact details, notification recipients, and individual information included in Customer instructions or support requests |
| Operations | Collection, receipt, organization, live audio processing, transcription, analysis, retrieval, consultation, transmission, storage, support access, restriction, deletion, and return |
| Special or sensitive data | Service addresses and access-related details may be sensitive. Customer must not intentionally submit regulated health, financial-account, government-ID, or biometric-template data unless the parties expressly agree and implement appropriate safeguards. |
Annex II: Technical and organizational measures
A. Access and authentication
- The authenticated dashboard uses server-side Supabase authentication and necessary session cookies.
- LeadLatch does not ship a browser Supabase database client or publishable database key for direct browser access.
- Database row-level security isolates Customer access through the dashboard.
- Authorized personnel access is limited to need-to-know support, operations, security, legal, and targeted quality-assurance purposes.
B. Service identities and least privilege
- The voice worker connects directly to Postgres through the scoped
leadlatch_workerrole. - The worker does not use the Supabase administrative service credential.
- Worker database access is concentrated in the audited worker database layer and booking repository.
C. Data integrity and truth controls
- Deterministic systems, rather than the voice model, determine service-area eligibility, authorized prices, availability, and booking results.
- Customer-entered content that the voice system may speak is treated as a trust-boundary input and is subject to validation and output controls.
D. Secrets and transmission
- Credentials are kept outside source control and supplied through deployment environment configuration.
- Application and provider connections are configured to use encrypted transport where supported by the relevant service.
E. Monitoring and diagnostics
- LeadLatch uses Sentry for error monitoring with default personal-information collection disabled and additional redaction controls.
- Redaction reduces risk but does not guarantee that personal information can never appear in an error event.
- Error context is designed to use operational identifiers rather than call content, transcripts, or addresses.
F. Retention and disposal
- A scheduled recording purge targets recordings matched to call rows after approximately 30 days.
- A known unmatched-recording gap means LeadLatch does not promise a firm 30-day maximum.
- Transcripts currently have no defined deletion schedule. Termination, backup, legal-hold, and provider-copy handling is described in Section 12.
G. Personnel and incident handling
- Authorized personnel are subject to confidentiality obligations.
- LeadLatch will maintain an incident process sufficient to perform Section 9.
H. Current assurance limitations
- LeadLatch is not SOC 2 certified.
- LeadLatch has not completed an external penetration test.
- LeadLatch does not provide a general uptime or incident-response-time SLA.
Annex III: Subprocessors
The current Subprocessor Register is incorporated into this DPA as a controlled schedule. It is subject to Section 11 and cannot reduce this DPA's protections.