Data Processing Agreement

    Version 2026-06-15

    This Data Processing Agreement ("DPA") forms part of the agreement between Four49 Media LLC ("Processor," "we," "us"), trading as Next Day Sales, and the customer that has accepted our Terms of Service (the "Controller" or "you"). This DPA reflects the parties' agreement on the processing of Personal Data submitted to the Service in connection with use of Next Day Sales.

    1. Definitions

    Capitalized terms not defined here have the meanings given in the GDPR (Regulation (EU) 2016/679) and the UK GDPR. "Personal Data," "Controller," "Processor," "Data Subject," and "Processing" carry their GDPR meanings. "Customer Personal Data" means Personal Data that we process on your behalf in providing the Service — primarily, the contact details and messages of leads who fill out forms on your sites or pricing tables.

    2. Role of the parties

    • You are the Controller of all Personal Data submitted by visitors and leads to your workspace, sites, proposals, and lead-capture forms.
    • We are the Processor acting on your documented instructions — namely, your use of the Service via its standard configuration.
    • We are an independent Controller only with respect to data we collect about you as a paying customer (billing details, account info, app usage analytics) — that is governed by the Privacy Policy, not this DPA.

    3. Subject matter and duration

    We process Customer Personal Data for the duration of your subscription, plus any retention period configured in your workspace (default 12 months for leads, 6 months for analytics). The subject matter is the operation of the Service — hosting pricing tables, capturing leads, sending notifications, and providing analytics.

    4. Nature and purpose of processing

    We process Customer Personal Data to: (a) deliver the Service; (b) send transactional emails on your behalf (lead notifications, auto-replies); (c) provide analytics and reporting; (d) maintain security and availability; (e) comply with legal obligations.

    5. Types of Personal Data and categories of Data Subjects

    • Types of data: name, email address, phone number, free-text messages, IP address, user agent, browser session identifiers, page visit history on your sites, selected plans/quotes.
    • Categories of data subjects: your prospects and leads, your customers, visitors to your hosted sites and pricing tables.
    • Special-category data: not processed. You agree not to submit health data, biometric data, or any data subject to HIPAA, GLBA, or comparable sectoral laws through the Service (see ToS §"Prohibited Data").

    6. Your instructions

    We process Customer Personal Data only as instructed by you through the Service, and as required by law. Your configuration (notification recipients, retention settings, privacy policy URL, etc.) constitutes documented instructions. We will notify you if we believe an instruction violates applicable data protection law.

    7. Sub-processors

    You authorize us to engage sub-processors. The current list is published at /legal/subprocessors. We will give at least 30 days' notice of any new sub-processor (via in-app notice and email). You may object on reasonable data-protection grounds; if we cannot accommodate the objection, you may terminate the affected portion of the Service for a pro-rated refund. We impose data-protection obligations on each sub-processor that are no less protective than this DPA.

    8. Data Subject Rights

    We will assist you in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection). You can also direct Data Subjects to our public self-serve form at /privacy-request — we verify the requester's email and route the request to the workspaces that hold matching lead data.

    9. Security

    We implement appropriate technical and organizational measures, including: encryption in transit (TLS 1.2+) and at rest, role-based access control, row-level security in our database, audit logging of administrative actions, regular dependency scanning, and least-privilege service accounts. A full list of measures is at Annex II below.

    10. Personal data breaches

    We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with sufficient detail to allow you to meet your own notification obligations under Article 33 GDPR.

    11. International transfers

    Customer Personal Data is hosted in the United States. Where you or your Data Subjects are in the EEA, UK, or Switzerland, transfers are governed by the EU Standard Contractual Clauses (Module 2: Controller to Processor) and the UK International Data Transfer Addendum, which are incorporated by reference into this DPA. We rely on supplementary measures (encryption, access controls, transparency reporting) consistent with the EDPB Schrems II guidance.

    12. Deletion and return

    On termination of your subscription, we will delete or return Customer Personal Data within 30 days, unless retention is required by law. You can also trigger workspace-scoped deletion at any time from Settings → Privacy.

    13. Audits

    We make available all information necessary to demonstrate compliance with this DPA. You may request an audit no more than once per year, at your expense, on reasonable notice, subject to mutually agreed scope and confidentiality. Industry-standard third-party audit reports (e.g. SOC 2) will satisfy this obligation if available.

    14. Liability and term

    This DPA forms part of the Terms of Service. The liability limitations in the Terms apply to this DPA. This DPA terminates automatically when the Terms terminate, except for clauses that survive by their nature.

    Annex I — Processing details

    • Categories of Data Subjects: as listed in §5.
    • Categories of Personal Data: as listed in §5.
    • Sensitive data: none (see §5 and ToS Prohibited Data).
    • Frequency: continuous, while you use the Service.
    • Nature of processing: collection, storage, organization, structuring, retrieval, transmission, deletion.
    • Purpose: as listed in §4.
    • Retention: per workspace settings (default 12 months for leads, 6 months for analytics); plus 30-day termination grace period.
    • Sub-processor transfers: all sub-processors are in the United States; SCCs apply where required.

    Annex II — Technical and organizational measures

    • Encryption in transit (TLS 1.2+) on all customer-facing endpoints.
    • Encryption at rest for the primary database and storage.
    • Row-level security on all customer-data tables; workspace isolation enforced by the database.
    • Multi-factor authentication available on customer accounts; required for staff accounts.
    • Least-privilege access for staff; production database access is audited.
    • Automated dependency vulnerability scanning.
    • Daily encrypted backups with point-in-time recovery.
    • Incident response runbook with 72-hour breach notification target.
    • Vendor security review prior to sub-processor onboarding.

    Staff access to Customer Personal Data

    Next Day Sales staff do not read, export, or otherwise access Customer Personal Data (including leads, contacts, deals, and submission payloads) in the course of normal operations. Staff access is permitted only in the following narrow circumstances:

    • Support: when a Customer submits a support request that cannot be resolved without inspecting the affected records, and only for the records strictly necessary to resolve the request.
    • Abuse, fraud & security investigations: to investigate suspected violations of the Terms of Service, abuse of the platform, or active security incidents.
    • Legal compulsion: in response to a valid legal process (subpoena, court order) after we have notified the Customer where lawfully permitted to do so.

    All such access is performed by authorized personnel under confidentiality obligations, is logged, and is reviewable on Customer request. Direct production-database queries by staff are restricted to a limited admin group, MFA-enforced, and recorded.

    Annex III — Sub-processors

    The current list of sub-processors is maintained at /legal/subprocessors.

    By using the Service, you are deemed to have entered into this DPA on the date you accepted the Terms of Service. For a counter-signed copy, contact privacy@nextdaysales.com.