Privacy Policy

Data Processing Addendum

Effective Date: July 24, 2026  Â·  Last Updated: July 24, 2026

Last Reviewed: July 24, 2026  Â·  Next Review Due: January 24, 2027


This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service (the "Terms") between Arora Edge, LLC ("Arora Edge," "we," "us," or "our") and the customer agreeing to the Terms ("you," "Client," or "your"). It governs the processing of Personal Information that Client uploads to, or generates within, the Services in connection with Section 15.2 of the Terms.

In the event of a conflict between this DPA and the Terms with respect to the processing of Personal Information, this DPA controls. All capitalized terms not defined here have the meaning given in the Terms.

1. Definitions

  • Applicable Privacy Laws — all data protection and privacy laws applicable to the processing of Personal Information under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), other comprehensive US state privacy laws, and, where applicable, the EU/UK General Data Protection Regulation ("GDPR").
  • Business, Controller, Processor, Service Provider, Sell, Share, Consumer, and Data Subject — have the meanings given under Applicable Privacy Laws.
  • Client Personal Information — Personal Information contained in Client Content that Arora Edge processes on Client's behalf under the Terms, such as the names, contact details, and lead or customer records of Client's own customers and prospects (e.g., homeowners).
  • Personal Information (or Personal Data) — any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.
  • Personal Data Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Information.
  • Process / Processing — any operation performed on Personal Information, whether or not by automated means, including collection, use, storage, disclosure, and deletion.
  • Sub-processor — a third party engaged by Arora Edge to Process Client Personal Information in connection with the Services.

2. Roles of the Parties

With respect to Client Personal Information, the parties agree that:

  • Client is the Controller / Business, and
  • Arora Edge is the Processor / Service Provider, acting on Client's documented instructions.

Each party will comply with its own obligations under Applicable Privacy Laws. Client is responsible for the accuracy, quality, and legality of Client Personal Information and for the lawful basis on which it was collected and made available to Arora Edge.

3. Scope and Instructions for Processing

3.1 Arora Edge will Process Client Personal Information only:

  • to provide, maintain, secure, and support the Services under the Terms;
  • in accordance with Client's documented lawful instructions, including those set out in this DPA, the Terms, and Client's configuration and use of the Services; and
  • as otherwise required by applicable law, in which case Arora Edge will inform Client of the legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.

3.2 The subject matter, duration, nature and purpose of the Processing, the types of Personal Information, and the categories of Data Subjects are described in Annex A.

3.3 Arora Edge will promptly notify Client if, in its opinion, an instruction from Client violates Applicable Privacy Laws, unless prohibited from doing so by law.

4. Restrictions on Processing (Service Provider / Processor Commitments)

Arora Edge will not:

  • Sell or Share Client Personal Information (as those terms are defined under CCPA/CPRA and other Applicable Privacy Laws);
  • retain, use, or disclose Client Personal Information for any purpose other than the specific purpose of performing the Services, or as otherwise permitted by Applicable Privacy Laws;
  • retain, use, or disclose Client Personal Information outside of the direct business relationship between the parties; or
  • combine Client Personal Information with Personal Information received from, or on behalf of, another party, or collected from its own interaction with the Data Subject, except as permitted by Applicable Privacy Laws to perform the Services.

Arora Edge certifies that it understands and will comply with these restrictions.

5. Confidentiality

Arora Edge will ensure that personnel authorized to Process Client Personal Information are bound by appropriate confidentiality obligations and Process the information only as necessary to provide the Services.

6. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, Arora Edge will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Client Personal Information against a Personal Data Breach. These measures are described in Annex C and may be updated from time to time provided the level of protection is not materially decreased.

7. Sub-processors

7.1 Client provides general authorization for Arora Edge to engage Sub-processors to Process Client Personal Information. The current Sub-processors are listed in Annex B.

7.2 Arora Edge will impose data protection obligations on each Sub-processor that are, in substance, no less protective than those in this DPA, and remains responsible for each Sub-processor's performance of its obligations.

7.3 Arora Edge will notify Client of any intended addition or replacement of a Sub-processor with a reasonable opportunity to object on legitimate data protection grounds. If Client reasonably objects and the parties cannot resolve the objection, Client's sole remedy is to terminate the affected Services in accordance with the Terms.

8. Data Subject Requests

8.1 Taking into account the nature of the Processing, Arora Edge will provide reasonable assistance, including through appropriate technical and organizational measures and the self-service functionality of the Platform, to help Client respond to requests from Data Subjects to exercise their rights under Applicable Privacy Laws (such as access, deletion, correction, portability, and opt-out).

8.2 If Arora Edge receives a request directly from a Data Subject relating to Client Personal Information, it will, unless legally required to respond, direct the Data Subject to Client and, where appropriate, promptly notify Client.

9. Personal Data Breach

9.1 Arora Edge will notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Client Personal Information.

9.2 The notification will describe, to the extent known and reasonably available, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it.

9.3 Arora Edge will take reasonable steps to mitigate and remediate the breach and will cooperate with Client's reasonable requests. This notification is not an acknowledgment of fault or liability.

