Legal Mentions (Mentions Légales)
Publisher:
NoFurther AI / NoFurther Systems – SAS
Registered with the Paris Trade and Companies Register (RCS) under 989 403 449
VAT Number: FR77 989 403 449
Registered Office: 46 Rue Chardon Lagache, PO Box Abi Aad, 75016 Paris, France
President: Mr. Omar Karl Abi-Aad
Directeur Général: Mr. Carl Souhait
Email: [email protected]
Phone: +1 270 260 3444
Hosting:
HighLevel Inc. (GoHighLevel)
400 North Saint Paul St., Suite 920
Dallas, Texas 75201, USA
Email: [email protected]
Privacy Policy
At NoFurther AI SAS (“we,” “NoFurther,” “our,” or “us”), protecting your personal information is a core priority. This Privacy Policy outlines how we collect, use, store, and share your data when you interact with nofurther.ai (the “Site”). We comply with all relevant privacy regulations, including the General Data Protection Regulation (GDPR) and A2P 10DLC rules for SMS communication.
1. Information We Collect
Device & Usage Data
Through our platform powered by GoHighLevel (GHL), we automatically collect:
Browser type and version
IP address and geographic time zone
Pages viewed and interaction behavior
Cookies and session tokens (e.g., session_id, ghl_visitor_id)
Tracking Technologies Used:
Cookies and session tracking
Behavioral page flow tracking
Pixel-based triggers for automation and retargeting
Form interaction and click-through monitoring
Booking & Personal Information
When you submit a form, make a booking, or interact with our Site, we collect:
Full name
Email address
Phone number (for communication via SMS, calls, or WhatsApp)
Billing address (if applicable)
2. How We Use Your Information
Your data may be used to:
- Confirm and manage bookings
-Send invoices and follow-up communications
- Personalize your experience and offer relevant services
- Provide customer support and technical assistance
- Send promotional messages if you’ve opted in
- Monitor fraud, misuse, or security threats
- Analyze performance and improve services
SMS, Call & WhatsApp Consent:
By submitting your phone number on our Site, you consent to receive:
- Appointment reminders
- Automated follow-ups and confirmations
- Exclusive offers and updates
You may opt out anytime by replying “STOP” to SMS messages. Standard message/data rates may apply. We comply with A2P 10DLC regulations and are registered with The Campaign Registry (TCR).
3. Sharing Your Information
We only share personal data with vetted third-party providers necessary to deliver our services:
GoHighLevel (GHL) – marketing automation & CRM
Twilio – SMS, voice, and WhatsApp messaging
Stripe – secure payment processing
We may also share data to comply with legal obligations or protect our legal rights. We do not sell or rent your personal data.
4. Your Rights (EU/EEA Residents)
As an EU/EEA resident, under the GDPR, you have the right to:
-Access your data
-Correct or update inaccurate information
-Request deletion of your data
-Withdraw previously given consent
-Object to or restrict data processing
To exercise your rights, email us at: [email protected]
5. Legal Basis for Data Processing
We process data based on:
Consent (opt-ins, subscriptions)
Contractual necessity (bookings, purchases)
Legitimate interest (analytics, communication)
Legal compliance
6. International Data Transfers
Your data may be processed outside the EU/EEA — notably in the USA or Canada, where partners like Twilio, GHL, and Stripe operate. All transfers comply with GDPR safeguards (e.g., Standard Contractual Clauses).
7. Data Retention
We retain your data only as long as necessary to:
Deliver services and support
Meet legal and accounting requirements
Fulfill regulatory obligations
You may request deletion at any time unless retention is legally required.
8. Updates to This Policy
We may revise this Privacy Policy periodically. All changes will be posted with the updated effective date. Please review regularly.
9. Contact Us
If you have any concerns, requests, or inquiries about your personal data, contact us:
📧 Email: [email protected]
🏢 Company: NoFurther AI SAS
🏣 Address: 46 Rue Chardon Lagache, 75016 Paris, PO Box Abi Aad, France
📌 RCS Number: 989 403 449 R.C.S. Paris
Effective date: 23 October 2025
Last updated: 19 June 2026
Download or access the document at any time here.
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the master service agreement, statement(s) of work, order form(s), proposal(s), addendum(s), online acceptance flow, or any other agreement between the Parties that references this DPA, together with all related contractual documents, as amended from time to time (collectively, the “Agreement”).
This DPA becomes legally binding upon the Client once both of the following conditions have been satisfied:
(a) the Agreement has been duly signed, accepted, or otherwise approved by the Client, including through an electronic signature or electronic acceptance workflow; and
(b) NoFurther Systems SAS has received the first payment due under the Agreement.
Until both conditions are satisfied, the person or entity is a prospective client only, and NoFurther has no obligation to perform the Services.
This DPA governs NoFurther’s processing of Personal Data on behalf of the Client in connection with the Services, including NoFurther’s platform, client portal, admin portal, CRM orchestration, AI-powered workflows, automation systems, marketing systems, integrations, reporting tools, and related operational environments.
PARTIES
Client / Controller:
The person or legal entity identified as the client, customer, or contracting party in the Agreement, including its legal name, jurisdiction, registration number, registered address, and contact details as set out in the Agreement (“Client” or “Controller”).
NoFurther / Processor:
NoFurther Systems SAS, a société par actions simplifiée registered in France under SIREN 989 403 449, with registered address at 46 Rue Chardon Lagache, PO Box Abi Aad, 75016 Paris, France, email: [email protected] (“NoFurther” or “Processor”).
Each is a “Party” and together they are the “Parties.”
1. DEFINITIONS
Unless otherwise defined in this DPA, capitalized terms have the meaning given to them in the GDPR.
Applicable Data Protection Law means all laws and regulations concerning data protection, privacy, electronic communications, cookies, marketing communications, and personal information that apply to the processing under the Agreement, including, where applicable, the GDPR, UK GDPR, Data Protection Act 2018, Swiss Federal Act on Data Protection, ePrivacy Directive and national implementing laws, CCPA/CPRA, and any applicable successor or replacement laws.
