Data Processing Addendum
1. Parties and scope
This Data Processing Addendum (“DPA”) is between Cody Rasmussen (individual seller), the provider of RuleCue (“Provider”), and the Customer that agreed to the RuleCue Terms. It applies only when Provider processes Customer Personal Data on Customer’s behalf in providing RuleCue. It forms part of the Terms and takes effect when Customer accepts the Terms or otherwise uses RuleCue to process Customer Personal Data.
“Customer Personal Data” means personal information submitted to RuleCue by or for Customer that Provider processes on Customer’s behalf. It does not include information Provider processes independently for account administration, direct business communications, security, billing, legal compliance, or its own relationship with Customer.
2. Roles and instructions
For Customer Personal Data, Customer is the controller, business, or equivalent decision maker, and Provider is the processor, service provider, or contractor, as those terms apply under relevant U.S. privacy law. Customer instructs Provider to process Customer Personal Data to provide, secure, maintain, and support RuleCue; comply with documented settings and requests; and perform the activities described in the Terms, Privacy Policy, this DPA, and the service.
Provider will process Customer Personal Data only on Customer’s documented instructions unless law requires otherwise. If legally permitted, Provider will notify Customer before required processing. Provider will inform Customer if it reasonably believes an instruction violates applicable data-protection law and may pause that instruction while the parties address it.
3. Processing details
| Item | Description |
|---|---|
| Subject matter | Operation of RuleCue’s business regulatory-information, workspace, account, reporting, delivery, and support functions. |
| Duration | The subscription term and the limited period afterward needed for return, deletion, secured backup rotation, audit integrity, dispute handling, and legal obligations. |
| Nature and purpose | Collection, organization, storage, retrieval, display, access control, report generation, delivery, support, security, correction, export, and deletion as directed through RuleCue. |
| Data subjects | Customer’s authorized users and business client contacts whose information Customer lawfully enters for the released service functions. |
| Data categories | Business identity and contact data, role and account data, authentication and request metadata, jurisdiction and service preferences, client profile and contact-routing data, brand assets, workflow actions, and related support communications. |
| Restricted data | Customer must not submit medical records, employee incident files, government identifiers, payment-card numbers, passwords, biometric data, or other sensitive data that RuleCue does not request. Customer-document intake and customer-content AI processing are not part of this release. |
4. Customer responsibilities
Customer is responsible for the lawfulness of its instructions and Customer Personal Data, providing required notices, obtaining required permissions, honoring individual rights, configuring access, and limiting submitted data to what is necessary for the authorized business purpose. Customer will not instruct Provider to process data that the released service is not designed to accept.
5. Confidentiality and security
Provider will ensure that people authorized to process Customer Personal Data are bound by confidentiality duties and access it only as needed for their responsibilities. Provider will maintain safeguards appropriate to the nature of the data and service, including access control, tenant separation, encryption in transit, private storage, secret management, logging, backup, vulnerability and dependency management, and incident-response procedures.
Customer is responsible for securing its email accounts, devices, sign-in links, and user permissions. Provider may update safeguards as technology and risks change, provided it does not materially reduce the overall protection of Customer Personal Data during an active paid term.
6. Subprocessors
Customer authorizes the providers on the current Subprocessor List to process Customer Personal Data for the functions described there. Provider will contractually restrict a subprocessor to appropriate data-protection and confidentiality obligations.
Provider will update the list and, when reasonably practicable, give account administrators advance electronic notice before a material new subprocessor begins processing Customer Personal Data. Customer may object within 10 calendar days after notice on reasonable, documented data-protection grounds by emailing info@rulecue.com. The parties will work in good faith on a reasonable alternative. If none is reasonably available, Customer may stop the affected processing or terminate the affected service before the new processing begins when operationally possible.
7. Individual requests and compliance assistance
Taking into account the nature of processing and information available to Provider, Provider will reasonably assist Customer with verified requests to access, correct, delete, or obtain Customer Personal Data and with Customer’s applicable privacy assessments, regulator inquiries, and compliance duties. If Provider receives a request concerning Customer Personal Data directly, it will direct the requester to Customer unless law permits Provider to handle it or Customer instructs otherwise.
8. Security incidents
Provider will notify Customer without undue delay after confirming unauthorized access to or acquisition, destruction, loss, alteration, or disclosure of Customer Personal Data for which Provider is responsible. Notice will include information reasonably available to Provider about the nature of the incident, affected data, likely consequences, and mitigation. Notice is not an admission of fault. Customer is responsible for notices and decisions required of Customer as controller, and Provider will reasonably assist.
9. Return, deletion, and retention
During the subscription, Customer may request an available export of Customer Personal Data. After termination or a verified request, Provider will delete or return Customer Personal Data within a commercially reasonable period unless retention is required or permitted for security, fraud prevention, legal compliance, dispute resolution, or preservation of transaction and audit integrity. Data remaining in secured backups will be isolated from ordinary use and removed through the backup rotation cycle.
10. Reviews and information
On reasonable written request, Provider will make available information needed to demonstrate compliance with this DPA, such as relevant security summaries, provider documentation, and responses to reasonable questionnaires. If that information is insufficient and applicable law requires more, the parties will agree on a proportionate review that protects other customers, security, confidentiality, and Provider systems. Customer bears its review costs unless a material Provider breach is found.
11. U.S. state privacy terms
Where a U.S. state privacy law treats Provider as Customer’s service provider, processor, or contractor, Provider will process Customer Personal Data only for the limited and specified purposes in this DPA; provide the same level of privacy protection required of that role; not sell Customer Personal Data or share it for cross-context behavioral advertising; not retain, use, or disclose it outside the direct business relationship except as permitted by law; notify Customer if Provider can no longer meet an applicable obligation; and allow Customer to take reasonable steps to stop and remediate unauthorized use.
Provider will not combine Customer Personal Data with personal information received from another customer or collected from Provider’s own interaction with a person, except as permitted to provide the business purpose under applicable law.
12. General
If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls for that conflict. The liability provisions in the Terms apply to this DPA. Changes to this DPA will follow the change process in the Terms and will not materially reduce required data-protection obligations during an active paid term.
The parties agree to this DPA electronically. Privacy instructions, subprocessor objections, and DPA questions may be sent to info@rulecue.com.