Solutions by Text, LLC Data Processing Agreement

Updated March 1, 2026

This Data Processing Agreement (the “DPA”) is incorporated into the agreement pursuant to which Customer obtains the right to use the products and services (the “Agreement”).  By beginning or continuing to use SBT’s products and services, Customer consents to be bound by this Data Processing Agreement unless otherwise expressly agreed to in writing by the parties. 

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Agreement between Solutions by Text, LLC, a Texas limited liability company (“SBT”), and Customer, and shall be effective on the effective date of the Agreement (“DPA Effective Date”). All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement. The purpose of this DPA is to ensure the Parties’ agreement with regard to the Processing of Data in accordance with the requirements of Data Protection Laws and Regulations.

1. Definitions

1.1.Affiliate” means any person or entity that now or hereafter directly, or indirectly through one or more intermediaries, controls, or is controlled by, or is under common control with, a Party.

1.2. Agreement” means the Subscription Agreement or other agreement in effect between Customer and SBT that governs Customer’s use of, and SBT’s provision to Customer of, the Services.

1.3. CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.

1.4. Data Controller” means the entity which determines the purposes and means of the Processing of Personal Data.

1.5. Data Processor” means the entity which Processes Personal Data on behalf of the Data Controller.

1.6. “Data Protection Laws and Regulations” means all data protection laws and regulations applicable to a Party’s Processing of Data under the Agreement, including, where applicable, GLBA, and the State Privacy Laws, each as may be amended from time to time.

1.7. Data Subject” means the individual to whom Personal Data relates.

1.8. GLBA” means the Graham-Leach-Bliley Act.

1.9. Personal Data” means any Data submitted, provided or otherwise disclosed to SBT, whether directly or indirectly, through the Services or otherwise, relating to an identified or identifiable person where such information is protected as personal data or personally identifiable information under applicable Data Protection Laws and Regulations.

1.10. Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.

1.11. Process”, “Processed” or “Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

1.12. SBT Privacy Policy” means SBT’s Privacy Policy available at https://solutionsbytext.com/privacy-policy/, which may be amended from time to time as set forth therein.

1.13. Services” means SBT products and services, including the SBT Services and those at https://solutionsbytext.com/ as well as any subdomains, website of SBT that links to this DPA, related websites, and other offerings.

1.14.State Privacy Laws” shall mean, as applicable, the CCPA, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Delaware Personal Data Privacy Act, the Iowa Consumer Data Protection Act, the Montana Consumer Data Privacy Act, the Nebraska Data Privacy Act, the New Hampshire Privacy Act, the New Jersey Data Privacy Law, the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, the Virginia Consumer Data Protection Act, and any similar state or local law or regulation currently in effect or which may come into effect during the term of this DPA and any binding regulations promulgated thereunder, each as may be amended from time to time and solely to the extent this DPA meets the requirements of such laws and regulations.

1.15.Subprocessor” means any Data Processor engaged by SBT.

1.16. All other terms used in this DPA and not defined herein or in the Agreement shall have the respective meanings ascribed to such terms and related or similar terms under the Data Processing Laws and Regulations.

2. Processing Personal Data

2.1. Relationship of the Parties. Customer is the sole “Data Controller” and SBT is the sole “Data Processor.”

2.2. Consent to Process Personal Data. Customer shall ensure that all Authorized Users and Data Subjects have consented to the Processing of their Personal Data in accordance with applicable Data Protection Laws and Regulations as a requirement for each of their access to and use of the Services.

2.3. Customer’s Processing of Personal Data. Customer shall, in its use of the Services and in its instructions to SBT, Process Personal Data in accordance with the requirements of Data Protection Laws and Regulations and any applicable Customer Privacy Policy or GLBA Privacy Notice. For the avoidance of doubt, Customer’s instructions for the Processing of Personal Data shall comply with Data Protection Laws and Regulations. Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data regardless of whether such Personal Data is collected by Customer directly or collected through the Services.

2.4. SBT’s Processing of Personal Data. Unless otherwise required by applicable Data Protection Laws and Regulations to which Processor is subject, SBT shall only Process Personal Data for the following purposes:

        • Processing in accordance with the Agreement;
        • Processing initiated by Authorized Users and/or Data Subjects in their use of Services according to the Agreement; and
        • Processing to comply with other reasonable written instructions provided by Customer that are consistent with the terms of the Agreement or the SBT Privacy PolicyScope, Purpose and Duration. The subject matter of Processing of Personal Data by SBT is the performance of the Services pursuant to the Agreement. The duration of such Processing is set forth in the Agreement or the SBT Privacy Policy, as applicable. The nature and the purposes of the Processing of Personal Data by SBT, the types of Personal Data and categories of Data Subjects Processed under this DPA shall be set forth in the Agreement or as otherwise mutually agreed to by the Parties in writing.

2.5. CCPA Addendum. Solely to the extent applicable, the Parties hereby agree to the CCPA Addendum attached hereto, which shall be incorporated by reference. To the extent there exists any conflict between this DPA and the CCPA Addendum, the terms and conditions of the section most protective of data security and privacy rights shall take precedence.

