Data Processing Agreement
Effective Date: June 25, 2026
Last Updated: June 25, 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the DealOracle Terms of Service (the "Agreement") between DealOracle (Supreme Score LLC) ("DealOracle," "we," "us") and the customer that uses the service (the "Customer," "you"). It governs DealOracle's processing of personal data relating to the Customer's leads, contacts, and website visitors ("Lead Data") that DealOracle processes on the Customer's behalf. Capitalized terms not defined here have the meaning given in the Agreement and our Privacy Policy.
1. Parties and Roles
This DPA allocates data-protection roles between the parties for Lead Data:
- Customer as Controller: For Lead Data, the Customer is the data controller (or "business" under U.S. privacy laws). The Customer determines the purposes and means of processing and is responsible for establishing a lawful basis, providing required notices, and honoring opt-outs.
- DealOracle as Processor: For Lead Data, DealOracle is the data processor (or "service provider"). DealOracle processes Lead Data only on the Customer's documented instructions and only to provide the service.
For the Customer's own account, platform, billing, and marketing data, DealOracle is the controller and processes that data as described in our Privacy Policy. That processing is outside the scope of this DPA.
2. Subject Matter, Duration, Nature, and Purpose of Processing
- Subject matter: DealOracle's processing of Lead Data to provide the marketing-attribution and lead-management services described in the Agreement.
- Duration: Processing continues for the term of the Agreement and until Lead Data is deleted or returned in accordance with Section 8.
- Nature and purpose: Collecting, organizing, storing, analyzing, and transmitting Lead Data to provide conversion tracking, attribution reporting, lead management, and related analytics, including the transmission of hashed identifiers to advertising platforms for conversion measurement on the Customer's instruction.
The categories of data subjects and personal data are described in Annex I.
3. Processor Obligations
DealOracle will:
- Process Lead Data only on the Customer's documented instructions, including with respect to international transfers, unless required to do otherwise by applicable law (in which case we will inform the Customer, unless legally prohibited).
- Promptly inform the Customer if, in our opinion, an instruction infringes applicable data-protection law.
- Ensure that personnel authorized to process Lead Data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organizational measures to protect Lead Data, as described in Annex II.
- Assist the Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting the Customer's obligations regarding security, breach notification, and data-protection impact assessments.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-Processors
The Customer provides a general authorization for DealOracle to engage sub-processors to support the service. DealOracle will impose data-protection obligations on each sub-processor that are substantially similar to those in this DPA, and remains responsible for its sub-processors' performance.
Our current sub-processors are the third-party processors listed in the "Sub-Processors" section of our Privacy Policy and summarized in Annex IV. We will provide the Customer with at least 30 days' prior notice of any addition or replacement of a sub-processor, giving the Customer an opportunity to object on reasonable data-protection grounds.
Customer-controlled sources are not sub-processors. Connected CRMs and landing-page providers (for example, GoHighLevel (LeadConnector), HubSpot, Salesforce, Pipedrive, Podio, Unbounce, and Heyflow) are lead sources controlled by the Customer, not DealOracle sub-processors. The Customer's own agreement with each provider governs that processing. Microsoft Clarity is used for anonymized usability analytics on DealOracle's own website as a controller-side measure and is not a sub-processor of Lead Data.
5. Assistance with Data-Subject Requests
Taking into account the nature of the processing, DealOracle will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights (such as access, rectification, erasure, restriction, portability, and objection). If a data subject contacts DealOracle directly regarding Lead Data, we will, where lawful, refer the request to the relevant Customer and assist that Customer in responding.
6. Personal Data Breach Notification
DealOracle will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Lead Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. DealOracle will reasonably cooperate with the Customer in investigating and remediating the breach.
7. Security
DealOracle implements and maintains appropriate technical and organizational measures designed to protect Lead Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures, including the one-way SHA-256 hashing of identifiers before transmission to advertising platforms, are described in Annex II.
8. Deletion or Return of Lead Data
On termination or expiry of the Agreement, DealOracle will, at the Customer's choice, delete or return the Lead Data it processes on the Customer's behalf, and delete existing copies, unless applicable law requires continued storage. Lead Data held in routine backups is deleted in accordance with our backup-rotation schedule.
