Legal
Data ProcessingAddendum
Effective Date: June 6, 2026
This Data Processing Addendum ("DPA") is incorporated into and forms part of the agreement between Caerus Marketing("Processor") and the client entity executing that agreement ("Controller"). This document governs how Caerus Marketing processes personal data on behalf of its clients in connection with the Services.
This DPA does not constitute legal advice. Caerus Marketing recommends that all clients consult with qualified legal counsel regarding their own data processing obligations.
1. Definitions
2. Scope and Nature of Processing
2.1 Subject Matter
Caerus Marketing processes Personal Data solely to provide the Services described in the applicable service agreement.
2.2 Duration
Processing continues for the duration of the service agreement and for such period as is necessary to fulfill post-termination obligations described in Section 9.
2.3 Categories of Data Subjects
- The Controller's current and prospective customers
- Leads and website visitors of the Controller's business
- The Controller's contacts imported into GoHighLevel CRM
2.4 Types of Personal Data Processed
- Contact data: full name, email address, phone number, physical address
- Behavioral data: website interaction data, email open/click data, SMS response data
- Business data: job title, company name, service history
- Device/technical data: IP address, browser type, device identifiers
- Communication data: contents of SMS messages, email content, call log metadata
2.5 Purpose of Processing
Personal Data is processed for the following purposes only:
- Delivering and operating the Services
- Fulfilling documented instructions from the Controller
- Complying with legal obligations applicable to Caerus Marketing
Caerus Marketing will not process Personal Data for any purpose beyond those listed above without prior written consent from the Controller.
3. Processor Obligations
3.1 Instructions
Caerus Marketing will process Personal Data only on documented instructions from the Controller. If Caerus Marketing believes an instruction violates Applicable Data Protection Law, it will promptly notify the Controller in writing.
3.2 Confidentiality
Caerus Marketing will ensure that all personnel authorized to process Personal Data are bound by written confidentiality obligations and have received appropriate data protection training.
3.3 No Sale or Sharing
Caerus Marketing will not sell, rent, trade, or share Personal Data with any third party for the third party's own commercial purposes. Caerus Marketing will not retain, use, or disclose Personal Data for any purpose other than providing the Services or as required by law.
3.4 No Cross-Client Commingling
Personal Data belonging to one Controller will be logically segregated and will not be combined with, shared with, or disclosed to any other client or third party.
3.5 Cooperation
Caerus Marketing will reasonably assist the Controller in fulfilling obligations under Applicable Data Protection Law, including responding to Data Subject requests, conducting data protection impact assessments, and complying with regulatory inquiries, to the extent Caerus Marketing has access to the relevant data and at the Controller's reasonable expense.
4. Controller Obligations
4.1 Lawful Basis
The Controller is solely responsible for ensuring it has a lawful basis for processing Personal Data (e.g., consent, contract, or legitimate interest) before providing Personal Data to Caerus Marketing.
4.2 Data Accuracy
The Controller is responsible for ensuring that Personal Data provided to Caerus Marketing is accurate, up-to-date, and obtained in compliance with Applicable Data Protection Law.
4.3 Compliance Responsibility
The Controller retains primary responsibility for complying with all obligations imposed on controllers under Applicable Data Protection Law, including maintaining appropriate privacy notices and processing records.
4.4 Instructions
The Controller agrees to provide lawful, documented instructions for processing and to update those instructions as needed to remain compliant with Applicable Data Protection Law.
5. Sub-processors
5.1 Authorized Sub-processors
The Controller provides general written authorization for Caerus Marketing to engage the following sub-processors in connection with the Services:
| Sub-processor | Purpose | Location |
|---|---|---|
| GoHighLevel (HighLevel, Inc.) | CRM, SMS, email automation, missed call text back, pipeline management | United States |
| Amazon Web Services (AWS) | Cloud infrastructure and data hosting | United States |
| Google LLC | Analytics, Maps API, advertising integrations | United States |
| Cloudflare, Inc. | DNS, CDN, DDoS protection | United States |
| Stripe, Inc. | Payment processing (billing data only) | United States |
| Vercel, Inc. | Website hosting and deployment | United States |
5.2 New Sub-processors
Caerus Marketing will provide at least 30 days' written notice before engaging any new sub-processor that will have access to Personal Data. Notice will be delivered by email to the Controller's contact on file.
