Data Processing Agreement (DPA)
Last Updated: August 19, 2026
This DPA is entered into by Gary Vogt ("Processor") and the Customer ("Controller") to define how Personal Data is processed within the Easy A2P application — what is retained, what is not, and how each category is handled.
1. Data Retention
1.1. Account & Contact Data (Retained): Processor retains Controller's account and contact information — including email address, SMS consent preferences, subscription and credit-balance state, agreement timestamps, and GoHighLevel sub-account identifiers (location and company ID) — for as long as the Controller's account is active, consistent with Processor's Privacy Policy. This data is stored in Processor's database (Supabase); it is not processed in-session only.
1.2. Workflow & Submission Content (Not Retained): Personal Data entered into the Easy A2P application as part of a compliance-review or draft-generation workflow — including message samples, campaign descriptions, and other A2P registration materials — is processed strictly in-session. It is forwarded to Anthropic, PBC (Section 5) for real-time analysis and is not stored, archived, or logged by Processor once a response is returned to Controller's browser.
2. Regulatory Alignment & TCPA
2.1. Scope: This agreement covers compliance with GDPR, CCPA, and the Telephone Consumer Protection Act (TCPA).
2.2. Intent: Processing is limited to scanning for compliance markers (e.g., opt-out language, sender identification) to facilitate A2P 10DLC registration.
3. Data Sovereignty & Intellectual Property
3.1. Controller Ownership: The Controller retains 100% ownership of any data passed through the application.
3.2. Processor IP: All proprietary scanning logic, AI prompt frameworks, and GoHighLevel "Snapshots" provided by Gary Vogt Consulting remain the exclusive Intellectual Property of the Processor.
4. Liability Shield (The "Veto" Clauses)
4.1. Third-Party Platform Actions: Processor is not liable for any account suspensions or "Platform Bans" (e.g., GMB, Twilio, or GoHighLevel) resulting from the Controller's messaging activities.
4.2. Carrier Filtering: Despite compliance scanning, Processor does not guarantee message delivery. Liability for "Carrier Filtering" or blocked campaigns is explicitly disclaimed.
4.3. Lost Revenue: Under no circumstances shall Processor be liable for indirect, incidental, or "Lost Revenue" damages.
5. Sub-processors (Transient Processing)
Controller acknowledges that data is transmitted to the following sub-processors as described in Section 1 — some for real-time analysis of Workflow & Submission Content only, others for ongoing storage or service delivery involving Account & Contact Data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Application hosting | United States |
| Supabase | Database, authentication | United States |
| Stripe, Inc. | Payment processing | United States |
| Resend | Transactional email | United States |
| HighLevel, Inc. (GoHighLevel) | CRM/marketing platform integration | United States |
| Google LLC (Analytics 4) | Usage analytics | United States |
| Anthropic, PBC | AI compliance scanning (if message content is sent to Claude API) | United States |
6. Security Measures
Processor employs TLS 1.2+ encryption for all data in transit. Workflow & Submission Content (Section 1.2) is not retained, limiting the exposure window for that category of data to the processing request itself. Account & Contact Data (Section 1.1) is retained in Processor's database for as long as the Controller's account is active; Processor maintains internal SOPs for session security, database access, and API key management.
Contact
For data protection inquiries:
- Gary Vogt
- Address: 6173 Stoffer Way, Orangevale, California, 95662
- Support phone: (888) 996-4227
- Email: [email protected]