Skip to main content

Legal

Data ProcessingAddendum

Effective Date: June 6, 2026

This Data Processing Addendum ("DPA") is incorporated into and forms part of the agreement between Caerus Marketing("Processor") and the client entity executing that agreement ("Controller"). This document governs how Caerus Marketing processes personal data on behalf of its clients in connection with the Services.

This DPA does not constitute legal advice. Caerus Marketing recommends that all clients consult with qualified legal counsel regarding their own data processing obligations.

1. Definitions

"Applicable Data Protection Law" All data privacy and security laws applicable to the processing of Personal Data under this DPA, including but not limited to: the EU General Data Protection Regulation (GDPR) 2016/679; the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA); the Texas Data Privacy and Security Act (TDPSA); and any other applicable U.S. state privacy laws.
"Controller" The Client entity that determines the purposes and means of processing Personal Data.
"Data Subject" The identified or identifiable natural person to whom Personal Data relates (typically the Controller's customers, leads, or contacts).
"Personal Data" Any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law. This includes names, email addresses, phone numbers, IP addresses, device identifiers, and behavioral data collected through the Services.
"Processing" Any operation performed on Personal Data, whether automated or manual, including collection, recording, storage, retrieval, use, disclosure, transmission, deletion, or destruction.
"Processor" Caerus Marketing, acting on documented instructions from the Controller to process Personal Data in connection with the Services.
"Security Incident" Any confirmed or reasonably suspected unauthorized access to, use, disclosure, alteration, or destruction of Personal Data processed under this DPA.
"Services" The digital marketing services provided by Caerus Marketing as described in the applicable service agreement, including website design, review automation, missed call text back, SMS remarketing, and email automation.
"Sub-processor" Any third-party engaged by Caerus Marketing to process Personal Data on behalf of the Controller.

2. Scope and Nature of Processing

2.1 Subject Matter

Caerus Marketing processes Personal Data solely to provide the Services described in the applicable service agreement.

2.2 Duration

Processing continues for the duration of the service agreement and for such period as is necessary to fulfill post-termination obligations described in Section 9.

2.3 Categories of Data Subjects

  • The Controller's current and prospective customers
  • Leads and website visitors of the Controller's business
  • The Controller's contacts imported into GoHighLevel CRM

2.4 Types of Personal Data Processed

  • Contact data: full name, email address, phone number, physical address
  • Behavioral data: website interaction data, email open/click data, SMS response data
  • Business data: job title, company name, service history
  • Device/technical data: IP address, browser type, device identifiers
  • Communication data: contents of SMS messages, email content, call log metadata

2.5 Purpose of Processing

Personal Data is processed for the following purposes only:

  • Delivering and operating the Services
  • Fulfilling documented instructions from the Controller
  • Complying with legal obligations applicable to Caerus Marketing

Caerus Marketing will not process Personal Data for any purpose beyond those listed above without prior written consent from the Controller.

3. Processor Obligations

3.1 Instructions

Caerus Marketing will process Personal Data only on documented instructions from the Controller. If Caerus Marketing believes an instruction violates Applicable Data Protection Law, it will promptly notify the Controller in writing.

3.2 Confidentiality

Caerus Marketing will ensure that all personnel authorized to process Personal Data are bound by written confidentiality obligations and have received appropriate data protection training.

3.3 No Sale or Sharing

Caerus Marketing will not sell, rent, trade, or share Personal Data with any third party for the third party's own commercial purposes. Caerus Marketing will not retain, use, or disclose Personal Data for any purpose other than providing the Services or as required by law.

3.4 No Cross-Client Commingling

Personal Data belonging to one Controller will be logically segregated and will not be combined with, shared with, or disclosed to any other client or third party.

3.5 Cooperation

Caerus Marketing will reasonably assist the Controller in fulfilling obligations under Applicable Data Protection Law, including responding to Data Subject requests, conducting data protection impact assessments, and complying with regulatory inquiries, to the extent Caerus Marketing has access to the relevant data and at the Controller's reasonable expense.

4. Controller Obligations

4.1 Lawful Basis

The Controller is solely responsible for ensuring it has a lawful basis for processing Personal Data (e.g., consent, contract, or legitimate interest) before providing Personal Data to Caerus Marketing.

4.2 Data Accuracy

The Controller is responsible for ensuring that Personal Data provided to Caerus Marketing is accurate, up-to-date, and obtained in compliance with Applicable Data Protection Law.

4.3 Compliance Responsibility

The Controller retains primary responsibility for complying with all obligations imposed on controllers under Applicable Data Protection Law, including maintaining appropriate privacy notices and processing records.

4.4 Instructions

The Controller agrees to provide lawful, documented instructions for processing and to update those instructions as needed to remain compliant with Applicable Data Protection Law.

