Inflowence LogoInflowenceEvery call answered. Reviews on autopilot.Every call answered. Reviews on autopilot. Built for local businesses.
  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Acceptable Use
  • Messaging & SMS
  • SMS Terms
  • Voice & AI Disclosure
  • Data Processing
  • Subprocessors
  • Datenschutz
  • Impressum

Data Processing Addendum

Effective Date: June 2, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer," "Controller," or "you") and Inflowence ("Processor," "we," "us," or "our").

This DPA governs the processing of Personal Data by Inflowence on behalf of Customer in connection with the Services, as required by applicable Data Protection Laws.

1. Definitions

"Data Protection Laws" means all applicable laws and regulations relating to privacy and data protection, including:

  • The EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679. Inflowence is established in the Federal Republic of Germany. Article 3(1) GDPR therefore applies to our processing by reason of that establishment — irrespective of where the Customer or any End Recipient is located. This is not optional and does not depend on a Customer being European.
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Virginia Consumer Data Protection Act (VCDPA)
  • Colorado Privacy Act (CPA)
  • Utah Consumer Privacy Act (UCPA)
  • Other applicable US state privacy laws

Note on this document. The Article 28 GDPR processing terms, the Standard Contractual Clauses, and the full processing annexes are set out in Schedule C (Data Processing Addendum) of our Master Services Agreement, which controls over this page in the event of any conflict. Customers processing personal data of EU/EEA data subjects should request the Schedule C DPA at legal@inflowence.ai.

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Inflowence in connection with the Services.

"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, transmission, erasure, or destruction.

"Sub-processor" means any third-party service provider engaged by Inflowence to process Personal Data on Customer's behalf (see Subprocessors List).

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"Controller" means the entity that determines the purposes and means of processing Personal Data.

"Processor" means the entity that processes Personal Data on behalf of a Controller.

"Services" means the Inflowence platform and all related services as described in the Terms of Service.

2. Roles and Scope

2.1 Roles of the Parties

Customer as Controller:

  • Customer is the Controller of Personal Data submitted to the Services
  • Customer determines the purposes and means of processing Personal Data
  • Customer is responsible for compliance with Data Protection Laws in its role as Controller

Inflowence as Processor:

  • Inflowence acts as a Processor processing Personal Data on Customer's behalf
  • Inflowence processes Personal Data only in accordance with Customer's documented instructions
  • Inflowence will not sell Customer's Personal Data

2.2 Scope of Processing

Types of Personal Data processed:

  • Contact information (names, email addresses, phone numbers, addresses)
  • Business information (company names, job titles, business addresses)
  • Communication content (emails, SMS messages, voice call recordings, direct messages)
  • Engagement data (opens, clicks, responses, website visits)
  • Social media profile information
  • Transaction and billing information
  • Technical data (IP addresses, device information, usage logs)

Categories of Data Subjects:

  • Customer's employees and authorized users
  • Customer's clients, leads, and prospects
  • Customer's customers and end-users

Purpose of Processing:

  • Answering inbound calls placed by End Recipients to Customer's published numbers
  • Missed-call-text-back replies and post-transaction review requests
  • Routing inbound leads captured in those flows to Customer's own systems
  • Honoring and propagating opt-out and consent-revocation signals
  • Technical support
  • Improving Inflowence's voice-AI prompts and conversation flows using de-identified transcripts only (Section 9.3 of the MSA; opt-out; never model training; never call audio)

Inflowence does not use the identifiable content of an End Recipient's call or message for any purpose other than delivering the Services to the Customer on whose behalf it was received, except that Inflowence uses de-identified transcripts — processed under NIST SP 800-188 so they cannot reasonably be linked to any individual — to improve its voice-AI prompts and conversation flows (MSA Section 9.3; never to train AI models; never using call audio). A Customer may opt out of this de-identified improvement use on thirty (30) days' notice.

Duration of Processing:

  • For the duration of the Services agreement
  • As specified in our data retention policies
  • See Privacy Policy for retention details

3. Customer's Obligations

3.1 Lawfulness of Processing

Customer represents and warrants that:

  • It has a lawful basis for processing Personal Data under Data Protection Laws
  • It has obtained all necessary consents and authorizations from Data Subjects
  • Processing instructions provided to Inflowence comply with Data Protection Laws
  • It has the right to transfer Personal Data to Inflowence for processing

3.2 Processing Instructions

Customer's instructions to Inflowence include:

  • Use of the Services in accordance with the Terms of Service
  • Configuration and settings chosen within the Services
  • Data import, export, and deletion requests
  • Technical support requests
  • Other written instructions mutually agreed upon

Inflowence will:

  • Process Personal Data only in accordance with documented instructions
  • Immediately inform Customer if instructions violate Data Protection Laws (in our reasonable opinion)
  • Not process Personal Data for any purpose other than as instructed

3.3 Data Subject Rights

Customer is responsible for:

  • Responding to Data Subject requests (access, rectification, erasure, etc.)
  • Providing Data Subjects with required notices and disclosures
  • Obtaining necessary consents for processing
  • Managing opt-outs and unsubscribe requests

4. Inflowence's Obligations

4.1 Confidentiality

Inflowence shall:

  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations
  • Limit access to Personal Data to personnel who need access to perform Services
  • Not disclose Personal Data to third parties except as authorized

4.2 Security Measures

Inflowence is a solo-operator business, and the measures below reflect that architecture honestly. They mirror Annex II (Technical and Organisational Measures) of our Master Services Agreement and are aligned to the NIST Cybersecurity Framework 2.0.

