Data Processing Addendum

Effective Date: 1 July 2026

This Data Processing Addendum ("DPA") forms part of the TurboHelp Terms of Service or other agreement between Textly Inc. ("TurboHelp") and Customer for the Services.

1. Scope

This DPA applies when TurboHelp processes personal data in Customer Data on behalf of Customer in connection with the Services.

For personal data processing, this DPA controls over conflicting terms in the Terms of Service, except where a signed agreement expressly states otherwise.

2. Roles

Customer is the controller or business for personal data in Customer Data, or acts as processor or service provider for its own customer.

TurboHelp is the processor or service provider for personal data in Customer Data when processing on Customer's behalf.

For Usage Data, account administration data, billing data, security data, and business contact data, TurboHelp may act as an independent controller or business as described in the Privacy Policy.

3. Processing Details

Subject matter: Provision of the Services, including AI customer support agent features, dashboards, integrations, analytics, support, security, and related operations.

Duration: The term of the agreement plus any period needed for deletion, export, legal compliance, backups, dispute resolution, security, and legitimate business purposes.

Nature and purpose: Hosting, storage, transmission, retrieval, search, AI generation, routing, summarization, classification, analytics, support, troubleshooting, security, billing, account administration, and service improvement.

Categories of data subjects: Customer's Permitted Users, End Users, prospects, website visitors, support contacts, employees, contractors, and other individuals whose data is included in Customer Data.

Categories of personal data: Names, email addresses, account identifiers, support messages, chat logs, ticket content, IP addresses, device data, usage events, conversation metadata, knowledge base content, files, and other personal data submitted by Customer or End Users.

Sensitive data: The Services are not intended for Protected Health Information, payment card data, government IDs, children's data, or other sensitive regulated data unless TurboHelp expressly agrees in writing. Customer must comply with the No-PHI / No-HIPAA Policy.

4. Customer Instructions

TurboHelp will process personal data only on Customer's documented instructions, including the agreement, this DPA, Customer's configuration of the Services, Customer's use of integrations, and Customer's support requests.

TurboHelp may refuse or suspend processing instructions that TurboHelp reasonably believes violate law, the agreement, or the rights of individuals.

Customer instructs and authorizes TurboHelp to process Customer Data for service improvement and model training as described in the Terms of Service, AI Product Terms, and Data Use and Model Training Addendum, unless Customer opts out of Customer Data model training as described in the Data Use and Model Training Addendum. This instruction does not permit third-party LLM providers to train or improve their own models on Customer Data.

5. Customer Responsibilities

Customer is responsible for:

  • Providing lawful instructions.
  • Having all rights, notices, consents, permissions, and lawful bases required for processing.
  • Ensuring Customer Data is accurate and lawful.
  • Responding to individual rights requests unless TurboHelp agrees to assist.
  • Configuring the Services appropriately for Customer's compliance obligations.
  • Avoiding prohibited sensitive regulated data unless expressly authorized in writing.

6. Confidentiality and Personnel

TurboHelp will ensure that personnel authorized to process personal data are bound by confidentiality obligations and receive appropriate instructions regarding data protection and security.

7. Security Measures

TurboHelp will maintain reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure.

Measures may include, as appropriate:

  • Access controls and least-privilege permissions.
  • Authentication controls.
  • Encryption in transit and at rest where supported.
  • Logging and monitoring.
  • Vulnerability management.
  • Backup and recovery processes.
  • Network and infrastructure security.
  • Employee confidentiality obligations.
  • Incident response procedures.
  • Vendor review and subprocessor controls.

Security measures may evolve over time, provided the overall level of security is not materially reduced during the subscription term.

8. Subprocessors

Customer authorizes TurboHelp to use subprocessors to provide, secure, support, and improve the Services.

TurboHelp will maintain a Subprocessors List describing subprocessors, purposes, data categories, locations or hosting regions, AI vendor status, training status, and links to relevant terms where available.

TurboHelp will impose written obligations on subprocessors that are designed to provide a level of data protection appropriate to the subprocessor's role.

TurboHelp will remain responsible for subprocessors' performance of data protection obligations to the extent required by applicable law.

9. Subprocessor Notice and Objection

TurboHelp will provide notice of material new subprocessors by updating the Subprocessors List, email, in-product notice, or another reasonable method.

