Back to site

Data Processing Addendum

Last updated 23 September 2026 · Delegated AI Inc (GrowthXL)

This Data Processing Addendum ("DPA") forms part of the agreement between Delegated AI Inc ("Processor", "we", "us", "our") and the business entity using our Services ("Controller", "you", "your"). It applies where we process personal information on your behalf in connection with the Services, and it supplements your agreement with us and our Privacy Policy.

1. Definitions

  • Applicable Privacy Laws means all privacy and data protection laws applicable to the processing described in this DPA, including the California Consumer Privacy Act as amended by the CPRA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and similar US state laws, each as applicable.
  • Personal Information has the meaning given in Applicable Privacy Laws and includes any information that identifies, relates to, describes or could reasonably be linked with a consumer or household.
  • Process and Processing mean any operation performed on Personal Information, including collection, use, storage, disclosure, analysis, deletion or disposal.
  • Services means the products and services we provide under our agreement, including the GrowthXL Platform, the websites we build, communications tools and related support.

2. Roles and scope

You are the business or controller of the Personal Information you submit to the Services about your customers, leads or personnel. We act as your service provider or processor, and we will Process that Personal Information only on your documented instructions and as described in this DPA and our agreement, unless the law requires otherwise.

3. Processing instructions and restrictions

  • We will Process Personal Information only to provide the Services, to comply with law, or as otherwise agreed in writing.
  • We will not sell Personal Information, and we will not retain, use or disclose it outside the direct business relationship with you, except as permitted by Applicable Privacy Laws or our agreement.
  • We will not use Personal Information for our own advertising, and we will not share it with advertising partners.
  • We will not combine Personal Information received in connection with the Services with Personal Information from other sources, except as necessary to provide or improve the Services, to detect security incidents, or as permitted by law.

4. Confidentiality and personnel

We ensure that anyone authorised to Process Personal Information is bound by appropriate confidentiality obligations, whether contractual or statutory, and receives data protection training appropriate to their role. Access is limited to those who need it to do their job, and staff access to a customer account is logged.

5. Sub-processors

5.1 Authorised sub-processors

You authorise us to engage the sub-processors below to Process Personal Information on your behalf. We remain responsible for each sub-processor's performance of its obligations under this DPA.

Sub-processorService providedLocation
CRM and messaging platform providerCRM, SMS and MMS, marketing automation, client portal and related platform servicesUnited States
Telephony carrierProvisioning of phone numbers and delivery of text messages and voice callsUnited States
Stripe, Inc.Payment processing and billingUnited States
Vercel Inc.Website hosting, CDN and application infrastructureUnited States
Google LLCGoogle Business Profile, analytics and advertising measurementUnited States
Meta Platforms, Inc.Advertising delivery, measurement and conversion trackingUnited States

The current named list of sub-processors is available on request by emailing care@growthxl.ai.

5.2 Changes to sub-processors

We will give you at least 30 days' advance notice of a new sub-processor or a material change to a sub-processor arrangement, unless legal or security reasons prevent it, in which case we will notify you as soon as reasonably practicable. If you object on reasonable data protection grounds, we will work with you in good faith to resolve the objection, and if we cannot, you may cancel without penalty.

6. Security

We implement and maintain appropriate technical and organisational measures designed to protect Personal Information against unauthorised access, loss or alteration, taking into account the nature of the processing and the risks involved. Measures include access controls and authentication, encryption in transit, encryption at rest with our hosting providers, logging, vendor review and incident response procedures.

Breach notification. If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of Personal Information we Process on your behalf, we will notify you without undue delay and give you the information you reasonably need to meet your own notification obligations.

7. Consumer requests and assistance

Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to consumer rights requests under Applicable Privacy Laws. Where a request is submitted directly to us, we will instruct the requester to contact you, unless we are legally required to respond directly.

8. Data retention and deletion

We retain Personal Information only as long as necessary to provide the Services and as described in our Privacy Policy. On termination of the Services, or on your written request, and subject to legal retention requirements, we will delete or return the Personal Information in our possession. Client Content is retained for 30 days after termination so that you can export it, as described in the Terms.

9. Audits

On reasonable written request, and not more than once a year unless a regulator requires otherwise, we will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security practices or completed security questionnaires. Where an on-site audit is required by Applicable Privacy Laws, it will be conducted during business hours, with reasonable advance notice, and subject to confidentiality and security controls.

10. International transfers

Personal Information may be Processed in the United States. If we transfer Personal Information across borders where the law requires safeguards, we will implement the appropriate safeguards described in our agreement or otherwise required by Applicable Privacy Laws.

11. Liability

Liability arising from our Processing of Personal Information under this DPA is subject to the limitations and exclusions in your agreement with us, except where Applicable Privacy Laws prohibit that limitation. Nothing in this DPA limits either party's own direct obligations under Applicable Privacy Laws.

12. Contact

For questions about this DPA or our Processing of Personal Information on your behalf:

Delegated AI Inc
Delegated AI Inc, 1130 Ogletown Road, Suite 2, #2749, Newark, DE 19711, USA
Email: care@growthxl.ai

Questions about this page? Email care@growthxl.ai.