Data Processing Addendum
Effective Date: August 25, 2026
Version: 1.0
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and each Order Form between ListenToMe LLC, d/b/a Parylex (“Parylex”), and the Client whenever Parylex processes Client Personal Data on the Client's behalf. It is incorporated automatically; no separate request or signature is required unless applicable law requires one.
1. Roles and Instructions
Client is the controller or business and Parylex is the processor or service provider for Client Personal Data. Parylex will process Client Personal Data only to provide, secure, support, and improve the configured Services; comply with documented lawful instructions in the agreement; or comply with law. If Parylex believes an instruction violates applicable data-protection law, it will notify Client unless prohibited by law.
2. Processing Details
| Subject matter | Managed websites, CRM, communications, lead handling, automation, analytics, support, and configured AI features |
| Duration | The Subscription term plus the export, deletion, legal-hold, and backup periods described in the agreement and Parylex retention schedule |
| Nature and purpose | Collection, organization, storage, retrieval, transmission, support, deletion, and other processing needed to provide the Services |
| Data subjects | Client personnel, prospects, customers, homeowners, website visitors, callers, message recipients, and other individuals whose data Client places in the Services |
| Data categories | Identifiers and contact details; inquiry and project details; communications, appointments, and consent records; website activity; account and support information; call or AI interaction data when configured |
| Sensitive data | Not intended for regulated health, payment-card, government-identifier, biometric, precise-geolocation, or similarly sensitive data unless an Order Form expressly authorizes and safeguards that processing |
3. Confidentiality and Security
Parylex will ensure that personnel authorized to process Client Personal Data are bound by confidentiality obligations and will maintain appropriate administrative, technical, and organizational safeguards proportionate to the risk. These include access control, least privilege, secure secret handling, encryption in transit, logging, dependency and patch management, incident response, and vendor review, as applicable to the Services.
4. Subprocessors
Client gives general written authorization for Parylex to use subprocessors needed for hosting, CRM, communications, telephony, AI, speech, transcription, storage, analytics, payment, security, and support. Parylex will bind each subprocessor by written terms that protect Client Personal Data to a standard appropriate to the service and will remain responsible for its obligations under this DPA.
A current subprocessor register is available from support@parylex.com. Parylex will provide reasonable advance notice of a new subprocessor when the change materially affects Client Personal Data. Client may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable resolution.
5. Restrictions on Secondary Use
Parylex will not sell Client Personal Data, share it for cross-context behavioral advertising, combine it with personal data received from another source except as permitted for a service provider, or independently use it to develop or train a Parylex-owned generalized AI model. Parylex will not affirmatively opt Client Personal Data into an optional subprocessor training program without Client's written authorization. Subprocessors may perform limited retention or processing for service delivery, security, abuse monitoring, or product improvement only as allowed by their disclosed contract and configured controls. Material provider data uses must be recorded in the applicable Order Form, DPA materials, or subprocessor register.
6. Assistance and Requests
Taking into account the nature of processing and information available, Parylex will reasonably assist Client with verified data subject requests, data-protection assessments, regulator inquiries, and Client's obligations concerning security and breach notification. Client remains responsible for responding to requests as controller unless the parties agree otherwise.
7. Security Incidents
Parylex will notify Client without undue delay after confirming a security incident involving Client Personal Data and will provide information reasonably available about the nature, affected data, likely consequences, and mitigation. Notice is not an admission of fault. Client is responsible for notices to individuals or authorities unless the parties agree otherwise or law requires Parylex to notify directly.
8. Return and Deletion
During the export window in the Terms, Parylex will make reasonably exportable Client Personal Data available to Client. After the window closes, Parylex will delete or de-identify Client Personal Data according to its retention schedule, unless law or a documented legal hold requires retention. Backup copies may remain until overwritten in the ordinary course and remain protected by this DPA.
9. Compliance Information and Audits
On reasonable written request, Parylex will provide information necessary to demonstrate compliance with this DPA. If that information is insufficient, Client may request one reasonable assessment per year by an independent auditor bound by confidentiality, during normal business hours, without access to other clients' data or disruption of the Services. Client bears its audit costs unless the audit identifies a material breach by Parylex.
10. International Transfers and Conflicts
Parylex will use a lawful transfer mechanism when applicable law requires one for an international transfer. If this DPA conflicts with the Terms regarding processing of Client Personal Data, this DPA controls. The governing-law and dispute provisions in the Terms otherwise apply.