2.6. Prohibited Data. Customer shall not without SBT’s prior written consent upload, submit, email, store, transmit, disclose or otherwise make available, whether directly or indirectly, any Data that (a) is defined as sensitive personal information under applicable law (including sensitive financial information); (b) is related to an individual’s biometric information; (c) is covered under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as may be amended from time to time, including without limitation, the Health Information Technology for Economic and Clinical Health (HITECH) Act and similar state laws; or (d) is related to a minor, as defined under applicable law.

2.7. Financial Information. Customer shall have the sole responsibility to determine whether Processing of any Data in accordance with the Agreement is subject to the GLBA. To the extent any Processing is or becomes subject to GLBA, Customer shall have the sole responsibility to: (a) notify SBT in writing; and (b) determine any necessary actions to ensure such Processing is compliance with any obligations placed on Customer or passed through to SBT either by GLBA or the applicable financial institution.

3. Subprocessing.

Customer acknowledges and agrees that SBT may retain certain Subprocessors to Process Personal Data on SBT’s behalf in order to provide Services under the Agreement. Prior to a Subprocessor’s Processing of Personal Data, SBT will impose contractual obligations on the Subprocessor that are substantially the same as those imposed on SBT under this DPA. SBT remains liable for its Subprocessors’ performance under this DPA to the same extent SBT is liable for its own performance. If Customer would like to receive notifications of SBT’s current or new Subprocessors, Customer must request such notifications in writing from SBT. Customer may reasonably object to SBT’s use of a Subprocessor by notifying SBT promptly in writing. After receiving an objection to the use of a Subprocessor, Customer and SBT shall work in good faith to determine the appropriate course of action.

4. Security. 

4.1. Security Level. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, SBT shall, in relation to Personal Data, implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures required by Data Protection Laws and Regulations.

4.2. Risk Consideration. In assessing the appropriate level of security, SBT shall consider the risks that are presented by Processing, in particular from a Personal Data Breach.

4.3. Personal Data Breach. SBT shall notify Customer without undue delay upon becoming aware of (a) a Personal Data Breach affecting Customer Personal Data or (b) a non-breach event or incident affecting Customer Personal Data by providing, in response to either clause (a) or (b), Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under applicable law, including the applicable Data Protection Laws and Regulations. SBT shall cooperate with Customer and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation and remediation of any such Personal Data Breach.

5. Rights of Data Subjects.

To the extent Customer, in its use of the Services, does not have the ability to locate, correct, amend, restrict, copy, block or delete Personal Data, as may be required by Data Protection Laws and Regulations, SBT shall comply with any commercially reasonable request by Customer (including by appropriate technical and organizational measures) to assist such actions to the extent SBT is legally permitted to do so. To the extent legally permitted and arising outside of SBT’s ordinary course of business, Customer shall be responsible for any costs arising from SBT’s provision of such assistance. SBT shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise their rights in respect of Personal Data. SBT may, but shall have no obligation to, respond directly to any such Data Subject request without Customer’s prior written consent. SBT shall provide Customer with commercially reasonable cooperation and assistance in relation to handling of a Data Subject’s request for access to that person’s Personal Data, to the extent legally permitted and to the extent Customer does not have access to such Personal Data through its use of the Services.

6. Deletion of Customer Personal Data.

Upon request by Customer, SBT shall delete or return Data and copies thereof in SBT’s possession to Customer, unless the applicable Data Protection Laws and Regulations require storage of all or part of the Data. Once the applicable Data Protection Laws and Regulations no longer require storage, SBT shall promptly delete or return the Data.

7. Data Protection Impact Assessment.

Upon Customer’s request, SBT shall provide Customer with reasonable cooperation and assistance needed to fulfill Customer’s obligations under applicable Data Protection Laws and Regulations to carry out any required data protection impact assessment related to Customer’s use of the Services, to the extent Customer does not otherwise have access to the relevant information and to the extent such information is available to SBT. SBT shall provide reasonable assistance to Customer in the cooperation to the extent required under applicable Data Protection Laws and Regulations.

8. Audit Rights.

SBT shall make available to the Customer, upon Customer’s request (such request to occur no more than once per calendar year) and subject to the confidentiality obligations set forth in the Agreement or any other confidentiality obligations to which SBT is bound, all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by Customer or an auditor in relation to the Processing of Customer Personal Data. Before the commencement of any such audit, Customer and SBT shall mutually agree upon the scope, timing, and duration of the audit. Any such audit shall be conducted during SBT’s normal business hours and shall not materially disrupt SBT’s ordinary court of business.

9. Term and Termination.

This DPA is effective as of the Effective Date and shall remain in full force and effect for the duration of the Agreement. If the applicable Data Protection Laws and Regulations require SBT to retain the data for a specific period of time, including after termination of the Agreement, this DPA shall remain in full force and effect until all such period of time has expired.

10. General 

This DPA and any dispute arising out of it or in connection with it shall be subject to the terms of the Agreement.

