Data processing addendum
Last updated: July 1, 2026
1. Introduction and roles
This Data Processing Addendum ("DPA") is entered into between Back At You, Inc. ("Back At You" or "BAY") and the customer that has agreed to the Back At You Terms of Service or a signed master services agreement or order form (the "Agreement") ("Customer"). This DPA is incorporated into and forms part of the Agreement and applies to the extent Back At You processes personal information on Customer's behalf in providing the services described in the Agreement (the "Services").
For personal information that Back At You processes on Customer's behalf, including personal information collected through websites Back At You builds, hosts, or operates for Customer ("Customer Sites") and personal information Customer stores in the Services (together, "Customer Data"): Customer is the "business," "controller," or equivalent responsible party, and Back At You is Customer's "service provider," "processor," or equivalent under applicable privacy laws, including the California Consumer Privacy Act as amended ("CCPA"), other U.S. state privacy laws, Canada's PIPEDA, and Quebec's Law 25 (together, "Privacy Laws"). This DPA does not apply to information Back At You collects and controls as a business for its own purposes, which is described in the Back At You Privacy Policy.
2. Processing instructions and limitations
Back At You will process Customer Data only to provide, maintain, secure, and improve the Services and as otherwise instructed by Customer in writing (including through Customer's configuration of the Services), and not for any other purpose. Without limiting the foregoing, Back At You will not:
- Sell or share Customer Data within the meaning of the CCPA.
- Retain, use, or disclose Customer Data for any purpose other than the business purposes specified in the Agreement and this DPA, including any commercial purpose of Back At You.
- Retain, use, or disclose Customer Data outside the direct business relationship between Back At You and Customer.
- Combine Customer Data with personal information received from another source, except as permitted by the CCPA for service providers (for example to detect security incidents or protect against fraud).
Back At You certifies that it understands and will comply with the restrictions in this section. If Back At You determines it can no longer meet its obligations under Privacy Laws, it will notify Customer, and Customer may take reasonable steps to stop or remediate any unauthorized use of Customer Data.
3. Confidentiality
Back At You ensures that personnel authorized to process Customer Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and access Customer Data only as needed to provide the Services.
4. Subprocessors
Customer generally authorizes Back At You to engage subprocessors to support the Services. Back At You maintains its current list of subprocessors at backatyou.com/subprocessors. Back At You will:
- Bind each subprocessor to written data-protection obligations consistent with this DPA.
- Update the subprocessor list before adding a new subprocessor that processes Customer Data. Customers may subscribe to updates by contacting privacy@backatyou.com.
- Consider in good faith any reasonable objection Customer raises to a new subprocessor within 15 days of the update; if the objection cannot be resolved, Customer may terminate the affected Services as its remedy.
- Remain responsible for its subprocessors' performance under this DPA.
5. Security
Back At You maintains reasonable administrative, technical, and physical safeguards designed to protect Customer Data, including encryption of sensitive data in transit and at rest where appropriate, role-based access controls and least-privilege access, network protections including firewall and edge security, logging and monitoring, and periodic review of security practices. Back At You will not materially decrease the overall security of the Services during a subscription term.
6. Consumer and data subject requests
Taking into account the nature of the processing, Back At You will provide reasonable assistance to Customer in responding to verifiable consumer or data subject requests (access, deletion, correction, portability, and opt-out) under Privacy Laws, including through the functionality of the Services. If Back At You receives such a request directed at Customer Data, it will forward the request to Customer without undue delay and will not respond except to direct the requester to Customer, unless required by law.
7. Security incidents
Back At You will notify Customer without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, and will provide information reasonably available to Back At You to help Customer meet its own notification obligations, along with reasonable cooperation on remediation.
8. Deletion and return
Upon termination or expiration of the Agreement, Back At You will, at Customer's choice, delete or return Customer Data, and will delete remaining copies within a reasonable period, except where retention is required by law, for backup cycles that expire in the ordinary course, or for records needed to establish or defend legal claims.
9. Cross-border processing
Customer Data is processed primarily in the United States. Where Customer Data of Canadian residents is processed, Back At You provides protection comparable to that required under PIPEDA and Quebec Law 25 through this DPA and its security measures, and remains responsible for Customer Data transferred to its subprocessors.
10. Audit and verification
Upon Customer's reasonable written request, no more than once per 12-month period, Back At You will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of security reviews or third-party attestations where available. Audits are limited to information reasonably related to the Services, subject to confidentiality, and may not unreasonably disrupt Back At You's operations.
11. Order of precedence and contact
This DPA forms part of the Agreement. If this DPA conflicts with the Agreement on the subject of processing Customer Data, this DPA controls. Nothing in this DPA increases either party's liability beyond the limitations stated in the Agreement. Questions about this DPA: privacy@backatyou.com, or Back At You, Inc., Attn: Privacy Officer, 16501 Ventura Blvd, Suite 400, Encino, CA 91436.