Concierge
DocsPricing Support
Back to Concierge
Legal

Core policies

PrivacyTermsCookiesAI DisclosureAcceptable UsePolicy Changes

Privacy and trust

Privacy ChoicesData DeletionSecurityAccessibilityData Retention

Business resources

Data Processing AddendumSubprocessors

Reporting

Report AbuseSecurity ReportingCopyright and DMCA
Concierge legal

Data Processing Addendum

The standard data-processing terms that apply when Testamplify LLC processes personal data for a Concierge customer.

Last updated: August 19, 2026

Part of the customer agreement. This Data Processing Addendum (DPA) supplements the Concierge Terms of Service between the customer and Testamplify LLC. It applies only to customer personal data that Testamplify processes on the customer's behalf.

1. Roles and instructions

The customer is the controller or business, and Testamplify LLC is the processor or service provider, except where applicable law assigns different terms. Testamplify will process customer personal data only to provide, secure, support, and improve the contracted service; follow documented customer instructions; meet legal obligations; and prevent fraud or abuse. The Terms, product configuration, support requests, and this DPA form the customer's documented instructions.

2. Processing details

Subject matterAI website assistance, conversations, routing, Pages, website analysis, customer-growth workflows, connected integrations, and related support.
DurationFor the customer relationship plus the controlled deletion, backup, dispute, security, and legal-retention periods described in the Data Retention Notice.
PeopleCustomer users and teammates; website visitors, prospects, contacts, and customers; and people whose information the customer submits through configured sources or integrations.
DataAccount and contact details, visitor and conversation data, site content and configuration, customer relationship fields, usage and device signals, connected-provider data, and support or security records.
OperationsCollection, transmission, organization, storage, retrieval, analysis, generation, display, routing, deletion, and other operations necessary for the service.

3. Confidentiality and security

Testamplify restricts personnel and service-provider access to legitimate operational needs, requires appropriate confidentiality, and maintains technical and organizational safeguards proportionate to the nature of the service and information. Current safeguards and assurance boundaries are described in the Security Overview.

4. Subprocessors

The customer authorizes the providers listed on the Subprocessors page. Testamplify remains responsible for a subprocessor's performance of its applicable data-protection obligations. We will publish material changes before a new core subprocessor begins processing, where practical. A customer with a reasonable data-protection objection should contact support promptly; the parties will work in good faith on a commercially reasonable alternative.

5. Assistance and requests

Taking into account the nature of processing and information available, Testamplify will reasonably assist the customer with verified data-subject requests, security incidents, required assessments, and regulator inquiries. Customers remain responsible for deciding whether a request is valid and for using available product controls before requesting operational assistance.

6. Security incidents

After confirming unauthorized access to customer personal data, Testamplify will notify the affected customer without undue delay as required by applicable law, provide information reasonably available for the customer's obligations, and take appropriate containment and remediation steps. Notice is not an admission of fault or liability.

7. Return and deletion

At the end of service, Testamplify will delete or return customer personal data according to product controls, verified instructions, the retention schedule, and applicable law. Limited security, financial, legal, request-fulfillment, and recovery-backup records may remain protected until their lifecycle ends.

8. International transfers

Where customer personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the legally recognized standard contractual clauses and relevant jurisdictional addenda are incorporated as needed. For EEA transfers, the applicable modules of the European Commission's 2021 Standard Contractual Clauses apply, with the customer as exporter and Testamplify as importer unless the parties' roles require another module.

9. Audit information

Testamplify will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, the customer may request a proportionate audit no more than once annually, unless a confirmed incident or regulator requires otherwise, subject to confidentiality, security, non-disruption, and reasonable-cost safeguards.

10. Regulated data

Concierge is not offered as a HIPAA-compliant service and no Business Associate Agreement is provided unless Testamplify expressly agrees in writing. Customers must not submit protected health information, payment card credentials, or other regulated data requiring controls not expressly included in their agreement.

11. Conflict and contact

If this DPA conflicts with the Terms about processing customer personal data, this DPA controls for that subject. Other terms remain unchanged. Questions and contract requests may be sent to support@poweredbyconcierge.com.

© 2026 Testamplify LLC. Concierge is built by PracticaLabs.

PrivacyTermsPrivacy choicesReport abuse