This DPA supplements and forms part of the DealerSense Terms of Service, or such other written agreement governing Customer's use of the Services (the "Agreement"). In the event of a conflict between this DPA and the Agreement with respect to the subject matter of this DPA, this DPA controls.

1. Definitions

1.1 Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1.2 For purposes of this DPA:

  • "Applicable Privacy Laws" means all United States federal and state laws and regulations relating to privacy, data protection, or data security that apply to the Processing of Customer Personal Data under this DPA, including the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq., and its implementing regulations at 16 C.F.R. Parts 313 and 314; the Colorado Privacy Act, C.R.S. § 6-1-1301 et seq.; the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended, and its implementing regulations; the Texas Data Privacy and Security Act, Tex. Bus. & Com. Code ch. 541; the Virginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq.; and any other comparable state statute, in each case as amended from time to time.
  • "Consumer Request" means a request from an individual to exercise a right afforded to that individual under Applicable Privacy Laws, including rights of access, correction, deletion, portability, opt-out, and appeal.
  • "Controller" means the entity that determines the purposes and means of Processing Customer Personal Data. For purposes of this DPA, Customer is the Controller. Where Applicable Privacy Laws use the term "business," that term is included within the meaning of Controller.
  • "Customer Personal Data" means Personal Data that DealerSense Processes on Customer's behalf in connection with the Services, including data synchronized from Customer's dealer management system.
  • "Dealer Data Laws" means state statutes governing third-party access to, and use of, dealer data, including A.R.S. §§ 28-4651 to 28-4654 (Arizona); MCA §§ 30-11-717 to 30-11-720 (Montana); Utah Code Ann. §§ 13-73-101 et seq.; ORS §§ 650.120 and 650.123 (Oregon); and N.C. Gen. Stat. § 20-305.7 (North Carolina).
  • "DMS" means a dealer management system or comparable system of record from which Customer authorizes DealerSense to receive data.
  • "Nonpublic Personal Information" or "NPI" has the meaning given in 16 C.F.R. § 313.3(n), and includes "customer information" as defined in 16 C.F.R. § 314.2(d).
  • "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual, and that is subject to Applicable Privacy Laws. Personal Data includes NPI.
  • "Processing" (and "Process," "Processes," and "Processed") means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, or destruction.
  • "Processor" means the entity that Processes Personal Data on behalf of a Controller. For purposes of this DPA, DealerSense is the Processor. Where Applicable Privacy Laws use the term "service provider," that term is included within the meaning of Processor.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data Processed by DealerSense or a Subprocessor. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and similar events.
  • "Services" means the DealerSense platform and related services provided under the Agreement.
  • "Subprocessor" means a third party engaged by DealerSense to Process Customer Personal Data in connection with the Services.

2. Roles, scope, and duration

2.1 Roles of the parties. With respect to Customer Personal Data, Customer is the Controller and DealerSense is the Processor. Each party is responsible for its own compliance with Applicable Privacy Laws in respect of the obligations that apply to it in that role.

2.2 Scope. This DPA applies to DealerSense's Processing of Customer Personal Data in connection with the Services.

2.3 Duration. DealerSense will Process Customer Personal Data for the term of the Agreement and for such additional period as is expressly permitted under Section 10 (Return and deletion) of this DPA.

2.4 Nature and purpose. The nature and purpose of the Processing, the categories of Personal Data, and the categories of individuals to whom the Personal Data relates are described in Annex A.

2.5 Customer responsibilities. Customer represents and warrants that (a) it has provided all notices and obtained all consents, permissions, and rights required under Applicable Privacy Laws for DealerSense to Process Customer Personal Data as contemplated by the Agreement and this DPA; (b) its instructions to DealerSense comply with Applicable Privacy Laws; and (c) it has the right to authorize DealerSense's access to Customer's DMS and to any other source system from which Customer Personal Data is obtained.