5. Sub-processors

5.1 Authorized Sub-processors

The Controller provides general written authorization for Caerus Marketing to engage the following sub-processors in connection with the Services:

Sub-processorPurposeLocation
GoHighLevel (HighLevel, Inc.)CRM, SMS, email automation, missed call text back, pipeline managementUnited States
Amazon Web Services (AWS)Cloud infrastructure and data hostingUnited States
Google LLCAnalytics, Maps API, advertising integrationsUnited States
Cloudflare, Inc.DNS, CDN, DDoS protectionUnited States
Stripe, Inc.Payment processing (billing data only)United States
Vercel, Inc.Website hosting and deploymentUnited States

5.2 New Sub-processors

Caerus Marketing will provide at least 30 days' written notice before engaging any new sub-processor that will have access to Personal Data. Notice will be delivered by email to the Controller's contact on file.

5.3 Right to Object

The Controller may object to a new sub-processor on reasonable data protection grounds by providing written notice within 14 days of receiving notification. If the Controller objects and the parties cannot resolve the dispute, the Controller may terminate the applicable Services on 30 days' notice without penalty.

5.4 Sub-processor Obligations

Caerus Marketing will bind each Sub-processor to data protection obligations that are no less protective than those in this DPA. Caerus Marketing remains liable to the Controller for the performance of each Sub-processor's obligations.

6. Security Measures

6.1 General Standard

Caerus Marketing will implement and maintain reasonable technical and organizational security measures appropriate to the risk of processing, designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

6.2 Technical Measures

  • Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 where applicable)
  • Multi-factor authentication for all systems that access Personal Data
  • Role-based access controls limiting data access to authorized personnel only
  • Network firewalls and intrusion detection on systems processing Personal Data
  • Regular software updates and patch management
  • Automated data backups with tested recovery procedures

6.3 Organizational Measures

  • Confidentiality agreements with all personnel who access Personal Data
  • Data protection training for personnel handling Personal Data
  • Access logging and monitoring for systems containing Personal Data
  • Documented incident response procedures
  • Vendor security assessments for all Sub-processors

6.4 No Guarantee

No security system is impenetrable. The security measures in this Section represent commercially reasonable efforts, not an absolute guarantee against all possible Security Incidents.

7. Security Incident Notification

7.1 Notification Obligation

In the event Caerus Marketing becomes aware of a confirmed Security Incident affecting Personal Data processed under this DPA, Caerus Marketing will notify the Controller without undue delay and in no event later than 72 hours after becoming aware of the incident (consistent with GDPR Article 33 requirements).

7.2 Notification Contents

Notification will include, to the extent then known:

  • Nature of the Security Incident and categories of Personal Data affected
  • Approximate number of Data Subjects and records affected
  • Likely consequences of the incident
  • Measures taken or proposed to address the incident and mitigate its effects
  • Contact information for Caerus Marketing's designated point of contact

7.3 Controller Responsibility

The Controller is solely responsible for determining whether the Security Incident triggers any notification obligations to Data Subjects or regulatory authorities under Applicable Data Protection Law and for providing any such notifications.

7.4 Cooperation

Caerus Marketing will reasonably cooperate with the Controller in investigating and remediating any Security Incident, including providing updated information as it becomes available.

8. Data Subject Rights

8.1 Assistance

Caerus Marketing will provide reasonable assistance to help the Controller fulfill Data Subject requests under Applicable Data Protection Law, including rights of:

  • Access — to obtain a copy of their Personal Data
  • Rectification — to correct inaccurate data
  • Erasure — to request deletion ("right to be forgotten")
  • Restriction — to limit processing in specific circumstances
  • Portability — to receive data in a structured, machine-readable format
  • Objection — to object to certain types of processing
  • Opt-out — from the sale or sharing of Personal Data (CCPA/TDPSA)

8.2 Direct Requests

If Caerus Marketing receives a Data Subject request directly, it will promptly forward the request to the Controller and will not respond to the Data Subject directly except on the Controller's documented instructions or as required by law.

8.3 Response Support

Caerus Marketing will fulfill Controller instructions to export, correct, or delete specific Personal Data within a commercially reasonable timeframe, not to exceed 30 days from instruction, except where technically infeasible.

9. Data Retention and Deletion

9.1 Retention During Services

Caerus Marketing will retain Personal Data only for as long as necessary to provide the Services or as required by law.

9.2 Post-Termination

Upon termination or expiration of the applicable service agreement, Caerus Marketing will, at the Controller's election:

  • Return all Personal Data to the Controller in a commonly used electronic format, or
  • Delete all Personal Data from its systems and Sub-processor systems

Caerus Marketing will complete the return or deletion within 60 days of the Controller's written election.

