← Elite Advisor AI
Data Processing Agreement
Last updated August 2, 2026

Elite Advisor AI — Data Processing Agreement (DPA)

Effective Date: July 29, 2026 Last Updated: August 18, 2026

⚠️ Attorney Review Required. A Data Processing Agreement carries significant legal obligations. Have a licensed attorney specializing in privacy law review this document before it governs any live customer data.


Parties

This Data Processing Agreement ("DPA") is entered into between:

Data Controller: You, the individual service advisor subscriber ("Advisor," "Controller," "you")

Data Processor: Elite AI Services LLC, a California limited liability company ("Company," "Processor," "we," "us")

This DPA is incorporated into and forms part of the Elite Advisor AI Terms of Service. By using the Service to store or process customer personal information, you agree to this DPA.


1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to a dealership customer's name, phone number, vehicle information, and service history.

"Processing" means any operation performed on Personal Data, including collection, storage, use, retrieval, disclosure, deletion, or destruction.

"Data Subject" means the individual to whom Personal Data relates — in this context, the dealership customer whose information the Advisor enters into the Service.

"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

"Data Breach" means any unauthorized access, disclosure, alteration, or destruction of Personal Data.

"Services" has the meaning given in the Terms of Service.


2. Nature and Purpose of Processing

2.1 Subject Matter

The Processor will process Personal Data on behalf of the Controller solely to provide the Elite Advisor AI coaching Service, as described in the Terms of Service.

2.2 Duration

Processing will occur for the duration of the Controller's active subscription, or until the Controller instructs the Processor to delete the data, whichever comes first.

2.3 Nature of Processing

The Processor will store, retrieve, and process Personal Data to:

  • Display pseudonymized customer records (initials + RO number) within the Advisor's account
  • Generate AI-assisted coaching scripts and suggested messages using customer context during active sessions
  • Schedule and track follow-up reminders
  • Provide coaching context during live call and SMS coaching sessions
  • Post-session transcript redaction: At the conclusion of each SMS or call coaching session, the Processor will pass the session transcript through an automated AI-based redaction process (via Anthropic's Claude API) that replaces all customer names and phone numbers with anonymized placeholders before the transcript is written to the database. No unredacted transcript is stored.

2.4 Types of Personal Data Processed

The Processor uses a pseudonymized data model. The following represents the full scope of customer-related data stored in the Processor's database:

  • Customer initials (e.g., "J.M.") — full name is never stored
  • RO number — dealership reference used by the Advisor to retrieve full customer details from their own DMS
  • Vehicle information: Year, Make, and Model only — VIN is not stored
  • Redacted conversation transcripts — all customer names and phone numbers are algorithmically removed before storage
  • Service history and interaction notes entered by the Advisor
  • Follow-up dates and status
  • Consent records (opt-in date, method, opt-out) — retained permanently

Data processed in active memory only (never written to database):

  • Customer full name (used for personalization during active session)
  • Customer phone number (used for SMS delivery via Twilio during active session)

2.5 Categories of Data Subjects

Dealership customers whose information is entered into the Service by the Advisor.


3. Controller's Obligations

The Controller (Advisor) agrees to:

3.1 Lawful Basis. Process Personal Data only where there is a lawful basis to do so, and ensure that Data Subjects have been provided appropriate notice and, where required, have given consent for their data to be stored in a third-party coaching application.

3.2 TCPA Compliance. Obtain documented, prior express written consent from any Data Subject before using their phone number to send marketing or promotional text messages. Maintain records of such consent and make them available upon request.

3.3 Accuracy. Ensure that Personal Data entered into the Service is accurate and limited to what is necessary for the coaching purpose.

3.4 Instructions. Issue lawful written instructions to the Processor regarding the processing of Personal Data. The Terms of Service and this DPA constitute the Controller's primary instructions.

3.5 Data Subject Rights. Respond to Data Subject requests regarding their Personal Data in a timely manner, using any assistance provided by the Processor.

3.6 Dealership Policies. Ensure that use of the Service complies with your dealership's data privacy policies and any applicable manufacturer or dealer agreements.


4. Processor's Obligations

The Processor (Elite AI Services LLC) agrees to:

4.1 Process Only on Instructions. Process Personal Data only in accordance with the Controller's documented instructions as set out in these Terms and this DPA, unless required to do so by applicable law.

4.2 No AI Model Training. Not use Personal Data entered by the Controller — including customer names, phone numbers, vehicle information, or session inputs — to train, fine-tune, or improve any AI or machine learning model, whether operated by the Processor or any third party. Inputs sent to Anthropic's Claude API for the purpose of generating coaching responses are governed by Anthropic's API usage policies, which prohibit the use of API inputs for model training without explicit consent.