3. Processing instructions and use limitations

3.1 Documented instructions. DealerSense will Process Customer Personal Data only (a) in accordance with Customer's documented lawful instructions, (b) as described in the Agreement, this DPA, and Annex A, and (c) as otherwise required by applicable law. The Agreement, this DPA, and Customer's configuration of and use of the Services constitute Customer's complete and final documented instructions as of the effective date.

3.2 Notification of unlawful instructions. If DealerSense determines that an instruction from Customer violates Applicable Privacy Laws, DealerSense will promptly notify Customer. DealerSense is not obligated to carry out an instruction it reasonably determines to be unlawful.

3.3 Prohibited uses. DealerSense will not:

  • sell or share Customer Personal Data, as those terms are defined under Applicable Privacy Laws;
  • retain, use, or disclose Customer Personal Data for any purpose other than performing the Services specified in the Agreement, including retaining, using, or disclosing Customer Personal Data for a commercial purpose other than performing those Services;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship between DealerSense and Customer;
  • combine Customer Personal Data with Personal Data received from or on behalf of any other person, or collected from DealerSense's own interactions with an individual, except as expressly permitted under Applicable Privacy Laws to perform a business purpose on Customer's behalf; or
  • use Customer Personal Data to develop, train, fine-tune, or improve any machine learning or artificial intelligence model, except (i) as necessary to provide the Services to Customer and to no other customer, or (ii) pursuant to Customer's separate written authorization and only to the extent permitted by 16 C.F.R. § 313.11 and other Applicable Privacy Laws.

3.4 Same level of protection. DealerSense will provide at least the same level of privacy protection with respect to Customer Personal Data as is required of Customer under Applicable Privacy Laws.

3.5 Notice of inability to comply. DealerSense will notify Customer promptly after making a determination that it can no longer meet its obligations under this DPA or Applicable Privacy Laws. Upon receiving such notice, Customer may take reasonable and appropriate steps to stop and remediate the unauthorized Processing, and may direct DealerSense to cease the Processing at issue.

3.6 Deidentified data. DealerSense may create and use deidentified or aggregated data derived from Customer Personal Data solely to the extent permitted by Section 3.3, Section 4.3, and Applicable Privacy Laws. Where DealerSense creates deidentified data, DealerSense will (a) take reasonable measures to ensure the data cannot be associated with an individual or household, (b) publicly commit to maintain and use the data in deidentified form and not attempt to reidentify it, and (c) contractually obligate any recipient to the same restrictions.

4. Gramm-Leach-Bliley Act obligations

4.1 Service provider status. Customer is a "financial institution" within the meaning of 16 C.F.R. § 313.3(k) and § 314.2(h). DealerSense is a "service provider" within the meaning of 16 C.F.R. § 314.2(r), receiving, maintaining, Processing, or otherwise being permitted access to customer information through its provision of services directly to Customer.

4.2 Safeguards commitment. In satisfaction of Customer's obligation under 16 C.F.R. § 314.4(f)(2) to require its service providers by contract to implement and maintain appropriate safeguards, DealerSense will implement and maintain administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of NPI, as further described in Section 6 and Annex B. Without limiting the foregoing, DealerSense will encrypt NPI in transit over external networks and at rest, and will require multi-factor authentication for any access by DealerSense personnel to Customer's network or to information systems containing NPI.

4.3 Reuse and redisclosure limits. DealerSense acknowledges that Customer Personal Data received under an exception in 16 C.F.R. § 313.14 or § 313.15 is subject to the reuse and redisclosure limitations of 16 C.F.R. § 313.11(a). DealerSense will disclose and use such data only in the ordinary course of business to carry out the activity covered by the exception under which it was received, and will not use such data for marketing purposes. DealerSense will contractually bind each Subprocessor to equivalent restrictions.

4.4 Assistance with FTC notification. DealerSense acknowledges that Customer must notify the Federal Trade Commission of a "notification event" involving the information of at least 500 consumers no later than thirty (30) days after discovery, under 16 C.F.R. § 314.4(j). DealerSense will provide Customer with the information reasonably necessary for Customer to make that notification within the time required by Section 7 of this DPA, including the categories of information involved, the date or date range of the event, the number of consumers affected or potentially affected, and a general description of the event.