9.3 Legal Retention

Notwithstanding the above, Caerus Marketing may retain Personal Data to the extent required by Applicable Law, provided that such data is stored securely and not processed for any other purpose.

9.4 Certification

Upon request, Caerus Marketing will provide written certification that deletion has been completed.

10. International Data Transfers

10.1 U.S. Processing

All Personal Data is processed in the United States by default. Caerus Marketing does not intentionally transfer Personal Data outside the United States.

10.2 EU/UK Data

If the Controller provides Personal Data relating to individuals located in the European Economic Area (EEA) or the United Kingdom, the parties agree to execute the applicable Standard Contractual Clauses (SCCs) under GDPR Article 46(2)(c) or the UK International Data Transfer Addendum (IDTA), as applicable. The Controller is responsible for notifying Caerus Marketing if EEA or UK resident data will be provided.

10.3 Compliance Responsibility

The Controller is responsible for ensuring that any cross-border transfer of Personal Data to Caerus Marketing is lawful under the Applicable Data Protection Law of the source jurisdiction.

11. Audit Rights

11.1 Documentation

Caerus Marketing will maintain reasonable records of its data processing activities and security practices and will make such records available to the Controller upon written request.

11.2 Third-Party Audits

No more than once per calendar year (unless a Security Incident has occurred), the Controller may, at its own expense and with at least 30 days' written notice, request a third-party security audit of Caerus Marketing's data processing practices. Such audits must be conducted during normal business hours and must not disrupt Caerus Marketing's operations.

11.3 Confidentiality of Audit

All audit findings and related materials are confidential and subject to the confidentiality obligations of the service agreement.

12. Texas Data Privacy and Security Act (TDPSA)

12.1 Service Provider Classification

For purposes of the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code § 541 et seq.), Caerus Marketing acts as a contractor or service provider as those terms are defined under the TDPSA, processing Personal Data on behalf of and under the instructions of the Controller.

12.2 TDPSA Obligations

Caerus Marketing will:

  • Process Personal Data only as specified in this DPA and the service agreement
  • Maintain reasonable administrative, technical, and physical data security practices consistent with TDPSA requirements
  • Assist the Controller in fulfilling Data Subject opt-out requests under the TDPSA
  • Notify the Controller of any Security Incident in accordance with Section 7

12.3 Global Privacy Control

Where technically feasible within the platforms Caerus Marketing operates, Caerus Marketing will support the Controller's implementation of Global Privacy Control (GPC) signals as required by the TDPSA for Texas residents.

13. California Consumer Privacy Act (CCPA/CPRA)

13.1 Service Provider Classification

For purposes of the CCPA, Caerus Marketing is a service provider as defined in Cal. Civ. Code § 1798.140. Caerus Marketing processes Personal Data on behalf of the Controller for the business purposes specified in this DPA only.

13.2 CCPA Obligations

Caerus Marketing will not:

  • Sell or share (as defined by CCPA/CPRA) any Personal Data received from the Controller
  • Retain, use, or disclose Personal Data for any commercial purpose other than providing the Services
  • Combine Personal Data received from the Controller with Personal Data received from or collected from any other source
  • Process Personal Data outside the direct business relationship with the Controller

13.3 Certification

Caerus Marketing certifies that it understands the restrictions of Cal. Civ. Code § 1798.140(ag) and will comply with them.

14. Limitations of Liability

Caerus Marketing's liability under this DPA is subject to the limitations of liability set forth in the applicable service agreement. Nothing in this DPA is intended to expand Caerus Marketing's liability beyond those limits.

15. Term and Termination

15.1 Term

This DPA is effective from the date of the applicable service agreement and remains in force for the duration of that agreement.

15.2 Termination

This DPA terminates automatically upon termination of the applicable service agreement, subject to survival of provisions that by their nature should survive (Sections 6, 7, 9, 11, and 14).

15.3 Updates

Caerus Marketing may update this DPA as required to comply with changes in Applicable Data Protection Law. Material changes will be communicated to active Clients with at least 30 days' notice.

16. General

16.1 Order of Precedence

In the event of a conflict between this DPA and the applicable service agreement, this DPA governs with respect to data protection matters only.

16.2 Governing Law

This DPA is governed by the laws of the State of Texas, without regard to its conflict of laws provisions, except where Applicable Data Protection Law mandates otherwise.

16.3 Severability

If any provision of this DPA is found invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force.

16.4 Entire Agreement

This DPA, together with the applicable service agreement, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior agreements, representations, and understandings relating to that subject matter.

17. Contact

For questions or concerns relating to this DPA, or to exercise rights under this agreement, contact:

Caerus Marketing

Data Privacy Inquiries

Houston, Texas

Email: ramsesmejia@caerus.marketing

Last updated: June 6, 2026  ·  Privacy Policy  ·  Terms of Service

Call NowGet Free Audit