Agreement means the master service agreement, statement of work, order form, proposal, addendum, acceptance workflow, or other contract between the Parties that incorporates this DPA.
Authorized User means any employee, contractor, representative, agent, administrator, client-side user, invited user, or other person authorized by the Client to access the NoFurther platform, Client Systems, Client data, or the Services.
Business Day means any day other than a Saturday, Sunday, or public holiday in Paris, France.
Client Data means all data, content, materials, files, records, information, and Personal Data submitted, uploaded, imported, synchronized, transmitted, generated, accessed, stored, or otherwise processed by or on behalf of the Client through the Services.
Client Systems means any systems, accounts, tools, databases, platforms, or environments owned, controlled, used, or authorized by the Client, including advertising accounts, CRM systems, GoHighLevel/LeadConnector, Meta Business Manager, Google Ads, LinkedIn Campaign Manager, TikTok Ads, Google Analytics, Twilio, WhatsApp, Stripe, Wistia, Vimeo, Google Workspace, calendars, landing pages, domains, CMS, hosting providers, email systems, payment systems, form tools, spreadsheets, and any other third-party system connected to or used with the Services.
Controller means the entity that determines the purposes and means of the processing of Personal Data. For Client Personal Data processed under this DPA, the Client is the Controller unless otherwise expressly agreed.
Data Subject means an identified or identifiable natural person whose Personal Data is processed under the Agreement.
Effective Date means the date on which both the Agreement has been signed or accepted by the Client and NoFurther has received the first payment due under the Agreement.
NoFurther Platform or Platform means NoFurther’s proprietary or controlled software, dashboards, databases, client portal, admin portal, automation systems, AI workflows, reporting tools, integrations, operational tools, hosted environments, and related technical infrastructure used to provide the Services.
Personal Data means any information relating to an identified or identifiable natural person that is processed by NoFurther on behalf of the Client.
Processor means the entity that processes Personal Data on behalf of the Controller. For Client Personal Data processed under this DPA, NoFurther is the Processor unless otherwise expressly agreed.
Restricted Transfer means a transfer of Personal Data from the EEA, United Kingdom, or Switzerland to a country, organization, or recipient that is not covered by an adequacy decision or equivalent lawful transfer mechanism under Applicable Data Protection Law.
Security Incident means any confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data processed by NoFurther under the Agreement.
Services means the services provided by NoFurther under the Agreement, including AI-powered client acquisition, marketing operations, CRM orchestration, automation, lead management, platform access, client portal, admin portal, reporting, analytics, campaign management, landing pages, forms, messaging workflows, calendar workflows, data syncs, integrations, AI agents, playbooks, support, maintenance, and related services.
Sub-Processor means any third-party processor engaged by NoFurther to process Personal Data on behalf of the Client in connection with the Services.
2. ROLES AND SCOPE OF PROCESSING
2.1 Roles
For Client Personal Data processed under the Agreement, the Client acts as Controller and NoFurther acts as Processor.
2.2 Independent Controller Activities
NoFurther may act as an independent Controller for its own internal business operations, including billing, accounting, fraud prevention, corporate administration, security, compliance, legal claims, client relationship management, and communications with Client representatives. Such processing is governed separately by NoFurther’s privacy policy and is not governed by this DPA, except where required by Applicable Data Protection Law.
2.3 Documented Instructions
NoFurther shall process Client Personal Data only on documented instructions from the Client, including with regard to transfers of Personal Data to third countries, unless NoFurther is required to process such data by applicable law. In that case, NoFurther shall inform the Client of the legal requirement before processing, unless the law prohibits such notification.
2.4 Instructions Through Platform Configuration
The Client’s instructions include:
(a) the Agreement;
(b) this DPA;
(c) onboarding materials, implementation requests, configuration choices, playbooks, workflows, and written instructions;
(d) actions, settings, approvals, integrations, imports, exports, automations, or permissions configured, approved, enabled, requested, or triggered by the Client or its Authorized Users through the NoFurther Platform; and
(e) reasonable instructions provided by the Client in writing.
2.5 Refusal of Unlawful Instructions
NoFurther shall promptly inform the Client if, in NoFurther’s reasonable opinion, an instruction infringes Applicable Data Protection Law, third-party platform terms, security requirements, or the Agreement. NoFurther may suspend performance of such instruction until it is corrected or clarified.
2.6 Details of Processing
The subject matter, duration, nature, purpose, categories of Data Subjects, categories of Personal Data, and transfer details are set out in Annex I.
3. ACCESS TO CLIENT SYSTEMS, AGENCY ACCESS, AND LEAST PRIVILEGE
3.1 Grant of Access
The Client may grant NoFurther access to Client Systems through user accounts, role-based permissions, OAuth, SSO, API keys, private integrations, agency access, partner access, service accounts, shared credentials, webhook endpoints, or other approved connection methods, solely to perform the Services.
3.2 Use Restrictions
NoFurther shall access Client Systems only as necessary to perform the Services and shall apply least-privilege principles where feasible. NoFurther shall not intentionally modify ownership settings, billing ownership, account ownership, or materially sensitive administrative settings unless expressly instructed or authorized by the Client.
3.3 Platform Terms
NoFurther shall use commercially reasonable efforts to comply with applicable third-party platform terms when accessing Client Systems. The Client remains responsible for ensuring that it has the right to authorize NoFurther to access and process data through such Client Systems.
3.4 Emergency Actions
In urgent circumstances, including ad account suspension, security threat, unauthorized access, campaign malfunction, data loss risk, platform abuse, or operational failure, NoFurther may take proportionate actions within the authorized scope of access. NoFurther shall inform the Client as soon as reasonably practicable, unless legally or operationally restricted.
3.5 Access Logs
Where technically feasible, NoFurther shall maintain logs or records of significant administrative access and material account changes performed by NoFurther personnel. Upon written request, NoFurther shall provide available access information within 40 Business Days, subject to confidentiality, security limitations, third-party platform limitations, and exclusion of other clients’ data.
