Liles Automation Legal Center
Data Processing

Data Processing Addendum

Last updated June 12, 2026 · Effective June 12, 2026

What this is: When Atlas handles your leads' and customers' personal data, you are the controller and we are your processor. This Addendum (“DPA”) sets the rules we follow with that data. It forms part of your Master Services Agreement. A countersigned copy is available on request.

1. Definitions

“Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” have the meanings given under applicable data-protection law, including the EU/UK GDPR and the California Consumer Privacy Act as amended (“CCPA”). “Client” means the customer that has engaged Liles Automation. “Sub-processor” means a third party engaged by us to process Personal Data.

2. Roles

For Personal Data that Atlas processes on the Client's behalf, the Client is the Controller and Liles Automation is the Processor. Where the CCPA applies, Liles Automation acts as a service provider and does not sell or share Personal Data, and does not retain, use, or disclose it for any purpose other than performing the Services.

3. Scope & instructions

We process Personal Data only to provide the Services and only on the Client's documented instructions (including those in the MSA, the SOW, and the Client's configuration of Atlas), unless required by law — in which case we will tell the Client first unless the law forbids it. The subject matter, duration, nature, and purpose of processing, and the categories of data and data subjects, are described in Annex A below.

4. Confidentiality

We ensure that anyone authorized to process Personal Data is bound by appropriate confidentiality obligations and processes the data only as instructed.

5. Security

We implement and maintain appropriate technical and organizational measures to protect Personal Data, including encryption in transit and at rest, OAuth-based authorization (no stored Client passwords), least-privilege access controls, segregation between Clients, and an operational kill switch. Details are summarized on our Trust & Security page.

6. Sub-processors

The Client gives general authorization for us to engage the Sub-processors listed on our Sub-processors page to help provide the Services. We impose data-protection obligations on each Sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give notice of intended changes to Sub-processors and allow a reasonable opportunity to object on legitimate data-protection grounds.

7. Data-subject requests

Taking into account the nature of the processing, we will help the Client respond to requests from data subjects to exercise their rights (access, correction, deletion, portability, objection). If a data subject contacts us directly, we will refer them to the Client unless legally required to act.

8. Personal-data breaches

We will notify the Client without undue delay after becoming aware of a Personal Data breach affecting the Client's data, and will provide the information reasonably available to help the Client meet its own notification obligations.

9. Deletion & return

On termination of the Services, and at the Client's choice, we will delete or return the Client's Personal Data within a reasonable period, and delete existing copies unless law requires retention. Routine backups are deleted on their normal rotation.

10. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable advance notice and no more than once per year (or after a breach), allow the Client to verify compliance through a documentation review, subject to confidentiality.

11. International transfers

Personal Data is processed in the United States. Where data is transferred from the EEA, UK, or Switzerland, the parties will rely on a lawful transfer mechanism (such as the Standard Contractual Clauses), which are incorporated by reference where applicable.

12. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms and the MSA.

Annex A — Details of processing

Subject matterProvision of AI-assisted operations automation (Atlas) to the Client.
DurationThe term of the engagement, plus the deletion/return period in Section 9.
Nature & purposeReceiving, storing, organizing, generating messages from, and transmitting Personal Data to operate lead response, follow-up, reactivation, scheduling, document processing, and reporting.
Categories of data subjectsThe Client's leads, prospects, customers, and the Client's own staff/contacts.
Categories of Personal DataName, phone number, email address, mailing/property address, job and estimate details, message content, and communication history.
Special categoriesNone intended. The Client agrees not to submit special-category data unless expressly provided for in the SOW.

Contact

Liles Automation · 11700 Mukilteo Speedway, Ste 201-4039, Mukilteo, WA 98275 · eric@lilesautomation.com