Data Processing Agreement

Last updated

In plain English

  • This governs personal data we process on a customer organization’s behalf. It supplements the Professional Terms.
  • You are the controller. We are the processor, and we act on your documented instructions.
  • We will not train any AI model on your data, and our model providers are under API terms that prohibit it.
  • We do not sell or share your personal data, and we never combine it with data from other sources.
  • A confirmed security incident is notified within 72 hours.
  • On termination we delete or return your data within 30 days, with encrypted backups aging out within 90.

This summary is here to help you find things. It is not the agreement. The full text below is what governs.

This Data Processing Agreement ("DPA") is between CollectionStopperMembership LLC, d/b/a KillDebt ("KillDebt" or "Processor") and the customer identified in the applicable subscription agreement or order form ("Customer" or "Controller").

This DPA supplements the KillDebt for Professionals subscription agreement or order form between the parties (the "Agreement") and governs KillDebt’s processing of Customer Personal Data in connection with the services described in the Agreement (the "Services"). This DPA is effective as of the effective date of the Agreement.

1. Definitions

1.1 "Personal Data" means any information relating to an identified or identifiable natural person that KillDebt processes on Customer’s behalf under the Agreement.

1.2 "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.

1.3 "Data Protection Laws" means all privacy and data protection laws applicable to the Processing of Personal Data under the Agreement, including, as applicable, U.S. state privacy laws (e.g., the CCPA/CPRA and comparable state statutes) and, if applicable, the EU/UK GDPR.

1.4 "Subprocessor" means a third party engaged by KillDebt to Process Personal Data on Customer’s behalf.

1.5 "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.

2. Roles and Scope of Processing

2.1 As between the parties, Customer is the controller (or a processor acting on behalf of its own clients) and KillDebt is a processor of Customer Personal Data.

2.2 KillDebt shall Process Customer Personal Data only (a) to provide, secure, and support the Services; (b) as documented in the Agreement, this DPA, and the description of processing provided with the executed Agreement; and (c) on Customer’s documented instructions, unless required otherwise by applicable law, in which case KillDebt will notify Customer unless legally prohibited.

2.3 The Services’ research tools are read-only: research queries go out and cited answers come back. KillDebt does not access Customer’s case-management systems or client records, does not require the upload of client files or case documents, and Customer’s personnel are never required to submit such materials to use the research Services. Files Customer’s personnel choose to upload to optional platform document features are Processed only as described in the description of processing provided with the executed Agreement. The categories of data actually Processed are limited to those described there.

2.4 KillDebt shall not sell or share Customer Personal Data (as those terms are defined under applicable U.S. state privacy laws), retain, use, or disclose it outside the direct business relationship with Customer, or combine it with data from other sources except as permitted for processors and service providers under Data Protection Laws.

3. No AI Training

3.1 KillDebt shall not use Customer Personal Data, research queries, uploaded files, or any content submitted by Customer’s users to train, fine-tune, or improve any artificial intelligence or machine learning model.

3.2 KillDebt engages the AI model providers listed on the Subprocessor List (including OpenAI, Anthropic, Google, and Mistral AI) under API terms that, as of the effective date, prohibit the use of API inputs to train those providers’ models. KillDebt does not control those providers’ terms. If KillDebt becomes aware of a material adverse change to a provider’s training terms as they apply to Customer content, KillDebt will notify Customer and the change will be treated as the addition of a new Subprocessor under Section 6, including Customer’s notice and objection rights.

4. Confidentiality

4.1 KillDebt shall ensure that all personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations and Process such data only as needed to provide the Services.

4.2 The parties acknowledge that research queries submitted by Customer’s personnel may relate to legal matters. KillDebt shall treat query content as Customer’s confidential information and shall not review it except as necessary for security, abuse prevention, support at Customer’s request, or as required by law. Nothing in this DPA is intended to waive any applicable privilege.

5. Security

5.1 KillDebt shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, including no less than the measures described on the Security Overview.

5.2 KillDebt may update those measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data.

6. Subprocessors

6.1 Customer provides general authorization for KillDebt to engage the Subprocessors and data recipients listed on the Subprocessor List.

6.2 KillDebt shall (a) impose data protection obligations on each Subprocessor no less protective than those in this DPA; (b) give Customer at least 30 days’ prior written notice (email sufficient) of any new Subprocessor; and (c) remain liable for its Subprocessors’ performance.

6.3 If Customer reasonably objects to a new Subprocessor on data protection grounds within the notice period, the parties will work in good faith to resolve the objection; if unresolved, Customer may terminate the affected Services and receive a pro rata refund of prepaid fees.

7. Assistance and Data Subject Requests

7.1 Taking into account the nature of the Processing, KillDebt shall provide reasonable assistance to Customer in responding to requests from individuals exercising rights under Data Protection Laws (access, deletion, correction, portability), to the extent Customer cannot fulfill such requests through the Services’ administrative tools.

7.2 If KillDebt receives such a request directly, it will direct the individual to Customer and will not respond substantively except as required by law.

8. Security Incidents

8.1 KillDebt shall notify Customer’s designated contact without undue delay, and in any event within 72 hours, after confirming a Security Incident affecting Customer Personal Data.

8.2 The notice shall describe, to the extent known, the nature of the incident, the data and users affected, the measures taken or proposed, and a contact point. KillDebt shall take reasonable steps to contain and remediate the incident and shall keep Customer reasonably informed. KillDebt’s notification of a Security Incident is not an acknowledgment of fault or liability.

9. Retention and Deletion

9.1 Upon termination or expiration of the Agreement, KillDebt shall, at Customer’s election made within 30 days, delete or return Customer Personal Data, and thereafter delete remaining copies within 30 days, except to the extent retention is required by law or the data resides in routine encrypted backups, which are deleted on the backup expiration cycle not to exceed 90 days.

10. Audits and Information

10.1 KillDebt shall make available information reasonably necessary to demonstrate compliance with this DPA, including completed security questionnaires and summaries of third-party certifications held by its infrastructure providers.

10.2 No more than once per 12-month period, and on at least 30 days’ notice, Customer may conduct a reasonable audit limited to KillDebt’s compliance with this DPA, first satisfied through written responses and documentation; any on-site or technical audit shall be scoped by mutual agreement, at Customer’s expense, and subject to KillDebt’s security and confidentiality requirements.

11. International Transfers

11.1 Customer Personal Data is stored and processed in the United States. KillDebt shall not transfer Customer Personal Data outside the United States without ensuring a lawful transfer mechanism under applicable Data Protection Laws.

12. General

12.1 Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.

12.2 In the event of a conflict between this DPA and the Agreement concerning the Processing of Personal Data, this DPA controls.

12.3 This DPA is governed by the law governing the Agreement, or if none is specified, the laws of the State of Florida.

Questions about this document

Write to support@killdebt.com. KillDebt is a product of CollectionStopperMembership, LLC, Jacksonville, Florida.

All legal documents