3.6 Credential Handling
NoFurther shall use reasonable security measures to protect Client credentials, API keys, OAuth tokens, and similar access mechanisms. Where feasible, credentials shall be stored in secure credential management systems and access shall be limited to personnel who require access for service delivery.
4. TRANSFER OF DATA TO THE NOFURTHER PLATFORM AND PLATFORM USE
4.1 Authorization to Transfer Data to the Platform
The Client authorizes NoFurther to receive, import, upload, synchronize, migrate, copy, transform, structure, host, store, retrieve, transmit, and otherwise process Client Personal Data from Client Systems into the NoFurther Platform solely for the purposes of providing, maintaining, supporting, securing, improving, documenting, and evidencing the Services under the Agreement.
4.2 Sources of Platform Data
Client Personal Data transferred to or processed through the NoFurther Platform may originate from:
(a) Client CRM systems;
(b) advertising accounts;
(c) websites, landing pages, funnels, forms, surveys, and chat widgets;
(d) calendars, scheduling systems, call-booking tools, meeting tools, and video tools;
(e) messaging systems, including email, SMS, WhatsApp, and chat;
(f) payment systems and billing platforms;
(g) analytics tools, pixels, tags, attribution systems, and tracking technologies;
(h) uploaded files, brand assets, transcripts, recordings, spreadsheets, documents, screenshots, briefs, and forms;
(i) manual imports or user entries;
(j) API integrations, webhooks, private integrations, OAuth connections, and automation tools; and
(k) any other Client-approved or Client-connected system used to provide the Services.
4.3 Categories of Platform Processing
The Client authorizes NoFurther to process Client Personal Data within the NoFurther Platform for the following operations:
(a) importing, mapping, cleaning, deduplicating, validating, normalizing, structuring, and formatting data;
(b) creating, updating, syncing, and enriching lead, prospect, customer, account, campaign, workflow, contract, billing, appointment, task, and reporting records;
(c) routing leads, messages, tasks, alerts, calls, forms, contracts, onboarding steps, client requests, and internal workflows;
(d) operating client portals, admin portals, dashboards, analytics, attribution views, campaign performance views, task views, billing views, agreement views, calendar views, and reporting systems;
(e) generating, executing, monitoring, and improving workflows, automations, playbooks, AI agents, assistant outputs, CRM actions, and operational recommendations;
(f) troubleshooting, debugging, testing, logging, quality assurance, support, security monitoring, incident response, fraud prevention, platform administration, and maintenance;
(g) producing aggregated, anonymized, or de-identified operational insights, provided such data does not identify the Client, its leads, customers, staff, users, or any other individual.
4.4 No Sale or Independent Commercial Use
NoFurther shall not sell, rent, disclose, share, or commercially exploit Client Personal Data for its own independent commercial purposes. NoFurther shall not use Client Personal Data to market unrelated services to the Client’s leads, prospects, customers, or users unless expressly instructed or authorized by the Client.
4.5 Platform User Access
The Client acknowledges that its Authorized Users may access Client Personal Data through the NoFurther Platform. The Client is responsible for ensuring that all Client-side users are authorized to access such data, that their access levels are appropriate, and that any Personal Data they upload, view, modify, export, download, copy, or use through the Platform is processed lawfully.
4.6 Admin and Client Portal Separation
NoFurther shall use commercially reasonable technical and organizational measures to segregate Client Personal Data from other clients’ data and to ensure that client-facing users may only access data made available to them through the intended role, permission, workspace, account, or portal configuration. NoFurther administrative users may access Client Personal Data only where reasonably necessary for service delivery, support, security, billing, compliance, troubleshooting, platform administration, or legal obligations.
4.7 API Connections, Webhooks, and Automated Syncs
The Client authorizes NoFurther to transmit Client Personal Data between the NoFurther Platform and Client Systems through APIs, webhooks, OAuth connections, API keys, private integrations, service accounts, agency access, embedded integrations, or other technical connections approved or enabled by the Client. Such transfers may include bidirectional synchronization where required for the Services, including the creation, update, deletion, tagging, routing, enrichment, or classification of records in Client Systems.
4.8 Platform Actions on Client Systems
Where the Services include automations, AI agents, CRM orchestration, campaign management, messaging, calendar operations, reporting, or operational workflows, the Client authorizes NoFurther to perform actions on Client Systems through the NoFurther Platform, including creating, updating, deleting, tagging, routing, or modifying contacts, opportunities, tasks, notes, custom fields, custom values, workflows, appointments, calendar events, messages, files, campaign records, pipeline records, tags, reports, and other operational records, within the scope of the Agreement and the Client’s documented instructions.
4.9 Client Instructions Through Automations
Actions configured, approved, enabled, requested, or triggered by the Client or its Authorized Users through the NoFurther Platform, including automations, playbooks, AI agents, workflows, integrations, and platform settings, shall constitute documented instructions from the Client for purposes of this DPA, unless NoFurther reasonably determines that such instruction violates Applicable Data Protection Law, the Agreement, third-party platform terms, or platform security requirements.
4.10 Client Responsibility for Uploaded and Imported Data
The Client is solely responsible for ensuring that Personal Data uploaded, imported, synchronized, transmitted, disclosed, or made available to NoFurther or the NoFurther Platform has been collected and disclosed lawfully, that all required notices and consents have been provided, and that the Client has the necessary rights, permissions, lawful bases, and authority to instruct NoFurther to process such data.
4.11 Sensitive Data Restrictions
The Client shall not upload, import, synchronize, transmit, or otherwise provide special category data, health data, biometric data, children’s data, government identification numbers, financial account credentials, passwords, criminal-offence data, precise geolocation data, or other highly sensitive information to NoFurther or the NoFurther Platform unless expressly agreed in writing by NoFurther and subject to any additional safeguards required by Applicable Data Protection Law.
4.12 Lead, Prospect, and End-User Interactions
Where the NoFurther Platform includes forms, chat widgets, AI assistants, call-booking flows, onboarding flows, payment flows, tracking tools, analytics scripts, pixels, tags, messaging workflows, or other mechanisms that collect Personal Data directly from leads, prospects, customers, staff, users, or other individuals on behalf of the Client, the Client remains responsible for providing legally adequate privacy notices, cookie notices, consent mechanisms, marketing opt-ins, call recording notices, opt-out mechanisms, and any other disclosures required by law.