4.3 Confidentiality. Ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

4.4 Security. Implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, as described in Section 6 of this DPA.

4.5 Sub-processors. Not engage additional sub-processors to process Personal Data without informing the Controller, except as listed in Section 5 of this DPA.

4.6 Assistance with Rights. Provide reasonable assistance to the Controller in responding to Data Subject rights requests (access, correction, deletion, portability).

4.7 Deletion or Return. Upon termination of the subscription or upon written request from the Controller, delete or return all Personal Data within 30 days, and delete existing copies unless retention is required by law.

4.8 Audit Assistance. Provide the Controller with information reasonably necessary to demonstrate compliance with this DPA.

4.9 Breach Notification. Notify the Controller without undue delay, and in any event within 72 hours, upon becoming aware of a Data Breach affecting Personal Data processed under this DPA.


5. Sub-processors

The Controller authorizes the Processor to use the following sub-processors:

| Sub-processor | Purpose | Location | |---|---|---| | Anthropic, PBC | AI coaching content generation and post-session transcript redaction. Processes session context in active memory; does not retain data for model training under API agreement. | United States | | Twilio Inc. | SMS message delivery. Message Redaction is enabled — message body and phone numbers are cleared from Twilio's systems within 24 hours of delivery. | United States | | Stripe, Inc. | Subscription payment processing. Handles billing data only; has no access to customer interaction data. | United States | | Supabase, Inc. | Cloud database (Postgres) for persistent storage of advisor and pseudonymized customer records. Hosted on AWS infrastructure in the United States. | United States | | Vercel, Inc. | Application hosting and delivery. Processes requests in transit; does not store Personal Data. | United States |

The Processor will notify the Controller of any intended changes to this list of sub-processors with reasonable advance notice. All sub-processors are contractually bound to protect Personal Data to a standard no less protective than this DPA.


6. Security Measures

The Processor maintains the following technical and organizational security measures:

  • Encryption in transit: All data transmitted between the application and servers is encrypted using TLS 1.2 or higher
  • Encryption at rest: Personal Data stored in the cloud database is encrypted at rest
  • Access controls: Access to Personal Data is limited to personnel who require it to provide the Service
  • Authentication: User accounts are protected by password authentication with industry-standard hashing
  • Vulnerability management: Regular review of known security vulnerabilities in application dependencies
  • Incident response: A documented process for identifying, containing, and reporting Data Breaches

7. Data Breach Notification

7.1 Processor Notification to Controller

Upon discovering a Data Breach affecting Personal Data processed under this DPA, the Processor will notify the Controller within 72 hours with the following information, to the extent available:

  • Nature of the Data Breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the Data Breach
  • Measures taken or proposed to address the breach

7.2 Controller's Obligations

The Controller is responsible for notifying affected Data Subjects and any applicable regulatory authorities as required by law (including California's data breach notification law, Cal. Civ. Code § 1798.82, if applicable). The Processor will cooperate reasonably with the Controller in connection with any such notifications.


8. Data Subject Rights

8.1 Requests Submitted to Processor

If a Data Subject submits a rights request directly to the Processor (e.g., requesting deletion of their personal information), the Processor will:

  • Notify the Controller within 5 business days of receiving the request
  • Not respond directly to the Data Subject without the Controller's authorization, except to acknowledge receipt and direct the Data Subject to contact the Controller
  • Assist the Controller in fulfilling the request

8.2 Request Types

The Processor will assist the Controller in fulfilling requests for:

  • Access: Providing a copy of Personal Data stored in the Service for a specific Data Subject
  • Correction: Updating inaccurate Personal Data
  • Deletion: Permanently deleting a Data Subject's Personal Data from the Service
  • Portability: Exporting Personal Data in a structured, machine-readable format

9. Transfers of Personal Data

All Personal Data processed under this DPA is stored and processed in the United States. If you are located in or processing data of individuals in a jurisdiction with cross-border data transfer restrictions, you are responsible for ensuring such transfers comply with applicable law. Contact jorge@eliteadvisorai.com to discuss data residency requirements.


10. Term and Termination

This DPA is effective for the duration of the Controller's subscription to the Service. It terminates automatically upon termination or expiration of the Terms of Service. Upon termination:

  • The Processor will delete all Personal Data within 30 days unless legally required to retain it
  • The Processor will certify deletion in writing upon request
  • Obligations of confidentiality and security that arose during the term of this DPA continue to apply

11. Limitation of Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA is intended to limit either party's liability for fraud, gross negligence, or willful misconduct.


12. Governing Law

This DPA is governed by the laws of the State of California, consistent with the Terms of Service.


13. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to data processing matters only. In all other respects, the Terms of Service control.


14. Contact

For questions related to this Data Processing Agreement:

Elite AI Services LLC Attn: Data Privacy jorge@eliteadvisorai.com eliteadvisorai.com


This Data Processing Agreement was last updated on August 18, 2026.