This Data Processing Addendum (“DPA”) forms part of the Master Subscription Agreement between MakeMyMonth and Customer and governs our processing of Personal Information on Customer’s behalf. If this DPA conflicts with the Agreement on any question of personal data processing, this DPA controls.
What we actually process. Employee names, work email addresses, roles, store assignment, the sales activity numbers those employees enter, commission figures they enter, and sign-in records. We do not process consumer or customer data. No buyer names, no credit applications, no deal jackets. That keeps this Service outside the scope of the Gramm-Leach-Bliley Act Safeguards Rule as applied to your customer information.
Customer is the Business and Controller. MakeMyMonth is the Service Provider and Processor. Customer determines the purposes and means of processing; we process only as described in this DPA and on Customer’s documented instructions. The Agreement, this DPA, and Customer’s configuration and use of the Service constitute Customer’s complete documented instructions.
Customer is responsible for the lawfulness of its collection of Personal Information, for providing any required notices to its employees, and for having a lawful basis for the processing it instructs.
The subject matter, duration, nature, purpose, types of Personal Information, and categories of Data Subjects are described in Annex I.
We will:
We certify that we do not Sell or Share Personal Information, and that we will not:
We will comply with the obligations applicable to a Service Provider under the CCPA and will provide the same level of privacy protection the CCPA requires of Customer. Customer may take reasonable and appropriate steps to ensure we use Personal Information consistently with Customer’s obligations, and to stop and remediate unauthorized use. We will notify Customer if we determine we can no longer meet these obligations.
Employee data. Customer acknowledges that under the CCPA its employees are Consumers with full rights in the employment context, and that Customer — not MakeMyMonth — is responsible for providing employees with a notice at collection and for responding to their rights requests, with our assistance under Section 10.
Customer provides general authorization for us to engage Subprocessors. Our current Subprocessors are listed in Annex III. We will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance.
We will give Customer at least 30 days’ notice before adding or replacing a Subprocessor that processes Personal Information. Customer may object on reasonable data protection grounds within that period. If we cannot provide a commercially reasonable alternative, Customer may terminate the affected subscription and receive a pro rata refund of prepaid unused fees.
We will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Personal Information. The notice will describe, to the extent known: the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed. We will provide reasonable cooperation and information to help Customer meet its own notification obligations.
Our notification is not an acknowledgment of fault or liability. Unsuccessful attempts that do not compromise Personal Information — such as blocked sign-in attempts or routine port scans — are not Security Incidents.
Personal Information is stored in Canada. Our primary database and authentication service are hosted by Supabase in the ca-central-1 region. Application hosting and email delivery are provided from the United States. Customer instructs and authorizes this arrangement. Canada is recognized by the European Commission as providing an adequate level of protection for personal data transferred to commercial organizations.
On Customer’s written request, no more than once per twelve months (and additionally after a Security Incident affecting Customer), we will provide: our then-current Security Overview, responses to a reasonable written security questionnaire, and any third-party audit reports or certifications we then hold. Information provided is our Confidential Information. On-site audits are not included; if Data Protection Laws require an audit that these measures cannot satisfy, the parties will discuss a mutually acceptable alternative at Customer’s expense.
The Service gives Customer’s administrators the ability to access, correct, export, and delete Personal Information about their Authorized Users directly. If we receive a request from a Data Subject relating to Customer’s Personal Information, we will not respond substantively and will forward it to Customer without undue delay, except where legally required to respond. We will provide reasonable assistance if Customer cannot address a request through the Service itself.
Where Personal Information originating in the European Economic Area, United Kingdom, or Switzerland is processed under this DPA, the parties agree that the applicable Standard Contractual Clauses, and the UK International Data Transfer Addendum where relevant, are incorporated by reference, with Customer as data exporter and MakeMyMonth as data importer, Module Two (controller to processor). Annex I and Annex II of this DPA populate the corresponding annexes of those clauses.
For 30 days after termination or expiry of the Agreement, Customer may export Personal Information through the Service or by written request. After that period, we will delete or de-identify Personal Information within 90 days, except where retention is required by law. Personal Information in encrypted backups is deleted on our normal backup rotation and remains subject to this DPA until then.
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement.
| Subject matter | Provision of the MakeMyMonth sales activity tracking service |
| Duration | The Subscription Term, plus the retention periods in Section 12 |
| Nature and purpose | Hosting, storage, calculation, display, and email reporting of employee sales activity data; authentication; customer support |
| Categories of Data Subjects | Customer’s employees and contractors: salespeople, sales managers, and dealership administrators |
| Types of Personal Information | Name; work email address; role; dealership/store assignment; account status; monthly income goal; average commission figure; daily activity entries (ups, demos, write-ups, sold units, appointments set/confirmed/shown, days off); commission tracker entries (deal dates, stock numbers, partial VIN, commission amounts); sign-in timestamps; IP address and browser data in server logs |
| Sensitive data | None. No government identifiers, financial account numbers, health data, biometric data, precise geolocation, or data revealing protected characteristics is collected by the Service. |
| Consumer data | None. The Service does not collect or process data about Customer’s vehicle buyers. |
| Frequency | Continuous during the Subscription Term |
Summarized here and described in full in the Security Overview, which is incorporated by reference.
| Subprocessor | Purpose | Personal Information | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, scheduled report generation | All categories in Annex I | Canada (ca-central-1) |
| Vercel Inc. | Application hosting and content delivery | IP address, browser data, request logs | United States / global edge |
| Resend (Plus Five Five, Inc.) | Transactional and report email delivery | Name, work email address, report contents | United States |