breeze logo

Data Processing Addendum

Data Processing Addendum

Effective Date: September 15, 2026

Last Updated: September 15, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Breeze Business Solutions LLC ("Processor," "Breeze," "we," "us," or "our") and the business entity using our Services ("Controller," "Client," "you," or "your"). It applies where we Process Personal Information on your behalf in connection with the Services. This DPA supplements our Terms of Service and Privacy Policy.

In the event of a conflict between this DPA and the Terms of Service regarding the Processing of Personal Information, this DPA controls.


1. Definitions

Applicable Privacy Laws means all privacy and data protection laws applicable to the Processing described in this DPA, including the California Consumer Privacy Act as amended by the CPRA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, and similar U.S. state laws, each as applicable.

Personal Information has the meaning given in Applicable Privacy Laws and includes any information that identifies, relates to, describes, or could reasonably be linked with a consumer or household.

Process or Processing means any operation performed on Personal Information, including collection, use, storage, disclosure, analysis, transmission, deletion, or disposal.

Services means the products and services we provide to you under our Terms of Service, including the Platform, websites, CRM, communications tools, automations, AI agents, advertising management, and related support.

Sub-processor means a third party engaged by Breeze to Process Personal Information on your behalf.


2. Roles and Scope

You are the business or controller of Personal Information you submit to the Services about your customers, leads, or personnel. We act as your service provider or processor.

We will Process that Personal Information only on your documented instructions and as described in this DPA and our Terms of Service, unless otherwise required by law. Your use of the Services, including the configurations and automations you enable, constitutes your documented instructions.

Your responsibilities. You are responsible for the lawfulness of the Personal Information you submit, including providing required privacy notices to your customers, obtaining required consents (including consent required under the TCPA, A2P 10DLC rules, and state call recording laws), honoring opt-out requests, and responding to consumer rights requests directed to you.


3. Processing Instructions and Restrictions

We will Process Personal Information only to provide the Services, comply with law, or as otherwise agreed in writing

We will not sell or share Personal Information, and will not retain, use, or disclose it outside the direct business relationship with you, except as permitted by Applicable Privacy Laws

We will not combine Personal Information received in connection with the Services with Personal Information we receive from other sources, except as necessary to provide or improve the Services, detect security incidents, or as permitted by law

We will not use Personal Information to train our own artificial intelligence models, and we require our AI Sub-processors to refrain from training on your Personal Information

We will notify you if we determine that we can no longer meet our obligations under Applicable Privacy Laws


4. Confidentiality and Personnel

We limit access to Personal Information to personnel who need it to provide the Services. Persons authorized to Process Personal Information are subject to appropriate confidentiality obligations, whether contractual or statutory.


5. Sub-processors

5.1 Authorized Sub-processors

You authorize us to engage the following Sub-processors to Process Personal Information on your behalf:

HighLevel LLC (GoHighLevel) — Platform, CRM, website hosting, mobile app, marketing automation, SMS/MMS and voice via LC Phone System, transactional email delivery, AI features. Processed in the United States.

Stripe, Inc. — Payment processing and billing. Processed in the United States.

Google LLC — Google Ads, Google Analytics, Google Business Profile, advertising delivery and measurement. Processed in the United States.

Meta Platforms, Inc. — Advertising delivery and measurement across Facebook and Instagram. Processed in the United States.

We remain responsible for each Sub-processor's performance of its obligations in accordance with this DPA.

5.2 Nested Sub-processors

You acknowledge that our platform provider, HighLevel LLC, engages its own sub-processors, including telecommunications carriers, cloud infrastructure providers, email delivery providers, and AI model providers, to deliver the platform services. We do not control that provider's selection of its sub-processors. Their current list and terms are governed by HighLevel's own agreements and are available through that provider.

5.3 Changes to Sub-processors

We may replace or appoint additional Sub-processors. When we do, we will update this DPA and post the revised version at our published DPA URL. Changes take effect on posting. Where practicable, we will notify you by email in advance; where we cannot, we will notify you as soon as reasonably practicable after the change.

If you object to a new Sub-processor on reasonable data protection grounds, notify us in writing within 30 days of the change taking effect. We will work with you in good faith to address the objection. If we cannot resolve it, your remedy is to terminate the affected Services under the cancellation terms in our Terms of Service.


6. Security

We implement and maintain reasonable technical and organizational measures designed to protect Personal Information against unauthorized access, disclosure, loss, or alteration, taking into account the nature of the Processing and the risks involved. These measures include access controls, encryption in transit, encryption at rest with our hosting providers, limiting internal access to authorized personnel, and vendor review.

You are responsible for the security of your own account, including credential management, user access you grant to your employees and contractors, and promptly removing access for departed personnel.


7. Security Incidents

We will notify you without undue delay after becoming aware of a security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Personal Information Processed on your behalf.

Our notice will describe, to the extent known, the nature of the incident, the categories of Personal Information involved, and the measures taken or proposed.

You are responsible for determining whether the incident requires notification to consumers or regulators under Applicable Privacy Laws, and for making those notifications. We will provide reasonable assistance.


8. Consumer Rights Requests

Taking into account the nature of the Processing, we will assist you, insofar as reasonably possible, in fulfilling your obligation to respond to consumer rights requests under Applicable Privacy Laws.

Where a consumer submits a request directly to us regarding Personal Information we Process on your behalf, we will direct the requester to you and forward the request, unless we are legally required to respond directly.


9. Data Retention and Deletion

We retain Personal Information only as long as necessary to provide the Services and as described in our Privacy Policy.

Upon termination of the Services, we will retain Personal Information for 30 days to allow you to export it, after which we may delete or archive it. Upon your written request at any time, we will delete or return Personal Information in our possession, subject to any retention required by law and subject to records we must keep to demonstrate compliance, including SMS consent and opt-out records.


10. Audits

Upon reasonable written request, and no more than once in any twelve month period unless required by Applicable Privacy Laws or following a security incident, we will make available information reasonably necessary to demonstrate compliance with this DPA. This may include summaries of our security practices or completed security questionnaires.

Where an on-site audit is required by Applicable Privacy Laws, it will be conducted during business hours, with at least 30 days' advance written notice, at your expense, and subject to confidentiality and security controls.


11. International Transfers

Personal Information is Processed in the United States. If we transfer Personal Information across borders where required by law, we will implement appropriate safeguards as required by Applicable Privacy Laws.


12. Liability

Liability arising from our Processing of Personal Information under this DPA is subject to the limitations and exclusions in our Terms of Service, except where prohibited by Applicable Privacy Laws.


13. Term

This DPA takes effect when you accept our Terms of Service and continues for as long as we Process Personal Information on your behalf. Provisions that by their nature should survive termination, including confidentiality, deletion, and liability, will survive.


14. Contact

Questions about this DPA or our Processing of Personal Information on your behalf:

Breeze Business Solutions LLC

Email: [email protected]

Phone: (801) 616-9347

Web: https://breezebusinesssolutionsllc.nebulabrandgroup.com/