← Back to Lead Validator Pro

Data Processing Agreement

Version 1.0 — Effective Date: March 4, 2026   Enterprise Template

This Data Processing Agreement ("DPA") is entered into between the Customer organization identified in the applicable Service Agreement ("Controller" or "Customer") and Lead Validator Pro LLC ("Processor" or "Company"), collectively referred to as the "Parties."

This DPA supplements and forms part of the Terms of Service and governs the Processor's processing of personal data on behalf of the Controller in connection with the Lead Validator Pro platform.

1. Definitions

2. Scope and Purpose of Processing

2.1 Subject Matter

The Processor processes Personal Data on behalf of the Controller for the purpose of providing insurance lead validation, quality scoring, fraud detection, and related analytical services.

2.2 Categories of Data Subjects

2.3 Types of Personal Data Processed

CategoryData Elements
Identity DataName, date of birth, gender
Contact DataPhone number, email address, mailing address
Vehicle DataVIN, make, model, year, registration state
Driver's License DataDL number, state, status, expiration
Insurance DataCurrent carrier, policy expiration, coverage type, claims history
Property DataOwnership status, property type, valuation, characteristics
Financial IndicatorsEstimated income range, credit tier (when provided)

2.4 Processing Purposes

3. Processor Obligations

  1. Process Personal Data only on documented instructions from the Controller, unless required by law
  2. Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
  3. Implement appropriate technical and organizational security measures (see Section 5)
  4. Assist the Controller in responding to data subject rights requests
  5. Assist the Controller in ensuring compliance with data breach notification obligations
  6. Delete or return all Personal Data upon termination, at the Controller's choice (see Section 7)
  7. Make available all information necessary to demonstrate compliance and allow for audits
  8. Immediately inform the Controller if an instruction infringes applicable data protection law

4. Sub-processors

4.1 Authorized Sub-processors

The Controller provides general written authorization for the Processor to engage the following Sub-processors:

Sub-processorPurposeData ProcessedLocation
Google LLCCloud infrastructure, Maps API, geocoding, Street ViewAddress data, property imagery requestsUSA
Trestle IQ Inc.Phone carrier intelligence (RealContact API)Phone numbers for carrier/line-type lookupUSA
Anthropic PBCAI analysis engine (Claude API)Lead data fields for legitimacy analysis; no persistent storage by Anthropic under API termsUSA
Enformion Inc. (EndatoGO)Identity verification, contact enrichmentName, address for identity matching and enrichmentUSA
IPQualityScore LLC (IPQS)Email and phone fraud scoringEmail address, phone number for fraud analysisUSA
ATTOM Data Solutions LLCProperty data validationAddress for property records lookupUSA

4.2 Sub-processor Changes

The Processor shall notify the Controller at least 30 days before engaging a new Sub-processor or replacing an existing one. The Controller may object to the change within 14 days. If the Processor cannot reasonably accommodate the objection, either party may terminate the affected services.

4.3 Sub-processor Obligations

Each Sub-processor is bound by a written agreement imposing data protection obligations no less protective than those in this DPA. The Processor remains fully liable for the acts and omissions of its Sub-processors.

5. Security Measures

The Processor implements and maintains the following technical and organizational security measures:

5.1 Technical Measures

5.2 Organizational Measures

6. Data Breach Notification

72-Hour Notification Commitment

The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Data Breach affecting the Controller's Personal Data.

6.1 Breach Notification Contents

The notification shall include, to the extent available:

  1. Description of the nature of the breach, including categories and approximate number of data subjects and records affected
  2. Name and contact details of the Processor's privacy/security contact
  3. Description of the likely consequences of the breach
  4. Description of measures taken or proposed to address the breach, including mitigation of potential adverse effects
  5. Timeline of events from detection through containment

6.2 Cooperation

The Processor shall cooperate with the Controller and provide all reasonably requested information to enable the Controller to fulfill its own breach notification obligations under applicable law (including the CCPA 30-day notification requirement for California residents).

7. Data Return and Deletion

7.1 Upon Termination

Upon termination or expiration of the Service Agreement:

  1. The Controller may request a complete export of all Personal Data in JSON or CSV format within 30 days
  2. After the 30-day export window (or upon written instruction), the Processor shall permanently delete all Personal Data from active systems within 14 days
  3. Personal Data in backup systems shall be deleted within 30 days of primary deletion
  4. The Processor shall provide written confirmation of deletion upon request

7.2 Retention Exceptions

The Processor may retain Personal Data beyond the termination date only to the extent required by applicable law (e.g., audit logs required for regulatory compliance). Such data shall be segregated and protected, and deleted when the legal requirement expires.

8. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA:

9. Liability

Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service, except that neither party's liability for breaches of this DPA relating to data protection obligations shall be limited to the extent prohibited by applicable law.

10. Term and Termination

This DPA takes effect on the date the Controller begins using the Service and remains in effect as long as the Processor processes Personal Data on behalf of the Controller. The Processor's obligations under Sections 5, 6, and 7 survive termination.

Signatures

By signing below, the Parties agree to be bound by the terms of this Data Processing Agreement.

Controller (Customer)

Authorized Signature

Printed Name and Title

Date

Processor (Lead Validator Pro LLC)

Authorized Signature

Printed Name and Title

Date