Customer may object to a new subprocessor on reasonable data protection grounds by notifying TurboHelp at [email protected] within thirty (30) days after notice. The parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may terminate the affected Services and receive a pro rata refund of prepaid unused fees for the terminated portion, unless the subprocessor is required for generally available Services and no reasonable alternative exists.

10. International Transfers

Customer authorizes TurboHelp and its subprocessors to process personal data in the United States and other countries where TurboHelp or its subprocessors operate.

Where required for transfers of personal data from the EEA, UK, or Switzerland to a country not recognized as providing adequate protection, the parties will use appropriate transfer mechanisms, such as Standard Contractual Clauses, the UK Addendum, the UK International Data Transfer Agreement, Swiss transfer terms, or another lawful mechanism.

SCC placeholder: The parties should attach or incorporate the applicable controller-to-processor Standard Contractual Clauses, including module selection, annexes, technical and organizational measures, and subprocessor details, before use.

Transfer appendix placeholder: Before publication, counsel should complete transfer details, including exporter/importer information, categories of data subjects, categories of personal data, sensitive data restrictions, frequency of transfer, processing nature, retention, competent supervisory authority if applicable, technical and organizational measures, and subprocessor transfer details.

TurboHelp will use reasonable efforts to provide information reasonably available to it that Customer needs to assess international transfer risks relating to the Services.

11. Individual Rights Requests

TurboHelp will provide reasonable assistance to Customer, taking into account the nature of the Services, to help Customer respond to requests from individuals to access, delete, correct, export, restrict, or object to processing of personal data in Customer Data.

If TurboHelp receives a request directly from an individual relating to Customer Data, TurboHelp may direct the individual to Customer unless prohibited by law.

12. Deletion and Export

During the subscription term, Customer may export or delete Customer Data using available product features where supported.

After termination, TurboHelp will delete or return Customer Data in accordance with the agreement and its retention practices, unless retention is required or permitted by law, backups, security, dispute resolution, audit, compliance, or legitimate business purposes.

Backups may persist for a limited period and will be protected from active processing except for restoration, security, legal compliance, or disaster recovery.

13. Personal Data Breach

TurboHelp will notify Customer without undue delay after confirming a personal data breach affecting Customer Data. Notice will include information reasonably available to TurboHelp, such as the nature of the incident, affected data categories, likely consequences, mitigation steps, and contact point, to the extent known and legally permitted.

Customer is responsible for any required notices to regulators, individuals, customers, or other third parties unless applicable law requires TurboHelp to provide notice directly.

14. Audits and Documentation

TurboHelp will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and reasonable scope limits.

Where required by applicable data protection law, Customer may request an audit no more than once per year, unless required after a confirmed personal data breach or by a regulator. Audits must be conducted during normal business hours, on reasonable notice, by an independent auditor bound by confidentiality, and without disrupting TurboHelp's operations or compromising other customers' data.

TurboHelp may satisfy audit requests through summaries, policies, questionnaires, security reports, certifications, or other documentation where available.

15. Assistance

TurboHelp will provide reasonable assistance, taking into account the nature of processing and information available to TurboHelp, for Customer's data protection impact assessments, prior consultations, security obligations, and regulatory inquiries relating to the Services.

TurboHelp may charge reasonable fees for assistance that is outside normal support or required because of Customer's specific circumstances.

16. CCPA/CPRA and U.S. State Privacy Terms

Where applicable, TurboHelp will process personal information in Customer Data as Customer's service provider or processor. TurboHelp will not sell or share Customer Data as those terms are defined by applicable U.S. privacy laws.

TurboHelp will not retain, use, or disclose personal information in Customer Data except to provide the Services, as permitted by the agreement, to improve the Services where allowed, to detect security incidents, to protect against illegal activity, to comply with law, or as otherwise permitted for service providers or processors.

17. Government and Law Enforcement Requests

If TurboHelp receives a legally binding request for Customer Data, TurboHelp will notify Customer unless prohibited by law or if notice would create risk of harm. TurboHelp will reasonably challenge overbroad or unlawful requests where appropriate.

18. Return or Destruction Certification

Upon Customer's reasonable written request after termination and completion of deletion processes, TurboHelp may provide written confirmation that Customer Data has been deleted from active systems, subject to backups and permitted retention.