BHPH Success Legal Center

Data Processing Addendum

This Data Processing Addendum establishes the data protection requirements that apply when BHPH Success processes Personal Data on behalf of a participating vendor or other business customer.

Last Updated: August 8, 2026

This Data Processing Addendum, or "DPA," is entered into between [INSERT LEGAL OPERATING ENTITY], operating as BHPH Success, referred to as "BHPH Success," "we," "us," or "our," and the vendor, service provider, technology company, advertiser, or other business customer receiving applicable BHPH Success services, referred to as "Vendor."

This DPA supplements and is incorporated into the BHPH Success General Vendor Terms, an insertion order, service order, subscription agreement, or other agreement governing services provided by BHPH Success to Vendor, collectively referred to as the "Agreement."

This DPA applies only to the extent BHPH Success Processes Personal Data on behalf of Vendor and Vendor determines the purposes and means of the Processing.

This DPA governs processor or service-provider Processing performed by BHPH Success on behalf of Vendor. Personal Data transferred by BHPH Success to Vendor for Vendor's own independent purposes is governed separately by the BHPH Success Data Transfer Addendum where applicable.

1. Scope And Incorporation

This DPA applies whenever BHPH Success Processes Personal Data on behalf of Vendor in connection with the Services and Applicable Privacy Law requires contractual data-processing terms.

The applicable Processing may arise through:

  • Vendor account administration;
  • Vendor-provided user or representative information;
  • Vendor-supplied customer or contact information;
  • Vendor marketing or campaign services;
  • Hosted Vendor Content containing Personal Data;
  • Vendor-requested integrations;
  • Data import, synchronization, or export features;
  • Reporting or analytics performed specifically on Vendor's behalf;
  • Vendor support services;
  • Future Vendor Services involving Vendor-controlled Personal Data; or
  • Other Processing expressly identified in an applicable service order or written agreement.

If BHPH Success determines the purposes and means of Processing independently rather than Processing Personal Data on behalf of Vendor, that Processing is not governed by this DPA solely because Vendor uses the Services.

2. Definitions

For purposes of this DPA:

  • Applicable Privacy Law means applicable privacy, data protection, security, breach notification, consumer privacy, or similar law governing Personal Data Processed under this DPA.
  • Controller means the person or entity that determines the purposes and means of Processing Personal Data, including equivalent terms such as "Business" where applicable.
  • Data Subject means an identified or identifiable individual to whom Personal Data relates.
  • Personal Data means information relating to an identified or identifiable individual and includes "personal information," "personal data," or similar information protected under Applicable Privacy Law.
  • Personal Data Breach means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed under this DPA.
  • Process or Processing means any operation performed on Personal Data, including collection, recording, organization, storage, access, use, transmission, disclosure, modification, retrieval, deletion, or destruction.
  • Processor means an entity Processing Personal Data on behalf of a Controller, including equivalent terms such as "Service Provider," "Contractor," or "Processor" under Applicable Privacy Law.
  • Subprocessor means a third party engaged by BHPH Success to Process Personal Data on behalf of Vendor in connection with the Services.
  • Vendor Personal Data means Personal Data Processed by BHPH Success on behalf of Vendor under this DPA.

Capitalized terms not defined in this DPA have the meanings provided in the Agreement.

3. Roles Of The Parties

For Processing covered by this DPA:

  • Vendor acts as the Controller or Business of Vendor Personal Data; and
  • BHPH Success acts as the Processor, Service Provider, or Contractor Processing Vendor Personal Data on Vendor's behalf.

Each party will comply with the obligations applicable to its role under Applicable Privacy Law.

Vendor retains control over the purposes for which Vendor Personal Data is Processed. BHPH Success will Process Vendor Personal Data only as permitted by this DPA, the Agreement, Vendor's documented instructions, or Applicable Law.

4. Details Of Processing

The following table describes the general Processing contemplated by this DPA. A service order, insertion order, or other written agreement may supplement these details for a particular Service.

