Data Processing Addendum
Effective September 1, 2026. This Data Processing Addendum ("DPA") supplements the Terms of Service, an order form, or another written service agreement between a business customer and Billions+ (the "Agreement"). It describes the parties' responsibilities when Billions+ processes customer personal data on the customer's behalf.
Purpose and Scope
This DPA applies when Billions+ processes personal data on behalf of a business customer in providing the AI Sales Agent, dashboard, catalog, customer, conversation, order, connected-channel, billing-support, security, and related services described in the Agreement.
This DPA forms part of the Agreement. It applies only to customer personal data for which the business customer determines the purposes and means of processing and Billions+ acts as processor. If a processor term in this DPA conflicts with the Agreement, this DPA controls to the extent of that conflict.
Roles and Instructions
2.1 Customer as controller
The business customer is the controller of customer personal data. It decides what data enters the Service, the lawful purpose and legal basis for processing, the people who may access it, the enabled channels and workflows, and the instructions Billions+ must follow.
2.2 Billions+ as processor
Billions+ acts as processor for customer personal data and processes it only on the customer’s documented instructions, including instructions expressed through the Agreement, product configuration, enabled features, connected services, support requests, and other written directions agreed by the parties.
If applicable law requires Billions+ to process customer personal data outside those instructions, Billions+ will inform the customer before processing unless the law prohibits that notice. Billions+ will promptly tell the customer if, in our reasonable view, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it.
Details of Processing
3.1 Subject matter and duration
The subject matter is the processing needed to provide, secure, support, and maintain the Service for the business customer. Processing continues for the duration of the Agreement and any limited period needed to return or delete customer personal data, meet legal obligations, or resolve an agreed support or security matter.
3.2 Nature of processing
Processing may include receiving, collecting, recording, organizing, structuring, storing, retrieving, consulting, using, generating, combining, transmitting, making available to an authorized connected service, restricting, returning, deleting, and protecting customer personal data.
3.3 Purposes of processing
The purposes are to authenticate authorized users; maintain a business workspace and catalog; receive and deliver connected-channel messages; ground AI Sales Agent responses in approved business information; preserve customer and conversation context; prepare and administer orders; support owner approval, takeover, and follow-up; deliver notifications; troubleshoot failures; prevent abuse; and provide customer-requested support.
Data Subjects and Personal Data
4.1 Data subjects
Data subjects may include the business customer’s customers and prospective customers, customer contacts, workspace owners, administrators, team members, contractors, and other people whose data the customer submits through an enabled workflow.
4.2 Categories of personal data
Customer personal data may include names, phone numbers, email addresses, channel and account identifiers, messages, attachments, conversation history, product interests, preferences and customer memory, support requests, order and line-item details, delivery information, payment-status information, business notes and instructions, team-member details, and technical or security events linked to use of the workspace.
The Service is not designed to require special-category or similarly sensitive personal data. The customer must not submit such data unless it has confirmed that the processing is lawful, necessary, and supported by appropriate instructions and safeguards.
Customer Responsibilities
- Give lawful, documented instructions and ensure that processing through the Service has a valid legal basis.
- Provide required privacy notices and obtain required permissions or consents from data subjects and authorized users.
- Keep catalog, business, customer, and workflow information accurate enough for the instructed purpose.
- Configure roles, approvals, channel access, retention choices, and human review appropriate to the processing risk.
- Respond to data-subject and authority requests unless assistance from Billions+ is needed.
The customer is responsible for the lawfulness of collection, the instructions it gives, and its use of outputs returned by the Service. Billions+ is not responsible for processing caused by unlawful or inaccurate customer instructions that we could not reasonably identify as unlawful.
Confidentiality and Personnel
Billions+ limits access to customer personal data to personnel and contractors who need it to provide, secure, or support the Service. People authorized to process that data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality and receive access appropriate to their responsibilities.