5.3 Right to Object
The Controller may object to a new sub-processor on reasonable data protection grounds by providing written notice within 14 days of receiving notification. If the Controller objects and the parties cannot resolve the dispute, the Controller may terminate the applicable Services on 30 days' notice without penalty.
5.4 Sub-processor Obligations
Caerus Marketing will bind each Sub-processor to data protection obligations that are no less protective than those in this DPA. Caerus Marketing remains liable to the Controller for the performance of each Sub-processor's obligations.
6. Security Measures
6.1 General Standard
Caerus Marketing will implement and maintain reasonable technical and organizational security measures appropriate to the risk of processing, designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
6.2 Technical Measures
- Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 where applicable)
- Multi-factor authentication for all systems that access Personal Data
- Role-based access controls limiting data access to authorized personnel only
- Network firewalls and intrusion detection on systems processing Personal Data
- Regular software updates and patch management
- Automated data backups with tested recovery procedures
6.3 Organizational Measures
- Confidentiality agreements with all personnel who access Personal Data
- Data protection training for personnel handling Personal Data
- Access logging and monitoring for systems containing Personal Data
- Documented incident response procedures
- Vendor security assessments for all Sub-processors
6.4 No Guarantee
No security system is impenetrable. The security measures in this Section represent commercially reasonable efforts, not an absolute guarantee against all possible Security Incidents.
7. Security Incident Notification
7.1 Notification Obligation
In the event Caerus Marketing becomes aware of a confirmed Security Incident affecting Personal Data processed under this DPA, Caerus Marketing will notify the Controller without undue delay and in no event later than 72 hours after becoming aware of the incident (consistent with GDPR Article 33 requirements).
7.2 Notification Contents
Notification will include, to the extent then known:
- Nature of the Security Incident and categories of Personal Data affected
- Approximate number of Data Subjects and records affected
- Likely consequences of the incident
- Measures taken or proposed to address the incident and mitigate its effects
- Contact information for Caerus Marketing's designated point of contact
7.3 Controller Responsibility
The Controller is solely responsible for determining whether the Security Incident triggers any notification obligations to Data Subjects or regulatory authorities under Applicable Data Protection Law and for providing any such notifications.
7.4 Cooperation
Caerus Marketing will reasonably cooperate with the Controller in investigating and remediating any Security Incident, including providing updated information as it becomes available.
8. Data Subject Rights
8.1 Assistance
Caerus Marketing will provide reasonable assistance to help the Controller fulfill Data Subject requests under Applicable Data Protection Law, including rights of:
- Access — to obtain a copy of their Personal Data
- Rectification — to correct inaccurate data
- Erasure — to request deletion ("right to be forgotten")
- Restriction — to limit processing in specific circumstances
- Portability — to receive data in a structured, machine-readable format
- Objection — to object to certain types of processing
- Opt-out — from the sale or sharing of Personal Data (CCPA/TDPSA)
8.2 Direct Requests
If Caerus Marketing receives a Data Subject request directly, it will promptly forward the request to the Controller and will not respond to the Data Subject directly except on the Controller's documented instructions or as required by law.
8.3 Response Support
Caerus Marketing will fulfill Controller instructions to export, correct, or delete specific Personal Data within a commercially reasonable timeframe, not to exceed 30 days from instruction, except where technically infeasible.
9. Data Retention and Deletion
9.1 Retention During Services
Caerus Marketing will retain Personal Data only for as long as necessary to provide the Services or as required by law.
9.2 Post-Termination
Upon termination or expiration of the applicable service agreement, Caerus Marketing will, at the Controller's election:
- Return all Personal Data to the Controller in a commonly used electronic format, or
- Delete all Personal Data from its systems and Sub-processor systems
Caerus Marketing will complete the return or deletion within 60 days of the Controller's written election.
9.3 Legal Retention
Notwithstanding the above, Caerus Marketing may retain Personal Data to the extent required by Applicable Law, provided that such data is stored securely and not processed for any other purpose.
9.4 Certification
Upon request, Caerus Marketing will provide written certification that deletion has been completed.
10. International Data Transfers
10.1 U.S. Processing
All Personal Data is processed in the United States by default. Caerus Marketing does not intentionally transfer Personal Data outside the United States.