Processing Element Description
Subject Matter Provision, operation, maintenance, support, security, administration, and improvement of Services purchased or requested by Vendor where BHPH Success Processes Vendor Personal Data on Vendor's behalf.
Duration For the term of the applicable Service and for any additional period during which BHPH Success lawfully retains Vendor Personal Data in accordance with this DPA or the Agreement.
Nature Of Processing Collection, receipt, organization, hosting, storage, retrieval, access, transmission, analysis, support, deletion, and other Processing necessary to provide the applicable Service.
Purpose Providing the Services requested by Vendor and carrying out Vendor's documented instructions.
Data Subjects Vendor personnel, representatives, users, customers, prospects, business contacts, dealership personnel, or other individuals whose Personal Data Vendor lawfully submits to the Services.
Personal Data May include names, business contact information, account information, professional information, communications, identifiers, technical information, and other Personal Data submitted by or on behalf of Vendor.
Sensitive Data Not intended unless expressly authorized for a specific Service. Vendor should not submit sensitive or regulated Personal Data unless the applicable Service expressly supports such Processing and the parties have agreed to any additional requirements.

5. Vendor Instructions And Processing Limitations

Vendor instructs BHPH Success to Process Vendor Personal Data:

  • To provide the Services;
  • To perform BHPH Success's obligations under the Agreement;
  • In accordance with Vendor's use and configuration of the Services;
  • In accordance with documented instructions provided by Vendor;
  • To protect the security and integrity of the Services;
  • As required by Applicable Law; and
  • For other purposes expressly authorized by Vendor in writing.

BHPH Success will not Process Vendor Personal Data for purposes materially inconsistent with Vendor's documented instructions unless required or expressly permitted by Applicable Law.

If BHPH Success believes a Vendor instruction violates Applicable Privacy Law, BHPH Success may notify Vendor and suspend the affected Processing until the parties resolve the issue.

6. Privacy Law Requirements

BHPH Success will Process Vendor Personal Data in accordance with Applicable Privacy Law applicable to BHPH Success in its role as Processor.

To the extent required by Applicable Privacy Law, BHPH Success will:

  • Process Vendor Personal Data only for the purposes specified in the Agreement and this DPA;
  • Follow Vendor's lawful documented instructions;
  • Provide the level of privacy protection required of a Processor or Service Provider;
  • Notify Vendor if BHPH Success determines it can no longer meet applicable Processor obligations;
  • Allow Vendor to take reasonable and appropriate steps to stop and remediate unauthorized Processing;
  • Assist Vendor with applicable privacy obligations as described in this DPA; and
  • Maintain appropriate records concerning Processing where legally required.

7. Confidentiality Of Personal Data

BHPH Success will ensure that persons authorized to Process Vendor Personal Data are subject to appropriate confidentiality obligations.

Access to Vendor Personal Data will be limited to personnel, contractors, and Subprocessors who reasonably require access to perform the applicable Services or other permitted Processing.

Confidentiality obligations will continue after an individual's access to Vendor Personal Data ends where appropriate.

8. Security Measures

BHPH Success will maintain reasonable administrative, technical, and organizational safeguards designed to protect Vendor Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Security measures may include, as appropriate to the Services and risk:

  • Access controls;
  • Authentication controls;
  • Role-based permissions;
  • Encryption in transit where appropriate;
  • Encryption at rest where appropriate;
  • Secure hosting practices;
  • Network and system protections;
  • Malware protection;
  • Logging and monitoring;
  • Backup and recovery procedures;
  • Vulnerability management;
  • Incident response procedures;
  • Personnel security practices;
  • Security awareness measures;
  • Subprocessor security review; and
  • Data retention and disposal controls.

The parties acknowledge that security requirements may evolve as technology, threats, Services, and Applicable Privacy Law change.

