Data Processing Addendum
This DPA supplements the SwipeSelect Terms of Service and applies whenever SwipeSelect processes personal data on behalf of a customer.
1. Roles of the parties
For personal data submitted to the SwipeSelect platform by a customer (for example, contacts uploaded to the CRM), the customer is the controller and SwipeSelect is the processor. For lead data sourced and offered through the marketplace, SwipeSelect acts as an independent controller until the lead is purchased.
2. Subject matter and duration
SwipeSelect processes personal data to deliver the services described in the Terms of Service, for the duration of the customer's active subscription and any retention period required by law.
3. Nature and purpose of processing
Processing includes hosting, storage, transmission, deduplication, fraud screening, support, and reporting needed to operate the platform.
4. Categories of data and data subjects
- Contact identifiers (name, email, phone, address) of consumers who submitted a consented inquiry.
- Account information for agents, agency staff, and administrators using the platform.
- Usage and device data generated through normal use of the services.
5. Sub-processors
SwipeSelect engages a limited set of sub-processors for hosting, infrastructure, email, payments, and analytics. A current list is available on request. We require sub-processors to maintain data protection obligations no less protective than those in this DPA.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data, including TLS 1.2+ in transit, AES-256 at rest, role-based access control, and audit logging. Our security posture is described in the Compliance page.
7. International transfers
Where personal data is transferred outside the customer's jurisdiction, SwipeSelect relies on appropriate safeguards such as Standard Contractual Clauses where required.
8. Data subject rights
SwipeSelect will provide reasonable assistance to the customer in responding to verified data subject requests (access, deletion, correction, portability, objection).
9. Breach notification
SwipeSelect will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, and will share information reasonably needed for the customer to meet its own notification obligations.
10. Return or deletion
On termination, and at the customer's written request, SwipeSelect will delete or return customer personal data within a reasonable period, subject to legal retention requirements.
11. Contact
Questions about this DPA or requests to execute a signed counterpart can be sent to garcia.algarcia@gmail.com.
This DPA is provided for informational purposes and does not constitute legal advice.