Technical Measures:

  • Encryption in transit: TLS 1.2 or higher for all Personal Data over public networks
  • Encryption at rest: AES-256 or stronger, as provided by the underlying infrastructure provider
  • Multi-factor authentication mandatory on every administrative account
  • Credentials held in a reputable password manager; least-privilege scoping on all provider accounts
  • Full-disk encryption and automatic OS updates on the workstation with production access
  • Application logging with direct identifiers (phone numbers, email addresses) redacted before forwarding
  • Version-controlled changes; production deployments require explicit invocation, never auto-deploy
  • Dependency vulnerability monitoring, patched on a risk-prioritized basis

Organizational Measures:

  • Production access is restricted to Don Vaughn personally. No contractor has access to production Personal Data without a written confidentiality undertaking and a documented need-to-know
  • Written incident-response runbook: detection, triage, containment, notification, evidence preservation, post-incident review
  • Documented restore-from-backup test at least annually
  • Annual review of these measures, and on any material change to the Services or subprocessors
  • Subprocessors vetted for a published DPA or transfer mechanism, data-residency disclosure, and breach-notification terms

4.3 Security Incident Notification

In the event of a Personal Data breach, Inflowence will:

  • Notify Customer without undue delay upon becoming aware
  • Provide reasonable information about the breach
  • Take reasonable steps to mitigate harm and prevent future breaches
  • Cooperate with Customer's investigation and regulatory notifications

Notification includes:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

Contact for Breaches: security@inflowence.ai

4.4 Assistance with Data Subject Requests

Inflowence will provide reasonable assistance to help Customer respond to Data Subject requests:

Access Requests: Tools to export Personal Data Rectification: Tools to update or correct Personal Data Erasure: Tools to delete Personal Data upon request Portability: Data export in machine-readable formats Objection/Restriction: Configuration options to limit processing

Response Time: Inflowence will respond to assistance requests within 10 business days.

Customer's Role: Customer is responsible for responding directly to Data Subjects. Inflowence provides tools and assistance only.

5. Sub-processors

5.1 Authorization

Customer authorizes Inflowence to engage Sub-processors to process Personal Data, subject to the terms of this DPA.

Current Sub-processors: See Subprocessors List

5.2 Sub-processor Obligations

Inflowence ensures that Sub-processors:

  • Are bound by written agreements imposing substantially the same obligations as this DPA
  • Implement appropriate security measures
  • Process Personal Data only as authorized
  • Maintain confidentiality

5.3 Changes to Sub-processors

Inflowence will:

  • Provide 30 days' advance notice of new Sub-processors for material processing
  • Maintain an up-to-date list at Inflowence Subprocessors
  • Allow Customer to object to new Sub-processors

Objection Process:

  • Customer must object in writing within 30 days of notice
  • Inflowence will work in good faith to provide an alternative solution
  • If no alternative is available, Customer may terminate the affected Services without penalty

5.4 Liability

Inflowence remains liable for the acts and omissions of Sub-processors to the same extent as if Inflowence performed the services directly.

6. Data Location and Storage

6.1 Primary Data Location

Personal Data is stored and processed in both the European Union and the United States, depending on the provider. See the Subprocessors List for the location of each.

  • European Union: application database and cache (Supabase, EU region — Ireland; Upstash, EU region)
  • United States: CRM, telephony and messaging (GoHighLevel and its carriers), model inference, payments
  • Content may be served from global CDN edge locations

6.2 Data Residency

Inflowence does not currently offer customer-selectable data residency. Where Personal Data is transferred out of the EEA, that transfer is made under the safeguards described in Schedule C of our Master Services Agreement, which incorporates the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914).

If you have a specific residency requirement, contact legal@inflowence.ai and we will tell you honestly whether we can meet it.

7. Data Retention and Deletion

7.1 Retention

Inflowence will retain Personal Data:

  • For the duration of the Services agreement
  • As necessary to provide the Services
  • As required by law or regulation
  • As specified in our Privacy Policy

7.2 Deletion

Upon termination or expiration of the Services agreement:

  • Customer may export Personal Data for 30 days after termination
  • Inflowence will delete or anonymize Personal Data within 90 days of termination
  • Exception: Data required to be retained by law or for legitimate business purposes (e.g., billing records)

Deletion Process:

  • Customer may request immediate deletion by contacting support
  • Deletion confirmation provided upon request
  • Backups may be retained for an additional 90 days per backup retention policies

8. Audits and Compliance

8.1 Audit Rights

Customer may audit Inflowence's compliance with this DPA:

Standard Audit Information:

  • Inflowence will provide a written description of its technical and organisational measures (Section 4.2) and its current subprocessor list, on written request, at no cost
  • Inflowence will pass through the compliance documentation published by its infrastructure providers, where those providers make it available

On-Site Audits:

  • Available upon mutual agreement, on reasonable advance notice
  • Conducted during business hours with minimal disruption
  • Customer pays reasonable costs
  • Subject to confidentiality agreement

8.2 Certifications

Inflowence does not hold a SOC 2 attestation or an ISO 27001 certification, and does not commission third-party penetration tests. We will not claim otherwise, and we will reassess this as the business scales or at a Customer's reasonable contractual request.