No information system can be guaranteed to be completely secure. BHPH Success's obligations under this section are obligations to maintain reasonable safeguards appropriate to the nature and risk of the Processing, not a guarantee that a security incident can never occur.

9. Subprocessors

Vendor generally authorizes BHPH Success to engage Subprocessors as reasonably necessary to provide, operate, secure, support, and maintain the Services.

Subprocessors may provide services such as:

  • Cloud infrastructure;
  • Data hosting;
  • Content delivery;
  • Email delivery;
  • Communications infrastructure;
  • Customer support technology;
  • Security services;
  • Analytics infrastructure;
  • Database services;
  • Development infrastructure; or
  • Other technology necessary to provide the Services.

BHPH Success will require Subprocessors that Process Vendor Personal Data to be subject to data protection obligations appropriate to the Processing and consistent with Applicable Privacy Law.

BHPH Success remains responsible for the performance of its Subprocessors to the extent required by the Agreement and Applicable Privacy Law.

Changes To Subprocessors

Where Applicable Privacy Law requires advance notice or an opportunity to object to a new Subprocessor, BHPH Success will provide a reasonable mechanism for doing so.

Any objection must be based on reasonable data-protection grounds. The parties will work in good faith to address a valid objection. If no commercially reasonable alternative is available, either party may terminate the affected Service as permitted by the Agreement.

10. Data Subject Rights

Taking into account the nature of the Processing, BHPH Success will provide reasonable assistance to Vendor in responding to valid Data Subject requests relating to Vendor Personal Data where Vendor cannot reasonably fulfill the request without BHPH Success's assistance.

Such requests may include rights to:

  • Access Personal Data;
  • Know or confirm Processing;
  • Correct inaccurate Personal Data;
  • Delete Personal Data;
  • Restrict Processing;
  • Object to Processing;
  • Obtain portable data;
  • Opt out of certain Processing; or
  • Exercise other rights established by Applicable Privacy Law.

If BHPH Success receives a request directly from a Data Subject concerning Vendor Personal Data, BHPH Success may direct the individual to Vendor unless Applicable Privacy Law requires BHPH Success to respond directly.

BHPH Success will not independently respond on Vendor's behalf to a request for which Vendor is responsible unless instructed by Vendor or required by law.

11. Compliance Assistance

Taking into account the nature of the Processing and information reasonably available to BHPH Success, BHPH Success will provide reasonable assistance to Vendor with applicable data-protection obligations relating to the Services.

This may include reasonable assistance concerning:

  • Data Subject requests;
  • Security obligations;
  • Personal Data Breach response;
  • Data protection impact assessments;
  • Regulatory consultations where legally required;
  • Processing records;
  • Deletion requests; and
  • Other Processor-assistance requirements imposed by Applicable Privacy Law.

Vendor remains responsible for determining whether a particular legal obligation applies to Vendor and for satisfying Vendor's obligations as Controller.

12. Personal Data Breaches

BHPH Success will notify Vendor without undue delay after becoming aware of a confirmed Personal Data Breach affecting Vendor Personal Data where notification to Vendor is required under Applicable Privacy Law.

To the extent reasonably available, BHPH Success will provide information concerning:

  • The nature of the Personal Data Breach;
  • The categories of Vendor Personal Data involved;
  • The categories or approximate number of affected Data Subjects, if known;
  • The likely consequences of the incident, if reasonably known;
  • Measures taken or proposed to address the incident;
  • Measures taken to mitigate reasonably foreseeable harm; and
  • A contact for additional information.

Where all information is not available at the same time, BHPH Success may provide information in phases as the investigation progresses.

BHPH Success will take reasonable steps to contain, investigate, remediate, and mitigate a Personal Data Breach for which BHPH Success is responsible.

Notification of a Personal Data Breach does not constitute an admission of fault, liability, or violation of law.

