Home/Data Processing Addendum

Data Processing Addendum

Last updated: September 20, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between AspirePro LLC (“AspirePro LLC”, “we”) and the customer organization using AspirePro (“Customer”), and applies whenever we process personal data on the Customer’s behalf.

1. Scope & roles#

For personal data the Customer’s team submits to AspirePro — client records, contacts, tickets, project data, files, meeting content, and similar (“Customer Data”) — the Customer is the controller (or a processor acting for its own clients) and AspirePro LLC is the processor (a “service provider” under U.S. state privacy laws). This DPA applies to that processing. Data we collect for our own purposes — account registration, billing, website analytics — is covered by our Privacy Policy, where AspirePro LLC acts as controller.

2. Details of processing#

  • Subject matter & duration. Providing the AspirePro platform to the Customer for the term of the agreement, plus the wind-down period described in Section 10.
  • Nature & purpose. Hosting, storage, transmission, display, backup, and — where a user invokes AI features — automated analysis of Customer Data, solely to provide and support the service.
  • Categories of data subjects. The Customer’s personnel and users; the Customer’s own clients, prospects, and their personnel; other individuals whose data the Customer’s team submits.
  • Categories of personal data. Contact and business information (names, emails, phone numbers, job titles, company details), communications and meeting content, project/ticket/billing records, and any other personal data the Customer chooses to submit. The service is not designed for special categories of data, and the Customer agrees not to submit them.

3. Customer instructions#

We process Customer Data only on the Customer’s documented instructions — which are: the agreement, this DPA, and the Customer’s use and configuration of the service (including which integrations it connects) — unless processing is required by law, in which case we’ll inform the Customer unless that law prohibits it. We do not sell Customer Data, use it for advertising, or use it to train AI models.

4. Confidentiality#

Persons we authorize to process Customer Data are bound by confidentiality obligations, and access is limited to what is needed to operate, support, and secure the service.

5. Security measures#

We implement appropriate technical and organizational measures to protect Customer Data, including per-customer database isolation, encryption in transit and at rest, a web application firewall, role-based access control, multi-factor authentication, nightly backups, and audit logging. These measures are described in more detail on our Security page, which forms the security annex to this DPA and which we may strengthen — but not materially weaken — over time.

6. Sub-processors#

The Customer generally authorizes the sub-processors listed on our Sub-processors page, which identifies each provider, its purpose, and its location. We impose data-protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We’ll update the list before adding or replacing a core sub-processor; Customers on the notice list are emailed. If the Customer reasonably objects on data-protection grounds and we can’t offer an alternative, the Customer may terminate the affected service and receive a pro-rated refund of prepaid fees for the unused period.

7. Assistance to the customer#

Taking into account the nature of the processing, we’ll assist the Customer with data-subject requests (access, correction, deletion, export), and with the Customer’s security, breach-notification, and impact-assessment obligations — primarily through the service’s built-in controls (record editing and deletion, exports, audit trails), and otherwise on request.

8. Personal data breaches#

If we become aware of a personal data breach affecting Customer Data, we’ll notify the Customer without undue delay, describe the nature and likely consequences of the breach, the measures taken or proposed, and a contact point — and we’ll cooperate with the Customer’s reasonable requests to investigate and mitigate.

9. International transfers#

Customer Data is hosted in the United States. Where data protection law requires a transfer mechanism for personal data originating elsewhere (for example, the EEA, UK, or Switzerland), the parties rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this DPA by reference with AspirePro LLC as data importer, or on any successor mechanism recognized by the relevant authority.

10. Return & deletion of data#

During the term, the Customer can export its data using the service’s built-in tools or by request. After termination, we retain the organization for a wind-down period (as described in our Terms) so the Customer can reactivate or export, after which — or earlier on the Customer’s written request — we delete Customer Data from production systems, with backup copies expiring on our standard 30-day backup rotation.

11. Audits & information#

We’ll make available information reasonably necessary to demonstrate compliance with this DPA — this page, our Security page, and written answers to reasonable security questionnaires. Where law grants the Customer a broader audit right, audits are subject to reasonable notice, scope, frequency (no more than annually absent a breach), confidentiality, and the Customer’s cost.

12. Order of precedence & general#

If this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA controls. Liability under this DPA is subject to the limitations in the Terms. If any provision is unenforceable, the remainder stays in effect.

13. Getting a signed copy#

This page is our standard DPA and applies automatically to every Customer. If your compliance process needs a countersigned copy (including executed Standard Contractual Clauses), email support@aspirepro.io and we’ll provide one for signature.

14. Contact us#

Privacy and data-processing questions: support@aspirepro.io.