4.13 Logs and Metadata
NoFurther may generate and retain technical logs, audit logs, security logs, workflow logs, API logs, message delivery logs, webhook logs, error logs, access logs, automation logs, and platform metadata to operate, secure, evidence, audit, debug, maintain, and improve the Services. Such logs may contain limited Personal Data and shall be protected under this DPA.
4.14 Exports and Downloads
The Client may export or download Client Data from the NoFurther Platform where enabled by the Services. Once exported, downloaded, copied, screenshotted, transferred, or otherwise removed from the NoFurther Platform by the Client or an Authorized User, the Client is responsible for the security, retention, use, sharing, access control, and deletion of such data unless NoFurther continues to process that data under the Agreement.
4.15 Platform Suspension for Security or Legal Risk
NoFurther may suspend or limit Platform access, integrations, automations, AI agents, exports, webhooks, API connections, or data transfers where reasonably necessary to prevent unauthorized access, data loss, legal violation, security compromise, abuse, spam, unlawful processing, third-party platform breach, service disruption, or material risk to NoFurther, the Client, other clients, Sub-Processors, or Data Subjects. NoFurther shall notify the Client where legally and operationally feasible.
5. CONFIDENTIALITY AND PERSONNEL
5.1 Confidentiality
NoFurther shall ensure that all personnel authorized to process Client Personal Data are bound by appropriate confidentiality obligations, whether contractual, statutory, or professional.
5.2 Personnel Access
NoFurther shall limit personnel access to Client Personal Data to individuals who require such access for the performance of the Services, support, maintenance, security, compliance, or legal obligations.
5.3 Training
NoFurther shall ensure that relevant personnel receive appropriate training regarding data protection, confidentiality, information security, and responsible use of Client Personal Data.
5.4 Background Checks
NoFurther may perform background checks where appropriate, legally permitted, and relevant to the personnel’s role and access level.
6. SECURITY OF PROCESSING
6.1 Technical and Organizational Measures
NoFurther shall implement and maintain appropriate technical and organizational measures designed to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other unlawful or unauthorized processing.
6.2 Security Measures
NoFurther’s technical and organizational measures include, as applicable:
(a) encryption in transit using TLS 1.2 or higher where supported;
(b) encryption at rest where supported by the relevant hosting, storage, or database environment;
(c) multi-factor authentication for privileged accounts where feasible;
(d) least-privilege access control;
(e) client data segregation;
(f) credential management;
(g) backups and disaster recovery measures;
(h) logging and monitoring;
(i) vulnerability management and patching;
(j) vendor due diligence and contractual safeguards;
(k) incident response procedures;
(l) data minimization and retention controls.
Additional technical and organizational measures are described in Annex II.
6.3 No Absolute Security Guarantee
The Parties acknowledge that no system, network, platform, integration, API, or transmission method can be guaranteed to be completely secure. NoFurther’s obligation is to implement and maintain appropriate technical and organizational measures in accordance with Applicable Data Protection Law and the nature of the Services.
7. PERSONAL DATA BREACH RESPONSE
7.1 Notification
NoFurther shall notify the Client without undue delay after becoming aware of a confirmed Security Incident affecting Client Personal Data and, where feasible, within 72 hours.
7.2 Notification Content
To the extent known and available, NoFurther’s notification shall include:
(a) the nature of the Security Incident;
(b) the categories and approximate number of Data Subjects affected;
(c) the categories and approximate number of records affected;
(d) likely consequences;
(e) measures taken or proposed to address the Security Incident; and
(f) available mitigation steps.
7.3 Cooperation
NoFurther shall cooperate reasonably with the Client in investigating, mitigating, remediating, and documenting a Security Incident.
7.4 No Admission
Notification of a Security Incident shall not constitute an admission of fault, liability, or violation by NoFurther.
8. DATA SUBJECT RIGHTS, DPIAS, AND REGULATORY ASSISTANCE
8.1 Data Subject Requests
Taking into account the nature of the processing, NoFurther shall provide reasonable assistance to the Client by appropriate technical and organizational measures, insofar as possible, to help the Client respond to Data Subject requests, including requests for access, rectification, erasure, restriction, portability, objection, or withdrawal of consent.
8.2 No Direct Response Unless Required
NoFurther shall not respond directly to Data Subjects regarding Client Personal Data unless instructed by the Client or required by applicable law. If NoFurther receives a request directly from a Data Subject relating to Client Personal Data, NoFurther shall, where legally permitted, direct the Data Subject to the Client or notify the Client.
8.3 DPIAs and Consultations
NoFurther shall provide reasonable assistance to the Client with Data Protection Impact Assessments and prior consultations with supervisory authorities where required by Applicable Data Protection Law, taking into account the nature of processing and information available to NoFurther.
8.4 Costs
Where assistance requires material effort beyond ordinary service operations, NoFurther may charge reasonable fees unless prohibited by law or otherwise agreed in the Agreement.
9. SUB-PROCESSORS
9.1 General Authorization
The Client grants NoFurther general written authorization to engage Sub-Processors to process Client Personal Data for the purpose of providing the Services.
9.2 Sub-Processor Obligations
NoFurther shall enter into written agreements with Sub-Processors that impose data protection obligations substantially equivalent to those imposed on NoFurther under this DPA, to the extent applicable to the nature of the services provided by the Sub-Processor.
9.3 Sub-Processor Registry
NoFurther shall maintain an internal Sub-Processor registry identifying relevant Sub-Processors, service categories, processing locations where known, and applicable safeguards. The registry shall be made available upon written request where required by Applicable Data Protection Law or the Agreement, subject to confidentiality, security, and commercial sensitivity limitations.
9.4 Notice of Changes
NoFurther shall provide at least 10 Business Days’ notice before adding or replacing a material Sub-Processor, unless urgent replacement is required for security, continuity, legal, or operational reasons. Notice may be provided by email, platform notice, website update, or another reasonable method.
