Data Processing Agreement

Last updated: August 12, 2026

Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ClientConnect ("we", "us", "our", or the "Data Processor") and our customers ("you", "your", or the "Data Controller") for the provision of ClientConnect services (the "Services").

This DPA sets out the provisions for the processing and security of Personal Data in accordance with applicable data protection law, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data privacy laws.

Definitions

"Personal Data" means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

"Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

"Data Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.

Processing of Personal Data

ClientConnect shall process Personal Data only in accordance with your documented instructions, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law; in such a case, ClientConnect shall inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

Types of Data Processed

In order to provide the Services, ClientConnect processes the following types of Personal Data:

  • Contact information (e.g., name, email address, phone number)
  • Account information (e.g., username, password)
  • Calendar data and appointment details
  • Call records and SMS message content
  • Client information provided by you
  • Usage data and analytics
  • Payment information (processed securely through our payment processors)

Purposes of Processing

ClientConnect processes Personal Data for the following purposes:

  • Providing and maintaining the Services
  • Managing user accounts and authentication
  • Processing and facilitating appointments and calls
  • Sending SMS notifications and reminders
  • Customer support and communication
  • Billing and payment processing
  • Improving and optimizing the Services
  • Compliance with legal obligations

Security Measures

ClientConnect implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest, with the credentials for your connected third-party accounts encrypted again by us before they are stored
  • Periodic security review of the application and its code
  • Access controls and authentication requirements
  • Reliance on established infrastructure providers (Google Cloud and MongoDB Atlas) for the resilience and physical security of the platform we run on
  • Review of the third parties we send data to, each of which is listed on our Subprocessors page

Subprocessors

ClientConnect uses third-party subprocessors to provide the Services. The current list is published at clientconnect.tech/subprocessors, and states for each one what it is used for, what data it receives, and whether it applies to every account or only to an integration you connect yourself. We update that page whenever we add or replace a subprocessor, and we do so before the new subprocessor begins processing Personal Data for you.

By using our Services, you provide general authorization for the engagement of subprocessors. If you object to a new subprocessor, please contact us promptly, and we will work with you to find a reasonable resolution.

Data Subject Rights

ClientConnect will assist you in responding to requests from data subjects exercising their rights under applicable data protection laws. The export described under "Return or Deletion of Data" below is the first place to look: it gives you, without asking us, everything we hold on your behalf about the individual concerned. If we receive a request directly from a data subject, we will promptly notify you.

Data Breach Notification

In the event of a personal data breach, ClientConnect will notify you without undue delay and provide information to help you fulfill any data breach reporting obligations.

Data Transfer Mechanisms

ClientConnect operates from the United States: our servers, database and file storage are located there, as are most of the subprocessors listed on our Subprocessors page. If you are located in the European Economic Area or the United Kingdom, using the Services therefore involves transferring Personal Data to the United States. Each subprocessor is engaged under its own published data processing terms. If you require Standard Contractual Clauses between you and us, contact us and we will enter into them.

Return or Deletion of Data

Both the return and the deletion of your data are in your own hands, and neither requires a request to us.

Return. You can download everything we hold for your account, as a single JSON file, from your account settings — at any time, as often as you like, for as long as the account exists. You do not have to be ending your subscription to use it. The file contains your profile, booking links and service offerings, appointments and calendars, availability and time off, contacts, maintenance records, SMS threads and message content, charges, invoices and referral records, and the settings of your connected integrations. It deliberately leaves out secrets — password hashes, and the access tokens for your connected Google, Outlook, Zoom, Apple and QuickBooks accounts — because an exported file gets copied to laptops and cloud drives and must never work as a key to your accounts; the file itself lists what was withheld and why. Uploaded documents are listed by name, type, size and date, and the files themselves remain downloadable from the app.

Deletion. You can permanently delete your account and its records yourself, from the app. Deletion is immediate and irreversible: there is no archive the data can be restored from. Because the export above is available only while the account exists, download it first if you want a copy. What survives a deletion is limited to records that are ours or someone else's rather than yours: anonymized financial records of completed transactions (amounts, dates, invoice numbers and payment-processor references, with names, email addresses and the link to a login removed), which we keep for as long as tax and accounting law requires; the do-not-text suppression record for any number that replied STOP, which we never remove because removing it would resume messages to someone who asked us to stop; and documents that are also held by a client account that still exists, which are destroyed when that account is deleted too. Our Privacy Policy and account deletion page set this out in full.

Ending a paid subscription is not the same as deleting your account: it disconnects your calendar and meeting integrations and restricts paid features, but your records stay in the account until you delete it. Where applicable law requires us to store particular Personal Data, we retain only what that law requires.

Audits and Compliance

ClientConnect will make available to you the information necessary to demonstrate compliance with the obligations set out in this DPA, and will answer reasonable written questions about how we process your data and how it is secured.

Where applicable data protection law requires you to audit us, we will contribute to one audit in any twelve-month period, on at least 30 days' written notice, conducted remotely and during business hours, at your cost and subject to confidentiality; if an audit follows a personal data breach affecting your data, it is on reasonable notice and at our cost. We are a small company and we hold no third-party security certification such as SOC 2 or ISO 27001. We would rather tell you that plainly than point you to a report that does not exist.

Contact Information

If you have any questions about our data processing activities or this DPA, please contact us at:

Email: support@clientconnect.tech
Address: 1404 Beechwood Ave Nashville, TN 37212

For more information about how we handle your data, please also review our Privacy Policy.