10. Assistance and Compliance

Taking into account the nature of Processing and the information available to Arora Edge, Arora Edge will provide Client with reasonable assistance necessary for Client to comply with its obligations regarding the security of Processing, breach notification, data protection impact assessments, and prior consultation with regulators, where such obligations apply to Client under Applicable Privacy Laws.

11. Return and Deletion of Personal Information

11.1 Upon termination or expiration of the Services, Arora Edge will, at Client's election and in accordance with Section 17 of the Terms, retain Client Personal Information for a period of thirty (30) days to allow Client to export it.

11.2 After that period, Arora Edge will delete or archive Client Personal Information, except to the extent that retention is required by applicable law or for the establishment, exercise, or defense of legal claims. Personal Information retained in routine backups will be deleted in the ordinary course of Arora Edge's backup cycle.

12. Audits and Records

12.1 Arora Edge will make available to Client, on reasonable written request and no more than once per twelve (12) month period, information reasonably necessary to demonstrate compliance with this DPA.

12.2 Where Applicable Privacy Laws grant Client an audit or assessment right, that right may be satisfied by Arora Edge providing relevant policies, summaries, or third-party attestations. Any on-site inspection will be conducted during business hours, with reasonable advance notice, subject to confidentiality obligations, and in a manner that does not disrupt Arora Edge's operations.

13. International Data Transfers

If Client Personal Information originating from the European Economic Area, the United Kingdom, or Switzerland is Processed by Arora Edge, the parties agree that any legally required transfer mechanism (including the applicable Standard Contractual Clauses and the UK Addendum) is incorporated into this DPA by reference and completed with the details in Annexes A and B. The Services are otherwise operated from the United States, and Client Personal Information will be Processed in the United States.

14. Client Obligations

Client represents and warrants that it has:

  • provided all notices and obtained all consents required under Applicable Privacy Laws to make Client Personal Information available to Arora Edge and to have it Processed as described in the Terms and this DPA;
  • a lawful basis for the Processing; and
  • complied, and will continue to comply, with its own obligations as Controller / Business under Applicable Privacy Laws, including with respect to its communications sent through the Services as described in Section 15 of the Terms.

15. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to a party's liability means the aggregate liability of that party under the Terms and this DPA combined.

16. Term

This DPA takes effect on the Effective Date and remains in force for as long as Arora Edge Processes Client Personal Information under the Terms. Provisions that by their nature should survive termination will survive.

17. Order of Precedence

This DPA supplements the Terms. Except as expressly modified here, the Terms remain in full force and effect. If there is a conflict between this DPA and the Terms regarding the Processing of Personal Information, this DPA prevails.

18. Contact

Arora Edge, LLC Email: [email protected]
Phone: (406) 212-8027
Web: aroraedge.com

Annex A — Details of Processing

ItemDescription
Subject matterProvision of the Services described in the Terms (custom-built website, form integration, technical account management, automations, and automated lead delivery).
DurationFor the term of the Client's Subscription, plus the retention period described in Section 11.
Nature and purposeHosting, storing, transmitting, displaying, organizing, and otherwise Processing Client Personal Information as necessary to operate the Services and deliver leads to Client.
Types of Personal InformationNames, email addresses, phone numbers, postal addresses, form submissions, lead and inquiry details, and other identifiers Client's customers and prospects submit through Client's website or that Client uploads to the Platform.
Categories of Data SubjectsClient's own customers, prospects, and leads (e.g., homeowners and other individuals who contact or transact with Client).
Sensitive dataThe Services are not intended for the Processing of sensitive categories of Personal Information. Client should not upload such data unless expressly agreed in writing.

Annex B — Approved Sub-processors

Sub-processorPurposeLocation
HighLevel, Inc. (GoHighLevel)White-label Platform, CRM, hosting, SMS/MMS, voice, email, and automation infrastructureUnited States
Stripe, Inc.Payment processing (billing and subscription payments)United States
Google LLCWebsite analytics (Google Analytics)United States

Arora Edge may update this list in accordance with Section 7. The current list of Sub-processors is available on request.

Annex C — Technical and Organizational Security Measures

Arora Edge maintains reasonable and appropriate safeguards, including:

  • Encryption in transit for data transmitted over public networks (e.g., TLS/HTTPS).
  • Access controls limiting access to Client Personal Information to authorized personnel on a need-to-know basis, using unique credentials and, where available, multi-factor authentication.
  • Platform security through reliance on the security controls of its principal Sub-processors (GoHighLevel and Stripe), which maintain their own industry-standard security programs.
  • Vendor due diligence before engaging Sub-processors that Process Client Personal Information.
  • Confidentiality obligations binding personnel with access to Client Personal Information.
  • Breach response procedures for identifying, escalating, and responding to suspected Personal Data Breaches, as described in Section 9.

No security program can guarantee absolute security. These measures represent Arora Edge's reasonable safeguards and may be updated as described in Section 6.

Copyright Arora Edge

2026 - All Rights Reserved

We’re on a mission to build a better future where technology creates good jobs for everyone.