MakeMyMonth

Data Processing Addendum

Version 1.0 · Effective August 19, 2026
Master Subscription Agreement · Security Overview · Privacy Policy

This Data Processing Addendum (“DPA”) forms part of the Master Subscription Agreement between MakeMyMonth and Customer and governs our processing of Personal Information on Customer’s behalf. If this DPA conflicts with the Agreement on any question of personal data processing, this DPA controls.

What we actually process. Employee names, work email addresses, roles, store assignment, the sales activity numbers those employees enter, commission figures they enter, and sign-in records. We do not process consumer or customer data. No buyer names, no credit applications, no deal jackets. That keeps this Service outside the scope of the Gramm-Leach-Bliley Act Safeguards Rule as applied to your customer information.

1. Definitions

2. Roles of the parties

Customer is the Business and Controller. MakeMyMonth is the Service Provider and Processor. Customer determines the purposes and means of processing; we process only as described in this DPA and on Customer’s documented instructions. The Agreement, this DPA, and Customer’s configuration and use of the Service constitute Customer’s complete documented instructions.

Customer is responsible for the lawfulness of its collection of Personal Information, for providing any required notices to its employees, and for having a lawful basis for the processing it instructs.

3. Scope of processing

The subject matter, duration, nature, purpose, types of Personal Information, and categories of Data Subjects are described in Annex I.

4. Our obligations

We will:

5. CCPA / CPRA service provider certification

We certify that we do not Sell or Share Personal Information, and that we will not:

We will comply with the obligations applicable to a Service Provider under the CCPA and will provide the same level of privacy protection the CCPA requires of Customer. Customer may take reasonable and appropriate steps to ensure we use Personal Information consistently with Customer’s obligations, and to stop and remediate unauthorized use. We will notify Customer if we determine we can no longer meet these obligations.

Employee data. Customer acknowledges that under the CCPA its employees are Consumers with full rights in the employment context, and that Customer — not MakeMyMonth — is responsible for providing employees with a notice at collection and for responding to their rights requests, with our assistance under Section 10.

6. Subprocessors

Customer provides general authorization for us to engage Subprocessors. Our current Subprocessors are listed in Annex III. We will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance.

We will give Customer at least 30 days’ notice before adding or replacing a Subprocessor that processes Personal Information. Customer may object on reasonable data protection grounds within that period. If we cannot provide a commercially reasonable alternative, Customer may terminate the affected subscription and receive a pro rata refund of prepaid unused fees.

7. Security incidents

We will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Personal Information. The notice will describe, to the extent known: the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed. We will provide reasonable cooperation and information to help Customer meet its own notification obligations.

Our notification is not an acknowledgment of fault or liability. Unsuccessful attempts that do not compromise Personal Information — such as blocked sign-in attempts or routine port scans — are not Security Incidents.

8. Location of processing

Personal Information is stored in Canada. Our primary database and authentication service are hosted by Supabase in the ca-central-1 region. Application hosting and email delivery are provided from the United States. Customer instructs and authorizes this arrangement. Canada is recognized by the European Commission as providing an adequate level of protection for personal data transferred to commercial organizations.

9. Audit

On Customer’s written request, no more than once per twelve months (and additionally after a Security Incident affecting Customer), we will provide: our then-current Security Overview, responses to a reasonable written security questionnaire, and any third-party audit reports or certifications we then hold. Information provided is our Confidential Information. On-site audits are not included; if Data Protection Laws require an audit that these measures cannot satisfy, the parties will discuss a mutually acceptable alternative at Customer’s expense.

10. Data subject requests

The Service gives Customer’s administrators the ability to access, correct, export, and delete Personal Information about their Authorized Users directly. If we receive a request from a Data Subject relating to Customer’s Personal Information, we will not respond substantively and will forward it to Customer without undue delay, except where legally required to respond. We will provide reasonable assistance if Customer cannot address a request through the Service itself.

11. International transfers

Where Personal Information originating in the European Economic Area, United Kingdom, or Switzerland is processed under this DPA, the parties agree that the applicable Standard Contractual Clauses, and the UK International Data Transfer Addendum where relevant, are incorporated by reference, with Customer as data exporter and MakeMyMonth as data importer, Module Two (controller to processor). Annex I and Annex II of this DPA populate the corresponding annexes of those clauses.

12. Return and deletion

For 30 days after termination or expiry of the Agreement, Customer may export Personal Information through the Service or by written request. After that period, we will delete or de-identify Personal Information within 90 days, except where retention is required by law. Personal Information in encrypted backups is deleted on our normal backup rotation and remains subject to this DPA until then.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement.

Annex I — Details of processing

Subject matterProvision of the MakeMyMonth sales activity tracking service
DurationThe Subscription Term, plus the retention periods in Section 12
Nature and purposeHosting, storage, calculation, display, and email reporting of employee sales activity data; authentication; customer support
Categories of Data SubjectsCustomer’s employees and contractors: salespeople, sales managers, and dealership administrators
Types of Personal Information Name; work email address; role; dealership/store assignment; account status; monthly income goal; average commission figure; daily activity entries (ups, demos, write-ups, sold units, appointments set/confirmed/shown, days off); commission tracker entries (deal dates, stock numbers, partial VIN, commission amounts); sign-in timestamps; IP address and browser data in server logs
Sensitive dataNone. No government identifiers, financial account numbers, health data, biometric data, precise geolocation, or data revealing protected characteristics is collected by the Service.
Consumer dataNone. The Service does not collect or process data about Customer’s vehicle buyers.
FrequencyContinuous during the Subscription Term

Annex II — Technical and organizational measures

Summarized here and described in full in the Security Overview, which is incorporated by reference.

Annex III — Approved subprocessors

SubprocessorPurposePersonal InformationLocation
Supabase, Inc.Database, authentication, scheduled report generationAll categories in Annex ICanada (ca-central-1)
Vercel Inc.Application hosting and content deliveryIP address, browser data, request logsUnited States / global edge
Resend (Plus Five Five, Inc.)Transactional and report email deliveryName, work email address, report contentsUnited States