4.5 Periodic assessment. DealerSense will cooperate with Customer's periodic assessment of DealerSense's safeguards under 16 C.F.R. § 314.4(f)(3), by providing the evidence described in Section 6.4 of this DPA.

4.6 Customer obligations preserved. Nothing in this DPA relieves Customer of its own obligations under the Gramm-Leach-Bliley Act, including its obligations to maintain an information security program, provide privacy notices, and obtain any required consents.

5. Confidentiality of personnel

5.1 DealerSense will ensure that each person it authorizes to Process Customer Personal Data is subject to a duty of confidentiality with respect to that data, whether by written contract or statutory obligation, and that the duty survives the termination of that person's engagement.

5.2 DealerSense will limit access to Customer Personal Data to those personnel who require access to perform the Services, and will apply the principle of least privilege in granting such access.

5.3 DealerSense will provide security awareness training to personnel with access to Customer Personal Data, at least annually and upon hire.

6. Security measures

6.1 Information security program. DealerSense maintains a written information security program containing administrative, technical, and physical safeguards appropriate to the size and complexity of DealerSense's business, the nature and scope of its activities, and the sensitivity of the Customer Personal Data at issue. The program is designed to (a) ensure the security and confidentiality of Customer Personal Data, (b) protect against anticipated threats or hazards to the security or integrity of that data, and (c) protect against unauthorized access to or use of that data that could result in substantial harm or inconvenience to any individual.

6.2 Specific measures. The technical and organizational measures DealerSense maintains are described in Annex B. DealerSense may update those measures from time to time provided that the updates do not materially diminish the overall level of protection.

6.3 Testing and monitoring. DealerSense regularly tests and monitors the effectiveness of its safeguards and remediates identified deficiencies on a risk-prioritized basis.

6.4 Evidence of compliance. Upon Customer's reasonable written request, and no more than once per twelve (12) month period except following a Security Incident, DealerSense will provide a completed security questionnaire or other written description of its safeguards sufficient to allow Customer to satisfy its obligations under 16 C.F.R. § 314.4(f)(1) and (f)(3). Where DealerSense maintains a current independent audit report covering the Services, it will provide that report in place of a questionnaire. Requests may be sent to [email protected].

7. Security incident notification

7.0 Statutory floor. DealerSense acknowledges that it is directly subject to Tex. Bus. & Com. Code § 521.053(c), which requires a person maintaining computerized data that includes sensitive personal information not owned by that person to notify the owner or license holder "immediately after discovering the breach," and to C.R.S. § 6-1-716(2)(b), which requires a third-party service provider to give notice to and cooperate with the covered entity "in the most expedient time possible and without unreasonable delay." Nothing in this Section 7 extends any deadline imposed by those statutes, and the shorter of the statutory deadline and the contractual deadline in Section 7.1 controls.

7.1 Notification. DealerSense will notify Customer of a Security Incident affecting Customer Personal Data without undue delay, and in any event no later than seventy-two (72) hours after DealerSense becomes aware of it.

7.2 Content of notification. The notification will include, to the extent known at the time and supplemented as further information becomes available: (a) a description of the nature of the Security Incident; (b) the categories and approximate number of individuals and records affected; (c) the date or date range of the incident and the date of discovery; (d) the likely consequences of the incident; (e) the measures taken or proposed to address the incident and mitigate its effects; and (f) the name and contact details of a DealerSense point of contact.

7.3 Cooperation. DealerSense will cooperate with Customer and take such reasonable steps as Customer directs to assist in the investigation, mitigation, and remediation of the Security Incident, including providing the information Customer requires to meet its notification obligations under 16 C.F.R. § 314.4(j) and applicable state breach notification statutes.

7.4 No admission. DealerSense's notification of or response to a Security Incident under this Section is not an acknowledgment by DealerSense of fault or liability.

