Data Processing Agreement (DPA)


Last Updated: June 30, 2026

This Data Processing Agreement ("DPA") supplements the Terms of Service and Privacy Policy of Smart To Action LLC. This agreement applies when you ("Customer" or "Data Controller") upload or input the private personal data of your own customers ("Data Subjects") into our Software as a Service (SaaS) platform.

By using our Service, you agree to this DPA on behalf of yourself and your business. Smart To Action LLC acts strictly as a "Data Processor" regarding your customers' private data.

1.  Definitions

●   Data Controller: The user or business entity using our SaaS who determines the purposes and means of processing personal data.


●    Data Processor: Smart To Action LLC, which processes personal data strictly on behalf of and under the instruction of the Data Controller.

●   Customer Personal Data: Any personal data belonging to the Data Controller's customers that is uploaded, stored, or processed within our software.


2.  Scope and Processing Instructions

●     Scope: This DPA applies solely to the handling of Customer Personal Data during your fixed-term use of our software.

●   Instructions:  Smart To Action LLC will only process this data to provide, maintain, and secure the Service. We will never process this data for our own marketing or independent commercial gains.

●    Compliance: Both parties agree to comply with applicable data protection laws in the execution of their duties under this DPA.


3.  Technical and Organizational Security

●   Confidentiality: We ensure that all personnel authorized to access or process Customer Personal Data are bound by strict confidentiality obligations.

●   Security Measures: We implement industry-standard technical, physical, and administrative safeguards to protect your customers' data from unauthorized access, loss, or alteration.

●  Breach Notification: In the event of a confirmed security incident affecting your Customer Personal Data, we will notify you via email without undue delay.


4.  Sub-Processors

●   Authorized Sub-Processors: You grant us general authorization to engage third-party infrastructure providers (such as cloud hosting and database providers) to help deliver our SaaS.

●    Oversight: We ensure that all sub-processors are bound by data protection obligations at least as restrictive as those outlined in this DPA.


5.  Data Subject Rights

●     Assistance: If one of your customers contacts us directly to exercise their data rights (such as data deletion or access requests), we will redirect them to you.

●   Controller Responsibility: As the Data Controller, you remain responsible for responding to your customers' data rights requests. Our platform provides the necessary tools to modify or delete this data.

  
6.  Strict Retention and Database Purging

●  14-Day Grace Period: Upon the expiration of your fixed-term software purchase, Customer Personal Data is temporarily retained for a grace period of exactly fourteen (14) days.

●   Irreversible Deletion: If you do not manually renew your access within this window, all Customer Personal Data will be permanently and irreversibly purged from our database systems.

●      Liability: Smart To Action LLC holds zero liability for data loss or business disruptions caused by the automated execution of this 14-day database purge policy.

 
7.  Governing Law

● Jurisdiction: This DPA is governed by the laws of the State of Wyoming, with arbitration to take place in the State of Michigan, aligning entirely with our core Terms of Service.


8.  Contact Information

For privacy questions or data deletion inquiries prior to the standard purge period, contact us at:

●    Company Name: Smart To Action LLC

●    Email Support: Support@SmartToAction.com

●    Mailing Address: 30 N Gould St Ste N Sheridan, WY 82801





© 2026 Smart To Action LLC