Billions+ remains responsible for directing authorized personnel to process customer personal data in accordance with this DPA and the customer’s documented instructions.
Security
Billions+ maintains technical and organizational measures designed for the risk of processing, including signed HTTP-only session cookies, authentication and role-based access controls, workspace boundaries, protected file access, transport security, security and audit logging, and rate limiting.
Billions+ may update security measures as technology, threats, and the Service change, provided the overall protection of customer personal data is not materially reduced. The customer remains responsible for secure credentials, authorized users, connected services, device security, and configuration choices under its control.
Sub-processors
The customer gives Billions+ general authorization to use sub-processors needed for application hosting, databases, queues and caches, private object storage, deployment, AI inference, email and notifications, identity, connected messaging, billing and payment, monitoring, backup, security, and support operations.
Billions+ will require a sub-processor to protect customer personal data through written terms that are no less protective in substance than the obligations applicable to Billions+ under this DPA. Billions+ remains responsible for the sub-processor’s performance to the extent required by applicable law.
Where applicable law requires it, Billions+ will provide reasonable advance notice of a material new sub-processor. The customer may object on reasonable data-protection grounds. The parties will work in good faith on a practical resolution; if none is available, the customer may stop the affected feature or terminate the affected Service according to the Agreement.
Data Subject Rights and Compliance Assistance
The customer is responsible for responding to requests to access, correct, delete, restrict, object to, or export customer personal data. Taking account of the nature of processing, Billions+ will provide reasonable assistance through available product functions and support when a request requires action in systems controlled by Billions+.
If Billions+ receives a request directly from a data subject about customer personal data, we will refer the person to the customer and will not respond for the customer unless instructed or legally required. Billions+ will also provide reasonable information and assistance for the customer’s security obligations, breach notifications, data protection impact assessments, and prior consultations with an authority, taking account of the processing and information available to us.
Personal Data Breach
If Billions+ becomes aware of a personal data breach affecting customer personal data, we will notify the customer without undue delay. Notification does not admit fault or liability.
As information becomes reasonably available, Billions+ will describe the nature of the breach, relevant data and data-subject categories, likely consequences where assessable, measures taken or proposed, and a contact point for follow-up. We may provide information in stages when it cannot be supplied at the same time.
International Transfers
Billions+ and authorized sub-processors may process customer personal data in countries where they operate. When applicable data-protection law requires a transfer mechanism or other safeguard, Billions+ will use an appropriate lawful mechanism and provide information reasonably needed for the customer’s transfer assessment.
Return and Deletion
At the end of the Service and at the customer’s choice, Billions+ will delete or return customer personal data, subject to available export capabilities, and delete remaining copies unless applicable law requires retention. The customer should request an available export before account closure when it wants data returned.
If applicable law requires Billions+ to retain particular customer personal data, the retention requirement applies only to that data and only for as long as the law requires.
Information and Audits
Billions+ will make available information reasonably necessary to demonstrate compliance with the processor obligations in this DPA. We may first provide relevant policies, architecture or security summaries, responses to questionnaires, and other suitable evidence, subject to confidentiality and security restrictions.
Where applicable law requires an audit or inspection, Billions+ will allow and contribute to a reasonable review by the customer or an independent auditor that is not a competitor. The review must use reasonable advance notice, protect confidential and third-party information, avoid unnecessary disruption, stay limited to relevant processing, and be paid for by the customer unless the review identifies a material breach by Billions+.
General Terms
The Agreement’s liability, suspension, termination, and dispute provisions apply to this DPA unless applicable data-protection law requires otherwise. The governing law and courts stated in the Terms or applicable order form also apply to this DPA.
If a provision of this DPA is unenforceable, the remaining provisions continue in effect. Changes to this DPA must be in writing or published as an updated addendum with notice when the Agreement and applicable law allow that method.
Contact Us
For questions about this addendum or Billions+ data-processing practices, contact Billions+ at [email protected].