9. International Data Transfers
Where DealOracle processes Lead Data originating from the European Economic Area, the United Kingdom, or Switzerland and transfers it to a country that does not benefit from an adequacy decision, the transfer is protected by an appropriate safeguard:
- EEA: the European Commission's Standard Contractual Clauses (SCCs), Module Two (controller to processor), which are incorporated by reference and completed as set out in Annex III.
- United Kingdom: the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs.
- Switzerland: the SCCs as amended for use under the Swiss Federal Act on Data Protection.
The details required to complete these transfer mechanisms are set out in Annex III.
10. CCPA / CPRA (Service Provider)
To the extent DealOracle processes Lead Data that is personal information subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), DealOracle acts as a "service provider." DealOracle does not sell or share Lead Data, does not retain, use, or disclose Lead Data for any purpose other than performing the services specified in the Agreement, and does not combine Lead Data with personal information received from other sources except as permitted by the CCPA/CPRA. DealOracle certifies that it understands and will comply with these restrictions.
Annex I: Categories of Data Subjects and Personal Data
Categories of Data Subjects
The Customer's own leads, contacts, and website visitors.
Categories of Personal Data
Lead Data may include: name, email address, phone number, postal address, city, state, ZIP or postal code, country, and, where the Customer provides them, date of birth and gender. From website visitors we may also process an anonymous visitor identifier, session identifier, IP address, browser user agent, page URL and referrer, device and timezone signals, advertising click identifiers (such as Google gclid, Meta fbclid, and equivalents for TikTok, Microsoft, Snapchat, Pinterest, LinkedIn, Reddit, and X), Meta browser cookies (_fbp and _fbc), and UTM campaign parameters.
Frequency and Duration
Processing is continuous for the term of the Agreement and until deletion or return under Section 8.
Annex II: Technical and Organizational Security Measures
- Industry-standard encryption for data in transit and at rest.
- One-way SHA-256 hashing of personal identifiers (such as email addresses, phone numbers, and names, and, where used, postal fields, date of birth, and gender) before transmission to advertising platforms for conversion measurement. Hashing is performed after normalization so that the platform receives an irreversible token rather than the raw value.
- Role-based access controls and access limited on a need-to-know basis, with multi-factor authentication.
- Confidentiality obligations for personnel authorized to process Lead Data.
- Regular security audits, vulnerability assessments, and logging and monitoring.
- Incident-response and breach-notification procedures consistent with Section 6.
Annex II describes the measures in effect as of the date of this DPA; specific controls may evolve, provided the overall level of protection is not reduced.
Annex III: International Transfer Details
- Data exporter: the Customer (controller of Lead Data).
- Data importer: DealOracle (Supreme Score LLC), acting as processor.
- Module: EU SCCs, Module Two (controller to processor).
- Docking clause: applicable. Governing law / forum: as completed in the executed SCCs.
- UK transfers: the UK IDTA or the UK Addendum to the SCCs applies.
- Swiss transfers: the SCCs apply as amended for use under Swiss law, with the Swiss Federal Data Protection and Information Commissioner as the competent authority.
- Subject matter, categories, and security measures: as described in Annexes I and II.
Annex IV: Sub-Processors
DealOracle's current sub-processors are the third-party processors listed in the "Sub-Processors" section of our Privacy Policy, which include Supabase, Vercel, Stripe, Google, Meta, TikTok, Microsoft, Snapchat, Pinterest, and OpenAI, each processing personal data only as needed for its function. That list is incorporated here by reference and may be updated subject to the 30-day prior-notice commitment in Section 4. Customer-connected CRMs and landing-page providers are lead sources controlled by the Customer, not DealOracle sub-processors.
Executing a Signed DPA
This page is a template that describes the data-processing terms that apply to DealOracle's processing of Lead Data. If your organization requires a signed, countersigned DPA (for example, to satisfy GDPR or a procurement requirement), please contact us and we will execute one with you.
DealOracle (Supreme Score LLC)
Email: [email protected]
Address: 1944 Whitley Ave, Los Angeles, CA 90068
We will respond to inquiries within 30 days.
