Data Processing Addendum
Current as of July 28, 2026
This Data Processing Addendum describes processing performed by CoreTV LLC for a client under the applicable services agreement.
1. Roles of the parties
For personal data relating to your business's own customers and contacts, you are the "Controller" (you decide why and how it is processed) and CoreTV LLC is the "Processor" (we process it on your documented instructions to provide the service). For data about your own account and our direct relationship with you, CoreTV LLC acts as Controller under our Privacy Policy.
2. Subject matter, duration & purpose
We process personal data only to provide and support the services you have engaged us for — hosting and operating your site or app, capturing and routing leads, running your chatbot or AI receptionist, sending the email/SMS workflows you configure, and related support. Processing lasts for the term of your services plus any limited retention described below.
3. Categories of data & data subjects
Depending on what you configure, this may include: identifiers and contact details (names, emails, phone numbers), lead and enquiry details, appointment and booking data, call and chat transcripts, and usage/analytics data. Data subjects are typically your customers, prospects, and site visitors. You agree not to route special-category or highly sensitive data through the services unless expressly scoped and agreed.
4. Our obligations as processor
We will: process personal data only on your documented instructions; ensure people authorized to process it are bound by confidentiality; implement appropriate technical and organizational security measures; assist you, taking into account the nature of processing, with data-subject requests and your own compliance obligations; and make available the information reasonably needed to demonstrate compliance.
If applicable law requires CORE to process client-controlled personal data outside your documented instructions, CORE will inform you of that legal requirement before the processing unless the law prohibits notice on important grounds of public interest.
5. Subprocessors
CoreTV LLC uses subprocessors for enabled functions such as cloud hosting and databases, email/SMS/voice delivery, payment processing, domains, monitoring, and AI or transcription. Representative core and optional provider categories are described in the Privacy Policy and the accepted order can identify project-specific providers.
Where Article 28 of the GDPR or UK GDPR applies, accepting this DPA gives CoreTV LLC general written authorization to use subprocessors for the covered services. CoreTV LLC will provide advance notice of an intended addition or replacement and a reasonable opportunity to object on documented data-protection grounds. If the parties cannot resolve a valid objection, they will work in good faith on a reasonable alternative or end the affected processing under the agreement.
CoreTV LLC will impose on each subprocessor the same data-protection obligations required for the covered processing, to the extent applicable to the subprocessor's service, and remains fully liable to the client for the subprocessor's performance of those obligations as required by Article 28, subject only to limits that applicable law and the controlling agreement permit.
6. Security measures
We maintain measures appropriate to the risk and configured service, including supported transport encryption, access controls and least privilege, network and dependency hardening, monitoring, secret management, and backup or restore procedures where the accepted service includes them. Measures are reviewed and updated as risks and services change without materially reducing overall protection.
7. Data-subject rights
Taking into account the processing and information available to us, we provide reasonable assistance and any available service tools so you can respond to applicable access, correction, deletion, portability, objection, or appeal requests. Applicable law sets the response period. Where a request reaches us directly about client-controlled data, we ordinarily refer it to you unless law requires another response.
8. Breach notification
If we become aware of a personal-data breach affecting data we process for you, we will notify you without undue delay and provide the information reasonably available to help you meet your notification obligations.
9. Return & deletion
At the client's choice, on termination or a valid documented instruction CORE will delete or return all covered client-controlled personal data through the configured export and operational process and delete existing copies, unless applicable law requires storage. The client should communicate its choice before the applicable transition deadline; a signed order may state a more specific return method or format.
Data that law requires CORE to retain is isolated and used only for the continuing lawful purpose. Backup copies age out under the configured lifecycle and are restricted from ordinary use after the validated instruction, subject to disaster recovery, security, and legal-hold safeguards.
10. International transfers
Where personal data is transferred across borders, we rely on a lawful transfer mechanism appropriate to the destination and the data involved, and require our subprocessors to do the same.
11. Feature-specific processing instructions
Documented instructions include the client's enabled catalog and portal features, approved knowledge sources, communication templates and recipients, scheduling rules, automation policies, remote-assist grants, support requests, retention settings, and signed order documents. CORE processes personal data only to provide, secure, support, and document those instructions or as required by law.
If applicable law requires CORE to process client-controlled personal data outside the client's documented instructions, CORE will inform the client of that legal requirement before the processing unless the law prohibits notice on important grounds of public interest.
Depending on configuration, processing may include leads and contacts; identity and browser-continuity signals; estimate, cart, quote, proposal and order data; outcome answers, budgets, source URLs, uploads, extracted text and citations, architecture and dependency records, timeline choices, proposal activity and attribution events; project and client-onboarding files; blueprint versions and assignments, tasks, milestones, readiness verifications or waivers, comments, collaborator invitations, deliverable and request decisions; support tickets and client requests; email, SMS, chat, call audio and transcripts; bookings; remote-assist events and limited prefill values; search queries and matching record identifiers; relationship links, service-health or client-success indicators, configured provider-usage measurements, decision history; usage, security, consent, suppression, approval, and audit records; and AI-generated summaries or classifications. CORE's own applicant, employment, and staff-administration data is controller processing under the Privacy Policy rather than a client's instruction under this DPA unless a separate service order expressly says otherwise.
