Skip to main content

Data Processing Agreement

Last Updated: August 6, 2026

This Data Processing Agreement ("DPA") applies automatically to every Customer who uses the Platform to process Personal Data. It forms part of, and is incorporated into, the Terms of Use. No signature is required for it to take effect. If your organization requires a countersigned copy, or a copy executed on your own paper, contact [email protected].

1. Parties and Roles

This DPA is between the customer entity that has accepted the Terms of Use ("Customer") and Elmob Marketing LLC, a Nevada limited liability company operating Elmob.ai ("Elmob," "we," "us," or "our").

For Personal Data that Customer or Customer's own end customers submit to, or that is generated within, the Platform:

  • Customer is the Controller (and, under the CCPA, the Business). Customer determines the purposes and means of processing, and is responsible for the lawful basis of that processing, including obtaining any consent required before contacting a data subject by email, SMS, or telephone.
  • Elmob is the Processor (and, under the CCPA, the Service Provider). Elmob processes Personal Data only on Customer's behalf.

Where Elmob processes data about Customer's own account and users for billing, security, and platform administration, Elmob acts as a Controller for that limited purpose, as described in the Privacy Policy.

2. Subject Matter and Details of Processing

Required by GDPR Article 28(3).

  • Subject matter: Provision of the Platform, being marketing automation, lead capture and qualification, customer messaging across email, SMS and voice, review and reputation management, advertising management, reporting, and related AI-assisted features.
  • Duration: The term of Customer's subscription, plus the retention period in Section 9.
  • Nature and purpose: Collection, recording, organization, storage, retrieval, transmission, analysis, and deletion of Personal Data, in each case to deliver the Platform's features at Customer's direction.
  • Categories of data subjects: Customer's personnel and authorized users; Customer's own customers, leads, and prospects; callers and message recipients.
  • Categories of Personal Data: Names, email addresses, telephone numbers, postal and service addresses, job and enquiry details, appointment and booking records, message and call content, call recordings and transcripts where enabled, marketing engagement data, device and usage identifiers, and IP addresses.
  • Special category data: The Platform is not designed for, and Customer must not submit, special category data under GDPR Article 9, health information subject to HIPAA, payment card numbers, government identifiers, or children's data.

3. Processing Instructions

Elmob processes Personal Data only on Customer's documented instructions, including for international transfers, unless required otherwise by applicable law. Customer's use of the Platform, and its configuration choices within it, constitute documented instructions. Elmob will inform Customer if it believes an instruction infringes applicable data protection law, unless legally prohibited from doing so.

Elmob will not sell or share Personal Data, and will not retain, use, or disclose it for any purpose other than performing the Platform's services, except as permitted by applicable law. Elmob will not combine Personal Data received from Customer with data from other sources except as permitted for a service provider under the CCPA. Elmob certifies that it understands and will comply with these restrictions.

4. Confidentiality

Elmob ensures that personnel authorized to process Personal Data are bound by an appropriate duty of confidentiality, receive training relevant to their role, and are granted access on a least-privilege basis limited to what their duties require.

5. Security Measures

Elmob implements appropriate technical and organizational measures under GDPR Article 32, including:

  • Encryption of data in transit using TLS, and encryption at rest for credentials, access tokens, and backup data
  • Logical separation of each customer's data, with tenant scoping enforced at the application layer
  • Role-based access control, authenticated sessions with revocation, and administrative access restricted to named operators
  • Audit logging of security-relevant and administrative actions, recording actor and change
  • Rate limiting, abuse controls, and spend ceilings on paid and automated operations
  • Regular encrypted backups with offsite replication and periodic restore testing
  • Secret management through a managed secret store, with a documented rotation runbook
  • Automated dependency and secret scanning in the deployment pipeline

Elmob may update these measures over time provided the overall level of security is not reduced.

6. Sub-processors

Customer grants Elmob general written authorization to engage sub-processors. The current list is maintained at elmob.ai/sub-processors.

Elmob imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to Customer for a sub-processor's performance. Elmob will give at least thirty (30) days' notice before adding or replacing a sub-processor. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected subscription without penalty as its exclusive remedy.

7. Data Subject Rights

Taking into account the nature of the processing, Elmob assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise data subject rights, including access, rectification, erasure, restriction, portability, and objection. The Platform provides self-service export and deletion tools for this purpose.

If Elmob receives a request directly from a data subject relating to Customer's data, Elmob will not respond substantively and will refer the request to Customer without undue delay, except where legally required to respond. Deletion instructions can also be submitted through elmob.ai/data-deletion.

8. Personal Data Breach

Elmob will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Elmob will provide reasonable assistance to Customer in meeting its own notification obligations under GDPR Articles 33 and 34 and applicable state breach notification laws.

Elmob also provides reasonable assistance with data protection impact assessments and prior consultations under GDPR Articles 35 and 36, taking into account the nature of processing and the information available to Elmob.

9. Return and Deletion

On termination or expiry of Customer's subscription, Elmob will, at Customer's election, delete or return Personal Data processed on Customer's behalf. Customer may export its data at any time during the subscription term and for thirty (30) days after termination. After that period, Elmob deletes Personal Data within ninety (90) days, except where retention is required by applicable law, in which case Elmob will retain it only for as long as required and continue to protect it under this DPA. Residual copies in routine encrypted backups are deleted on the ordinary backup expiry cycle.

10. Audits and Demonstrating Compliance

Elmob makes available to Customer the information reasonably necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by Customer or an auditor it mandates. Audits are limited to once per twelve (12) month period unless required by a supervisory authority or following a Personal Data Breach, must be requested at least thirty (30) days in advance, must be conducted during business hours in a manner that does not disrupt Elmob's operations, and are subject to confidentiality. Elmob may satisfy an audit request by providing a current third-party assessment or completed security questionnaire where one is available.

11. International Transfers

Elmob is established in the United States and processes data there. Where Customer transfers Personal Data subject to the GDPR or UK GDPR to Elmob, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor), and the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference and apply to that transfer. For those clauses, Customer is the data exporter and Elmob is the data importer; the appendices are populated by Sections 2, 5, and 6 of this DPA; and the governing law and forum provisions default to Ireland unless another EU member state is required. Elmob will implement supplementary measures where necessary and will challenge any government access request that is unlawful.

12. Customer Responsibilities

Customer is responsible for the lawfulness of the Personal Data it submits and of the instructions it gives. In particular, Customer warrants that it has a valid lawful basis and, where required, documented prior express written consent before using the Platform to send marketing email, SMS, or voice messages, and that it complies with the TCPA, CAN-SPAM, CASL, applicable do-not-call rules, and A2P messaging requirements. Customer must not upload purchased, harvested, or otherwise unconsented contact lists. The Acceptable Use provisions of the Terms of Use apply.

13. Liability, Conflict, and Governing Law

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Use. If there is a conflict between this DPA and the Terms of Use regarding the processing of Personal Data, this DPA controls. If there is a conflict between this DPA and the Standard Contractual Clauses, the Clauses control. This DPA is governed by the laws of the State of Nevada, without regard to conflict of law principles, except where applicable data protection law requires otherwise.

14. Contact

Questions about this DPA, requests for a countersigned copy, sub-processor objections, and audit requests should be sent to [email protected].

Elmob Marketing LLC, 7322 S Rainbow Blvd Ste 316, Las Vegas, NV 89139, United States.

Elmob Assistant
Online
Hey! Are you an agency or a local business?
Want us to reach out?
Drop your info and we'll follow up personally.