1. Draft framework
This draft is a planning framework and is not an executed data processing addendum. A production DPA must be reviewed by counsel and completed with the actual customer agreement, processing details, subprocessors, transfer mechanisms, and security schedule.
2. Roles and scope
Where a customer submits personal data for LeadRx to process on documented instructions, the customer may act as controller or business and Tellbyte LLC may act as processor or service provider, depending on applicable law and the specific activity. Tellbyte LLC may act independently for account administration, security, legal compliance, and its own legitimate business operations.
3. Documented instructions
Tellbyte LLC should process customer personal data to provide, secure, support, and improve the contracted service, follow authorized product actions, and comply with law. If an instruction appears unlawful or outside scope, the parties should pause and clarify it where legally permitted.
4. Processing details
A signed DPA should identify duration, nature, purpose, data subjects, data categories, sensitive-data restrictions, retention, and authorized processing operations. LeadRx is not designed for unnecessary sensitive personal information.
5. Confidentiality and personnel
People authorized to process customer personal data should be bound by appropriate confidentiality and receive access only as needed for their responsibilities.
6. Security measures
The production schedule should describe applicable identity controls, access boundaries, encryption in transit, managed secrets, logging, change management, incident response, backup and recovery, vendor management, and review practices. Measures should reflect the service and risk rather than a generic checklist.
7. Subprocessors
A production DPA should identify subprocessors used for hosting, authentication, databases, communication, analytics, and support, along with an update and objection process appropriate to the agreement. This preview does not publish a final subprocessor list.
8. Data subject requests
Taking into account the nature of processing, Tellbyte LLC should provide reasonable assistance when a customer responds to a valid rights request. The customer remains responsible for evaluating the request and communicating with the individual unless law requires otherwise.
9. Security incidents
A signed DPA should define notification, available information, cooperation, and communication responsibilities for a confirmed personal-data breach. Notification does not by itself constitute an admission of fault or liability.
10. International transfers
Where required, the parties should use an applicable transfer mechanism and supplementary safeguards. The correct mechanism depends on data location, provider architecture, and the parties' legal roles at the time of execution.
11. Return and deletion
At the customer's choice and subject to the agreement, law, security, and technical feasibility, customer personal data should be returned or deleted after service termination. Backup and legal-retention copies may remain protected until ordinary deletion.
12. Information and audits
A production DPA should provide proportionate information needed to demonstrate compliance and define how audits are requested, scoped, protected, and paid for, while avoiding unreasonable disruption or risk to other customers.
13. Completion and contact
This framework requires legal and technical completion before execution. Start that review through the privacy contact path.