CCPA ADDENDUM

This CCPA Privacy Addendum (the “Addendum”), is made by and between Customer and SBT, and sets forth the terms and conditions relating to compliance with the CCPA in connection with SBT fulfilling its obligations and exercising its rights set forth in the DPA to which this Addendum is attached.

1. Definitions. 

Capitalized and undefined terms used in this Addendum shall have the meanings ascribed to them in the DPA unless otherwise defined herein. In addition, as used in this Addendum: (a) “Business,” “Business Purpose,” “Collect,” “Commercial Purpose,” “Consumer,” “Personal Information,” “Processing,” “Sell,” “Service Provider,” and “Share” shall have the respective meanings given to such terms in the CCPA; and (b) “Customer Personal Data” means Personal Information, including Data, but only to the extent such Personal Information is Processed by SBT as a result of SBT’s provision of the Services to Customer in Customer’s capacity as a Business under the Agreement.

2. Details of Processing.

The Business Purpose and subject matter of the Processing of Personal Data by SBT is the performance of the Services upon lawful documented instructions from Customer, including those in the Agreement, the DPA, this Addendum, and Customer’s use and configuration of the Services or as otherwise necessary for SBT to provide the Services.

3. Roles of the Parties.

SBT is acting solely as a Service Provider with respect to Customer Personal Data.  SBT does not determine the purposes or means of Processing of the Customer Personal Data and Customer agrees that Customer is the party responsible for determining the purposes and means of Processing Customer Personal Data.

4. Obligations and Restrictions.

4.1. CCPA Compliance. SBT shall comply with obligations applicable to Services Providers under the CCPA and shall provide the same level of privacy protection to Customer Personal Data as required by the CCPA, including the same privacy protection required to be provided by Customer as a Business. Customer shall comply with obligations applicable to Businesses under the CCPA.  Customer shall publish and keep on Customer’s site, a privacy notice which accurately reflects and provides all required information under any applicable Data Protection Laws and Regulations, including without limitation, the CCPA, concerning the Processing of Personal Information by Customer and SBT under the Agreement.

4.2. CCPA Compliance Monitoring and Remediation. SBT shall notify Customer no later than five (5) business days after determining that it can no longer meet its obligations under the CCPA. Upon receiving such notice, Customer may direct SBT to take reasonable and appropriate steps to stop and remediate any unauthorized use by SBT of Customer Personal Data.

4.3. Limitations on Use of Customer Personal Data. SBT shall not:

    1. sell or Share Customer Personal Data;
    2. retain, use, or disclose Customer Personal Data for any purpose other than for the Business Purposes, expect where and to the extent permitted by the CCPA, including for any other Commercial Purpose;
    3. retain, use or disclose Customer Personal Data outside of the direct business relationship between SBT and Customer; or
    4. combine Customer Personal Data with Personal Information that SBT receives from, or on behalf of, another person or company, except as permitted under the CCPA.

5. Consumer Requests.

5.1. SBT shall, upon Customer’s instructions and at Customer’s sole expense, provide commercially reasonable assistance to Customer in fulfilling Customer’s obligations to respond to verifiable CCPA-related Consumer rights requests regarding Customer Personal Data, including requests to access, correct, delete or receive information about Customer Personal Data pertaining to such Consumer, and requests to delete a Consumer’s Customer Personal Data, except where SBT is unable to do so as set forth below. In the event SBT is unable to delete the Customer Personal Data for reasons permitted under the CCPA, SBT shall (i) promptly inform Customer of the reason(s) for its refusal of the deletion request, (ii) ensure the privacy, confidentiality and security of such Customer Personal Data, and (iii) delete the Customer Personal Data promptly after the reason(s) for SBT’s refusal has expired.

5.2. Customer shall promptly inform SBT in writing of any verifiable CCPA-related Consumer rights request that SBT must comply with and shall provide SBT with the information necessary for SBT to comply with any such request.

6. Sub-processors.

Where SBT provides a subcontractor or sub-processor access to Customer Personal Data, SBT shall notify Customer and enter into a written agreement with each such subcontractor and sub-processor that imposes obligations on such Party that are at least as equivalent to those imposed on SBT pursuant to this Addendum.

7. Obligations at Termination.

Promptly after termination or expiration of the Agreement, SBT will, return or destroy all Customer Personal Data in its possession. This requirement shall not apply to the extent that SBT is required by any applicable law to retain some or all of the Customer Personal Data or to the extent otherwise permitted under the CCPA.

8. Changes to the CCPA.

Notwithstanding anything to the contrary contained in this Agreement, if the CCPA is modified, amended or updated following the execution of this Addendum in a manner that requires that this Addendum be amended in order to be consistent with the CCPA and/or for Customer or SBT to be and remain in compliance with the CCPA, then this Addendum shall be automatically amended and deemed to incorporate such revised CCPA requirements until such time as the Parties formally document such amendment(s) to this Addendum, and the Parties agree to cooperate in good faith to enter into such amendment(s).