How Blinker, Inc. processes Consumer personal information on behalf of each Client. This Addendum is incorporated into and forms part of the Master Services Agreement.
This Data Processing Addendum (the “DPA”) is entered into between Blinker, Inc., a Colorado corporation with offices at 220 S. Wilcox St. #1300, Castle Rock, CO 80104 (“Blinker”), and the Client identified on the applicable Order Form (“Client”). This DPA is incorporated into and forms part of the Master Services Agreement (the “MSA”) between the parties and governs Blinker's processing of Consumer personal information on Client's behalf in connection with the Services. Capitalized terms not defined here have the meanings given in the MSA.
1.1 “Personal Information” means information relating to an identified or identifiable individual that Blinker processes on Client's behalf under the MSA, as defined under applicable U.S. privacy laws.
1.2 “Controller / Business” means the party that determines the purposes and means of processing Personal Information. As between the parties, Client is the Controller / Business.
1.3 “Processor / Service Provider” means the party that processes Personal Information on behalf of, and under the instructions of, the Controller / Business. Blinker is the Processor / Service Provider.
1.4 “Consumer” / “Data Subject” means an individual to whom Personal Information relates, including Client's prospects, leads, and customers.
1.5 “Sub-Processor” means a third party engaged by Blinker to process Personal Information in connection with the Services.
1.6 “Applicable Privacy Laws” means U.S. federal and state privacy and data-protection laws that apply to the processing, including the CCPA/CPRA and comparable state laws, and, where applicable, the Gramm-Leach-Bliley Act.
2.1 Allocation of roles. Client is the Controller / Business for Consumer Personal Information it submits to or generates through the Services. Blinker processes that Personal Information as a Processor / Service Provider solely on Client's documented instructions, which include the MSA, this DPA, and Client's use of the Services.
2.2 Restrictions on Blinker. Blinker will not: (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than performing the Services, or outside the direct business relationship between the parties; (c) combine Personal Information with information from other sources except as permitted by Applicable Privacy Laws to perform the Services; or (d) use Personal Information for its own commercial purposes. Blinker certifies that it understands and will comply with these restrictions.
3.1 Blinker processes Personal Information only as needed to provide, maintain, secure, and support the Services and the Products, and to facilitate the interactions between Client, its Consumers, and Partners contemplated by the MSA. The subject matter, nature, purpose, and duration of processing, the categories of Data Subjects, and the categories of Personal Information are described in Section 4.
4.1 The following table describes the processing carried out under this DPA.
| Element | Details |
|---|---|
| Categories of Data Subjects | Client's Consumers — prospects, leads, and customers — whom Client engages through the Services. |
| Categories of Personal Information | Identifiers and contact details (name, phone, email, address); vehicle information (year, make, model, mileage, VIN); existing loan, coverage, and protection details; quote, application, and enrollment data; call and text-message metadata and, where enabled by Client, recordings and message content; and, where applicable, certain financial information subject to the GLBA. |
| Nature & Purpose of Processing | Hosting, storing, transmitting, organizing, and otherwise processing Personal Information to operate the platform; enable Client outreach to Consumers; facilitate quotes, applications, and enrollments for Products; route information to Partners; and provide support, security, and related services. |
| Duration of Processing | For the term of the MSA and the applicable Order Form, plus the transition and deletion periods described in Section 12 and the MSA, unless a longer period is required by law. |
5.1 Lawful basis and notices. Client is responsible for establishing a lawful basis for the processing, for providing all required privacy notices to Consumers, and for the accuracy and lawfulness of the Personal Information it submits.
5.2 Consents. Client is responsible for obtaining and maintaining all consents and authorizations required to process Consumer Personal Information and to contact Consumers, including consents for calls, texts, and recordings. These obligations are further set out in the Telemarketing & TCPA Compliance Addendum.
5.3 Instructions. Client's instructions to Blinker will comply with Applicable Privacy Laws. Client will not instruct Blinker to process Personal Information in a manner that would violate those laws.
6.1 Documented instructions. Blinker will process Personal Information only on Client's documented instructions, except where required by law, in which case Blinker will inform Client unless legally prohibited.
6.2 Confidentiality. Blinker will ensure that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations.
6.3 Security. Blinker will implement and maintain the technical and organizational security measures described in Section 9.
6.4 Assistance. Taking into account the nature of the processing, Blinker will provide reasonable assistance to Client in responding to Consumer rights requests (Section 8) and in meeting Client's security, breach-notification, and consultation obligations under Applicable Privacy Laws.
6.5 Breach notification. Blinker will notify Client without undue delay after becoming aware of a confirmed breach of security leading to the unauthorized access, disclosure, or loss of Personal Information, and will provide information reasonably available to Blinker to help Client meet its notification obligations.
7.1 General authorization. Client authorizes Blinker to engage Sub-Processors — including hosting and infrastructure providers and Partners — to process Personal Information in connection with the Services.
7.2 Flow-down and responsibility. Blinker will impose data-protection obligations on each Sub-Processor that are substantially similar to those in this DPA, and Blinker remains responsible for its Sub-Processors' performance of those obligations.
7.3 Changes. Blinker will make available a means for Client to learn of Sub-Processors and, on reasonable request, information about material changes.
8.1 As Controller / Business, Client is responsible for responding to Consumer requests to exercise their rights (such as access, deletion, correction, portability, and opt-out). If Blinker receives such a request directly, it will, where permitted, direct the Consumer to Client. Blinker will provide reasonable assistance to enable Client to fulfill verified requests, taking into account the nature of the processing.
9.1 Blinker maintains a written information-security program with technical and organizational measures appropriate to the risk, including: (a) role-based access controls and least-privilege access to Personal Information; (b) encryption of Personal Information in transit; (c) authentication controls and logging for access to production systems; (d) network and application safeguards and vulnerability management; and (e) personnel security and confidentiality obligations. Blinker may update these measures provided the level of protection is not materially reduced.
10.1 Blinker processes and stores Personal Information in the United States. Blinker will not transfer Personal Information outside the United States without Client's prior authorization and appropriate safeguards required by Applicable Privacy Laws.
11.1 On reasonable prior written notice, no more than once per year (unless required by a regulator or following a confirmed breach), and subject to confidentiality and to reasonable limits on scope, timing, and duration, Blinker will make available information reasonably necessary to demonstrate compliance with this DPA. Blinker may satisfy audit requests by providing then-current third-party audit reports or security summaries where available. Audits will not unreasonably disrupt Blinker's operations or compromise the confidentiality or security of other customers' data.
12.1 On termination or expiration of the MSA, Blinker will make Personal Information available for export and will delete or de-identify Personal Information in accordance with the transition and data-export provisions of the MSA (Section 6 of the MSA), subject to retention required by law and to routine backup cycles. Copies retained in backups will be protected in accordance with this DPA until deleted in the ordinary course.
13.1 Liability. Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the MSA, and any reference in the MSA to a party's liability means the aggregate liability of that party under the MSA and this DPA together.
13.2 Order of precedence. This DPA forms part of the MSA. In the event of a conflict between this DPA and the rest of the MSA regarding the processing of Personal Information or other data-protection matters, this DPA controls. In all other respects, the MSA remains in full force and effect.
← Back to Legal