10.2 EU/UK Data
If the Controller provides Personal Data relating to individuals located in the European Economic Area (EEA) or the United Kingdom, the parties agree to execute the applicable Standard Contractual Clauses (SCCs) under GDPR Article 46(2)(c) or the UK International Data Transfer Addendum (IDTA), as applicable. The Controller is responsible for notifying Caerus Marketing if EEA or UK resident data will be provided.
10.3 Compliance Responsibility
The Controller is responsible for ensuring that any cross-border transfer of Personal Data to Caerus Marketing is lawful under the Applicable Data Protection Law of the source jurisdiction.
11. Audit Rights
11.1 Documentation
Caerus Marketing will maintain reasonable records of its data processing activities and security practices and will make such records available to the Controller upon written request.
11.2 Third-Party Audits
No more than once per calendar year (unless a Security Incident has occurred), the Controller may, at its own expense and with at least 30 days' written notice, request a third-party security audit of Caerus Marketing's data processing practices. Such audits must be conducted during normal business hours and must not disrupt Caerus Marketing's operations.
11.3 Confidentiality of Audit
All audit findings and related materials are confidential and subject to the confidentiality obligations of the service agreement.
12. Texas Data Privacy and Security Act (TDPSA)
12.1 Service Provider Classification
For purposes of the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code § 541 et seq.), Caerus Marketing acts as a contractor or service provider as those terms are defined under the TDPSA, processing Personal Data on behalf of and under the instructions of the Controller.
12.2 TDPSA Obligations
Caerus Marketing will:
- Process Personal Data only as specified in this DPA and the service agreement
- Maintain reasonable administrative, technical, and physical data security practices consistent with TDPSA requirements
- Assist the Controller in fulfilling Data Subject opt-out requests under the TDPSA
- Notify the Controller of any Security Incident in accordance with Section 7
12.3 Global Privacy Control
Where technically feasible within the platforms Caerus Marketing operates, Caerus Marketing will support the Controller's implementation of Global Privacy Control (GPC) signals as required by the TDPSA for Texas residents.
13. California Consumer Privacy Act (CCPA/CPRA)
13.1 Service Provider Classification
For purposes of the CCPA, Caerus Marketing is a service provider as defined in Cal. Civ. Code § 1798.140. Caerus Marketing processes Personal Data on behalf of the Controller for the business purposes specified in this DPA only.
13.2 CCPA Obligations
Caerus Marketing will not:
- Sell or share (as defined by CCPA/CPRA) any Personal Data received from the Controller
- Retain, use, or disclose Personal Data for any commercial purpose other than providing the Services
- Combine Personal Data received from the Controller with Personal Data received from or collected from any other source
- Process Personal Data outside the direct business relationship with the Controller
13.3 Certification
Caerus Marketing certifies that it understands the restrictions of Cal. Civ. Code § 1798.140(ag) and will comply with them.
14. Limitations of Liability
Caerus Marketing's liability under this DPA is subject to the limitations of liability set forth in the applicable service agreement. Nothing in this DPA is intended to expand Caerus Marketing's liability beyond those limits.
15. Term and Termination
15.1 Term
This DPA is effective from the date of the applicable service agreement and remains in force for the duration of that agreement.
15.2 Termination
This DPA terminates automatically upon termination of the applicable service agreement, subject to survival of provisions that by their nature should survive (Sections 6, 7, 9, 11, and 14).
15.3 Updates
Caerus Marketing may update this DPA as required to comply with changes in Applicable Data Protection Law. Material changes will be communicated to active Clients with at least 30 days' notice.
16. General
16.1 Order of Precedence
In the event of a conflict between this DPA and the applicable service agreement, this DPA governs with respect to data protection matters only.
16.2 Governing Law
This DPA is governed by the laws of the State of Texas, without regard to its conflict of laws provisions, except where Applicable Data Protection Law mandates otherwise.
16.3 Severability
If any provision of this DPA is found invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force.
16.4 Entire Agreement
This DPA, together with the applicable service agreement, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior agreements, representations, and understandings relating to that subject matter.
17. Contact
For questions or concerns relating to this DPA, or to exercise rights under this agreement, contact:
Caerus Marketing
Data Privacy Inquiries
Houston, Texas
Email: ramsesmejia@caerus.marketing
Last updated: June 6, 2026 · Privacy Policy · Terms of Service