12. Controller instructions, notices & consents
The client, as controller, is responsible for the lawfulness, fairness, accuracy, and transparency of its instructions; for giving notices and honoring rights; and for obtaining and documenting consent or another lawful basis for contact lists, automated or artificial-voice communications, recording and transcription, marketing, remote assistance, and any sensitive-data processing. CORE will notify the client if, in CORE's reasonable view, an instruction violates applicable data-protection law and may suspend the affected processing.
The client must have authority to submit each file, recording, URL, knowledge source, collaborator identity, credential, and instruction and must use the designated protected channel for secrets. The client must review material AI extractions, source references, proposed relationships, readiness waivers, and automated-workflow rules before relying on them for its own obligations or decisions.
13. AI, communications & subprocessing
CORE may engage subprocessors for hosting, database and storage, authentication, network protection, payment processing, email, telephony and messaging, transcription and speech, AI models and embeddings, vector retrieval, monitoring, and support. Where Article 28 of the GDPR or UK GDPR applies, the client's acceptance of this DPA is general written authorization for subprocessors used by the covered service. CORE provides advance notice of an intended addition or replacement and a reasonable opportunity to object on documented data-protection grounds; if a valid objection cannot be resolved, the parties work in good faith on an alternative or end the affected processing under the agreement.
CORE imposes the same data-protection obligations required for the covered processing on each subprocessor to the extent applicable to that service and remains fully liable to the client for the subprocessor's performance of those obligations as required by Article 28, subject only to limits permitted by applicable law and the controlling agreement. Current subprocessor information is available from CORE on request.
Private client data is not authorized for public foundation-model training. A provider may retain limited abuse-monitoring or service records under its enterprise terms and applicable law. A client-specific training or fine-tuning project requires a separate written instruction and risk review.
14. Remote-assist & privileged-access safeguards
Remote-assist sessions use explicit, time-limited grants; allowed-path and allowed-field restrictions; expiring commands; participant revocation; role checks; encryption for protected command values; and audit events. The command set excludes credential, payment, signature, legal-acceptance, and final-approval controls.
CORE applies least-privilege and assignment-based access, tenant isolation, input validation, upload controls, rate limiting, encryption in transit and for protected data at rest, secret management, monitoring, and incident procedures appropriate to the risk. Security measures may evolve without materially reducing the overall protection of personal data.
15. Rights, risk assessments & incidents
Taking into account the nature of processing and information available to CORE, CORE will reasonably assist the client with data-subject requests, security and breach obligations, and any legally required privacy impact or automated-decision assessment. CORE's assistance does not replace the client's legal analysis or controller responsibilities and may be subject to reasonable fees for work outside the included service.
CORE will notify the client without undue delay after becoming aware of a personal-data breach affecting client-controlled data and provide available information needed for the client's assessment. Applicable law establishes notification deadlines; the client determines which controller duties apply to the incident and fulfills them with CORE's reasonable processor assistance.
16. Retention, return & compliance evidence
At the client's choice, on termination or a valid documented instruction CORE will delete or return all covered client-controlled personal data within the applicable operational and backup cycle and delete existing copies, unless applicable law requires storage. Data retained by law is isolated and used only for that continuing purpose. Backup copies age out under the configured lifecycle and are restricted from ordinary use after the validated instruction.
Consent, suppression, billing, security, audit, legal-hold, and acceptance records outside the client's return-or-delete instruction may be retained only for the period reasonably necessary to establish compliance, prevent renewed contact, resolve disputes, and satisfy applicable limitation and recordkeeping periods.
On reasonable written request, CORE will provide information needed to demonstrate compliance. Audits must protect other customers, confidential systems, and security controls, use existing independent reports where sufficient, and be coordinated in advance. Unless a demonstrated incident or law requires more, on-site or custom audits are limited to once per year and may be charged at the agreed professional-services rate.
17. Security screening & rights-case processing
To protect public and authenticated workflows, CORE may process request IP addresses and network ranges, submitted email domains, request route and time, rate-limit state, configured deny and allow rules, disposable-domain matches, generic denial outcomes, and related security evidence. When CORE performs those controls to secure its own platform, prevent abuse, or comply with law, CORE determines that security processing as an independent controller to the extent applicable. When a signed order directs materially different screening on the client's behalf, the order identifies the instruction, roles, data, retention, and review process.
For a client-directed data-subject request, CORE may process requester contact and authority evidence, request scope, affected record categories, search and fulfillment logs, communications, decision and appeal state, deadlines, legal holds, and proof of completion. CORE assists within the responsibilities and timeframes allocated by applicable law and the agreement, while the client remains responsible for controller decisions unless CORE is independently responsible for the relevant processing.
Raw blocked IP addresses, network ranges, and domain values are restricted to authorized security administration and are not copied into ordinary super-admin configuration-audit summaries, which use bounded metadata such as actor, action, timestamp, and list counts. Security evidence and rights-case records follow documented purpose-based retention, access logging, deletion or restriction, and legal-hold controls.
Download this document
Save a PDF copy for your records.