Data Processing Addendum
Customer Personal Data processing terms · Version 2026-10-01
Document version 2026-10-01 · Novi Most LLC · Texas, United States
Scope and definitions
This Data Processing Addendum (DPA) is incorporated into the Novi Most Terms of Service and signed Order Form when Novi Most processes personal information in Customer Data on Customer's behalf. It applies only to that processing. Customer Personal Data means personal information within Customer Data processed by Novi Most for Customer, including End Client names, contact information, property addresses, reports, and estimates. Data Protection Law means a U.S. federal or state privacy, security, or breach-notification law applicable to the processing. Subprocessor means a third party engaged by Novi Most to process Customer Personal Data on Novi Most's behalf.
This is a U.S. business-to-business processing arrangement for the use described in the Agreement. It does not supply international transfer terms, certify compliance with a particular privacy regime, or authorize unsupported sensitive or regulated information. The parties must agree in writing on appropriate additional terms before using the Service for processing that requires such commitments.
Roles, instructions, and Customer duties
Customer determines the purposes and essential means for its Customer Personal Data and is responsible for a lawful basis to collect, submit, and use it, the accuracy of information, notices and consents to individuals, and responding to data-subject requests. Customer is responsible for its messaging consent and compliance. Novi Most processes Customer Personal Data only to provide, secure, maintain, troubleshoot, and support the Service, follow Customer's instructions through use of the Service or a written support request, and comply with law. If Novi Most reasonably believes an instruction violates applicable law, it may notify Customer and decline the instruction.
Novi Most processing commitments
Novi Most will not sell Customer Personal Data, use it for targeted advertising, or use it for a purpose unrelated to providing the Service except as permitted by law. Novi Most will not train a general-purpose or third-party AI model on Customer Personal Data without Customer's separate written opt-in. It will limit access to personnel with a business need to provide or support the Service and require appropriate confidentiality obligations. Novi Most will use reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data, as described in the Security Overview. These safeguards are not a guarantee against all incidents and do not promise dedicated physical infrastructure.
Novi Most will use the subprocessors listed in the version incorporated into the Order Form, including providers for hosting, database and object storage, platform analytics, billing, email, optional text messaging, and public web asset delivery as described in the Privacy Policy and Subprocessors attachment. Novi Most may make a change to its subprocessor arrangements and will provide advance notice when reasonably practicable and legally required. Customer may raise a reasonable, documented privacy or security objection by emailing admin@novimost.app. The parties will discuss a reasonable resolution in good faith. If no reasonable resolution is available, Customer may terminate the affected Service before the change takes effect and receive a pro-rated refund of prepaid unused fees.
Security incidents and assistance
Novi Most will notify Customer without undue delay after it becomes aware of a confirmed security incident involving unauthorized access to, or unlawful loss, alteration, or disclosure of, Customer Personal Data that Novi Most processes for Customer. Notice will be sent to the Customer contact on record or another contact Customer has designated. The notice will provide information then reasonably available about the incident, affected data, containment or remediation, and further updates as information becomes available. Novi Most will not delay a notice required by law. This is not an absolute promise of immediate notification within a fixed number of hours and is not an admission of fault.
Novi Most will reasonably cooperate with Customer's legally required response, taking account of information available and the nature of processing. Customer is responsible for determining and making any notice to individuals, regulators, or other parties unless applicable law assigns that duty to Novi Most. Each party will cooperate as reasonably required by applicable law.
Requests, return, and deletion
Novi Most will provide the Service's available capabilities and reasonable manual assistance, where practicable, to help Customer respond to access, correction, or deletion requests concerning Customer Personal Data. If Novi Most directly receives such a request, it will forward it to Customer unless law requires Novi Most to respond. Customer may request an export by emailing admin@novimost.app during the 30 days after the Service ends. Novi Most will make reasonable efforts to provide a usable export and then to delete or de-identify Customer Personal Data within 90 days after that export period, except for legally required retention, protected records retained for security or disputes, and backups overwritten on their normal schedule. These are manual operational commitments subject to reasonable effort, not guarantees of automated export, immediate deletion, or verified deletion from every backup. Any retained data remains subject to this DPA while retained.
Information, location, and liability
On reasonable written request no more than once annually, Novi Most will provide reasonably available written information about its relevant data protection practices. This does not include unrestricted access to systems, security-sensitive materials, other customers' information, or on-site audits. Any additional audit must be agreed in writing, scheduled reasonably, protect confidentiality and security, and be paid for by Customer unless law provides otherwise.
The Service is intended for U.S. business use. Providers may process information according to their service locations and applicable provider terms. Customer must obtain a separate written agreement before using the Service for international or regulated processing that requires additional safeguards or transfer terms.
The liability limits and damages waiver in the Terms apply to claims under this DPA, subject to the Terms' express exceptions and mandatory law. This DPA controls over the Terms only for a direct conflict about processing Customer Personal Data; it does not create unlimited liability or waive fraud, willful misconduct, gross negligence, or nonwaivable statutory rights.
Questions about this document? Contact admin@novimost.app.