Several of our subprocessors do maintain such certifications in their own right (see the Subprocessors List); those are the subprocessor's certifications, not ours.

Questions: compliance@inflowence.ai

8.3 Compliance Assistance

Inflowence will provide reasonable assistance with:

  • Data protection impact assessments (DPIAs)
  • Consultations with supervisory authorities
  • Regulatory inquiries and investigations
  • Customer's compliance obligations

Additional Fees: May apply for extensive compliance assistance beyond standard services.

9. Liability and Indemnification

9.1 Limitation of Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service.

Exception: Neither party limits liability for:

  • Data breaches caused by that party's negligence or willful misconduct
  • Violations of Data Protection Laws by that party
  • As prohibited by applicable law

9.2 Indemnification

Inflowence Indemnifies Customer for:

  • Claims arising from Inflowence's breach of this DPA
  • Inflowence's violations of Data Protection Laws in its role as Processor
  • Unauthorized processing by Inflowence

Customer Indemnifies Inflowence for:

  • Claims arising from Customer's processing instructions
  • Customer's violations of Data Protection Laws in its role as Controller
  • Customer's failure to obtain necessary consents

10. Term and Termination

10.1 Term

This DPA takes effect on the date Customer first uses the Services and continues for the duration of the Services agreement.

10.2 Effect of Termination

Upon termination:

  • Inflowence will cease processing Personal Data (except for deletion)
  • Customer may export Personal Data during the post-termination period
  • Inflowence will delete or return Personal Data as directed
  • Provisions requiring ongoing performance will survive (e.g., confidentiality, deletion)

11. Conflict and Precedence

In the event of conflict between this DPA and the Terms of Service:

  • This DPA prevails for data protection matters
  • Terms of Service prevail for other matters

12. Amendments

Inflowence may update this DPA:

  • To reflect changes in Data Protection Laws
  • To reflect changes in our Services or Sub-processors
  • For clarification or improved readability

Notice of Changes:

  • Material changes: 30 days' advance notice via email
  • Non-material changes: Posted on website, effective immediately

13. Governing Law

This DPA is governed by the same law as the Terms of Service, except where Data Protection Laws require otherwise.

14. Contact Information

Data Protection Officer

For data protection inquiries:

  • Email: dpo@inflowence.ai
  • Mail: [To be provided upon request]

General Inquiries

  • Privacy Questions: privacy@inflowence.ai
  • Security Questions: security@inflowence.ai
  • Legal Questions: legal@inflowence.ai
  • Compliance Questions: compliance@inflowence.ai

15. Acceptance

By using the Services, Customer agrees to the terms of this DPA.

For customers requiring a signed DPA:

  • Contact legal@inflowence.ai
  • Executed DPA available for Enterprise customers
  • Standard DPA incorporated into Terms of Service for all customers

Related Documents

  • Terms of Service
  • Privacy Policy
  • Subprocessors List
  • Acceptable Use Policy

Exhibits

Exhibit A: Details of Processing

Nature of Processing: Marketing automation, CRM, communication management, AI services

Purpose: Providing the Services to Customer

Duration: Duration of Services agreement + retention period

Data Subjects: Customer's employees, users, clients, leads, prospects, customers

Categories of Data: Contact info, communications, engagement data, social profiles, business data

Exhibit B: Security Measures

See Section 4.2 (Security Measures) above and our Security Overview (available upon request).

Exhibit C: Sub-processors

See Subprocessors List


Last Updated: December 19, 2025

This DPA is effective as of the date Customer first uses the Services or accepts the Terms of Service, whichever is earlier.

For questions or to request an executed copy, contact: legal@inflowence.ai

Inflowence LogoInflowence

Every call answered. Reviews on autopilot. Built for local businesses.

Done-for-you Google reviews for Houston HVAC, plumbing, & home inspectors.

Services

  • All services
  • Google review automation
  • Missed call text back
  • AI answering service
  • For home inspectors
  • Pricing
  • Best review software for HVAC
  • Review automation in Houston

Resources

  • Missed call calculator
  • Blog
  • Contact
  • Sitemap

Legal

  • Terms of Service
  • Privacy Policy
  • Messaging & SMS Terms
  • Datenschutz
  • Impressum

© 2026 Inflowence LLC. All rights reserved.

525 Randall Ave Ste 100 PMB 1133, Cheyenne, WY 82001, USA

Your phone is ringing
Get Started