7.5 Communications. Neither party will make any public statement or notification to individuals or regulators identifying the other party in connection with a Security Incident without the other party's prior written consent, except where required by law. Customer, as Controller, is responsible for determining whether notification to individuals or regulators is required and for making any such notification.

8. Subprocessors

8.1 General authorization. Customer generally authorizes DealerSense to engage Subprocessors to Process Customer Personal Data, subject to this Section 8.

8.2 Current Subprocessors. The Subprocessors engaged by DealerSense as of the effective date are listed in Annex C. DealerSense maintains an up-to-date list of Subprocessors at dlrsense.com/subprocessors and, upon Customer's request, will provide a listing of all entities with which it shares Customer Personal Data.

8.3 New Subprocessors and right to object. DealerSense will notify Customer at least thirty (30) days before engaging a new Subprocessor, by email to the Customer contact of record and by updating the subprocessor page above. Customer may object to the new Subprocessor on reasonable grounds relating to data protection by providing written notice within fifteen (15) days of DealerSense's notice. If Customer objects, the parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees for the terminated portion of the term.

8.4 Flow-down. DealerSense will engage each Subprocessor under a written contract that requires the Subprocessor to meet obligations with respect to Customer Personal Data that are at least as protective as those imposed on DealerSense under this DPA.

8.5 Liability. DealerSense remains responsible to Customer for the performance of each Subprocessor's obligations to the same extent DealerSense would be liable if performing the Subprocessor's services directly.

9. Consumer requests and controller assistance

9.1 Assistance with Consumer Requests. Taking into account the nature of the Processing, DealerSense will provide reasonable assistance to Customer, through appropriate technical and organizational measures and insofar as commercially reasonable, to enable Customer to respond to Consumer Requests.

9.2 Requests received directly. If DealerSense receives a Consumer Request directly from an individual relating to Customer Personal Data, DealerSense will not respond substantively except to confirm receipt and to direct the individual to Customer, and will notify Customer of the request without undue delay.

9.3 Other assistance. DealerSense will provide reasonable assistance to Customer with respect to (a) Customer's obligation to maintain reasonable security measures, (b) Customer's breach notification obligations, and (c) Customer's data protection assessments or similar obligations under Applicable Privacy Laws, in each case taking into account the nature of the Processing and the information available to DealerSense.

9.4 Cost. Assistance under this Section is provided at no additional charge, except that DealerSense may charge a reasonable fee for assistance that is (a) not attributable to DealerSense's failure to comply with this DPA and (b) materially in excess of the assistance reasonably contemplated by the Agreement, provided DealerSense notifies Customer of the fee in advance and Customer approves it.

10. Return and deletion

10.1 Customer's choice. At Customer's choice, upon termination or expiration of the Agreement DealerSense will delete or return all Customer Personal Data to Customer, unless retention is required by applicable law.

10.2 Export window. Customer may request an export of Customer Personal Data within thirty (30) days after termination or expiration. DealerSense will provide the export in a secure, structured, commonly used, machine-readable format within a commercially reasonable time.

10.3 Deletion. Following the export window and Customer's instruction, DealerSense will delete Customer Personal Data from its production systems within thirty (30) days, and from backups in accordance with its ordinary backup rotation schedule, which does not exceed ninety (90) days.

10.4 Retained data. Where DealerSense retains Customer Personal Data as required by law, it will continue to protect that data in accordance with this DPA and will limit Processing to the purposes requiring retention.

10.5 Certification. Upon Customer's written request, DealerSense will certify in writing that deletion has been completed.

10.6 Secure transition. Where applicable Dealer Data Laws so require, DealerSense will work in good faith to ensure a secure transition of Customer's data to a successor vendor designated by Customer.

11. Relationship to the Agreement

11.1 Order of precedence. In the event of a conflict, the order of precedence is: (a) this DPA, with respect to its subject matter; (b) any executed order form or custom written agreement; and (c) the Agreement.

