CUSTOMER DATA PROCESSING ADDENDUM

Last Updated September 2025

If you would like a signed copy of this agreement, please click here.

This Customer Data Processing Addendum, including its exhibits and appendices (the “Addendum”) is entered into between HighLevel, Inc., a corporation incorporated under the laws of Dallas, Texas, and its relevant Affiliates (“HighLevel”), and the counterparty accepting this Addendum (“Customer”) (each, a “Party” and, collectively, the “Parties”) by virtue of the Customer signing and accepting the Terms of Services Agreement (the “Agreement”). As of the effective date of the Agreement (the “Effective Date”), the terms of this Addendum shall be incorporated by reference and be part of the Agreement...

1. Definitions

  • For the purpose of interpreting this Addendum, the following terms (and their applicable cognates) shall have the meanings set out below:

  • Account” means any accounts or instances created by, or on behalf of, Customer or its Affiliates within the Services.

  • Affiliate” means any entity within a controlled group of companies that directly or indirectly, through one or more intermediaries, is controlling, controlled by, or under common control with one of the Parties.

  • Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data...

  • Capitalized terms which are used but not defined herein shall have the meanings given to them in the Agreement. Except as modified or supplemented above, the definitions of the Agreement shall remain in full force and effect.

2. Scope and Applicability.

  • Duration. This Addendum shall take effect on the Effective Date and shall continue concurrently for the duration that Personal Data is Processed...

  • Scope. This Addendum will apply to the Processing of all Customer Personal Data, regardless of country of origin, place of Processing, location of Data Subjects, or any other factor...

3. Processing of Customer Personal Data.

  • HighLevel will act as a Processor of Customer Personal Data. Customer will act as the Controller of Customer Personal Data...

  • HighLevel shall:

    • Comply with all Applicable Data Protection Laws in the Processing of Customer Personal Data;
    • Not Process Customer Personal Data other than on Customer’s relevant documented instructions...

4. Personnel.

HighLevel shall take reasonable steps to ensure:

  • the reliability of any employee, agent, or contractor who may have access to Customer Personal Data;
  • that access to Customer Personal Data is strictly limited...

5. Security of Processing.

HighLevel shall implement and maintain the administrative, technical, and organizational security measures identified within Appendix I to Exhibit A...

6. Contracted Processors.

  • Customer authorizes HighLevel to continue using those Contracted Processors engaged as of the Effective Date and set out within HighLevel’s website...

7. Rights of the Data Subjects.

  • Taking into account the nature of the Processing, HighLevel shall assist Customer by implementing appropriate technical and organizational measures...

8. Personal Data Breaches.

  • Breach Response. If HighLevel discovers, is notified of, or has reason to suspect a Personal Data Breach affecting Customer Personal Data...

9. Data Protection Assessment and Prior Consultation.

HighLevel shall provide Customer with relevant information and documentation...

10. Deletion or Return of Personal Data.

  • HighLevel shall provide Customer with the technical means, consistent with the way the Services are provided, to request the deletion of Customer Personal Data...

11. Audit Rights.

HighLevel shall allow for and contribute to audits, including remote inspections, by Customer or an auditor mandated by Customer...

12. Jurisdiction Specific Terms.

To the extent HighLevel Processes Customer Personal Data originating from or protected by Applicable Data Protection Laws...

13. Restricted Transfers.

  • Restricted Transfers of Customer Personal Data within the scope of this Addendum shall be conducted in accordance with Exhibit B...

14. No Selling of Customer Personal Data.

HighLevel acknowledges and confirms that it does not receive any Customer Personal Data as consideration for any Services...

15. Amendment and Online Hosting.

  • Subject to the conditions specified in this Addendum, HighLevel may host the content of the exhibits and appendices of this Addendum online...

16. Liability.

  • Subject to Applicable Data Protection Laws, the liability of each Party under this Addendum shall be subject to the exclusions and limitations...

17. General Terms.

  • Notice. The Parties shall use the Data Protection Contact provided in Part A of Exhibit A as contact points for all matters related to this Addendum...

Exhibit A

Details of Processing

A. LIST OF PARTIES:

Name and Address: HighLevel:
HighLevel Inc. and its relevant Affiliates
5473 Blair Rd Ste 100, PMB 383313, Dallas, Texas 75231-4227
Customer:
Customer Name as defined in HighLevel’s Terms of Service and its relevant Affiliates
Customer address as specified by Customer’s Platform Account.

B. DETAILS OF PROCESSING:

Subject Matter of the Processing: The subject matter of the Processing of Customer Personal Data pertains to the provision of Services pursuant to the Agreement.
Nature and Purpose of Processing: HighLevel will process Customer Personal Data as necessary to provide the Services under the Agreement...
Retention Criteria (Duration): The duration of the period in which the Customer accesses and uses the HighLevel platform under the Services Agreement. ...

Appendix I to Exhibit A

Technical and Organizational Security Measures

Throughout the term of the Agreement and for so long as HighLevel has access to any Customer Personal Data...

Type of TOMs Description of TOMs
Measures for pseudonymization and encryption of Personal Data: • All personal data at rest is encrypted with: AES 256 CBC...
Other: • Personal data can be downloaded by customers from within the Service. ...

Exhibit B

Jurisdiction Specific Terms

  1. Australia. When applicable, the Processing of Customer Personal Data shall be compliant with the Australian Privacy Principles...

  2. Brazil. Wherever the Processing pursuant to the Addendum falls within the scope of Brazil’s Lei Geral de Proteção de Dados...

  3. Canada. When applicable, the Processing of Customer Personal Data shall be compliant with the Canadian Federal Personal Information Protection...

  4. European Economic Area.

  • Definitions.

  • EEA” means the European Economic Area...

  1. Switzerland.
  • Definitions.

  • EU 2021 SCCs” means the contractual clauses adopted by the Commission...

  1. United Kingdom.
  • Definitions.

  • EU 2021 SCCs” means the contractual clauses adopted by the Commission...

  1. United States Data Protection Laws include, individually and collectively, enacted state and federal laws...

Appendix I to Exhibit B

Supplemental Clauses to the Standard Contractual Clauses

By this Exhibit C (this “Exhibit”), the Parties provide additional safeguards and redress to the Data Subjects whose Personal Data is transferred pursuant to SCCs...