9.5 Objection Right
The Client may object to a new or replacement Sub-Processor on reasonable data protection grounds by providing written notice during the notice period. The Parties shall work in good faith to resolve the objection.
If the objection cannot be resolved within 30 days, the Client may terminate only the affected portion of the Services, and NoFurther may provide a pro-rata refund for prepaid unused fees related to the affected portion, unless otherwise stated in the Agreement.
9.6 Liability for Sub-Processors
NoFurther remains responsible to the Client for the performance of its Sub-Processors’ data protection obligations to the extent required by Applicable Data Protection Law.
10. INTERNATIONAL TRANSFERS
10.1 Transfer Mechanisms
Where NoFurther or its Sub-Processors transfer Client Personal Data outside the EEA, United Kingdom, or Switzerland in a manner that constitutes a Restricted Transfer, NoFurther shall rely on one or more lawful transfer mechanisms, including:
(a) adequacy decisions;
(b) EU Standard Contractual Clauses;
(c) the UK International Data Transfer Addendum or equivalent UK transfer mechanism;
(d) the Swiss Addendum or equivalent Swiss transfer mechanism;
(e) another valid transfer mechanism permitted by Applicable Data Protection Law.
10.2 EU Standard Contractual Clauses
For Restricted Transfers governed by the GDPR, the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference and deemed executed between the Parties where applicable.
The relevant modules are:
(a) Module 2: Controller to Processor; and
(b) Module 3: Processor to Processor, where NoFurther transfers Client Personal Data to a Sub-Processor.
10.3 UK and Swiss Addenda
For Restricted Transfers governed by UK or Swiss data protection law, the UK International Data Transfer Addendum and Swiss-specific adaptations shall apply where relevant.
10.4 Transfer Impact Assessments
Where required by Applicable Data Protection Law, NoFurther shall provide reasonable information available to it to support transfer impact assessments, subject to confidentiality, security, and commercial sensitivity limitations.
10.5 Conflict
In the event of conflict between this DPA and applicable Standard Contractual Clauses, the Standard Contractual Clauses shall prevail for the relevant Restricted Transfer.
11. RETENTION, RETURN, AND DELETION
11.1 General Retention
NoFurther shall retain Client Personal Data only for as long as reasonably necessary to provide the Services, comply with the Agreement, comply with legal obligations, resolve disputes, enforce rights, maintain security, perform audits, or complete offboarding.
11.2 Return or Deletion
Upon termination of the Agreement or upon valid written request from the Client, NoFurther shall return or securely delete Client Personal Data within 30 days, unless continued retention is required or permitted by applicable law, security obligations, legitimate dispute management, backup retention, accounting requirements, audit obligations, or the Agreement.
11.3 Certification
Upon written request, NoFurther may provide reasonable certification or confirmation of deletion, subject to technical limitations and the exclusion of backup, archival, log, and legally retained copies.
11.4 Backups, Logs, and Residual Data
Following termination or a valid deletion request, Client Personal Data may remain for a limited period in backups, security logs, audit logs, archival systems, disaster recovery systems, or similar technical environments until overwritten or deleted according to NoFurther’s standard retention cycles. Such data shall remain protected and shall not be actively processed except for restoration, security, legal, compliance, audit, or disaster recovery purposes.
11.5 Aggregated and De-Identified Data
NoFurther may retain anonymized, aggregated, or de-identified data that no longer identifies the Client, Authorized Users, Data Subjects, leads, customers, or any individual. Such data may be used for operational statistics, system performance metrics, security analytics, benchmarking, product telemetry, service improvement, and internal business intelligence.
12. AUDIT AND COMPLIANCE
12.1 Records
NoFurther shall maintain records and information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law.
12.2 Compliance Information
Upon written request, NoFurther shall provide reasonable information necessary to demonstrate compliance with this DPA, subject to confidentiality, security, legal privilege, commercial sensitivity, and protection of other clients’ data.
12.3 Audits
Where required by Applicable Data Protection Law, the Client may conduct or mandate an audit of NoFurther’s compliance with this DPA, subject to the following conditions:
(a) at least 30 days’ prior written notice;
(b) no more than once per 12-month period unless required by a supervisory authority or following a confirmed Security Incident;
(c) during normal business hours;
(d) in a manner that does not unreasonably disrupt NoFurther’s operations;
(e) subject to reasonable confidentiality and security requirements;
(f) limited to systems, records, and personnel relevant to the Client’s Personal Data;
(g) excluding access to other clients’ data, trade secrets, source code, privileged materials, security-sensitive information, and commercially sensitive information.
12.4 Costs
The Client shall bear its own audit costs and shall reimburse NoFurther for reasonable costs incurred in supporting an audit, unless prohibited by law or otherwise agreed in writing.
13. CCPA/CPRA AND US STATE PRIVACY LAWS
13.1 Service Provider / Contractor Status
Where the CCPA/CPRA or similar US state privacy laws apply, NoFurther acts as a Service Provider or Contractor with respect to Personal Information processed on behalf of the Client, as those terms are defined under applicable law.
13.2 Restrictions
NoFurther shall not:
(a) sell or share Client Personal Information;
(b) retain, use, or disclose Client Personal Information for any purpose other than the business purposes specified in the Agreement or as otherwise permitted by applicable law;
(c) retain, use, or disclose Client Personal Information for a commercial purpose other than the business purposes specified in the Agreement, unless permitted by applicable law;
(d) retain, use, or disclose Client Personal Information outside the direct business relationship between NoFurther and the Client, unless permitted by applicable law;
(e) combine Client Personal Information with Personal Information obtained from other sources, except as permitted by applicable law.
13.3 Assistance and Compliance
NoFurther shall provide the same level of privacy protection required of Service Providers or Contractors under applicable law and shall reasonably assist the Client in responding to verifiable consumer requests where required.
13.4 Notice of Inability to Comply
NoFurther shall notify the Client if it determines that it can no longer meet its applicable obligations under this Section.
