Easy A2P

← Back to Home

Data Processing Agreement (DPA)

Last Updated: August 19, 2026

This DPA is entered into by Gary Vogt ("Processor") and the Customer ("Controller") to define how Personal Data is processed within the Easy A2P application — what is retained, what is not, and how each category is handled.

1. Data Retention

1.1. Account & Contact Data (Retained): Processor retains Controller's account and contact information — including email address, SMS consent preferences, subscription and credit-balance state, agreement timestamps, and GoHighLevel sub-account identifiers (location and company ID) — for as long as the Controller's account is active, consistent with Processor's Privacy Policy. This data is stored in Processor's database (Supabase); it is not processed in-session only.

1.2. Workflow & Submission Content (Not Retained): Personal Data entered into the Easy A2P application as part of a compliance-review or draft-generation workflow — including message samples, campaign descriptions, and other A2P registration materials — is processed strictly in-session. It is forwarded to Anthropic, PBC (Section 5) for real-time analysis and is not stored, archived, or logged by Processor once a response is returned to Controller's browser.

2. Regulatory Alignment & TCPA

2.1. Scope: This agreement covers compliance with GDPR, CCPA, and the Telephone Consumer Protection Act (TCPA).

2.2. Intent: Processing is limited to scanning for compliance markers (e.g., opt-out language, sender identification) to facilitate A2P 10DLC registration.

3. Data Sovereignty & Intellectual Property

3.1. Controller Ownership: The Controller retains 100% ownership of any data passed through the application.

3.2. Processor IP: All proprietary scanning logic, AI prompt frameworks, and GoHighLevel "Snapshots" provided by Gary Vogt Consulting remain the exclusive Intellectual Property of the Processor.

4. Liability Shield (The "Veto" Clauses)

4.1. Third-Party Platform Actions: Processor is not liable for any account suspensions or "Platform Bans" (e.g., GMB, Twilio, or GoHighLevel) resulting from the Controller's messaging activities.

4.2. Carrier Filtering: Despite compliance scanning, Processor does not guarantee message delivery. Liability for "Carrier Filtering" or blocked campaigns is explicitly disclaimed.

4.3. Lost Revenue: Under no circumstances shall Processor be liable for indirect, incidental, or "Lost Revenue" damages.

5. Sub-processors (Transient Processing)

Controller acknowledges that data is transmitted to the following sub-processors as described in Section 1 — some for real-time analysis of Workflow & Submission Content only, others for ongoing storage or service delivery involving Account & Contact Data:

Sub-processor Purpose Location
Railway Application hosting United States
Supabase Database, authentication United States
Stripe, Inc. Payment processing United States
Resend Transactional email United States
HighLevel, Inc. (GoHighLevel) CRM/marketing platform integration United States
Google LLC (Analytics 4) Usage analytics United States
Anthropic, PBC AI compliance scanning (if message content is sent to Claude API) United States

6. Security Measures

Processor employs TLS 1.2+ encryption for all data in transit. Workflow & Submission Content (Section 1.2) is not retained, limiting the exposure window for that category of data to the processing request itself. Account & Contact Data (Section 1.1) is retained in Processor's database for as long as the Controller's account is active; Processor maintains internal SOPs for session security, database access, and API key management.

Contact

For data protection inquiries: