Data Processing Addendum

Last updated: July 26, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer,” the controller) and Automate Admits, Inc. (“Automate Admits,” the processor) for the use of the Automate Admits platform (the “Service”). It describes how we process personal data on the Customer’s behalf. Capitalized terms not defined here have the meaning given in our Terms of Service.

1. Roles of the parties

For personal data contained in Customer Data, the Customer is the controller (or, where the Customer acts on behalf of a third party, the processor), and Automate Admits is the processor (or subprocessor) acting on the Customer’s documented instructions. Automate Admits processes personal data only to provide and support the Service, as set out in this DPA, our Terms, and our Privacy Policy, or as otherwise instructed by the Customer in writing and as permitted by law.

2. Subject matter, duration & purpose

The subject matter is the provision of the Service. Processing continues for the duration of the Customer’s use of the Service and until data is deleted or returned as described below. The purpose is to receive, store, organize, transmit, and respond to messages and lead information through the Customer’s connected channels, including the optional AI agent.

3. Types of data & data subjects

4. Processor obligations

5. Subprocessors

The Customer authorizes Automate Admits to engage the subprocessors below to provide the Service. We impose written data-protection obligations on each subprocessor and we remain responsible for their performance under this DPA. Where a business associate agreement is in place we say so; where one is not, we say that too.

Each subprocessor without a business associate agreement supports an optional feature the Customer can leave disabled. The current status of each is published on our Trust page and updated when it changes.

We will give notice of intended changes to subprocessors so the Customer has an opportunity to object on reasonable data-protection grounds.

6. Data subject requests

Taking into account the nature of the processing, Automate Admits will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligations to respond to requests from data subjects to exercise their rights. Where we receive a request directly from a data subject relating to Customer Data, we will, where lawful, direct them to the Customer or forward the request.

7. Security measures

Automate Admits maintains technical and organizational measures designed to protect personal data, including encryption in transit (TLS, with HSTS and enforced TLS to the database and object storage) and at rest (AWS KMS customer-managed key with rotation), role-based access control, optional two-factor authentication, PBKDF2 password hashing, per-organization audit logging, brute-force lockout, signature verification of incoming platform webhooks, automated daily backups with cross-region replication, and logical isolation of each Customer’s data in our multi-tenant environment enforced by an automated tenant-isolation audit in our release process. Further detail — including the controls we have not yet implemented — is on our Security page.

8. Personal data breach

Automate Admits will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Customer meet its notification obligations.

9. Deletion or return of data

Upon termination of the Service, and at the Customer’s choice, Automate Admits will delete or make available for return the Customer’s personal data, and delete existing copies unless retention is required by law. During the term, Customer Data is retained until the Customer deletes it — there is no automatic expiry — and Customers can delete individual contacts and conversations, disconnect channels, and request deletion of account data at any time, as described in our Privacy Policy.

10. Audits

Automate Admits will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security conditions.

11. International transfers

The Service and all subprocessors listed in Section 5 process personal data in the United States. Where required by applicable law, the parties will put in place an appropriate transfer mechanism.

12. General

If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls. Where Customer Data includes protected health information, the Business Associate Agreement controls as to that subject matter; where it includes records subject to 42 CFR Part 2, the Qualified Service Organization Agreement controls as to that subject matter. This DPA is governed by the laws of the State of Wyoming, consistent with the Terms.

To request a signed copy of this DPA, or for any data-protection question, contact privacy@automateadmits.com.