13.5 Client Monitoring Rights
The Client may take reasonable and appropriate steps to ensure that NoFurther uses Client Personal Information in a manner consistent with the Client’s obligations under applicable US state privacy laws, subject to the audit and confidentiality limitations in this DPA.
14. AI PROCESSING AND AUTOMATED SYSTEMS
14.1 AI Processing
Where the Services involve AI models, language models, machine learning systems, automated agents, assistants, classifiers, workflow engines, or similar technologies, NoFurther may process Client Personal Data through such systems solely to provide the Services, including lead qualification, message drafting, CRM updates, workflow execution, content generation, analysis, summarization, routing, classification, reporting, recommendations, and operational support.
14.2 No Training on Client Personal Data
NoFurther shall not intentionally use Client Personal Data to train general-purpose AI models or third-party foundation models unless expressly authorized in writing by the Client. This restriction does not prevent NoFurther from using anonymized, aggregated, or de-identified operational learnings that do not identify the Client or any Data Subject.
14.3 Human Review and Client Responsibility
The Client acknowledges that AI-generated outputs may require human review. The Client remains responsible for reviewing, approving, and lawfully using AI-generated content, recommendations, lead scoring, messages, workflows, CRM actions, campaign outputs, and decisions where such outputs affect individuals, customers, prospects, legal rights, commercial terms, regulated activities, eligibility, pricing, or access to services.
14.4 No Solely Automated Legal or Significant Decisions Unless Agreed
NoFurther shall not knowingly use AI systems to make solely automated decisions producing legal or similarly significant effects on individuals unless expressly instructed by the Client and unless appropriate safeguards required by Applicable Data Protection Law are implemented.
14.5 AI Sub-Processors
AI providers used by NoFurther shall be treated as Sub-Processors where they process Client Personal Data on behalf of the Client. NoFurther shall apply contractual safeguards designed to protect Client Personal Data and shall identify such providers in its Sub-Processor registry where required.
14.6 Prompts, Outputs, and Logs
Prompts, AI inputs, AI outputs, summaries, classifications, chat logs, transcripts, and automation logs may contain Client Personal Data and shall be treated as Client Personal Data where they relate to an identified or identifiable person.
14.7 Client Instructions for AI Use
The Client is responsible for ensuring that its use of AI-enabled features, automation settings, prompts, workflow configurations, and outputs complies with laws applicable to the Client’s business, including advertising, consumer protection, employment, financial services, health, anti-discrimination, anti-spam, and sector-specific laws.
15. CLIENT RESPONSIBILITIES
15.1 General Client Responsibilities
The Client is responsible for:
(a) having a valid lawful basis for processing Client Personal Data;
(b) providing transparent and legally adequate privacy notices;
(c) obtaining all required consents, permissions, and authorizations;
(d) ensuring data accuracy, quality, and relevance;
(e) complying with marketing, cookie, tracking, electronic communications, telemarketing, anti-spam, consumer protection, advertising, and industry-specific laws;
(f) securing its own systems, devices, accounts, users, credentials, and environments;
(g) ensuring that NoFurther is legally authorized to access and process data from Client Systems;
(h) avoiding the transmission of prohibited or sensitive data unless expressly agreed in writing.
15.2 Platform Responsibilities
The Client is responsible for:
(a) ensuring all Personal Data transferred to NoFurther or the NoFurther Platform has been collected lawfully;
(b) ensuring the Client has authority to connect Client Systems to the NoFurther Platform;
(c) maintaining accurate privacy notices, cookie notices, consent banners, marketing consents, call-recording notices, and opt-out mechanisms;
(d) ensuring that Client users have appropriate permissions and are removed when access is no longer needed;
(e) reviewing platform configurations, automations, AI outputs, workflows, messages, and CRM actions before using them in regulated, sensitive, legal, financial, medical, employment, or high-impact contexts;
(f) ensuring that imported data does not include prohibited sensitive data unless expressly agreed;
(g) ensuring that exports, downloads, screenshots, reports, and copied data are handled securely after leaving the NoFurther Platform;
(h) complying with all laws applicable to the Client’s own use of the Services and Client Data.
15.3 Responsibility for Client Systems
The Client remains responsible for the configuration, security, legality, ownership, licensing, subscription status, permissions, notices, and lawful use of Client Systems, even where NoFurther accesses such systems to provide the Services.
15.4 Responsibility for Authorized Users
The Client is responsible for all acts and omissions of its Authorized Users, including their access to, use of, export of, modification of, deletion of, or disclosure of Client Data through the Services.
16. LIABILITY AND INDEMNITY
16.1 Liability
Each Party is liable for its own violations of this DPA and Applicable Data Protection Law, subject to the limitations, exclusions, and caps of liability set out in the Agreement.
16.2 No Expansion of Liability
This DPA does not expand, increase, or override the liability caps, exclusions, disclaimers, or indemnity limitations in the Agreement, except to the extent prohibited by Applicable Data Protection Law.
16.3 Client Indemnity
To the extent permitted by law and the Agreement, the Client shall indemnify and hold harmless NoFurther from claims, fines, losses, costs, damages, and expenses arising from:
(a) Client’s unlawful collection, use, disclosure, or transfer of Personal Data;
(b) Client’s failure to provide required notices or obtain required consents;
(c) Client’s unlawful instructions;
(d) Client’s misuse of the Services, Platform, AI outputs, automations, or integrations;
(e) Client’s upload or transmission of prohibited sensitive data;
(f) acts or omissions of Client’s Authorized Users.
16.4 NoFurther Indemnity
To the extent permitted by law and the Agreement, NoFurther shall be responsible for claims, fines, losses, costs, damages, and expenses finally determined to arise directly from NoFurther’s breach of this DPA or Applicable Data Protection Law while acting as Processor, subject to the Agreement’s limitations of liability.
17. SUSPENSION AND SECURITY MEASURES
NoFurther may suspend or restrict access to the Services, Platform, Client Systems, integrations, APIs, webhooks, automations, exports, AI agents, or data processing where NoFurther reasonably believes that continued access or processing may cause:
(a) unauthorized access;
(b) data loss;
(c) security compromise;
(d) violation of Applicable Data Protection Law;
(e) violation of third-party platform terms;
(f) spam, abuse, fraud, or unlawful marketing;
(g) harm to NoFurther, the Client, other clients, Sub-Processors, or Data Subjects;
(h) material operational disruption.
NoFurther shall notify the Client where legally and operationally feasible.
18. MISCELLANEOUS
18.1 Conflicts
If there is a conflict between this DPA and the Agreement regarding data protection matters, this DPA shall prevail. If there is a conflict between this DPA and applicable Standard Contractual Clauses, the Standard Contractual Clauses shall prevail for the relevant Restricted Transfer.
18.2 Amendments
This DPA may be updated by written agreement of the Parties, except for Sub-Processor changes handled under Section 9 and non-material operational updates that do not reduce the level of protection for Client Personal Data.
18.3 Severability
If any provision of this DPA is held invalid, unlawful, or unenforceable, the remaining provisions remain in full force and effect.
18.4 Governing Law and Jurisdiction
The governing law and jurisdiction are those defined in the Agreement. If the Agreement does not specify governing law or jurisdiction, this DPA shall be governed by the laws of France, and the competent courts of Paris, France shall have jurisdiction, subject to mandatory law and applicable Standard Contractual Clauses.
18.5 Order of Priority
For data protection matters, the order of priority shall be:
(a) applicable Standard Contractual Clauses for Restricted Transfers;
(b) this DPA;
(c) the Agreement;
(d) other contractual documents, unless expressly stated otherwise.
19. CONTACTS
Client Privacy Contact:
As identified in the Agreement, or if not identified: [Client privacy contact name, email, and address].
NoFurther Systems SAS Privacy Contact:
[email protected]
NoFurther Systems SAS
46 Rue Chardon Lagache
PO Box Abi Aad
75016 Paris
France
ANNEX I — DESCRIPTION OF PROCESSING
A. Data Exporter / Controller
The Client.
B. Data Importer / Processor
NoFurther Systems SAS.
C. Subject Matter
Provision of NoFurther’s AI-powered client acquisition, lead management, CRM orchestration, automation, advertising, analytics, reporting, client portal, admin portal, onboarding, calendar, messaging, workflow, platform operations, support, and maintenance services.
D. Duration
For the term of the Agreement, plus any limited period required for offboarding, deletion, backup expiry, dispute handling, accounting, legal retention, security, audit, or compliance purposes.
E. Nature of Processing
Collection, receipt, recording, import, migration, storage, hosting, organization, structuring, mapping, cleaning, deduplication, enrichment, synchronization, retrieval, consultation, analysis, classification, scoring, routing, segmentation, tagging, transmission, disclosure to authorized Sub-Processors, restriction, deletion, return, and other processing operations necessary to provide the Services.
F. Purpose of Processing
The purpose of processing is to provide, operate, secure, monitor, support, improve, document, and maintain NoFurther’s Services, including:
(a) lead generation and lead management;
(b) CRM setup, sync, orchestration, and automation;
(c) advertising campaign management and reporting;
(d) landing pages, forms, funnels, onboarding flows, and client portals;
(e) AI assistants, AI agents, workflow automation, and operational playbooks;
(f) messaging, follow-up, appointment booking, calendar synchronization, and call tracking;
(g) analytics, attribution, dashboards, performance reporting, and business intelligence;
(h) client support, debugging, security, audit logging, and compliance.
G. Categories of Data Subjects
The categories of Data Subjects may include:
(a) Client’s leads, prospects, customers, and former customers;
(b) Client’s staff, contractors, users, admins, sales representatives, setters, closers, and service providers;
(c) individuals who submit forms, book calls, interact with chat widgets, respond to messages, view landing pages, or otherwise interact with Client campaigns or systems;
(d) NoFurther users acting on behalf of the Client;
(e) other individuals whose data is contained in Client Systems or transmitted to NoFurther by or on behalf of the Client.
H. Categories of Personal Data
The categories of Personal Data may include:
(a) identity data: name, surname, company, role, job title, username, user ID;
(b) contact data: email, phone number, messaging handles, social profile URLs;
(c) CRM data: lead status, pipeline stage, tags, notes, custom fields, opportunity records, qualification answers, lead source, owner, assignment, tasks, deal data;
(d) marketing data: campaign interactions, form submissions, landing page activity, ad attribution, UTM parameters, pixels, cookies, consent status, opt-in status, opt-out status;
(e) communications data: emails, SMS, WhatsApp messages, chat messages, call notes, transcripts, summaries, recordings where applicable, support messages;
(f) scheduling data: appointment times, calendar metadata, meeting links, attendee information, timezone, booking history;
(g) technical data: IP address, device data, browser data, logs, API events, webhook payloads, authentication metadata, access logs;
(h) billing and payment metadata: invoice references, subscription status, transaction metadata, Stripe customer references, non-PCI payment metadata;
(i) uploaded content: documents, files, screenshots, brand assets, briefs, recordings, transcripts, spreadsheets, and other materials uploaded by the Client or its Authorized Users.
I. Special Category Data
Special category data, children’s data, health data, biometric data, criminal-offence data, government identification numbers, financial account credentials, passwords, and other highly sensitive information are not intended for processing and must not be submitted unless expressly agreed in writing with additional safeguards.
J. Frequency of Transfer
Continuous, recurring, event-based, API-based, webhook-based, manual, scheduled, or one-off, depending on the Services and Client-approved integrations.
K. Processing Locations
France, the European Economic Area, and any other locations where approved Sub-Processors process Personal Data subject to applicable transfer safeguards.
L. Supervisory Authority
CNIL, France, unless otherwise required by Applicable Data Protection Law or agreed in writing.
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
NoFurther shall implement and maintain appropriate technical and organizational measures, including the following where applicable to the Services.
1. Governance
(a) privacy and security responsibility assigned internally;
(b) confidentiality obligations for personnel;
(c) employee and contractor NDAs where appropriate;
(d) data protection and security training;
(e) internal policies and procedures for handling Client Personal Data.
2. Access Control
(a) least-privilege access principles;
(b) role-based access controls where feasible;
(c) MFA for privileged accounts where feasible;
(d) periodic access reviews;
(e) secure credential storage;
(f) removal or restriction of access when no longer required.
3. Encryption
(a) TLS 1.2 or higher for data in transit where supported;
(b) encryption at rest where supported by the hosting, database, or storage provider;
(c) appropriate protection for API keys, tokens, and credentials.
4. Network and Infrastructure Security
(a) firewalls and network controls where applicable;
(b) patch management;
(c) vulnerability monitoring;
(d) secure hosting environments;
(e) environment separation where feasible.
5. Application Security
(a) code review where appropriate;
(b) dependency management;
(c) vulnerability remediation;
(d) secure development practices;
(e) testing before material production changes where feasible.
6. Data Management
(a) client data segregation;
(b) data minimization;
(c) retention controls;
(d) backup procedures;
(e) deletion and offboarding workflows;
(f) pseudonymization, masking, or minimization where appropriate and feasible.
7. Monitoring and Incident Response
(a) centralized logging where feasible;
(b) access, API, workflow, and error logs;
(c) incident response procedures;
(d) investigation and containment processes;
(e) notification workflows.
8. Business Continuity
(a) backup and recovery measures;
(b) disaster recovery procedures appropriate to the Services;
(c) continuity planning for critical operational services.
9. Vendor Management
(a) vendor and Sub-Processor due diligence;
(b) contractual safeguards;
(c) periodic reassessment where appropriate;
(d) transfer safeguards where required.
10. Client-Specific Options
Where commercially available and agreed in writing, NoFurther may provide additional client-specific security options, including IP allowlisting, custom audit reports, masking, data loss prevention controls, custom retention settings, or enhanced access controls.
11. Privacy by Design
NoFurther shall use reasonable efforts to apply privacy by design and by default principles, including data minimization, segregation, access limitation, and appropriate retention controls.
ANNEX III — SUB-PROCESSORS
NoFurther may use Sub-Processors to provide hosting, storage, infrastructure, CRM, messaging, email, analytics, payments, AI processing, advertising, scheduling, automation, monitoring, support, collaboration, and security services.
The categories of Sub-Processors may include:
(a) cloud hosting and infrastructure providers;
(b) database, storage, logging, and monitoring providers;
(c) CRM and marketing automation providers;
(d) messaging, email, SMS, WhatsApp, and telephony providers;
(e) payment processors handling payment metadata only;
(f) advertising, analytics, attribution, and tracking providers;
(g) calendar, video, meeting, and call-recording providers;
(h) AI model, AI infrastructure, and automation providers;
(i) customer support, ticketing, documentation, and collaboration providers;
(j) security, authentication, backup, and incident-response providers.
Potential Sub-Processors or service categories may include, depending on the Services:
(a) hosting: AWS, Google Cloud Platform, Microsoft Azure, Supabase, or similar infrastructure providers;
(b) CRM and marketing automation: GoHighLevel / LeadConnector or similar providers;
(c) messaging: Twilio, WhatsApp Business providers, email providers, SMS providers, or similar providers;
(d) payments: Stripe or similar providers, limited to payment metadata and non-PCI data where applicable;
(e) advertising platforms: Meta, Google, LinkedIn, TikTok, X, or similar platforms;
(f) analytics and video: Google Analytics, Wistia, Vimeo, or similar providers;
(g) collaboration and productivity: Google Workspace, Slack, Notion, or similar providers;
(h) AI and automation: OpenAI, Anthropic, Google, automation providers, or similar providers.
NoFurther shall maintain an internal Sub-Processor registry identifying the provider, service category, processing location where known, and applicable safeguards. The registry shall be made available upon written request where required by Applicable Data Protection Law or the Agreement, subject to confidentiality, security, and commercial sensitivity limitations.
ANNEX IV — ACCESS TO CLIENT SYSTEMS
The Client may grant NoFurther access to Client Systems through partner access, agency access, OAuth, SSO, API keys, private integrations, service accounts, user accounts, webhook connections, or shared credentials.
NoFurther shall:
(a) access Client Systems only as necessary to provide the Services;
(b) use commercially reasonable efforts to apply least-privilege access;
(c) avoid altering billing, ownership, or account ownership settings unless expressly instructed;
(d) avoid exporting full datasets unless necessary for the Services or expressly authorized;
(e) log or annotate significant account changes where feasible;
(f) use staging environments for website updates where available and appropriate;
(g) maintain backups or rollback options where feasible before material website or system changes;
(h) delete, return, or disable credentials at the end of the engagement where technically feasible and no longer required.
The Client remains responsible for revoking NoFurther’s access from Client Systems where the Client controls the relevant access mechanism and for ensuring that Client-side users are removed when no longer authorized.
ANNEX V — STANDARD CONTRACTUAL CLAUSES
Where applicable, the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply by incorporation to Restricted Transfers of Client Personal Data.
1. Modules
The following modules apply where relevant:
(a) Module 2: Controller to Processor;
(b) Module 3: Processor to Processor.
2. Clause 9
For Clause 9(a), the Parties select general authorization for Sub-Processors, subject to 10 Business Days’ notice as described in this DPA.
3. Clause 17
For Clause 17, the governing law shall be the law of France, unless another eligible governing law is required for the applicable transfer.
4. Clause 18
For Clause 18, the competent courts shall be the courts of Paris, France, unless another forum is required for the applicable transfer.
5. Annexes
Annexes I, II, and III of this DPA complete the corresponding appendices to the Standard Contractual Clauses.
6. UK and Swiss Addenda
Where relevant, the UK International Data Transfer Addendum and Swiss-specific adaptations apply to Restricted Transfers governed by UK or Swiss data protection law.
EXECUTION
This DPA becomes binding upon:
(a) the Client’s signature or acceptance of the Agreement; and
(b) the Client’s initial payment to NoFurther Systems SAS.
By signing or accepting the Agreement, the Client agrees to this DPA and authorizes NoFurther to process Client Personal Data as described herein.