Data Processing Addendum

Last updated: July 20, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Work Stream Apps LLC (d/b/a SeenOnMain) ("Processor," "we," "us") and the business customer that uses our Service ("Controller," "you") and applies where we process personal data on your behalf. It supplements our Terms of Service and Privacy Policy. Where you are subject to the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), or similar laws, this DPA governs that processing.

1. Roles of the Parties

For the leads, contacts, and customer information you collect and manage through the Service ("Customer Personal Data"), you are the controller (and, under CCPA/CPRA, the "business") and we are the processor (and, under CCPA/CPRA, a "service provider"). We process Customer Personal Data only on your documented instructions and only to provide the Service. We do not sell or share Customer Personal Data, and we do not use it for our own purposes or for cross-context behavioral advertising.

2. Scope, Nature & Duration

  • Subject matter: our provision of lead-capture, CRM, and automated email/SMS follow-up on your behalf.
  • Duration: the term of your use of the Service, plus any limited retention described in Section 6.
  • Categories of data subjects: your leads, prospects, and customers.
  • Categories of personal data: names, phone numbers, email addresses, message content, and the business/contact details submitted through your forms.

3. Our Obligations

  • Process Customer Personal Data only on your documented instructions, including as configured through the Service, unless required by law.
  • Ensure personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Section 4).
  • Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
  • Delete or return Customer Personal Data at the end of the Service, as described in Section 6.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

4. Security

We maintain administrative, technical, and physical safeguards designed to protect Customer Personal Data, including encryption in transit, encryption of sensitive stored credentials at rest, access controls, isolated per-customer infrastructure, and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

5. Subprocessors

You authorize us to engage the subprocessors below to help provide the Service. We impose data-protection obligations on each subprocessor consistent with this DPA and remain responsible for their performance. We will give notice of any intended addition or replacement of a subprocessor and give you the opportunity to object on reasonable data-protection grounds.

SubprocessorPurposeLocation
Twilio Inc.SMS/messaging delivery and A2P 10DLC registration (per-customer subaccounts)USA
DigitalOcean, LLCCloud infrastructure hosting the customer's automation stack and lead databaseUSA
Stripe, Inc.Payment processing for platform subscriptions and purchasesUSA
Anthropic, PBCAI model used to draft message content from customer-provided informationUSA
Neon, Inc.Managed Postgres database for the control plane (accounts, configuration)USA
Resend (Plus Five Five, Inc.)Transactional and notification email deliveryUSA

6. Return & Deletion

You can export your Customer Personal Data at any time from your dashboard. On termination, and following any grace period described in our Terms of Service, we will delete or return Customer Personal Data in our control, except where retention is required by law. Because your automation stack and lead database run on infrastructure dedicated to you, offboarding also decommissions that infrastructure.

7. Data Subject Requests

If an individual asks to access, correct, delete, or restrict their Customer Personal Data, you are responsible for responding as the controller. Given the nature of the Service, we will provide reasonable assistance to help you respond, including tools to locate, export, or delete the data.

8. Breach Notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your Customer Personal Data, and will provide information reasonably available to help you meet your own notification obligations.

9. International Transfers

Our subprocessors are located in the United States. Where you transfer personal data subject to the EU/UK GDPR to us, the parties will rely on an appropriate transfer mechanism (such as the Standard Contractual Clauses) as required, which are incorporated by reference where applicable.

10. Contact

To request a signed copy of this DPA or with any data-protection questions, contact [email protected].