11.2 Limitation of liability. Each party's liability arising out of or related to this DPA is subject to the limitations of liability set forth in the Agreement. DealerSense's obligations under Section 4 (GLBA), Section 6 (Security measures), and Section 7 (Security incident notification), and either party's breach of its confidentiality obligations, are subject to the enhanced cap for security and confidentiality set forth in the Agreement rather than the general cap. Neither cap applies to a party's gross negligence, willful misconduct, or fraud, or to Customer's obligation to pay fees.

11.3 No third-party beneficiaries. This DPA does not confer any rights on any person other than the parties.

11.4 Survival. Sections 4.3, 5, 7, 10, and 11 survive termination or expiration of the Agreement.

11.5 Governing law. This DPA is governed by the laws of the State of Colorado, without regard to conflict of laws principles, and disputes are subject to the dispute resolution provisions of the Agreement.

11.6 Amendment. DealerSense may amend this DPA on thirty (30) days' written notice where reasonably necessary to comply with Applicable Privacy Laws, provided the amendment does not materially diminish the protections afforded to Customer Personal Data. All other amendments require the written agreement of both parties.

11.7 Severability. If any provision of this DPA is held unenforceable, the remaining provisions remain in full force and effect.

Annex A — Details of processing

A.1 Subject matter of the processing

Provision of the DealerSense platform, including synchronization of data from Customer's dealer management system, financial and accounting reporting, and analysis and reporting features.

A.2 Duration of the processing

The term of the Agreement, plus the retention and deletion periods described in Section 10 of this DPA.

A.3 Nature and purpose of the processing

Collection, receipt, storage, organization, structuring, retrieval, analysis, transmission, display, and deletion of Customer Personal Data for the purpose of providing the Services described in the Agreement.

A.4 Categories of individuals

  • Customer's retail and commercial vehicle purchasers who financed or leased, and co-buyers.
  • Customer's employees and authorized users of the Services.

A.5 Categories of Personal Data

A.6 Sensitive Personal Data

The Services do not Process any of the following, and DealerSense does not request, require, or ingest them through the DMS integration:

  • Social Security numbers or taxpayer identification numbers.
  • Consumer reports, credit scores, or credit application data as defined under the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq.
  • Driver's license, state identification, or passport numbers.
  • Financial account numbers, payment card numbers, or ACH credentials.
  • Biometric, genetic, health, precise geolocation, or demographic data treated as sensitive under Applicable Privacy Laws.
  • Passwords, security questions and answers, or other authentication secrets. Authentication is federated to DealerSense's identity provider and DealerSense stores issued tokens only.

Accordingly, DealerSense Processes no "sensitive personal information" as that term is defined under the California Consumer Privacy Act, and no "sensitive data" as that term is defined under the Colorado Privacy Act, the Texas Data Privacy and Security Act, or the Virginia Consumer Data Protection Act.

A.7 Frequency of transfer

Continuous, on the synchronization schedule configured by Customer.

A.8 Processing locations

Customer Personal Data is stored and Processed in the United States, in DigitalOcean data center regions located in the United States.

Annex B — Technical and organizational measures

Annex C — Subprocessors

The current list, including any additions since the effective date of this DPA, is maintained at dlrsense.com/subprocessors.

C.1 Current subprocessors

C.2 Artificial intelligence services

DealerSense uses Anthropic's Claude for internal software development, engineering troubleshooting, and processing of DealerSense's own accounts payable.

No Customer Personal Data is transmitted to Anthropic or to any other third-party artificial intelligence or model provider. Anthropic is accordingly not a Subprocessor under this DPA. DealerSense maintains the controls described in Annex B.16 to ensure this remains accurate, and will amend this Annex and notify Customer in accordance with Section 8.3 before any change to this arrangement.

Contact

Questions about this DPA, requests for a countersigned copy, or requests for current security documentation may be sent to [email protected].

DealerSense
a dba of Omnify93, LLC
Colorado, United States