13. Return And Deletion Of Vendor Personal Data

Upon termination or expiration of the applicable Services, BHPH Success will, subject to the functionality of the Services and Applicable Law, delete or return Vendor Personal Data as required by the Agreement, Vendor's lawful instructions, or Applicable Privacy Law.

BHPH Success may retain Vendor Personal Data where:

  • Retention is required by law;
  • Retention is necessary for legitimate legal claims or dispute resolution;
  • Information remains temporarily in secure backup systems;
  • The information has been lawfully aggregated or de-identified so that it is no longer Personal Data; or
  • Another lawful retention basis applies under the Agreement or Applicable Privacy Law.

Any Vendor Personal Data retained after termination will remain subject to applicable protections under this DPA for as long as BHPH Success Processes it as Vendor's Processor.

14. Compliance Information And Audits

BHPH Success will make available information reasonably necessary to demonstrate compliance with Processor obligations under this DPA and Applicable Privacy Law.

Where Applicable Privacy Law provides Vendor with an audit right, Vendor will first use available documentation, certifications, questionnaires, security information, or other reasonable compliance materials where those materials are sufficient to satisfy the applicable requirement.

If additional verification is legally required, the parties will cooperate on a reasonable audit process designed to minimize disruption, protect confidential information, and avoid unnecessary access to information belonging to other BHPH Success customers.

Unless required because of a confirmed security incident, material compliance concern, or regulatory requirement, any audit will:

  • Be conducted on reasonable advance notice;
  • Occur during normal business hours;
  • Be limited to relevant data-protection matters;
  • Be subject to reasonable confidentiality requirements;
  • Avoid unreasonable interference with BHPH Success operations; and
  • Be performed no more frequently than reasonably necessary.

15. Government And Legal Requests

If BHPH Success receives a legally binding request from a governmental authority, regulator, law enforcement agency, or court requiring disclosure of Vendor Personal Data, BHPH Success may disclose the information as required by law.

Where legally permitted and reasonably appropriate, BHPH Success will:

  • Review the request for legal validity;
  • Limit disclosure to information legally required;
  • Notify Vendor where permitted;
  • Take reasonable steps to protect confidential information; and
  • Challenge or seek to narrow requests that appear unlawful or materially overbroad where reasonable under the circumstances.

16. International Data Transfers

BHPH Success is primarily designed to serve the United States independent automotive marketplace. However, the parties acknowledge that Vendor Personal Data may be Processed using infrastructure, service providers, or personnel located in different jurisdictions.

If Applicable Privacy Law requires a specific mechanism for an international transfer of Vendor Personal Data, the parties will implement the legally required transfer mechanism as applicable to that transfer.

Such mechanisms may include:

  • European Commission Standard Contractual Clauses;
  • United Kingdom approved international data-transfer provisions;
  • Recognized data-transfer frameworks;
  • Adequacy decisions;
  • Contractual safeguards;
  • Transfer impact assessments; or
  • Another legally recognized transfer mechanism.

References to international transfer mechanisms in this DPA do not represent that any particular framework currently applies to BHPH Success. A particular mechanism applies only where legally required and actually implemented for the relevant Processing.

17. U.S. State Privacy Terms

To the extent Vendor Personal Data is subject to a U.S. state privacy law that regulates Processors, Service Providers, or Contractors, BHPH Success will comply with the obligations applicable to its role.

To the extent required by Applicable Privacy Law, BHPH Success:

  • Will Process Vendor Personal Data only for the business purposes specified in the Agreement and this DPA;
  • Will not sell Vendor Personal Data;
  • Will not share Vendor Personal Data for cross-context behavioral advertising where prohibited for a Service Provider or Processor;
  • Will not retain, use, or disclose Vendor Personal Data outside the direct business relationship with Vendor except as permitted by Applicable Privacy Law;
  • Will not combine Vendor Personal Data with Personal Data received from other businesses or collected from BHPH Success's own interactions with individuals where such combination is prohibited, except as legally permitted;
  • Will provide the same level of privacy protection required of the applicable Processor, Service Provider, or Contractor role;
  • Will notify Vendor if BHPH Success determines it can no longer meet applicable obligations; and
  • Will permit Vendor to take reasonable and appropriate steps to stop and remediate unauthorized use of Vendor Personal Data.

BHPH Success may use Vendor Personal Data for purposes expressly permitted to Processors or Service Providers under Applicable Privacy Law, including security, fraud prevention, debugging, maintaining the Services, and other legally permitted business purposes.

18. Vendor Responsibilities

Vendor represents and warrants that it has all rights, permissions, notices, consents, and lawful bases necessary to provide Vendor Personal Data to BHPH Success and instruct BHPH Success to Process that information as contemplated by the Agreement.

Vendor is responsible for:

  • The lawfulness of Vendor's collection of Vendor Personal Data;
  • The accuracy and quality of data submitted by Vendor;
  • Providing legally required privacy notices;
  • Obtaining legally required consent;
  • Responding to Data Subject requests for which Vendor is responsible;
  • Determining appropriate retention periods;
  • Configuring the Services appropriately;
  • Protecting Vendor account credentials;
  • Limiting Vendor-user access appropriately;
  • Ensuring Vendor instructions comply with law; and
  • Avoiding submission of Personal Data that the Services are not designed or authorized to Process.

Vendor should not submit Social Security numbers, consumer credit reports, bank account credentials, payment-card data, medical information, biometric identifiers, driver's license data, dealership customer financing files, or other highly sensitive or regulated Personal Data unless a specific BHPH Success Service expressly supports that information and the parties have agreed to the applicable safeguards and contractual requirements.

19. Responsibility And Liability

Each party is responsible for complying with the data-protection obligations applicable to its role.

The liability limitations, exclusions, indemnification provisions, remedies, and other risk-allocation provisions contained in the Agreement apply to this DPA except to the extent Applicable Privacy Law expressly requires otherwise.

Nothing in this DPA expands either party's liability beyond the liability established by the Agreement except where such limitation is prohibited by Applicable Law.

20. Term And Survival

This DPA becomes effective when BHPH Success first Processes Vendor Personal Data on Vendor's behalf under an applicable Service and remains effective for as long as BHPH Success Processes Vendor Personal Data as Vendor's Processor.

Termination of the Agreement does not terminate data-protection obligations that by their nature must continue while Vendor Personal Data remains in BHPH Success's possession or control.

Obligations concerning confidentiality, security, Personal Data Breaches, deletion, international transfers, and other provisions intended to survive will remain effective for the applicable retention period.

21. Order Of Precedence

This DPA supplements the Agreement.

If there is a conflict between this DPA and the Agreement concerning BHPH Success's Processing of Vendor Personal Data as a Processor, this DPA will control with respect to that specific data-protection issue.

If an applicable international transfer mechanism or mandatory privacy-law provision conflicts with this DPA, the mandatory provision will control only to the extent of the conflict.

The BHPH Success Data Transfer Addendum governs applicable independent controller-to-controller transfers and does not replace this DPA where BHPH Success acts as Vendor's Processor.

22. Changes To This Addendum

BHPH Success may update this DPA to reflect changes in the Services, Processing activities, security practices, Applicable Privacy Law, regulatory requirements, or business operations.

The "Last Updated" date at the top of this page identifies the most recent revision.

Where Applicable Privacy Law or the Agreement requires additional notice or consent for a material change, BHPH Success will comply with the applicable requirement.

23. Contact Us

Questions regarding this Data Processing Addendum or BHPH Success's Processing of Vendor Personal Data may be directed to:

BHPH Success

Legal Entity: [INSERT LEGAL OPERATING ENTITY]

Privacy Email: [INSERT PRIVACY EMAIL ADDRESS]

Legal Email: [INSERT LEGAL EMAIL ADDRESS]

Mailing Address: [INSERT BUSINESS MAILING ADDRESS]